Sightglass What it doesPricingField notes Start a trial

Privacy Policy

Last updated 5 September 2026. Sightglass is a product of Crowdstake. Questions, or any request under this policy: privacy@sightglass.vip.

Changes

2026-09-05 additions and amendments — pending counsel re-review. The 2026-09-03 version was reviewed by counsel. This update adds Placement Announcement Ads, Meta permissions and regulatory retention; Slack scopes, token storage and delivery controls; Apollo.io data flows and opt-in controls; the self-serve trial; and customer data isolation. The affected sections below are marked pending counsel re-review.

Sightglass reads a beverage-alcohol supplier's own distributor depletion reports and tells their sales reps which accounts are slipping, which are winning, and who to contact. This policy describes exactly what that involves: what we hold, where it sits, who else sees it, and how long we keep it. It is written from the actual system rather than from a template, and it names the things we do not yet do as plainly as the things we do.

Who is who

Two different relationships matter throughout this policy:

  • Our customer — the supplier or importer that buys Sightglass. Their staff sign in and use the product. For their data we are the processor: we hold it on their behalf and act on their instructions.
  • Their trade contacts — buyers, owners and managers at the retail accounts and distributors our customer sells to. Sightglass holds information about these people even though they have no relationship with us. We describe that squarely in Information about people who are not our customers, because it is the most sensitive thing the product does.

What we collect

When you sign up

Your company name, your work email address, the plan you chose, and a workspace name we derive from your company name. We never see your card: payment details are entered on Stripe's own hosted checkout page and never reach our servers — there is no card field anywhere in Sightglass, and no card data, not even the last four digits, appears in anything we store.

Pending counsel re-review — 2026-09-05. We also record the version of the Terms and this policy accepted at signup, who accepted it, and the acceptance time. The self-serve trial is a 14-day trial. Stripe saves the card; it is not charged until day 15. You can cancel at any time through the billing portal. Cancel before the trial ends to avoid the first charge. Once cancellation takes effect, access is suspended; data follows the retention rules below, rather than being erased automatically.

Your sales data

You give Sightglass your distributor depletion and account reports — typically VIP iDIG exports. Depending on which reports you supply, these contain:

  • Retail account names, street addresses, city, state, ZIP, phone numbers and distributor outlet IDs
  • Distributor and wholesaler names and codes
  • Your SKUs and supplier/brand names
  • Monthly case-equivalent volumes. These exports carry no order-level dates — the finest grain is a calendar month, and any "last ordered" date you see in the product is an approximation we derive from it

Your team

Names, work email addresses and a short alias for each rep; which accounts each rep covers; and a record of what they did in the product — which briefing cards they were shown, and which they approved, sent or skipped. This activity log is append-only by design: it is the audit trail of what outreach was authorised, and we do not edit it.

Emails Sightglass drafts

Where you use outreach, we store the drafted message — recipient address, subject and body — so a rep can review and edit it before it goes. A draft is only ever sent after a person approves it.

Drafts are written inside your own workspace, from your own data: the account, the SKU, the volumes and the dates already in your reports. No third-party model provider is involved and none of your data leaves your workspace to produce a draft. If that ever changes we will name the provider in the table below and email your workspace admin before it takes effect.

Connected accounts

If you connect Slack or Meta, the relevant permissions and stored data are described below. If a rep connects their mailbox, we store the OAuth refresh token that lets us send as them, plus their mailbox address. See Connected mailboxes.

Placement Announcement Ads and Meta

Pending counsel re-review — 2026-09-05. When you enable Placement Announcement Ads, you direct Sightglass to create and manage campaigns on your own Meta ad account. The purpose is informing the public where a product may be purchased. Activation depends on the required Meta access being available and approval of the current proposal. Human creative inspection is required for the current image.

We hold the supplier identity and permit details you provide, ad account and Page identifiers, placement events, proposal revisions, creative assets and their identifying hashes, compliance findings, inspection records, approvals, payor attestations and spend ledgers. These records identify who reviewed or attested and when. When campaigns run, performance records include spend, impressions, reach and clicks.

Meta receives the creative, approved copy, selected Page, destination, delivery geography, audience settings, budget and flight dates needed to run the campaign. The connection uses Facebook Login for Business and requests ads_management, pages_show_list and pages_manage_ads to manage campaigns, list selectable Pages and create Page-associated ads. Connection tokens are stored encrypted at rest and deleted locally on disconnect.

The customer is the sole payor and attests that retailers contribute nothing. The ban on off-platform reimbursement or reciprocal arrangements is a contractual obligation, supported by periodic manual review. Sightglass cannot verify off-platform arrangements or beneficial ownership of the payment instrument from Meta's account data. We retain the declaration as evidence, not as proof that those arrangements are technically impossible.

Meta's terms and privacy policy govern Meta's handling of data. Our own retention obligations are set out below.

