1. Who we are
The Pavoot platform is operated by Pavoot Inc., 2261 Market Street STE 76439, San Francisco, CA 94114, United States of America. You can reach us at hello@pavoot.com. For help with the product, write to support@pavoot.com.
2. Our roles
People who use Pavoot. For your account, settings and how you use the platform, Pavoot Inc. is the controller for the purposes of the GDPR and the Swiss FADP. Sections 3, 4 and 11 describe this.
Guests and contacts of an organizer. When an organizer uses Pavoot to invite people, collect registrations, check guests in, take notes or send follow-ups, the organizer decides how that data is used. Pavoot processes it only on the organizer's instructions, under its agreement with us and our Data Processing Agreement. Section 5 describes this.
Professional profiles. Pavoot maintains professional profile information, such as names, job titles and companies, to help organizers find people who fit their events. For this information, Pavoot Inc. is the controller. Section 6 describes this.
3. Data about people who use Pavoot
3.1 Your account
- Your name, email address, organization and role.
- A profile photo and email signature, if you add them.
- How you sign in: email and password or email code, Sign in with Google, or Sign in with Apple. Sign-in is handled by our authentication provider, Clerk. We don't receive your Google or Apple password.
3.2 Content you create
Event details, guest lists, invitations, registration forms, notes, voice memos and their transcripts, photos, contacts, follow-up emails, reports and documents you upload. This content usually includes information about other people, which is covered in sections 5 and 6.
3.3 Connected services
You can connect other services to Pavoot. We only access them for the features you use, and you can disconnect them at any time.
- Gmail or Microsoft Outlook: so emails are sent from your own address, including from a shared mailbox your administrator has given you access to. We ask for permission to send email and to manage events in your calendar. We do not ask for permission to read your inbox. See section 3.4 for exactly how we use Google and Microsoft data.
- Luma, HubSpot or Salesforce: to import and sync events, guests and contacts.
- API keys: you can create keys to connect Pavoot to your own tools. Treat them like passwords.
3.4 Google and Microsoft account data
When you sign in with Google or connect Gmail, Google Calendar or Microsoft Outlook, Pavoot receives only what those permissions allow and uses it only for the features you use:
| Permission | What we use it for |
|---|---|
| Your name, email address and profile picture | Signing you in and showing who you are |
Send email on your behalf (Gmail gmail.send, Outlook Mail.Send, and Mail.Send.Shared for shared mailboxes) |
Sending the invitations and follow-ups you write or approve, from your own address |
Manage calendar events (Google calendar.events, Outlook Calendars.ReadWrite) |
Adding meetings you book to your calendar, updating or removing those events, and checking guest responses to them |
- We never read the emails in your inbox, and we only access calendar events that Pavoot created.
- We keep a copy of the emails you send through Pavoot, so you and your team can see what was sent.
- Access tokens are stored encrypted. When you disconnect an account or delete your Pavoot account, we delete them and revoke our access. You can also remove Pavoot's access at any time in your Google or Microsoft account settings.
- We do not use Google or Microsoft user data for advertising, sell it, or use it to train AI models. We do not share it with anyone except as needed to provide these features, to comply with law, or with your permission.
- Pavoot staff do not read this data unless you ask us to (for example for support), it is needed for security or to investigate abuse, or the law requires it.
Pavoot's use and transfer of information received from Google APIs, including any raw or derived user data, will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3.5 Device permissions on iPhone
The Pavoot app asks for access only the first time you use a feature that needs it: the microphone for voice memos, the camera for scanning and photos, and adding to your photo library when you tap download. You can change these at any time in iOS Settings → Pavoot.
3.6 Usage and technical data
- Web app: we use Userlens for product analytics. When you are signed in, it records the pages you view, what you click and the requests the app makes, linked to your account and organization. We use this to understand how Pavoot is used and to improve it.
- iPhone app: the app contains no third-party analytics, advertising or tracking tools.
- Server logs: when you use Pavoot, our servers receive your IP address, device or browser type, app version and request details. We use these for security and troubleshooting.
- On your iPhone: the app keeps a copy of recent data, plus changes made offline, so it works without a connection. Signing out removes it.
We do not collect payment card data from people who use Pavoot. Guests who buy tickets pay through Stripe (see section 5).
4. How we use it
We process personal data about people who use Pavoot for the following purposes and legal bases:
- To provide Pavoot (performance of a contract, Art. 6(1)(b) GDPR): running your account, syncing your data across devices, and sending the emails and messages you choose to send.
- To keep Pavoot secure and working (legitimate interest, Art. 6(1)(f) GDPR): server logs, usage limits, abuse prevention and troubleshooting.
- To improve Pavoot (legitimate interest, Art. 6(1)(f) GDPR): product analytics in the web app.
- For AI features where we ask for your agreement (consent, Art. 6(1)(a) GDPR): see section 7. You can withdraw consent at any time without affecting processing that took place before.
- To comply with legal obligations (Art. 6(1)(c) GDPR): accounting, tax, and responding to lawful requests from authorities.
