Privacy Policy

How We Handle Your Data

BaseCommand is operated by Ewing Ventures LLC ("BaseCommand", "we", "us"). This Privacy Policy explains what personal and business data we collect, how we use it, who we share it with, and the choices you have.

Effective 2026-05-11. Last updated 2026-07-04.

The short version

  • We connect to your HubSpot via OAuth. We never receive your HubSpot password.
  • The BaseCommand Suite syncs a working copy of your HubSpot deals, contacts, and companies into Supabase to power the dashboard and the agents that run in the background.
  • We do not sell your data, share it with advertisers, or send it to third-party data brokers.
  • All processing happens in the United States.
  • You can disconnect HubSpot, export, or delete your account at any time by emailing privacy@basecommand.ai.

1. Data we collect

Account data

When you sign up for a BaseCommand account at agent.basecommand.ai, we collect: your email address, an encrypted password hash (managed by Supabase Auth), your subscription status (managed by BaseCommand via Stripe), and any preferences you set in the Suite.

HubSpot OAuth connection

When you authorize the BaseCommand HubSpot app, we store encrypted OAuth access and refresh tokens, the HubSpot portal ID, the granted scopes, and the connection timestamp. These are stored in Supabase, encrypted at rest. We never see, store, or transmit your HubSpot login credentials.

Synced HubSpot data (Suite only)

To power the BaseCommand Suite dashboard, we periodically sync a working copy of your HubSpot deals, contacts, companies, and engagement metadata into our database. We store the fields necessary for renewal analysis (deal name, amount, stage, close date, owner, contact email and role, company name and industry, engagement timestamps). We do not sync the body content of emails. Data is refreshed on every sync tick and retained for as long as your portal remains connected.

Agent run history

When you run an agent, we log the agent name, the inputs you provided, the timestamp, and a summary of the output (e.g., account count, risk distribution). This history is visible only to you and is used to show your dashboard activity.

Beta feedback

If you use the in-app feedback button, we store what you wrote, an optional screenshot, the page you were on, and technical context our system captures automatically (recent navigation, console errors, failed requests, browser and viewport). Our support team uses this to triage and reproduce the issue. When a report needs a code fix, an admin can route it into our engineering issue tracker on GitHub; that copy carries the feedback text and its classification only, never your email address or the page URL, both of which stay in our database.

Marketing-site interactions

When you submit your email on basecommand.ai (newsletter signup, demo request, sign-up flow), we record your email, the source page, the day the capture happened, and consent metadata. If you initiate a Stripe Setup Intent to add a payment method, we record the Stripe customer ID and the completion timestamp. We do not store credit card numbers: those are held by Stripe.

Analytics and product usage

We use Google Analytics 4 to understand traffic to basecommand.ai. GA4 cookies record anonymous identifiers, page paths, referrers, and event triggers. We do not enable advertising features or audience-list sharing. You can opt out via your browser settings or by using a privacy-respecting browser.

2. How we use your data

  • To provide the service. Sync HubSpot records, run agents you initiate, write computed values (e.g., risk tier, save play) back to your HubSpot records when you enable writeback, and surface the results in the Suite or on HubSpot record cards.
  • To bill you. Subscription payments are processed by BaseCommand via Stripe. We use your email address to associate your BaseCommand account with your subscription.
  • To communicate with you. Transactional emails (welcome, security notices, billing receipts) sent via Resend. If you opt in, occasional product updates. You can unsubscribe at any time.
  • To improve the product. We review aggregate usage patterns (which agents run, error rates, sync performance) to debug and prioritize. We do not use individual customer HubSpot data for product analytics.
  • To meet legal obligations. Respond to lawful requests (subpoenas, court orders), enforce our terms, and protect against fraud.

We do not use your HubSpot data, your account data, or any data we collect from you to train AI models. No customer data is shared with our LLM provider (Anthropic) for training purposes, only ephemeral inference under enterprise-tier terms.

3. Sub-processors

BaseCommand uses the following sub-processors to deliver the service. Each has been evaluated for security posture and is engaged under a data processing agreement or equivalent.