Slack permissions and delivery

Pending counsel re-review — 2026-09-05. Slack OAuth requests chat:write to post briefings, im:write to open direct messages, users:read to identify workspace members, and users:read.email to match their email addresses to reps. We store the workspace ID, bot token encrypted at rest, member IDs and emails, rep matches, and direct-message channel IDs in your isolated database.

Connecting Slack does not enable posting. Briefings are delivered by DM only after your company enables delivery, on the configured days and subject to any recipient allowlist. The message can contain account names, sales context, suggested actions and outreach drafts. Where Slack is connected or delivery is configured, we retain rendered briefings and delivery outcomes, including held records when nothing was posted. These permissions do not grant access to read channel or message history.

Disconnecting in Sightglass deletes local tokens and member mappings. Previously posted messages remain subject to your Slack workspace's retention settings and Slack's own terms. Local disconnect does not delete Slack's copies.

Information about people who are not our customers

This section matters more than the rest, so it is not buried. Sightglass holds contact details for individuals at the retail accounts and distributors our customers sell to. Those people did not sign up for Sightglass and may not know it exists.

For an account or distributor, we may hold a contact's name, work email address, phone number, business website and public social handles. This comes from two places: it may already be present in the reports our customer uploads, or — where a contact is missing and you have enabled enrichment — we may look it up through Apollo.io, as described below.

We use this solely to let our customer's sales rep contact a business they already sell to or want to sell to. We do not sell it, we do not build a profile beyond what is described here, and we do not use it to train any model.

If you are one of these contacts and you want your information removed, email privacy@sightglass.vip. We will remove it from the customer workspaces we control and tell you which of our customers held it, so you can take it up with them directly. Pending counsel re-review — retention exception, 2026-09-05: if information must remain in regulatory evidence or under a litigation hold, we retain it only for that purpose and explain the exception.

Contact enrichment through Apollo.io

Pending counsel re-review — 2026-09-05. Apollo.io is a sub-processor for optional contact enrichment. It is off by default and enabled per customer. An API key alone does not turn it on.

For a lookup, the connector sends the account name and address information in the form of city and state. Organisation lookups send the website/domain when available. To reveal a selected contact's details, it sends that person's name and the organisation domain returned by Apollo. Results may include a business contact's name, phone, email, website and public social handles; unavailable fields stay empty. Apollo may return a personal email address associated with the business contact. Organisation lookups can also return industry, employee count and business keywords.

We fill missing contact fields rather than overwrite details already on file. Configured credit caps limit contact-reveal attempts per run and repeated account lookups are cached within that run. Apollo determines the credits it charges. Apollo's privacy policy and terms apply to its processing. You may also contact Apollo directly about information it holds.

Where your data lives

Pending counsel re-review — isolation clarification, 2026-09-05. Every customer's sales data, contacts and placement records live in their own isolated instance and database, with their own storage volume. This customer data is never pooled with another customer's data. Regulatory evidence retained after deletion must also remain separate for each customer. Everything runs on Google Cloud in the United States.

Traffic to and from Sightglass is encrypted in transit (TLS). On disk, we rely on Google Cloud's default encryption of the underlying storage. At the application layer we additionally encrypt stored integration tokens, including Slack bot tokens and mailbox refresh tokens, with a key unique to that customer and held outside the storage volume. Uploaded source reports rely on the underlying disk-level encryption.

Who else sees it

We do not sell data. Optional Placement Announcement Ads are campaigns you direct on your own ad account. We use these providers to run the service:

ProviderWhat it doesWhat reaches it
StripePayments Your company name, work email, plan and workspace name. Your card details go directly to Stripe and never pass through us.
WorkOSSign-in Sign-in happens on WorkOS's hosted page. Your company name, workspace name, admin email and email domain, plus each rep's email address and name at sign-in.
SlackDelivering briefings, after you enable delivery The briefing content — account names and the suggested action — sent as a direct message to each rep, plus the rep's Slack user ID and email for mapping.
MicrosoftSending as a rep, if they connect Outlook The complete approved email — recipient address, subject and body. Microsoft delivers it and keeps a copy in the rep's own Sent Items.
Apollo.ioContact enrichment, if you enable it Account name, city/state, website/domain where available, and the selected contact's name for matching. See Apollo data flows.
MetaPlacement Announcement Ads, if you enable them Ad account and Page identifiers, approved creative and copy, destination, targeting, budget and flight dates. See Meta data flows.
Google CloudHosting Everything, as the underlying infrastructure. Google does not access it.
ResendSending briefing emails from Sightglass to your reps The rep's email address and the briefing content.

We will also disclose data if the law requires it, and we would tell you unless we were legally prevented from doing so.

Connected mailboxes

A rep can connect their own work mailbox so approved emails come from them rather than from us. This is optional, per rep, and reversible.