5. Guests and contacts of an organizer
If you were invited to, registered for or attended an event run with Pavoot, the organizer is responsible for your data. Depending on the event, the organizer may use Pavoot to handle:
- Contact and profile details: name, email address, phone number, company, job title and LinkedIn profile.
- Registration: your answers to the organizer's registration questions, your RSVP, and how you found the event page.
- Attendance: check-in status, and notes or voice memos the organizer's team took after meeting you.
- Messages: invitations, reminders and follow-ups sent by email or text message, and your replies.
- Tickets: if an event is paid, the payment is handled by Stripe. Pavoot receives the payment status and your email address, not your card details.
- Engagement: whether an email was opened or a link in it was clicked, measured through a small image and link redirects in the email. When you open an event page from an invitation, we record the visit and the page that referred you. Your IP address is stored only in shortened, hashed form.
If an event is co-hosted, the organizers running it together can see its guest list. To access, correct or delete your data, or to stop receiving messages from an organizer, contact the organizer named in the invitation. You can also write to us at hello@pavoot.com and we will pass your request to the organizer.
Public event pages do not use analytics or advertising cookies. The browser stores a check-in code so you can find your ticket again. Event pages load fonts from Google Fonts, and a map from Google Maps when you open it.
6. Professional profiles
Organizers use Pavoot to find people who would be a good fit for their events, such as marketing leaders in a certain city. To make this possible, Pavoot uses professional information about people in business roles.
What information. Name, job title, company, work history, professional contact details, LinkedIn profile URL, public profile photo and general location, such as the city.
Where it comes from.
- Business data providers (Apollo, People Data Labs, Crustdata and ContactOut).
- Publicly available sources, such as company websites, public professional profiles and web search.
- Information organizations add to Pavoot themselves.
How it is used. To suggest relevant people to organizers for their events, and to keep job titles and companies up to date. When an organizer adds you to their contacts or invites you, they become responsible for how they use your information, as described in section 5. We do not use professional profiles for sensitive categories of data, and we do not make decisions about people that have legal or similarly significant effects.
Organizers' own data stays theirs. Contacts, notes and messages an organization adds to Pavoot stay within that organization and are not shown to other organizations. When an organization asks Pavoot to look up a person's professional details, the details returned by the data provider are added to the professional profile described here.
Legal basis. Our legitimate interest, and that of organizers, in connecting relevant professionals with business events (Art. 6(1)(f) GDPR).
Your choices. You can ask us at any time what information we hold about you, to correct it, or to delete it. Email hello@pavoot.com from the address you want us to look up, and we will respond within the timelines required by law.
7. AI features
Pavoot uses AI to draft invitations and follow-ups, research events and guests, summarize notes, transcribe voice memos, read business cards and generate cover images. Each feature sends only the content needed for that task to the provider that performs it:
- OpenAI and Anthropic: writing drafts, summaries and research, reading images, and generating cover images.
- Google (Gemini): researching people and companies from public sources.
- Deepgram: transcribing voice memos.
In the iPhone app, AI features run only after you agree on the in-app screen, and you can turn them off at any time in Settings → Privacy. In the web app, AI features run when you use them.
OpenAI, Anthropic and Deepgram do not use data sent through their APIs to train their models.
AI output can be wrong. Please check drafts, summaries and suggestions before relying on them or sending them.
8. Sharing & service providers
We share personal data only with service providers that help us run Pavoot. They may process personal data only as necessary to provide their services and subject to applicable contractual and data protection obligations.
We work with these service providers:
- Hosting and storage: Amazon Web Services, Supabase
- Sign-in: Clerk
- AI: OpenAI, Anthropic, Google (Gemini), Deepgram
- Professional data and research: Apollo, People Data Labs, Crustdata, Exa, ContactOut (via Orthogonal)
- Email and text messages: Resend, AgentPhone, and Gmail or Microsoft Outlook if you connect them
- Payments for paid events: Stripe
- Maps and fonts: Google
- Product analytics (web app): Userlens
- iPhone app: Apple (Sign in with Apple, App Store)
- Integrations you choose to connect: Luma, HubSpot, Salesforce
Most of these providers process data in the United States; some operate globally or in the European Union. International transfers are covered in section 13.
Within your organization. Content in your organization's workspace, including contacts, notes and uploaded connection lists, is visible to other members of your organization. Your organization's admins manage who has access. Co-hosting organizations can see the guest list of events they co-host.
Pavoot staff. Authorized Pavoot staff can access data when needed for support, security or to fix a problem, under least-privilege controls. Google and Microsoft account data is handled as described in section 3.4.
Legal and business transfers. We may disclose information if required to do so by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud or abuse. If Pavoot is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we will continue to protect it consistent with this Policy.
9. Selling and advertising
We do not use personal data for advertising, we do not show ads, and we do not use advertising identifiers or track people across other companies' apps or websites.
