Privacy Policy
Here you can find how we collect, store, and use your personal data and other information you share with us, and how you can change or delete your information from Tamozo (hereinafter — «our Platform»).
Please read it carefully, because to use our services via our Platform you need to accept this Privacy Policy (by accepting the Terms & Conditions).
Who we are and how to contact us?
Tamozo (https://www.tamozo.com) is operated by GLOZO GLOBAL Inc. (hereinafter — our Company), which is the data controller and is responsible for personal data on our Platform. You can contact us by email: [email protected]
Why do we collect your personal data and how do we use it?
We collect and use your personal data in order to:
- provide, support, improve and develop more personalized services
- analyze your content for spam, malware and illegal content — to improve the safety of our services and protect the users
- measure performance — to understand how our services are used by our clients
- contact you directly — for example, we may let you know about upcoming changes or improvements to our services. If you contact us, we'll keep a record of your request to help solve any issues you might be facing.
Which information do we collect?
- your name and email address, from the Google account you sign in with
- company name
- billing details processed by our payment provider (we never see full card numbers)
- the search criteria you describe, the leads returned to you, and the outreach messages you compose on our Platform
- session statistics and product usage events
- approximate geolocation
- browser and device information
- advertisement source
- conversion date and conversion page
How do we collect your personal data?
We use various technologies to collect and store information, including cookies, pixel tags, and local storage, such as browser web storage or application data caches, databases, and server logs.
Tracking technologies and third-party processors
We work with the following service providers (sub-processors). Each is bound by a data processing agreement and processes data only for the purposes described below.
- PostHog (PostHog Inc., United States) — product analytics and session replay, served through our own domain. We use the US cloud. Default retention: 12 months for events, 1 month for session recordings. Session recordings capture page content and text you type, so that we can see where the product is confusing. Password fields are excluded from recording. If you would rather not be recorded, email us and we will exclude your account.
- Google LLC (United States) — sign-in only. See the Google User Data section below for exactly what we receive.
- Unipile (Unipile SAS, France) — the provider through which you connect your own mailbox or LinkedIn account and through which outreach messages are sent and replies are read. You authorize Unipile directly; mailbox credentials are never sent to or stored by us.
- Stripe (Stripe, Inc., United States) — subscription billing and payment processing. Stripe collects your payment details on its own infrastructure and shares only the identifiers and status we need to run your subscription.
- Google Cloud Platform (Google LLC, United States) — hosting and managed database. Our application and its data run in the United States.
We do not run advertising trackers, and we do not currently operate a cookie consent banner because we do not set advertising or profiling cookies. If your browser sends the Global Privacy Control (GPC) signal, or you email us directly, we treat it as a request to opt out of analytics and of any sale or sharing of personal information as those terms are defined under California law.
Lawful basis for processing (where applicable)
Depending on where you visit from, the lawful basis we rely on differs:
- European Economic Area, United Kingdom, Switzerland, Brazil, Quebec: we rely on your consent (GDPR Art. 6(1)(a) and equivalents) for statistics and marketing processing. You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- United States and other regions without an opt-in cookie regime: we rely on our legitimate interest in measuring and improving the product, and provide a clear opt-out mechanism (a request by email, and respect for GPC).
- Your account, your subscription and support responses: we rely on contract / pre-contract necessity — we need this data to give you the service you signed up for and to reply to the request you sent us.
Your privacy rights — California and other US states
If you reside in California, Virginia, Colorado, Connecticut, Utah, or another US state with applicable consumer privacy law, you have the following rights regarding personal information we collect about you:
- Right to know. You can request a description of the categories of personal information we collect about you, the sources, purposes, and any third parties with whom we share it.
- Right to access / portability. You can request a copy of the specific pieces of personal information we hold about you.
- Right to delete. You can request that we delete personal information we collected from you, subject to legal-retention exceptions.
- Right to correct. You can request correction of inaccurate personal information.
- Right to opt out of "sale" or "sharing" (for cross-context behavioral advertising). We do not sell or share personal information for cross-context behavioral advertising, and we run no advertising trackers. You can still send us an opt-out request, or configure your browser to send the Global Privacy Control signal.
- Right to non-discrimination. We will not deny services, charge different prices, or provide a different level of service because you exercised any of these rights.
To exercise any of these rights, email [email protected]. We will respond within the timeframe required by applicable law (typically 45 days under CCPA). We may need to verify your identity before fulfilling the request.
Google User Data
How we use Google services
We use Google Sign-In so that you can create and access your Tamozo account without a separate password. That is the only Google integration we operate. We do not request access to your Gmail mailbox, your contacts, your calendar, your Drive, or any other Google service.
Google data we access and why
Google Sign-In (authentication)
- Scopes we request:
openid,email,profile— and no others. - What we access: your Google account identifier, email address, and name.
- Why we need it: to create and authenticate your account on our Platform.
- How we use it: solely for authentication and to personalize your experience. Your email address also identifies your workspace for billing and support.
Your mailbox is connected through Unipile, not through us
Tamozo can send outreach email and LinkedIn messages from your own account, and can read the replies to the threads it started. That connection is made through Unipile's hosted authorization page, where you authorize Unipile directly. In practice this means:
- We never receive, request, or store your mailbox password, or a Google OAuth token granting mailbox access.
- We can only send messages you have composed or approved on our Platform, and only from an account you connected yourself.
- We read replies only on conversation threads that started from our Platform. We do not read, access, or store the rest of your inbox.
- We do not modify, delete, or move your messages.
- You can disconnect the account at any time from your Tamozo settings, which revokes our ability to send or read on your behalf.
