Approvaq Privacy Policy
Approvaq is operated by MRB Info Technologies Inc. ("Approvaq," "we," "us," or "our"). This Privacy Policy explains how we handle information when a customer installs or uses the Approvaq HubSpot application and related services.
Information We Process
- HubSpot account identifiers, user and owner identifiers, installation and connection status, and OAuth authorization data.
- Deal identifiers and the deal properties needed to evaluate configured approval policies, including deal-stage and amount information.
- Product and line-item identifiers used for product-policy assignments.
- Customer-configured policies, approvers, approval requests, decisions, evaluation snapshots, and audit records.
- Operational queue records, webhook metadata, error categories, and service diagnostics needed to deliver and support the service.
- Billing and subscription state when a paid plan is used. Payment card data is handled by Stripe and is not stored by Approvaq.
We do not request sensitive-data scopes for the HubSpot application. We do not sell customer data or use customer CRM data for advertising.
Sources and Use
We receive information from the installing HubSpot customer and from HubSpot through the scopes approved during installation. We use it to evaluate and record approval decisions, project governed state back to HubSpot where configured, authenticate authorized administrators and approvers, operate queues/retries/notifications/billing/security/support, and investigate failures and maintain auditability.
HubSpot Authority and Approvaq Authority
HubSpot remains authoritative for CRM deal facts. Approvaq PostgreSQL is authoritative for governance state, including policies, approval requests, decisions, snapshots, and audit history.
Retention and Minimization
- Completed queue rows are retained for 30 days.
- Raw webhook payloads are minimized after 30 days; required row metadata is retained for operational traceability.
- Active, failed, and dead-letter work is retained until operationally resolved.
- Uninstall marks the tenant inactive but does not itself delete customer data.
- Approval and audit history is retained for now; final retention and delete-versus-anonymize treatment remain subject to legal review.
Uninstall and Customer Deletion
Uninstall or disconnect is not a customer data deletion request. On uninstall, we mark the tenant inactive, stop active processing, and retain tenant state so an authorized reconnect or reinstall can preserve continuity.
A customer may submit a deletion request through contactus@mrbinfotech.com. Requests use a manual authenticated owner/admin workflow. Our target is to complete a verified request within 30 days.
V1 deletion requests are handled through an approved manual process; no automated deletion endpoint or job currently exists.
Sharing and Service Providers
We share information only as needed to operate the service, including with HubSpot, infrastructure and database providers, email providers used when applicable, and Stripe.
Security
We use HTTPS for public service traffic, encrypted OAuth refresh-token storage, tenant-scoped authorization, bounded retries, and audit records. No security measure guarantees absolute security.
Your Choices and Requests
For privacy questions, access requests, correction requests, or deletion requests, contact contactus@mrbinfotech.com.
Changes
We may update this Policy when the service or legal requirements change. We will publish the updated version at https://approvaq.com/privacy with a new effective date.
Contact
Privacy and support: contactus@mrbinfotech.com
Business address: 2389 Main St., STE 100, Glastonbury, CT 06033, United States