Skip to main content ↓

Privacy Policy

Last updated: June 2, 2026

Nutshell, Inc. (“Nutshell,” “we,” “our,” or “us“) provides customer relationship management (CRM) and related software products, websites, and services (collectively, the “Service“). This Privacy Policy explains what personal data we collect about visitors to our websites, prospects, customers, customers’ authorized users, and other individuals whose data we process; how we use it; with whom we share it; how long we keep it; and the rights and controls available to you.

This Privacy Policy applies to nutshell.com, app.nutshell.com, the Nutshell mobile applications, our APIs, our Model Context Protocol (MCP) connectors, and any other product or website that links to or references this Privacy Policy. It is incorporated by reference into our Terms of Service and, where applicable, our Data Processing Addendum (DPA).

If you are a contact of a Nutshell customer (i.e. a record in a Nutshell customer’s CRM, or a visitor to a website that uses Nutshell features like forms, chat, or analytics), please note that the Nutshell customer — not Nutshell — is generally the “controller” of personal data about you, and you should direct privacy requests to that customer in the first instance. We assist our customers in honoring valid requests, as described below.


1. Roles

For data that our customers upload, sync, or otherwise submit to the Service (“Customer Data“), Nutshell acts as a “processor” or “service provider” under applicable data protection laws (including the EU and UK GDPR, the Swiss FADP, the California Consumer Privacy Act (“CCPA”), the Canadian PIPEDA, and the Brazilian LGPD), and the Nutshell customer is the “controller” or “business.” Our processing of Customer Data on behalf of customers is governed by the DPA.

For data we collect from visitors to our websites, prospective customers, account administrators, billing contacts, support correspondents, recipients of our marketing communications, and applicants for employment, Nutshell is the “controller” or “business.” Sections 2–11 of this Privacy Policy describe that processing.


2. Personal Data We Collect

We collect personal data in the following categories.

2.1 Information You Provide Directly

When you create an account, request a demo, contact sales, attend an event, communicate with us, or otherwise interact with the Service, you may provide us with:

  • Account and contact information: name, business email address, business phone number, mailing address, job title, company name, industry, company size, and login credentials.
  • Billing information: payment-card information (collected and stored by our PCI-compliant payment processors, not by Nutshell directly), billing address, and tax identification information.
  • Communications content: the content of emails, chat messages, contact-form submissions, and support tickets you send us, including any attachments.
  • Profile information: profile photo and preferences you choose to share.
  • Survey, event, and marketing responses: including registration information for webinars, events, and product surveys.

2.2 Information Collected Automatically

When you visit our websites or use the Service, we and our service providers automatically collect:

  • Device and connection data: IP address, browser type and version, operating system, device identifiers, language preferences, referring URL, and timestamps.
  • Usage data: pages viewed, features used, buttons clicked, session duration, error logs, click paths, and other telemetry generated by your interaction with the Service.
  • Location data (approximate): approximate geographic location inferred from IP address. We do not collect precise GPS coordinates from end users through our public apps or MCP connectors (see Section 8).
  • Cookies and similar technologies: as described in Section 6.

2.3 Information from Third Parties

We may receive personal data about you from:

  • Data enrichment and lead-intelligence providers (e.g., to enrich a sales prospect’s company information).
  • Advertising partners and platforms (e.g., LinkedIn, Google Ads, Meta, The Trade Desk) that report on campaign performance and audience attributes.
  • Single sign-on / OAuth providers (e.g., Google, Microsoft) when you sign in to Nutshell using those services. We receive only the profile fields you authorize via the relevant consent screen.
  • Integrated services Customer connects to the Service (e.g., email, calendar, communication, and accounting systems Customer authorizes Nutshell to access on Customer’s behalf).
  • Public sources such as social media profiles and corporate registries.

2.4 Information We Generate

We generate certain personal data, including unique user and account identifiers, audit logs, security event records, account-health scores, and inferences drawn from how you use the Service (for example, “active user” or “feature adopter” flags used for our own product analytics).

2.5 Sensitive and Restricted Data

We do not knowingly collect, request, or process: protected health information (PHI) subject to HIPAA, full payment-card numbers (these are processed by our PCI-compliant processors), government-issued identifiers (such as Social Security numbers, driver’s-license numbers, or passport numbers), biometric identifiers, precise geolocation, or other categories considered “sensitive” or “special category” data under applicable law.

