Legal

Privacy Policy

Last updated August 16, 2026. TryGTM.

Who we are

This policy describes how TryGTM handles personal data on trygtm.com and in the GTM product at app.trygtm.com. TryGTM is the company and the product. We have not published a distinct registered entity name.

Controller and processor

It depends on the data.

When you connect a mailbox or LinkedIn account and we send, store sequences, or handle replies on your behalf, we act as a processor. You decide the campaign, the audience you upload or approve, and the message.

When we source leads ourselves — find people and companies that match an ICP and store their fields — we act as a controller for that sourced data. That is a deliberate product choice. It is our current reading, not a certification, and it is not legal advice. We have not executed a data processing agreement with you by default. Enterprise plans may include a custom DPA when we offer one.

We do not claim GDPR certification, an EU adequacy decision, or EU data residency.

What we collect

Waitlist (trygtm.com/join):

  • Full name
  • Company name
  • Work email
  • Phone number

The form includes a hidden honeypot field. If it is filled, we discard the submission. We also see the network address of the request so we can rate-limit abuse. That address is used in memory for the limiter. It is not stored as a waitlist field.

Product (app.trygtm.com), when you have an account:

  • Account data: name, email, authentication identifiers
  • Workspace data: company profile, ICP, sequences, drafts, send history, replies, booking state
  • Connected-channel data: mailbox OAuth tokens and profile identifiers; LinkedIn connection credentials held through a connection vendor; Instagram connection data if you connect it
  • Sourced lead fields: identity and firmographic fields we collect to run outbound, plus when and where a field came from
  • Billing data: plan, credit usage, and payment references from the processor
  • Operational data: workspace settings, agent mode, daily send caps

We do not ask the waitlist for a password. Product auth is handled by our auth provider.

Why we use it

  • To run the waitlist and tell you when a seat is open
  • To provide the service: source, write, send, reply, book
  • To keep connected channels working
  • To meter credits and charge the subscription you chose
  • To prevent abuse and keep the service up
  • To meet law that applies to us, including keeping suppression records so we do not contact someone who opted out

We do not sell waitlist or product personal data.

Vendors

We use other companies to run the service. The ones we can name today:

  • Vercel hosts the sites
  • Supabase provides authentication and the database

We also use vendors that connect email and LinkedIn accounts, language-model providers to draft messages, and a payment processor when you subscribe. We do not publish a full subprocessor schedule on this page. If that list is formalized, we will add it here.

Content you generate or we source — messages, lead fields, ICP notes — may be sent to those vendors so the feature can run. Mailbox tokens are used to send and read mail on the account you connected.

Where it is stored

The United States. The database we use is in AWS us-east-2. We do not offer EU residency. If you use the service from outside the US, you are sending data to the US.

How long we keep it

Waitlist records stay until you ask us to delete them, or until we close the list and have no further use.

For sourced lead fields, retention is tied to when we collected the field, not when it was last updated. We do that on purpose.

Suppression — unsubscribe and do-not-contact records — is kept so we do not email someone again after they opt out. Those records are exempt from ordinary deletion of a workspace's prospect list.

Account and workspace data stays for as long as the account is open, then for a short wind-down so we can close billing and handle a chargeback or a legal hold. You can disconnect a channel. We then stop using that connection to send.

Logs

The product is built so application logs, error tracking, and model-prompt logs should not contain personal data. That is an engineering rule, not an audit or a certification. We can still see personal data in the application itself, because that is the service.

Cookies

The marketing site does not use advertising or analytics cookies.

Submitting the waitlist may set a short-lived technical cookie so the form can show its result.

The product app uses session cookies to keep you signed in. Those are required for the app to work.

If we add analytics later, we will update this page before we do.

Your choices

For waitlist data, write to us through trygtm.com — the form at /join is the public path — and ask us to access, correct, or delete your row.

For a product account, use the app where we have built those controls, or contact us through the site. You can disconnect channels and close an account.

We honor unsubscribe on mail we send. Where the product injects an unsubscribe link, postal address, or notice, that injection is not something you can turn off.

If you are in a jurisdiction that grants further rights, we will handle a request that identifies you. We do not claim we already meet every EU or UK transfer requirement.

Children

GTM is a business product. It is not directed at children. Do not submit a waitlist entry for anyone under 16.

Changes

We may update this policy. The date at the top will change. Material changes will be posted on this page.

Contact

TryGTM, via trygtm.com. See also the Terms of Service.