We do not sell personal data about people who use Pavoot or about organizers' guests. Professional profiles (section 6) are made available to our customers as part of the service. If you live in California or another state that gives you the right to opt out of the sale or sharing of personal data, you can opt out of this at any time by emailing hello@pavoot.com with the subject "Do not sell or share my information". We will stop making your profile available to customers.
10. Retention
- Account data: kept while your account is active. After you delete your account, it is removed from our production systems within 30 days and from backups within 90 days, unless the law requires us to keep it longer.
- Organization content, including guests, contacts and notes: kept for as long as the organization keeps it. When an organization's contract ends, it is exported and deleted as described in General Terms and Conditions and Data Processing Agreement.
- Professional profiles: kept while the information remains current and relevant for events, or until you ask us to delete it.
- Connected services: when you disconnect a service or delete your account, we delete the access tokens we stored and revoke our access.
- Logs and analytics: retained for as long as reasonably needed for security, troubleshooting and improving Pavoot.
11. Deleting your account
How to delete. In the iPhone app, go to Settings → Delete account. You can also email hello@pavoot.com from the email address on your account.
What we delete. Your login, your profile, your connected services, your API keys and your settings.
What stays with your organization. Events, contacts and notes you created belong to your organization's workspace, so your team keeps its records. Your organization can ask us to delete them.
We confirm by email when your account has been deleted. Removing the app from your phone does not delete your account.
12. Data security & Limited Use
We apply appropriate measures to protect personal data, including sensitive personal data such as names, email addresses, and phone numbers:
- Encryption in transit: all data is transmitted over encrypted TLS/HTTPS connections.
- Encryption at rest: personal data is encrypted at rest on our infrastructure.
- Credential protection: passwords and OAuth tokens are hashed or encrypted at rest, never stored in plaintext.
- Access controls: access is restricted under least-privilege controls and data is logically isolated per organization.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to protect your information and to limit access to it.
Limited Use. Pavoot's use and transfer of information received from Google APIs, including any raw or derived user data, will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third-party AI services to train or improve generalized AI or machine-learning models.
13. International transfers
Our servers are hosted by Amazon Web Services in the United States (Oregon). Pavoot Inc. is based in the United States, and some of our sub-processors operate globally. When personal data is transferred outside the EU/EEA or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the Swiss addendum where applicable) and assess each transfer to ensure an essentially equivalent level of protection.
14. Your rights
14.1 EU/EEA, UK and Switzerland
Subject to applicable law, you have the right to access, rectify, delete, restrict, or object to our processing of your personal data, and the right to data portability. Where we process your data based on consent, you can withdraw that consent at any time without affecting the lawfulness of processing before withdrawal. You also have the right to lodge a complaint with your local data protection authority (in Switzerland, the FDPIC).
Where we rely on legitimate interest, including for professional profiles, you can object at any time, and we will stop unless we have compelling grounds to continue.
14.2 United States, including California
Depending on the state you live in, you may have the right to:
- know what personal data we collect and how we use it, and access a copy;
- correct inaccurate personal data;
- delete personal data;
- receive your data in a portable format;
- opt out of targeted advertising (we do not do this) and, where applicable, the sale or sharing of personal data;
- limit the use of sensitive personal data (we use it only to provide Pavoot);
- not be treated differently for exercising these rights.
You can use an authorized agent to make a request for you. We verify requests by confirming they come from the email address concerned. If we decline a request, you can appeal by replying to our decision.
14.3 Guests and contacts
For data an organizer controls, we pass your request to the organizer and act on its instructions.
To exercise any of these rights, email us at hello@pavoot.com. Requests are handled within the timelines required by applicable law, including any extension permitted for complex or multiple requests.
15. Do Not Track and Global Privacy Control
Pavoot does not respond to browser Do Not Track signals. Because a browser signal can't be linked to a professional profile, please use the email opt-out in section 9.
16. Children
Pavoot is intended for business use. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
17. California notice at collection
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Identifiers | Name, email address, phone number, account ID, IP address | You, organizers, business data providers, automatically | Providing Pavoot, security |
| Customer records | Organization, role, registration answers | You, organizers, guests | Providing Pavoot |
| Professional information | Job title, company, work history, LinkedIn profile | You, organizers, business data providers, public sources | Providing Pavoot, suggesting relevant guests |
| Commercial information | Ticket purchases for paid events | Guests, via Stripe | Providing Pavoot |
| Audio and visual information | Voice memos, photos, public profile photos | You, public sources | Providing Pavoot |
| Internet activity | Product analytics, server logs, email opens and link clicks | Automatically | Security, troubleshooting, improving Pavoot, event engagement for organizers |
We keep each category for the periods described in section 10 and disclose it to the service providers listed in section 8. We do not sell or share personal data about people who use Pavoot or about organizers' guests. For professional profiles, see section 9, including how to opt out.
18. Changes & contact
We may update this Privacy Policy from time to time. The "Last change" date at the top of this page reflects the most recent update. If we make material changes, we will also tell you in the product.
Questions or requests? Email us at hello@pavoot.com.