We also do not solicit, request, or intentionally collect access credentials, multi-factor authentication or one-time-passcode (MFA/OTP) values, API keys, encryption keys, or other authentication secrets through any channel — whether in the Nutshell UI, in support interactions, in our forms, or through our AI features and MCP connectors. The only credentials Nutshell handles are those required to authenticate you to your own Nutshell account (which are stored as salted, hashed values, never in plaintext) and OAuth tokens issued by third-party services you choose to integrate (which are encrypted at rest and used only to operate the integration you authorized). If you receive a request that appears to ask for a credential outside this scope, do not provide it and report it to [email protected].

Customers must not upload restricted or sensitive data to the Service (see Section 3.4 of the Terms of Service).

We do not knowingly collect personal data from children under 13 (or the applicable minimum age in your jurisdiction). If we learn we have collected such data, we will delete it.

2.6 Recording of Communications

By interacting with Nutshell through chat, contact forms, email, phone, video, AI chatbots, or any other channel, you acknowledge that the interaction may be recorded, logged, or transcribed. We use these recordings and transcripts to provide and improve customer support, train our team, ensure quality, prevent fraud, and meet legal obligations. Recordings and transcripts are subject to the same protections as other personal data described in this Privacy Policy.


3. How We Use Personal Data

We process personal data for the following purposes:

  • Provide and operate the Service — authenticate you, deliver requested features, route messages and notifications, and synchronize integrations.
  • Customer support and account management — respond to your inquiries, troubleshoot issues, and communicate about your account.
  • Billing and collections — process payments, issue invoices, and recover unpaid fees.
  • Service improvement and analytics — diagnose problems, monitor performance, understand which features are useful, and develop new functionality. We rely on aggregated and de-identified data for these purposes wherever feasible.
  • Security and abuse prevention — detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service.
  • Marketing and sales — send you product updates, newsletters, event invitations, and other communications about Nutshell, where permitted by law. You may opt out at any time using the unsubscribe link in any email or by contacting [email protected].
  • Advertising — measure the effectiveness of our marketing campaigns and serve relevant ads to you on third-party websites, as described in Sections 5 and 6.
  • Legal compliance and enforcement — comply with applicable laws, respond to lawful government requests, enforce our agreements, and protect our rights, property, and safety and those of our users and the public.
  • Recruitment — evaluate candidates who apply for jobs at Nutshell.

3.1 Legal Bases (for individuals in the EEA, UK, and Switzerland)

Where the EU/UK GDPR or Swiss FADP applies, we rely on the following legal bases:

  • Contract — to provide the Service to customers and account holders.
  • Legitimate interests — to operate, secure, improve, and market the Service, in each case where our interests are not overridden by your rights. You may object to processing based on legitimate interests as described in Section 9.
  • Consent — for certain marketing communications, non-essential cookies, and where otherwise required by law. You may withdraw consent at any time.
  • Legal obligation — to comply with tax, accounting, employment, and other legal requirements.

3.2 No Sale of Personal Information; No Training of Generalized AI

We do not “sell” your personal information for money. We engage in certain advertising activities (see Section 5) that may be classified as “sharing” or as “sale” of personal information under some U.S. state privacy laws even though no money changes hands; you may opt out of these activities as described in Section 9.

We do not use Customer Data to train, fine-tune, or otherwise improve generalized AI or machine-learning models, whether Nutshell’s own models or those operated by our AI subprocessors. We may use Service Data, aggregated data, and de-identified data to evaluate and improve the Service.


4. How We Share Personal Data

We share personal data only as described below.

4.1 Service Providers and Subprocessors

We use service providers (“Subprocessors”) to host, store, transmit, secure, monitor, and otherwise support the Service. Subprocessors include cloud-infrastructure providers (e.g., Amazon Web Services), email and SMS delivery providers, payment processors, analytics providers, AI model providers (used to power AI features in the Service), customer-support tooling, and similar vendors. A current list is maintained at trust.nutshell.com/subprocessors. Each Subprocessor is bound by written terms requiring confidentiality, security, and use of personal data only for the purposes we authorize.

Geographic restriction: Nutshell does not engage Subprocessors that are domiciled in, or that store Customer Data in, the Democratic People’s Republic of Korea (North Korea) or the Islamic Republic of Iran.

