Privacy Policy
Last updated 1 September 2026
FunnelFab is operated by RETHINK AI ("RETHINK AI", "we", "us"). This policy explains what personal information the FunnelFab service at funnelfab.com and app.funnelfab.com handles, why, and what choices you have.
1. Two different roles
FunnelFab is a tool businesses use to build marketing funnels and collect enquiries. That means we handle two kinds of personal information, under two different responsibilities, and it matters which one applies to you.
- Operators — the people who sign up for a FunnelFab account and build funnels. For their account data we are the controller: we decide why and how it is processed, and this policy governs it directly.
- Leads — the people who fill in a form on a funnel an operator published. For that data we are a processor: we store and transmit it on the operator's instructions. The operator is the controller and their own privacy policy governs it. If you submitted a form and want your data corrected or erased, contact the business whose funnel you filled in. If you cannot reach them, write to us and we will route the request.
2. Information we collect from operators
| Category | What it includes | Why |
|---|---|---|
| Account | Name, email address, hashed password or Google sign-in identifier, email verification state, sessions | To create and secure your account and keep you signed in |
| Workspace | Workspace names, members, invitations, roles, API keys | To let teams share funnels and control access |
| Content | Funnels, pages, uploaded images and media, custom domains, email and automation content you author | To render and publish what you build |
| Billing | Subscription and plan state, discount codes redeemed, invoice and payment events | To operate paid plans and issue receipts |
| Connections | Credentials and access tokens for services you connect, always encrypted at rest | To send email or pass leads to tools you have chosen |
| Usage | Page views, clicks, scroll depth, form field interactions, device type, coarse location derived from IP, and periodic screenshots of your own published pages used to render heatmaps | To give you funnel analytics and to keep the service reliable |
We do not handle your card details. Payments are taken by Stripe on their own systems. We receive only the subscription status and the last four digits and brand of the card, never the full number.
3. Information collected through published funnels
When someone completes a funnel an operator published, we store the answers they submit — which typically include a name, email address and phone number, and whatever else that operator chose to ask — together with the interaction events described above. We hold this for the operator. We do not sell it, we do not use it to build advertising profiles, and we do not use one operator's leads to benefit another.
4. Google user data
FunnelFab offers two separate, optional Google integrations. Each is a distinct OAuth client and each asks only for what it needs.
Sign in with Google
If you choose to sign in with Google, we request the openid, email and profile scopes. We receive your Google account's email address, name and profile picture, and we use them solely to create your FunnelFab account, identify you at sign-in and display who you are to your own workspace. We do not receive or request access to your Gmail messages through this integration.
Connect a Gmail sending mailbox
If you choose to send funnel email from your own mailbox, we request the https://www.googleapis.com/auth/gmail.send scope. This scope permits sending only. It does not permit reading, searching, modifying or deleting any message in your mailbox, and we do not do any of those things. We use it exclusively to deliver the email you have configured your funnel to send, from your own address. We store the resulting refresh token encrypted with AES-256-GCM and use it for no other purpose.
Limited Use. FunnelFab's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising, we do not sell it, and we do not allow humans to read it except with your explicit permission, to resolve a specific support issue you have raised, for security purposes, or where required by law.
You can disconnect a mailbox at any time from the senders screen in the FunnelFab studio, or revoke our access directly at myaccount.google.com/permissions. Disconnecting deletes the stored token.
5. Service providers
We share personal information with the following providers, only as needed to run the service. We do not sell personal information to anyone.
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting, database, file storage, caching, analytics and page-screenshot rendering |
| Stripe | Subscription billing, and payment processing for operators who sell through their funnels |
| Resend | Transactional and platform email we send you |
| Sign-in, and sending from a Gmail mailbox you connect | |
| Microsoft | Sending from an Outlook mailbox you connect |
| Pexels | Stock image search, when you use it |
| Tools you connect yourself | Whatever integration you enable, such as a CRM, receives the data you direct to it |
We may also disclose information where we are legally required to, or to protect the rights and safety of our users and the service.
6. Retention
- Account and workspace records are kept while your account is open.
- Funnels, leads and media are kept until you delete them or close your account. Deleting a funnel removes its leads.
- Connected-mailbox tokens are deleted as soon as you disconnect the mailbox.
- Billing records are retained for as long as tax and accounting rules require, even after an account closes.
- Analytics events are retained on a rolling basis for reporting, and are not tied to a named individual once aggregated.
Closing your account removes your content. Ask us and we will confirm the deletion in writing.
7. Security
Traffic is encrypted in transit with TLS. Credentials and OAuth refresh tokens are encrypted at rest with AES-256-GCM using keys held outside the database, so database contents alone cannot decrypt them. Passwords are stored hashed, never in readable form. Access to production systems is limited to people who need it. No system is perfectly secure, and we do not claim otherwise — if a breach affects your data we will tell you.
8. Your choices and rights
Depending on where you live you may have the right to access, correct, export or delete your personal information, to object to or restrict how it is used, and to complain to a data protection authority. Most of this is self-service in the studio; for anything else, write to us at privacy@funnelfab.com and we will respond within 30 days.
Platform emails about tips and product news carry an unsubscribe link and opting out never affects transactional mail such as verification, password resets and billing notices.
9. International transfers
FunnelFab runs on globally distributed infrastructure, so your information may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for those transfers.
10. Children
FunnelFab is a business tool and is not directed at children under 16. We do not knowingly collect their personal information. If you believe a child has given us data, contact us and we will delete it.
11. Changes
We may update this policy. When we make a material change we will revise the date at the top and, for significant changes affecting operators, notify you by email.
12. Contact
Questions, requests or complaints about privacy go to privacy@funnelfab.com.