Privacy Policy

Last updated: August 13, 2026

Bu sayfanın Türkçe sürümü (KVKK aydınlatma metni dahil) için Gizlilik Politikası'na bakın.

This policy explains how Jaunty House ("the Platform") collects, uses, stores, and shares personal data. The Platform is a B2B sales-outreach service for small and medium-sized exporters: it retrieves business contact (lead) data for potential buyer companies from verified B2B data sources, drafts a personalized introduction email for each contact with AI, and sends the messages the user has reviewed and approved from the user's own Gmail or Outlook account connected via OAuth. Each message is addressed to a single business recipient and carries an unsubscribe link; a reply, a bounce, or an unsubscribe stops all further sending to that address automatically.

1. Data controller and contact

Jaunty House is the data controller for the personal data described in this policy. For any question or request, contact us at info@jauntyhouse.com.

2. Personal data we process

  • Account and profile data: email address, name, company name, product/sector details (HS codes), and target country preferences.
  • Mailbox connection data: when you connect your Gmail or Outlook account, the OAuth access and refresh tokens we receive and the connected email address. Your password is never shared with us; tokens are stored encrypted with AES-256-GCM.
  • Campaign content: the email templates and sequences you create, and the content and status records of sent emails (sent, opened, replied, bounced).
  • Recipient (lead) data: name, job title, business email address, company, and country details retrieved from third-party B2B data sources (Apollo, Hunter) for your campaigns.
  • Payment and subscription data: plan, subscription status, and billing period. Payments are processed by iyzico; your card details are never stored on Jaunty House servers.
  • Usage and log data: session information, usage counters, and error logs.
  • Cookies: only strictly necessary session cookies are used; no third-party advertising or tracking cookies.

3. Google and Microsoft account data (Limited Use)

When you connect your Gmail account, the Platform requests two restricted Gmail scopes: gmail.send (to send the emails you have approved, on your behalf) and gmail.readonly (to detect replies and delivery-failure "bounce" notices for the campaigns you sent, so that the remaining steps of a sequence stop automatically). Alongside them we request the non-sensitive openid and email scopes, which only tell us which mailbox you connected. No other Google scope is requested. For Outlook connections the equivalent Microsoft Graph scopes are used: Mail.Send, Mail.Read, User.Read, plus openid, email and offline_access.

Here is how Jaunty House accesses, uses, stores, and shares Google user data:

  • Access and use: your Gmail data is processed only to provide user-facing features you initiate — sending the campaign emails you approved and detecting replies and bounces to stop sequences automatically. For that detection we poll the Gmail History API for new messages in the connected mailbox and read only their metadata (sender, subject, thread identifier, timestamp) together with the short preview snippet Gmail returns, which is what lets us match a delivery-failure notice to the recipient it concerns. We do not scan, profile, or analyze the contents of your mailbox, and we never use your data for advertising.
  • Storage: OAuth tokens are encrypted at rest with AES-256-GCM. We never request or store message bodies. Of the data read for reply and bounce detection we keep only what updates campaign status — the reply or bounce timestamp and the thread identifier of the affected message; the preview snippet is evaluated in memory and discarded.
  • Sharing: we do not sell or transfer your Google user data to any third party, and we do not use it to develop or train artificial intelligence or machine learning models, including generalized AI/ML models.
  • Human access: no human reads your Google user data, except with your explicit permission, when necessary for security purposes, or to comply with applicable law.
  • Revoking access: you can disconnect your account at any time from the Platform's mailbox settings or from your Google/Microsoft account security settings. For Gmail, disconnecting also revokes the grant at Google, so Jaunty House disappears from your Google account's third-party access list. Microsoft provides no equivalent per-application revocation API: we delete the stored Outlook tokens immediately, and you can remove the app itself from your Microsoft account app permissions page (work or school accounts: My Apps).

Jaunty House's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Purposes and legal bases

We process personal data on the following legal bases (under the Turkish Personal Data Protection Law No. 6698, "KVKK", and equivalent principles):

  • Performance of a contract: account creation, campaign management, email sending, reply tracking, subscription and payment processing.
  • Legitimate interest: service security, debugging, abuse prevention, and enforcement of sending limits.
  • Legal obligation: retention duties arising from financial and commercial regulations.
  • Consent: use of the service providers below that involve international data transfer, tied to your use of the related features.

5. Data sharing and international transfer

We share data with the following service providers only to the extent necessary to provide the service:

  • Supabase (EU region): database and authentication infrastructure — your data is hosted in the European Union.
  • Vercel (USA): web application hosting — your requests to the app are processed on Vercel's infrastructure.
  • Railway (USA): background sending worker — schedules and sends your campaign emails; during processing it decrypts your stored mailbox tokens and handles email sending and reply data.
  • Google LLC / Microsoft Corporation (USA): email sending, and reply and bounce detection, through your connected mailbox.
  • OpenAI (USA): email draft generation — only your company/product profile and the recipient's business context are sent to the model.
  • Apollo, Hunter (USA): B2B lead data sourcing and email verification.
  • iyzico (Türkiye): payment processing.

Your data is never sold or transferred to any other third party for marketing purposes.

6. Data retention

Your data is retained for as long as your account is active.

You can delete your account yourself at any time: in the dashboard, go to Settings › Account (/ayarlar/hesap) and confirm by typing your email address. Your account, profile, campaigns, lead lists, reports, suppression list and mailbox connections are then permanently deleted — not anonymized and not held for a grace period — and your stored mailbox tokens are erased. For Gmail, the grant is also revoked at Google (see section 3 for the Microsoft limitation).

The one exception is records we are legally required to keep: invoices and payment records are held by our payment provider and remain there for the applicable statutory period.

7. Data security

Your data is stored on access-controlled infrastructure; OAuth tokens are encrypted at rest with AES-256-GCM, all data is transmitted over TLS, and each user's data is accessible only within their own account.

8. Email recipients (leads)

The business contact details of people who receive emails through the Platform are processed on behalf of our users for B2B commercial communication. Every email includes an unsubscribe link; recipients who unsubscribe, reply, or whose emails bounce are automatically removed from further sending and added to a suppression list. If you received an email and want your data deleted, contact info@jauntyhouse.com.

9. Your rights

You may contact us to learn whether your personal data is processed, request information about it, learn the purpose of processing, know the third parties it is transferred to, request correction of incomplete or inaccurate data, request deletion, and object to results arising from purely automated processing. Requests sent to info@jauntyhouse.com are answered within 30 days at the latest. The full list of rights under KVKK Article 11 is available in the Turkish version of this policy.

10. Changes

This policy may be updated when needed. Material changes are announced on the Platform; the current version is always published on this page.

Privacy Policy — Jaunty House