4.2 Advertising and Analytics Partners

We work with third-party advertising and analytics providers, including Google Analytics, Google Ads, Microsoft Advertising, LinkedIn, Meta, X/Twitter, and The Trade Desk, to measure marketing performance and to deliver targeted advertising on third-party sites based on your interactions with our websites and emails. These partners may use cookies, web beacons, and similar technologies to collect information about you, including your IP address, device identifiers, and browsing activity. See Section 6 for cookie controls and Section 9 for advertising opt-outs.

4.3 Integrations You Authorize

When you or a user in your account connect a third-party service to your Nutshell account (for example, Google Workspace, Microsoft 365, an email or accounting tool, or an MCP-compatible AI assistant), we share data with that service as necessary to operate the integration you have enabled. You can revoke these authorizations at any time in your account settings or in the third-party service.

4.4 AI Features, MCP Connectors, and Connected AI Assistants

Nutshell offers AI-powered features within the Service and publishes MCP (Model Context Protocol) connectors that allow customers to interact with Nutshell from compatible AI assistants such as ChatGPT (via the OpenAI Apps SDK) and Claude (via Anthropic Connectors). When you or your end user invokes an AI feature or MCP tool:

  • Inputs: Nutshell sends only the specific inputs needed to execute the requested tool. We do not pull, reconstruct, or infer the full chat-log content of your conversation with an AI assistant. Inputs are limited to the narrow, task-specific fields defined in the tool schema.
  • Processing by AI providers: Inputs may be transmitted to the AI provider (e.g., OpenAI, Anthropic) so the model can interpret them and to Nutshell so the requested operation can be performed. AI model providers are contractually required to (a) process inputs only to deliver the requested response, (b) not use inputs to train, fine-tune, or otherwise improve their generalized models, and (c) limit retention of inputs to the period necessary to provide the response, comply with applicable law, and conduct reasonable trust-and-safety, abuse-prevention, and security monitoring consistent with the provider’s standard published practices.
  • Outputs: Tool responses are limited to data directly relevant to the user’s request. We do not include internal identifiers, trace IDs, telemetry, or diagnostic metadata in tool responses unless required to fulfill the request.
  • Authentication: Access to authenticated Nutshell data through MCP connectors uses OAuth 2.0 and is limited to the scopes the user grants. Users may revoke an AI assistant’s access at any time. Consistent with Section 2.5, Nutshell tool schemas never request passwords, MFA/OTP values, API keys, or other authentication secrets as tool inputs.
  • Recordings: Conversations with Nutshell-provided chatbots and AI features may be recorded, logged, and used to operate, secure, and improve the Service, subject to Section 2.6 and Section 3.2.

4.5 Group Companies

Nutshell is part of a corporate group. We may share personal data with our parent company and sibling companies for shared corporate functions such as finance, security, and legal compliance. They are bound by the same protections in this Privacy Policy.

4.6 Legal, Safety, and Enforcement

We may disclose personal data if we believe in good faith that disclosure is necessary to: (a) comply with applicable law, legal process, or an enforceable government request; (b) enforce our agreements; (c) protect the rights, property, or safety of Nutshell, our users, or others; or (d) investigate or prevent illegal activity, fraud, or abuse. Where legally permitted, we will direct law enforcement to request Customer Data directly from the customer.

4.7 Business Transfers

If Nutshell is involved in a merger, acquisition, financing, reorganization, or sale of all or substantially all of its assets or equity, personal data may be transferred to the surviving or acquiring entity as part of that transaction, subject to commitments at least as protective as those in this Privacy Policy.

4.8 With Your Consent or At Your Direction

We share personal data in any other manner that you specifically direct or consent to.


5. Advertising and Cross-Site Tracking

We use advertising and remarketing technologies provided by Google, Microsoft, LinkedIn, Meta, X/Twitter, The Trade Desk, and other ad platforms to measure the effectiveness of our marketing and to deliver advertising about Nutshell to people who have visited our website, used our Service, or otherwise expressed interest in similar products. These technologies may set cookies in your browser, embed tracking pixels, or share hashed identifiers (such as a hashed email address) with the ad platform so it can match you with its user base and serve targeted ads on its properties. The ad platforms may also use this information for their own purposes, subject to their privacy policies.

You can opt out of interest-based advertising as described in Section 9.


