Privacy Policy

Last Updated: September 16, 2026

Introduction

Reachkit (“Reachkit,” “we,” “our,” or “us”) provides B2B cold email outreach software. Our platform lets businesses connect their own email inboxes, build and send outreach campaigns, warm up inboxes, verify addresses, find leads, and manage replies in a unified inbox. This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have.

We handle personal information in two distinct roles:

  • As a controller — for information about our own users, prospects, and website visitors (your account details, billing, and how you use Reachkit). This policy is primarily about that information.
  • As a processor — for the contact data our customers upload or generate to run their own campaigns (their recipient lists, the messages they send, and the replies they receive). We process that data on our customers’ instructions to provide the Service. If you received an outreach email sent through Reachkit and want your data handled or removed, the sender is the controller of that data — contact them directly, or contact us at privacy@reachkit.ai and we will route your request to the relevant customer and honor any suppression request.

California Notice at Collection: See “California Privacy Rights” below for information about your rights under California law.

Personal Information We Collect

Information You Provide to Us

  • Account data, such as your name, email address, password, company name, and professional title.
  • Billing data, such as billing address and the information needed to process your subscription. Payment card details are collected and processed directly by our payment processor (Stripe); we do not store your full card number.
  • Connected inbox data, such as the credentials and access tokens you provide when you connect an email account (for example via Google/Microsoft OAuth or IMAP/SMTP), which we use to send and receive email on your behalf through the Service.
  • Domain and inbox provisioning data, such as the domain names, sender names and business details needed to register domains and set up email inboxes on your behalf when you purchase them through us.
  • Content you create in the Service, such as campaigns, sequences, settings, and preferences.
  • Communications data, such as messages you send us through support or other channels.
  • Job application data, such as the details and any video you submit when applying for a role with us, which we may transcribe using a service provider.

Information We Collect Automatically

  • Device and usage data, such as IP address, browser and operating system type, coarse location inferred from IP address (by us or our analytics providers), pages and features used, and access times.
  • Cookies and similar technologies on our website, used to keep you signed in, remember preferences, measure our advertising, and understand site usage. You can manage cookies through your browser settings.

Information from Third-Party Sources

  • Lead and enrichment providers, which supply business contact and company information used in our lead-finding features.
  • Advertising and analytics platforms, which provide aggregate measurement of our ads and website.
  • Our customers, when they invite you to a workspace or provide your business contact information.

How We Use Your Personal Information

  • Provide and operate the Service — create and maintain your account, connect your inboxes, deliver features, process transactions, and provide support.
  • Secure the Service — authenticate users, send security codes, and prevent fraud and abuse.
  • Communicate with you — send service and transactional messages, and, where permitted, marketing communications you can opt out of.
  • Improve the Service — analyze usage, debug, and develop new features, including through aggregated or de-identified data.
  • Advertise our own Service — measure ad performance and reach existing and similar audiences (see “How We Share”).
  • Comply with law — meet legal obligations and enforce our terms.

How We Share Your Personal Information

We are not a data broker. Except for the advertising activity described below (which some privacy laws classify as a “sale” or “share”), we do not sell your personal information. We share personal information only as described here:

  • Service providers / processors — companies that host, secure, and operate the Service on our behalf. These include cloud hosting, our payment processor (Stripe), product analytics, internal alerting and team communication tools that receive operational notifications (for example a new signup or a billing event), bot-protection and anti-fraud providers, email-delivery and email-verification providers, and AI/LLM providers we use to generate and process content within the Service. They may use the data only to provide services to us.
  • Integrations you enable — if you connect a third-party service such as a CRM, we send the relevant contact and activity data to that service at your direction to keep it in sync. These integrations are optional and controlled by you.
  • Domain registrars and mailbox providers — when you purchase domains or inboxes through us, we may share the details needed to register the domains and create the inboxes on your behalf.
  • Advertising platforms (custom-audience uploads) — to advertise our own Service, we may upload a limited identifier (a hashed email address) to advertising platforms so we can show or suppress ads to existing users, build similar (“lookalike”) audiences, and measure conversions from our ads. Under some privacy laws this is considered a “sale” or “share” for cross-context behavioral advertising, and you can opt out (see “Your Choices” and “California Privacy Rights”). We do not use the contact data our customers process through the Service for this purpose.
  • Warmup network participants — if you use our email warmup feature, your warmup emails are exchanged with other inboxes in the network to build sender reputation, which involves other participants’ systems receiving and interacting with those messages. Warmup is separate from your outreach campaigns.
  • Professional advisors — lawyers, auditors, and insurers, where needed.
  • Authorities — law enforcement or regulators where we believe in good faith it is required by law or necessary to protect rights, safety, or the Service.
  • Business transfers — a party to a merger, acquisition, financing, or sale of assets, in which case personal information may transfer as part of the transaction.

