Privacy

RepCloud privacy policy

RepCloud provides connected CRM, Workspace, Drive, Publisher, Account Center, desktop, and mobile services. Signed-in team members can access only the business information, files, and workflows their organization has enabled for them.

Effective September 7, 2026

Information RepCloud processes

Depending on workspace configuration and the features a user chooses, RepCloud may process account identity, workspace membership and role, customer and contact records, leads, products and pricing, orders and estimates, tasks and appointments, workspace mail metadata and content, files, field reports, return requests, asset records, support messages, device identifiers, push-notification preferences, and application diagnostics.

Photos, files, camera, contacts, microphone, and location

  • Photos and files are accessed only when a user selects, scans, captures, previews, or uploads an item for a RepCloud workflow.
  • Business-card recognition runs on the iPhone. The card image is not uploaded or retained by RepCloud; the user reviews extracted text before choosing whether to match or create a CRM record.
  • Contacts are accessed only when the user invokes a contact picker for a supported sharing workflow.
  • Microphone and speech recognition are used only when the user starts dictation.
  • Location is used while the app is in use for territory maps, directions, and user-initiated field-visit evidence. RepCloud Mobile does not present continuous employee tracking.

How information is used

Information is used to authenticate the user, enforce workspace and record permissions, provide requested CRM, Mail, Calendar, Drive, reporting, scanning, and sharing features, synchronize authorized work, deliver configured notifications, maintain audit history, prevent duplicate submissions, provide support, and protect service reliability and security.

Google user data and connected storage

When a user connects Google Drive, RepCloud uses the Google permissions shown during authorization only to provide the user-requested file workflow. Depending on the approved connection, this can include browsing, searching, previewing, downloading, or copying existing files from administrator-approved folders and creating a new edited copy in an approved destination. RepCloud does not use Google user data for advertising, unrelated profiling, or sale to third parties.

RepCloud's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Digital business cards

A user may publish a RepCloud-hosted card containing the name, company, photo, title, phone number, email address, website, and social links they choose to provide. The card can be disabled without changing its QR address. If the optional contact-exchange form is enabled, submitted information is matched to an existing authorized CRM record or stored as a lead owned by that representative.

Sharing and service providers

RepCloud does not sell personal information or use it for cross-app tracking. Information may be shared with the organization that controls the applicable workspace, authorized workspace users and connected services, infrastructure and delivery providers needed to operate RepCloud, or authorities when required by law or necessary to protect users and the service.

Data protection, storage, and retention

RepCloud protects browser, app, API, and provider traffic with HTTPS/TLS encryption in transit. OAuth access tokens, refresh tokens, and connector client secrets are encrypted at rest and kept in server-side credential custody; they are not exposed to customer-facing APIs or stored in browser code. Production systems require configured encryption keys, use restricted service accounts and file permissions, and apply tenant-scoped authorization and server-side role checks before protected records or files are returned.

Administrative and file operations are recorded through security and activity logs. RepCloud maintains operational monitoring, controlled backups, and recovery procedures. Access is limited to authorized service operation, support, security, and legal purposes.

Workspace data is retained according to the organization’s agreement, operational backup requirements, and legal obligations. Disconnecting a provider prevents future connector access and removes the stored active authorization from RepCloud. Users or workspace administrators may also revoke access with the provider. Verified access, export, correction, and deletion requests are processed subject to security, legal, and operational-integrity requirements. Signing out or removing a mobile workspace clears supported protected workspace caches from the device.

Choices and requests

Users can manage iPhone permissions in Settings, change notification preferences in RepCloud, disable a public Digital Card or its contact form, and sign out. Requests to access, correct, export, or delete workspace information should normally be sent to the organization that controls the workspace. Privacy and support questions may be sent to support@repcloud.app.