Trust and data handling

Practical answers about where product data goes and why.

This page explains FoundryOps data flows, provider roles, retention boundaries and security-review practices. The binding policy is the Privacy Policy.

Operating commitments

These commitments apply across the product without turning qualified practices into unsupported absolutes.

Purpose limits

FoundryOps does not sell customer data or use it for advertising, credit decisions or training generalized models.

Qualified processing

Customer data may be processed, stored or logged when needed to perform a requested workflow, keep the service reliable, secure accounts or meet legal obligations.

User control

Users choose the connected services and product workflows they invoke. Access can be revoked at the connected provider, and deletion requests can be made through support.

How product data moves

The exact path depends on the workflow the user selects. These are the principal product flows relevant to a buyer review.

Salesforce reports, queries and refresh

The product reads the Salesforce records a user requests and writes the returned data to the user’s spreadsheet. These workflows do not write changes back to Salesforce.

List preparation and matching

The selected spreadsheet data is processed to produce the requested standardized or matched output. Depending on the workflow, selected inputs and generated artifacts may pass through FoundryOps application storage and processing services.

Webhook workflows

Webhook data supplied to a configured endpoint can be written to a selected destination tab using the mode the user chooses, including Append or Replace. Delivery state, operational records and limited payload context may be retained to operate, troubleshoot and secure the workflow.

User-selected AI workflows

Only data selected for the requested workflow is sent to its configured provider. Provider handling depends on the workflow and is disclosed in the product or accompanying documentation.

Salesforce report, query and refresh workflows are read-only. Separately labeled write-capable workflows, if offered, are disclosed and qualified independently.

Google Workspace data

FoundryOps does not sell Google Workspace user data or use it for advertising, credit decisions or training generalized models. Google Workspace data is used and transferred only as needed to provide or improve user-facing features, maintain security, comply with law, or as otherwise permitted by the Google User Data Policy and Limited Use requirements.

The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Google Workspace API User Data Policy

AI data handling

FoundryOps does not sell customer data or use it for advertising, credit decisions or training generalized models. When a user chooses an AI-powered workflow, selected data may be sent to the configured provider solely to perform that requested workflow. Provider handling is disclosed in our security and data-handling documentation.

Service providers and subprocessors

Provider involvement depends on the services and workflows an account uses. A provider does not automatically receive every category of customer data.

Google Cloud
Application hosting, storage, processing and selected model services.
Salesforce
Connected CRM report, query and refresh workflows authorized by the user.
Clerk
Account authentication and identity flows.
Stripe
Billing and payment account functions; not spreadsheet-content processing.
Resend
Transactional and service email delivery.
Configured AI providers
Selected data for a user-invoked AI workflow, when that workflow is used.

Retention, logging and deletion

  • Retention varies by record type, connected service and operational purpose.
  • Operational, security, billing and audit records may be kept when needed to run and protect the service, comply with law or resolve disputes.
  • Deletion requests are handled according to the data’s location, applicable obligations and the capabilities of the relevant system.

Security review methodology

FoundryOps uses layered security testing that includes automated analysis, secret scanning, tenant-isolation tests, adversarial code review and human-reviewed release gates. AI-assisted review is one input to this process and is not a third-party certification.

FoundryOps does not claim a completed penetration test, SOC 2 or ISO certification, or endorsement by an AI provider.

Operator accountability

Built by Mike Heilmann, a B2B sales and RevOps operator with 30 years of experience working with CRM, spreadsheet and GTM systems. FoundryOps reflects the accountability he expects when teams handle customer, revenue and operational data.