6. Cookies and Similar Technologies

A “cookie” is a small file placed on your device by a website. We use cookies and similar technologies (such as web beacons, pixels, local storage, and SDKs) for the following purposes:

  • Strictly necessary — to authenticate you, maintain your session, and provide the core features of the Service.
  • Functional — to remember your preferences (e.g., language, recently used filters).
  • Analytics — to understand how visitors and users interact with our websites and the Service. We use Google Analytics to analyze trends; analytics data is collected on a non-personally-identifying basis where possible.
  • Advertising — to deliver targeted advertising on third-party sites based on your prior interactions with our websites and emails, including retargeting (see Section 5).

Visitor cookies on customer websites: If you are visiting a website operated by one of our customers, that customer may have embedded a Nutshell code snippet to power features such as VisitorIQ, Nutshell Analytics, Nutshell Forms, or chat. The customer is the controller of that data, and you should consult the customer’s privacy policy for details and exercise rights through them.

Your choices: You can manage cookies through your browser settings, our cookie consent banner (where available), and the opt-out mechanisms in Section 9.


7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which we collected it, including to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention practices include:

  • Customer Data: retained for the duration of the customer’s subscription and as described in the DPA. Following termination, Customer Data is available for export for 30 days, then deleted from production systems. Residual copies may persist in encrypted backups for a longer period and may be fully purged upon request.
  • Account, billing, and contract records: retained for the duration of the customer relationship and indefinitely thereafter for accounting, tax, and audit purposes.
  • Marketing prospect records: retained until you opt out.
  • Support tickets, chat transcripts, phone recordings: retained for as long as necessary for support, training, quality assurance, legal, and security purposes.
  • Backups: as described under Customer Data above.

Upon your request, we will delete personal data we hold about you sooner, subject to legal exceptions described in Section 9.


8. International Transfers

Nutshell is headquartered in the United States, and our Subprocessors operate in the United States, Canada, the EU/EEA, the United Kingdom, and other jurisdictions outside your country of residence. By using the Service, you understand that personal data may be transferred to, processed, and stored in jurisdictions whose laws may not provide the same level of protection as the laws of your country.

For transfers of personal data from the EEA, UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss-equivalent mechanisms set forth in the DPA. For transfers from other jurisdictions, we use the transfer mechanism approved or accepted by that jurisdiction’s authorities.

As described in Sections 4.1 and 8 of the Terms of Service, Nutshell does not engage Subprocessors that are domiciled in North Korea or Iran.


9. Your Rights and Choices

Depending on where you live, you may have the following rights with respect to personal data we hold about you:

  • Access — to request a copy of the personal data we hold about you.
  • Correction — to request that we correct inaccurate or incomplete data.
  • Deletion / erasure — to request that we delete your personal data.
  • Portability — to request that we provide your data in a structured, machine-readable format.
  • Restriction or objection — to restrict or object to certain processing, including processing based on legitimate interests and direct marketing.
  • Withdrawal of consent — to withdraw consent where we rely on it.
  • Non-discrimination — not to be discriminated against for exercising your rights (CCPA).
  • Opt out of “sales” and “sharing” for cross-context behavioral advertising under CCPA and similar U.S. state privacy laws.
  • Opt out of profiling that produces legal or similarly significant effects (where applicable).

How to exercise these rights: Email [email protected], or use the in-product privacy controls in your account. We will respond within the time frame required by applicable law (typically 30 days, extendable to 90 days for complex requests). We may need to verify your identity. There is no charge for reasonable requests.

End users of our customers: If your personal data is in a Nutshell customer’s CRM or otherwise was uploaded to the Service by a customer, the customer is the controller. Please direct your request to that customer.

9.1 Marketing and Cookie Choices

9.2 Complaints

If you have a privacy concern, we ask that you contact us first at [email protected].


10. Security

We maintain administrative, technical, and physical safeguards designed to protect personal data against loss, theft, unauthorized access, disclosure, alteration, and destruction. These measures include encryption of data in transit (TLS 1.2+) and at rest (AES-256), network segmentation, access controls and least-privilege provisioning, multifactor authentication for production systems, continuous vulnerability management and annual third-party penetration testing, secure software-development practices, security training for personnel, and incident-response procedures. Nutshell is SOC 2 Type 1 attested by an independent third-party auditor. Our security commitments to customers are described in Annex II of the DPA. Trust center materials, including the most recent attestation report, are available under NDA at trust.nutshell.com.