How we store Google data
- Sign-in data: we store your Google account identifier, email address, and name for as long as your account is active. We use short-lived authorization codes and do not retain a long-lived Google refresh token.
- Session: your signed-in state is held in a signed cookie on your browser, not in Google's systems.
- Message content and metadata: we store the outreach messages you compose, the timestamp and recipient of what was sent, and the content and sender of replies to those threads, so that we can show you the conversation and its status.
- What we don't store: messages in your mailbox that are unrelated to outreach started on our Platform.
How we protect Google data
- All data is encrypted in transit and at rest using industry-standard encryption
- Access to user data is restricted to authorized personnel only and protected by strict access controls
- We use industry-standard security practices including SSL/TLS encryption, secure cloud infrastructure, encrypted databases, and regular security review
- All traffic between our servers and Google APIs is encrypted
- We implement secure coding practices and regular security updates to protect against vulnerabilities
- We do not share your Google data with third parties except as described in this policy
How we share Google data
We do not sell, rent, or share your Google user data with third parties for their marketing purposes. We only share your information in the following limited circumstances:
- With your explicit consent
- With service providers who help us operate our Platform (Google Cloud Platform for hosting and databases, Stripe for billing, Unipile for message delivery) under strict confidentiality agreements and data processing agreements that limit their use of your data
- When required by law to comply with legal obligations, court orders, governmental requests, or to protect our rights and safety
We do not allow any third parties to use your Google user data for their own purposes.
Your control over Google data
You can revoke our access to your Google account at any time by:
- Visiting your Google Account Permissions page
- Removing Tamozo from the list of connected apps
- Contacting us at [email protected] to request data deletion
When you revoke access or delete your account:
- We will immediately stop using your Google sign-in data
- We will delete your sign-in profile data within 30 days
- We will delete or anonymize associated outreach data within 30 days, except where we are required to retain it for legal, security, or financial record-keeping purposes
- You can request immediate deletion of all your data by contacting us at [email protected]
Compliance with Google API Services User Data Policy
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We commit to the following:
- Limited Use: we only use Google user data for the purpose explicitly described in this privacy policy — authenticating you and identifying your account
- No Ads: we do not use Google user data for serving advertisements
- No Third-Party Transfer: we do not transfer Google user data to third parties except as necessary to provide our core services (for example, cloud hosting), for security purposes, or as required by law
- Human Access: we do not allow humans to read your Google user data unless we have your explicit permission for support purposes, it is necessary for security purposes (for example, investigating abuse), or it is required for compliance with applicable law
- Secure Handling: we handle all Google user data with appropriate security measures including encryption, access controls, and secure storage
How long do we store your personal data?
We retain data according to the following schedule:
- Sign-in profile data: retained while your account is active, deleted within 30 days of account closure
- Leads and outreach data: retained while your account is active for reporting and follow-up, deleted or anonymized within 30 days of account closure
- Account data: retained while your account is active
- Legal and security data: some data may be retained longer when reasonably necessary for legitimate business or legal purposes, such as security, fraud prevention, abuse prevention, or financial record-keeping
- Communication records: we store information on direct communications with our Company for customer support purposes
How do we protect your security on our Platform?
To protect you and our Company from unauthorized access, alteration, disclosure, or destruction of information:
- we use encryption to keep your data private while in transit using SSL/TLS
- we encrypt sensitive data at rest in our databases
- we review information on collection, storage, and processing to prevent unauthorized access to our systems
- we restrict access to personal information to our employees, contractors, and agents who need that information to perform their services for us. Anyone with this access is subject to strict contractual confidentiality obligations
- we implement regular security review and updates to protect against vulnerabilities
- we use secure cloud infrastructure with industry-leading security practices
Do we share your personal data?
We do not share the information you provided to us with third parties, except in the following cases:
- with your consent
- when we use the services of other companies or persons (cloud hosting providers, database services, analytics providers, payment processors, message delivery providers, customer support tools). In this case, we only share your personal data with third parties as reasonably necessary to enable them to perform their services for us and under conditions of non-disclosure agreements and data processing agreements
- when it is reasonably necessary to:
- meet any applicable law, regulation, legal process, or enforceable governmental request
- enforce applicable Terms & Conditions, including investigation of potential violations
- detect, prevent, or otherwise address fraud, security, or technical issues
- protect against harm to the rights, property, or safety of our Company, our users, or the public as required or permitted by law
We may share non-personally identifiable, aggregated information publicly — for example, to show trends in the general use of our services. Such information cannot be used to identify you.
How can you edit or delete your data from our Platform?
Where data protection law applies to the processing of your information, you can exercise your right to request access to, update, remove, and restrict the processing of your information. You also have the right to object to the processing of your information or export your information to another service.
To manage your data specifically:
- Disconnect a mailbox or LinkedIn account: from your Tamozo account settings
- Revoke Google Sign-In: visit Google Account Permissions and remove Tamozo
- Request data deletion: contact us at [email protected]
- Export your data: contact us at [email protected] to request a copy of your data
When you delete your data, we follow a deletion process to make sure that your data is safely and completely removed from our servers or retained only in anonymized form. We try to ensure that our services protect information from accidental or malicious deletion, and for this reason there may be delays in when the copies you deleted are entirely deleted from our active and backup systems.
Data deletion timeline:
- Sign-in profile data: deleted within 30 days
- Leads and outreach data: deleted or anonymized within 30 days
- Backup systems: may take up to 60 days to be completely removed from all backup systems
If you have any questions about this Privacy Policy, you can contact us by email: [email protected]. You can contact your local data protection authority if you have concerns regarding your rights under local law.
This Privacy Policy was most recently updated on: August 26, 2026.