The short version: PipeChamp reads your HubSpot CRM data to generate pipeline analytics. We display it to you, we do not sell it, and we do not store your contact or deal records. Monthly aggregate scores (not individual records) are stored to show you trends over time.

1. Who we are

PipeChamp ("we", "us", "our") is a pipeline analytics application that connects to HubSpot CRM and analyses deal and contact data to generate pipeline health scores and insights. PipeChamp is operated as an independent product and is not affiliated with HubSpot, Inc.

For privacy questions, contact us at: support@pipechamp.app

2. Data we access from HubSpot

When you authorise PipeChamp via HubSpot OAuth, we request the following permissions:

We access only what is necessary for the analytics features you use. We do not access email content, notes, attachments, or any data not listed above.

3. How we use your data

Analytics and scoring

HubSpot data is fetched, processed in memory, and returned to your browser as pipeline metrics and scores. This processing happens on our servers (hosted on Railway) and the results are displayed directly to you.

Session caching

To avoid repeated API calls and respect HubSpot rate limits, fetched data is cached in server memory for up to 5 minutes per session. This cache is keyed to your HubSpot access token and is discarded when the cache expires or the server restarts.

Monthly aggregate snapshots

We store one aggregate record per HubSpot portal per month in a secure database. This record contains only computed scores (e.g. overall grade, win rate percentage, speed-to-lead average) โ€” never individual contact names, email addresses, deal names, or other personally identifiable information from your CRM.

These snapshots power the month-over-month trend feature. They can be deleted upon request.

4. Optional integrations

If you choose to connect Google Analytics 4 or Google Search Console, we access those APIs under separate Google OAuth authorisation. The same principles apply: data is processed in memory, displayed to you, and not stored or sold.

5. What we do not do

6. Data retention

7. Your rights

Depending on where you are located, you may have the following rights:

To exercise any of these rights, email support@pipechamp.app.

8. Security

OAuth tokens are stored in a server-signed, encrypted session cookie and never exposed in URLs or logs. Server infrastructure is hosted on Railway (US region) with TLS encryption in transit. We do not log HubSpot record content.

9. Children

PipeChamp is a B2B business tool and is not directed at children under 16. We do not knowingly collect data from anyone under 16.

10. Changes to this policy

If we make material changes to how we handle your data, we will update the effective date at the top of this page and, where appropriate, notify connected users by email.

11. Contact

For any privacy questions or to exercise your rights: support@pipechamp.app