Refidly

Privacy Policy

What Refidly collects, why, who it goes to, and what you can ask us to do about it.

Last updated · August 11, 2026

Who this policy covers

Information we collect

  • Account information. Name, work email, password credentials or Google sign-in identifier, organization name, role within the organization, and profile image.
  • Workspace content. The facility, lead, and referral records your team creates, including any custom fields your organization defines and the notes kept against them. Depending on how your organization configures those fields, this content can include protected health information.
  • Field activity. Visit, expense, and calendar entries your team logs, and the files attached to them.
  • Integration data. Where a user connects a Google or Microsoft account, the authorization and account address needed to send outreach email on that user's behalf.
  • Billing information. Subscription plan, seat count, and billing status. Card numbers are collected and stored by Stripe, our payment processor, and never reach Refidly servers.
  • Technical and usage data. IP address, browser and device type, pages and features used, timestamps, and session and audit records of actions taken inside a workspace.

How we use information

  • To operate the service: sign users in, keep a team's records available to the people entitled to see them, and keep a record of changes.
  • To provide the features your organization has enabled, including analytics, AI assistance, exports, and outreach email sent through a connected mailbox.
  • To bill for subscriptions, prevent fraud, and enforce the Customer Agreement.
  • To provide support, respond to your requests, and send service notices about availability, security, and material product changes.
  • To improve reliability and performance using aggregated, de-identified usage metrics.
  • To comply with legal obligations and to establish, exercise, or defend legal claims.

AI features

Outreach email

How we share information

  • Service providers who process data on our behalf under contract: cloud hosting and object storage, our database and cache infrastructure, Stripe for payments, Resend for transactional email, and Google for AI processing.
  • Other members of your organization, according to the role and permissions assigned to each user by a workspace owner.
  • Integration providers you connect, limited to what the integration needs to function.
  • Legal and safety disclosures where required by law, valid legal process, or to protect rights and safety. Where we may lawfully do so, we notify the affected organization first.
  • A successor in a merger, acquisition, or asset sale, subject to this policy and to notice before any change in how data is handled.

Data retention

Security

Your rights

Children and international users

Changes

Privacy questions