Microsoft 365. We request only permission to send mail as the signed-in rep and to read their basic profile. This is limited to that rep's own mailbox — it gives us no access to anyone else's mail, and no ability to read the rep's inbox. We call exactly one Microsoft operation: send a message.

Google Workspace / Gmail. The Gmail sender requests only the gmail.send scope. It permits sending and nothing else: we cannot read, search, or list the rep's mail, and we cannot create or read drafts. We deliberately do not request the broader Gmail scopes. It is not yet available to customers. Google classifies gmail.send as sensitive, our OAuth verification is not complete, and until it is we hold no Google credential for anyone — a rep on Google Workspace copies an approved draft out of the dashboard and sends it from their own mail client. The disclosure below states how we treat Google user data for whenever that scope is in use.

Limited Use. Sightglass's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalised AI or ML models, we do not sell it, and we do not transfer it except as needed to provide the feature the rep asked for, to comply with law, or in a merger where it stays subject to this policy.

A rep can disconnect at any time from their Sightglass settings, or revoke access in their Microsoft or Google account. Disconnecting deletes the stored token immediately.

How long we keep it

Pending counsel re-review — placement retention and cancellation amendments, 2026-09-05. Placement records have the following retention requirements:

Placement dataRetentionOn account deletion
Compliance evaluations, approvals, payor attestations and spend ledgers Seven years as regulatory evidence Retained; these records survive account deletion
Creative assetsUntil rights expiry or disconnect, whichever comes first Deleted
Placement events and performance dataThree years, then anonymised Anonymised earlier on a deletion request
Connection tokensUntil disconnectDeleted immediately
Meta campaign objectsDeletion at Meta 30 days after completion Deleted at Meta; our regulatory evidence is retained separately

These are retention obligations, not a claim of automatic enforcement. Placement data requires manual retention and deletion review, including preserving required regulatory evidence before deleting a workspace. Retained evidence is restricted to regulatory, audit and legal purposes. A litigation hold suspends deletion and anonymisation until the hold is released.

Plainly stated, because it is easy to be vague here:

  • Ordinary workspace data stays while your workspace is active. Outside the placement retention requirements above, Sightglass does not run an automatic deletion schedule. Your uploaded reports, the history derived from them, the drafts and the activity log are retained so that trends stay comparable year on year — which is the point of the product.
  • Cancelling suspends your workspace; it does not by itself erase it. We keep it so you can come back without losing your history.
  • We delete on request. Email privacy@sightglass.vip and we will delete your workspace and its data within 30 days, except for the regulatory evidence and litigation-hold exceptions above, and confirm what was deleted or retained. That means the running instance, its storage volume, its sign-in organisation and its record with us — not a status flag on data we still hold.
  • One final copy, then it goes too. Immediately before erasing a workspace we take a single export of it, so that we can hand you your data and so a deletion made in error is not irreversible. It is held off the running service and purged no later than 30 days after the deletion. Ask us and we will destroy it as soon as you have your copy. This ordinary export window does not shorten the separate seven-year regulatory retention requirement.
  • Backups lag. Encrypted infrastructure backups roll on a 14-day retention, so a copy of deleted data can persist in them for up to 14 further days before it rolls off. We do not restore deleted data from them.
  • An abandoned signup — a form filled in but never paid for — is discarded automatically within the hour.

Your rights

Whoever you are and wherever you live, you can ask us to show you what we hold about you, correct it, delete it, or send you a copy in a portable format. Email privacy@sightglass.vip. We answer within 30 days and we do not charge for it.

Pending counsel re-review — retention exception, 2026-09-05. Deletion rights are subject to the regulatory evidence periods and litigation holds above. We will explain any information that must be retained and restrict it to those purposes.

If you are an employee of one of our customers, we will usually direct your request to your employer, since the data is theirs — but we will help them action it, and we will never use "ask your employer" to avoid a deletion request from someone whose data we hold as a trade contact.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California law.

Security

Each customer runs in an isolated container with its own storage. Sign-in is handled by WorkOS rather than by passwords we store — we never hold a customer password. Mailbox and Slack tokens are encrypted with a per-customer key kept outside the data volume. Access to production is limited to Crowdstake staff who need it.

No system is perfectly secure. If we discover a breach affecting your data we will tell you promptly and tell you what we know, including what we do not yet know.

International transfers

Sightglass runs in the United States. If you use it from elsewhere, your data is transferred to and processed in the US.

Children

Sightglass is a business tool for the licensed beverage-alcohol trade. It is not for anyone under 21 and we do not knowingly collect data from children.

Policy updates

If we change this policy in a way that materially affects you, we will email the workspace admin before it takes effect. The date at the top always reflects the current version.

Contact

Crowdstake · privacy@sightglass.vip

Sightglassa Crowdstake productPrivacyTermsField notesBuilt for the three-tier trade · 21+