Sub-processorPurposeLocation
Anthropic (Anthropic PBC)LLM provider (Claude). Called directly by the Suite for agent analysis. API data not used for training under enterprise terms.United States
Supabase (Supabase Inc.)Authentication, encrypted HubSpot OAuth token storage, and the synced HubSpot record cache that powers the SuiteUnited States
Vercel (Vercel Inc.)Hosting for basecommand.ai and agent.basecommand.aiUnited States
Stripe (Stripe, Inc.)Payment processing for the BaseCommand subscriptionUnited States
HubSpot (HubSpot, Inc.)CRM source connected via OAuth; origin of the deal, contact, company, and engagement data the Service analyzesUnited States
Salesforce (Salesforce, Inc.)CRM source connected via OAuth; origin of the account, opportunity, contact, and activity data the Service analyzes on a five-minute incremental read-only syncUnited States
Google (Google LLC)Gmail connector (optional) for email-based renewal context, only when you connect itUnited States
Fathom (Fathom Video, Inc.)Meeting intelligence (optional) for call summaries and transcripts, only when you connect itUnited States
Resend (Resend, Inc.)Transactional email delivery (welcome, security notices).United States
GitHub (GitHub, Inc.)Internal engineering issue tracker, used only when an admin routes a beta feedback report for a fix. Carries the feedback text and its classification, never the email address or page URL of the person who submitted it.United States
Slack (Slack Technologies, LLC)Internal operational alerts to the BaseCommand team about failed jobs or sync errors. Carries system metadata only (job names, error text, an account identifier), never CRM records or contact information.United States
Intercom (Intercom, Inc.)Optional support-health connector for customers who paste an Intercom access token in Settings. Pulls conversation volume and CSAT. Scheduled refresh is not turned on yet, so a connected account does not sync on an ongoing basis today.United States
Amplitude (Amplitude, Inc.)Optional product-usage connector for customers who connect it in Settings. Pulls usage event counts. Same status as Intercom: connectable, scheduled refresh not turned on yet.United States

We will give at least 30 days' notice of new sub-processors that handle customer data. Email privacy@basecommand.ai to subscribe to sub-processor change notices.

4. Sharing and disclosure

We share data only with the sub-processors listed above and only as necessary to deliver the service. We do not:

  • Sell personal data to third parties.
  • Share data with advertising or marketing data brokers.
  • Append, enrich, or resell your HubSpot data to anyone.
  • Use your data to train AI models.

We may disclose data when required by law (subpoena, court order, governmental request) or to investigate suspected fraud, abuse, or violation of our terms. We will notify affected customers unless legally prohibited from doing so.

5. Security

We apply industry-standard safeguards including:

  • HTTPS-only across all surfaces.
  • HubSpot OAuth tokens encrypted at rest with AES-256.
  • Every request is scoped to your account or workspace before it touches the database, so you only ever see your own records. Row-level security is enabled underneath as an additional, defense-in-depth layer.
  • Principle of least privilege for service accounts.
  • Vendor selection biased toward providers with established security posture (SOC 2 Type II or equivalent where available).

BaseCommand itself is not yet SOC 2 certified. See our Security page for current compliance status and the sandbox evaluation path for security reviews.

If we discover a security incident affecting your data, we will notify you in writing within 72 hours of confirmation.

6. Data retention

We retain your data while your account is active and your CRM stays connected. Disconnecting a HubSpot portal or deleting your account purges the synced working copy of your HubSpot data immediately, not on a 30-day timer. Disconnecting Salesforce revokes access and stops the sync; the synced-copy purge for Salesforce isn't wired up yet, so email us to request deletion in the meantime. Residual copies in encrypted backups age out on the normal backup rotation, within 30 days. Some metadata (billing records, audit logs) is retained for up to 7 years to meet tax and legal obligations.

Email privacy@basecommand.ai to request earlier deletion. We will honor the request unless we have a legal obligation to retain the data.

7. Your rights and choices

Depending on where you live, you may have the following rights:

  • Access. Request a copy of the personal data we hold about you.
  • Correction. Ask us to fix inaccurate or incomplete data.
  • Deletion. Request that we delete your personal data, subject to legal retention requirements.
  • Portability. Receive your data in a portable, machine-readable format.
  • Objection. Object to certain processing, such as direct marketing.
  • Withdrawal of consent. Withdraw any consent you previously gave.

To exercise any of these rights, email privacy@basecommand.ai. We respond within 30 days. Disconnecting your HubSpot portal can also be done directly from the connected-apps page in your HubSpot account.

8. International users

BaseCommand is based in the United States and processes data on US infrastructure. If you access the service from outside the United States, you understand that your data will be transferred to and processed in the US. We rely on standard contractual clauses and equivalent transfer mechanisms where applicable. A Data Processing Addendum is available on request for EEA, UK, and Swiss customers.

9. Children

BaseCommand is intended for use by businesses and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, email privacy@basecommand.ai and we will delete it.

10. Changes to this policy

We may update this policy from time to time to reflect changes to the product, our sub-processors, or applicable law. Material changes will be announced via email to active subscribers and via a banner on basecommand.ai at least 14 days before they take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.

Contact us

BaseCommand — Ewing Ventures LLC

Privacy questions: privacy@basecommand.ai

Security incidents: security@basecommand.ai

General support: help@basecommand.ai

For data subject requests, please include your registered email address and the specific right you wish to exercise.

See also: Terms of Service · Security & Trust

The renewal foundation, free to start

Get started free →