You are responsible for choosing a strong, unique password, keeping it confidential, and notifying us promptly of any suspected account compromise. Nutshell is not responsible for data loss or compromise due to


11. Google API Services User Data

If you authorize Nutshell to access your Google account (for example, to sync email or calendar events), Nutshell’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

This includes transmitting Google user data to our AI and transcription Subprocessors (listed at https://trust.nutshell.com/subprocessors) solely to power the specific features you invoke — for example, email content may be sent to an AI model provider to generate a summary or reply suggestion, and meeting recordings from Google Meet may be sent to a transcription provider to generate a transcript.

Specifically:

  • We use Google user data only to provide and improve the Google-integrated features you have enabled within Nutshell.
  • Google user data we may access includes: email messages and metadata (Gmail), calendar events and attendee information (Google Calendar), meeting recordings and transcripts (Google Meet), and contact information (Google Contacts), in each case only where you have authorized the integration.
  • We do not transfer Google user data to others except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  • We do not use Google user data for serving advertisements.
  • We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, are doing so for security purposes (such as investigating abuse), to comply with applicable law, or where the data has been aggregated and de-identified for internal operations.
  • We do not use Google Workspace APIs to develop, improve, or train generalized AI or ML models.

You can revoke Nutshell’s access to your Google data at any time at myaccount.google.com/permissions.


12. Children

The Service is not directed to children under 13 (or the equivalent minimum age in the applicable jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact [email protected] and we will delete it.


13. Links to Third-Party Sites

The Service and our websites may contain links to third-party sites and services. We are not responsible for the privacy practices of those third parties. You should review their privacy policies before providing them with personal data.


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent revision. We will post the revised policy at nutshell.com/legal/privacy. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.


15. Contact Us

For questions about this Privacy Policy or to exercise your rights:

  • Email: [email protected]
  • Mail: Nutshell, Inc., Attn: Privacy, 1705 North Front St., Harrisburg, PA 17102, USA

For privacy complaints we have been unable to resolve, see Section 9.2.


Appendix A — Categories of Personal Information Collected, Used, and Disclosed (CCPA / U.S. State Privacy Laws)

The following table summarizes the categories of personal information we have collected, used, and disclosed in the preceding 12 months for purposes of the California Consumer Privacy Act (as amended by the CPRA) and similar U.S. state privacy laws.

Category Examples Sources Purposes Disclosed to (categories)
Identifiers name, email, phone, IP, account ID you; cookies; integrations; data enrichment provide Service; marketing; security Subprocessors; ad partners; integrations you authorize
Customer records billing address, payment info (tokenized) you billing; tax compliance payment processors; accounting providers
Commercial information products purchased, transaction history you; the Service provide Service; account management Subprocessors
Internet/network activity browsing history on our sites; usage logs; click data automatic analytics; security; advertising analytics & ad providers
Geolocation (approximate) IP-derived city/region automatic analytics; security analytics providers
Audio/visual recordings of chat, phone, and chatbot interactions you support; training; quality support tooling Subprocessors
Professional/employment job title, company, industry you; integrations; enrichment marketing; CRM functionality Subprocessors; ad partners
Inferences inferred buyer-stage, account-health score the Service analytics; product improvement none, except aggregated

We do not knowingly collect “sensitive personal information” as defined under the CCPA (other than account log-in credentials, which we use only to authenticate you and which we do not “sell” or “share”). We do not knowingly sell or share personal information of consumers under 16.


Appendix B — Region-Specific Disclosures

California (CCPA / CPRA)

You have the right to know, delete, correct, opt out of “sale” and “sharing,” limit use of sensitive personal information, and to non-discrimination. Submit requests at [email protected] or via the “Do Not Sell or Share My Personal Information” link on our website.

Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other U.S. states

You have rights of access, deletion, correction, portability, and opt-out of targeted advertising, “sale,” and certain profiling. Submit requests at [email protected].

European Economic Area, United Kingdom, Switzerland

See Section 3.1 for legal bases and Section 9 for the full list of rights, including the right to lodge a complaint with your supervisory authority.

Brazil (LGPD)

You have rights of confirmation, access, correction, anonymization, blocking, deletion, portability, information about sharing, and revocation of consent.

Canada (PIPEDA)

You have rights of access and correction, and may file a complaint with the Office of the Privacy Commissioner of Canada.