Your Choices

  • Marketing emails — opt out via the unsubscribe link in any marketing email, or by contacting us. You may still receive service and transactional messages.
  • Advertising opt-out — email privacy@reachkit.ai to opt out of custom-audience sharing, and use the Global Privacy Control (GPC) signal, which we honor as an opt-out of “sale”/“sharing.”
  • Cookies — manage or delete cookies through your browser settings.
  • Account data — review and update your account information by signing in.

Data Retention

We keep personal information for as long as your account is active and as needed to provide the Service, then for a limited period as required to comply with legal obligations, resolve disputes, and enforce our agreements. Customer campaign data is retained per our agreement with the customer and deleted on their instruction or after account closure.

Security

We use appropriate technical, organizational, and physical safeguards to protect personal information. Our Security page describes these safeguards in detail. No system is completely secure, and you are responsible for keeping your account credentials confidential.

International Data Transfers

We are based in the United States and use service providers in other countries. Your personal information may be transferred to and processed in the United States or elsewhere. Where we transfer personal information out of Europe, we rely on appropriate safeguards such as the European Commission’s standard contractual clauses. See “Notice to European Users.”

Children’s Privacy

The Service is for business use and is not intended for anyone under 18. We do not knowingly collect personal information from children under 18.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service. Your continued use of the Service after the effective date indicates acceptance of the changes.

California Privacy Rights

This section applies to California residents under the California Consumer Privacy Act (“CCPA”).

Your Rights

  • Right to Know / Access the categories and specific pieces of personal information we collect, our sources, purposes, and the categories of third parties we share it with.
  • Right to Delete personal information we collected from you, subject to exceptions.
  • Right to Correct inaccurate personal information.
  • Right to Opt-Out of the “sale” or “sharing” of your personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination for exercising your rights.

Categories We Collect and Share

In the past 12 months we have collected: identifiers (name, email, IP address), commercial information (subscription and transaction history), internet/network activity (site and product usage), and professional information (job title, company).

We disclose these categories to service providers for business purposes. We “share” (and, under the CCPA’s broad definition, may “sell”) one identifier — a hashed email — with advertising platforms for cross-context behavioral advertising to promote our own Service, as described in “How We Share.” Apart from that activity, we do not sell personal information, and we do not “sell” or “share” the contact data our customers process through the Service.

Exercising Your Rights

Submit a request by email to privacy@reachkit.ai or by phone at +1 (415) 212-9062. We will verify your identity before responding. You may use an authorized agent with proper permission. To opt out of “sale”/“sharing,” email us or send a Global Privacy Control (GPC) signal.

Notice to European Users

This section applies to individuals in the European Economic Area, United Kingdom, and Switzerland.

Controller and Processor Roles

Reachkit is the controller for personal information about our users, prospects, and website visitors. For the contact data our customers upload or generate to run campaigns, our customer is the controller and Reachkit acts as a processor on their instructions.

Legal Bases for Processing

  • Performance of a contract — to provide the Service you signed up for.
  • Legitimate interests — to secure, operate, improve, and market our own Service, balanced against your rights.
  • Consent — where required, for example certain cookies and marketing.
  • Legal obligation — to comply with applicable law.

Your Rights

You have rights to access, correct, delete, restrict, and port your personal information, and to object to processing (including direct marketing). Where we rely on consent, you may withdraw it at any time. Contact privacy@reachkit.ai to exercise these rights. You may also lodge a complaint with your local supervisory authority.

International Transfers

When we transfer personal information out of Europe, we rely on appropriate safeguards such as adequacy decisions or the European Commission’s standard contractual clauses.

Contact Us

  • Email: privacy@reachkit.ai
  • Address: 2041 East St PMB 1563, Concord, California, 94520, United States
  • Phone: +1 (415) 212-9062
Book a Call
Quinten - Founder
Want to see Reachkit in action?
Book a demo with the founder