Privacy notice
Effective September 24, 2026
This notice explains what personal information Chasing Shade ("we", "us") collects through shade.ly, the Chasing Shade CRM and partner platform our team uses, the presentation links we send, and the Chasing Shade API, and what we do with it. Questions or requests: legal@shade.ly.
What we collect
- Our team's accounts. Name, work email, role, a password hash or a Google sign-in identifier, and sign-in records (time, IP address, browser).
- Business contacts. For the companies we work with: contact names, business email addresses, job titles, company details, our notes, the documents we send and sign, and the emails and meetings we log.
- Presentation links. When you open a presentation we send you, you confirm your email address with a one-time code. We then record that email address, your IP address and browser, which sections you view and for how long, and whether you accepted the confidentiality terms. The page tells you this before you continue. If you share the link, we record who shared it with whom.
- The partner API. The API is designed not to receive personal information: partners refer to seats and subscribers by opaque references, and requests that contain personal information are rejected.
- The website. Our servers log IP addresses and browsers for security. The home page and the demo map load fonts from Google Fonts, which receives your IP address.
Google and Microsoft accounts our team connects
A member of our team can connect their own Google or Microsoft account to the CRM:
- Gmail (send only). With the
gmail.sendpermission we send, from that person's mailbox, the emails they send from the CRM (for example a presentation link). We never read, store, search or index their mailbox. - Google Calendar or Outlook Calendar. With the
calendar.events(Google) orCalendars.ReadWrite(Microsoft) permission we add the meetings they book in the CRM to their calendar, invite the contacts they choose, and remove the event if they cancel. We do not read their other events.
The access tokens are encrypted at rest and used only for these actions. A connection can be removed at any time from My account in the CRM, or from the Google or Microsoft account's security settings.
Chasing Shade's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google or Microsoft user data for advertising, do not sell it, do not use it to train AI models, and do not let people read it except with the user's permission, for security, or where the law requires.
How we use information
- To run our sales process and customer relationships, and to deliver the presentations, documents and emails involved.
- To operate, secure and improve the CRM, the partner platform and the API.
- To meet legal obligations.
We do not sell personal information and do not use it for advertising.
Who we share it with
Service providers that run parts of the service for us, under agreements that limit their use of the data:
- Hetzner (hosting, Finland) and Cloudflare (content delivery and protection).
- Google (Gmail delivery; Google Calendar when a team member connects it) and Microsoft (Outlook Calendar when a team member connects it).
- Google (Gemini API) and Anthropic (interpreting venue design documents our team uploads; these documents are not personal information).
We may also disclose information when the law requires it, or to protect our rights and users.
How long we keep it
- Presentation viewing records: deleted 12 months after a person's last activity (we keep anonymous totals).
- Email delivery records: 90 days.
- Sign-in sessions and one-time codes: until they expire.
- Business records (accounts, contacts, contracts): for as long as the business relationship and our legal obligations require.
Your choices and rights
You can ask us to access, correct or delete your personal information, or object to our use of it, by writing to legal@shade.ly. We can delete a person's presentation viewing records on request. Depending on where you live, you may also have the right to complain to a data protection authority.
Cookies
We use only the cookies needed to sign in and to keep a presentation open for you. We do not use advertising or third-party analytics cookies.
Security
Traffic is encrypted in transit (HTTPS). Access tokens and integration keys are encrypted at rest. Access to the CRM is limited to named team accounts.
Changes
We will post any change to this notice here with a new effective date.