ACQUIRED

Privacy policy

Last updated: 7 October 2026

This policy explains how Acquired (“we”, “us”) handles information when you use our business acquisition research, deal pipeline and outreach service.

1. Information we collect

  • Account information, such as your name, email address, organisation, account membership and authentication records.
  • Workspace information you provide or save, including acquisition mandates, buyer profiles, company research, business contacts, notes, message drafts and campaign settings.
  • Business research from public websites and configured data providers, including company information, source evidence and business contact details.
  • Connected-account information, including account identifiers, granted permissions and authentication credentials needed to operate integrations you enable.
  • Service records, including session information, operational logs, errors, audit events and campaign delivery or reply status.

2. How we use information

We use information to authenticate users, maintain organisation workspaces, research businesses, evaluate acquisition criteria, generate and save outreach drafts, run campaigns you enable, detect replies, provide support and protect the service. Information saved in an organisation workspace may be accessible to other authorised members of that organisation.

3. Connecting Gmail

Connecting Gmail is optional and separate from signing in. We request your Google account identity and email address, plus these Gmail permissions:

  • gmail.compose: create, update and delete Gmail drafts and send messages for outreach features you authorise. The Google permission also allows reading drafts.
  • gmail.readonly: search relevant message history and read message metadata to check for existing conversations, detect replies and prevent inappropriate follow-ups. This permission technically allows reading email, although the current reply checks use message identifiers, sender headers and timestamps rather than message bodies.

We store the connected email address, granted scopes and encrypted refresh token, together with relevant Gmail draft, message or thread identifiers and campaign status records. Draft content you create in Acquired is stored in your workspace and sent to Google when you save or send it. Approving a draft and enabling an automated campaign are different actions; enabled campaigns may send messages without a further approval for every scheduled message.

You can revoke Acquired’s access at any time through your Google Account connections. Revocation prevents further access once existing access tokens expire or Google rejects them. It does not automatically delete workspace records or messages already saved or sent in Gmail. Contact us to request deletion of information held by Acquired.

4. Google data and Limited Use

Acquired’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.

Google user data is used only to provide or improve the user-facing features you enable. We do not sell Google user data, use it for advertising, or use it to develop, improve or train general-purpose or non-personalised AI or machine-learning models. Transfers are limited to delivering these features, security purposes, legal obligations or a business transfer consistent with these policies. Human access to Google user data is limited to circumstances allowed by those policies, such as your affirmative consent for support, security investigations, legal requirements or permitted aggregated and anonymised internal operations.

5. Service providers and AI features

Acquired uses infrastructure providers for hosting, database storage, research, authentication and email delivery. AI features send relevant buyer-profile information, business research and contact context to the configured AI provider to generate research or outreach content. Current Gmail reply checks do not send inbox message bodies to AI providers.

Providers process the information needed to deliver their services. Where you connect other outreach channels, those providers receive the account and message information needed for the features you enable. Information may be processed outside your country, depending on the provider and deployment configuration. We may disclose information where required by law or necessary to address fraud, abuse or threats to security.

6. Cookies and security

We use session cookies for authentication and browser storage for preferences such as your colour theme. The service encrypts stored Gmail refresh tokens and applies organisation-scoped access controls. You are responsible for protecting your account credentials and controlling access to your workspace.

7. Retention and deletion

Workspace records are retained to provide your account and organisation’s service. Revoking an integration is separate from deleting stored information. You may request account closure, deletion of connected-account credentials or deletion of personal information by contacting us. We may retain records needed to meet legal obligations, resolve disputes or protect the service; backup copies may remain until their normal replacement cycle. We will explain any applicable retention limits when responding to your request.

8. Your choices

You can update information through available account and workspace controls, choose which integrations to connect, revoke Google access, and request access to or correction or deletion of your personal information. Organisation administrators may control workspace information shared with their members. Acquired is intended for business users and is not directed at children.

9. Changes and contact

We may update this policy as the service changes. The date above identifies the latest version. Material changes to how we use Google data will require any additional notice or consent required by Google’s policies.

For questions about Acquired, privacy requests, account closure or complaints, contact the Acquired support contact who provided your account or the user support email shown on the Google consent screen. Identify your account and organisation and describe your request. Do not send passwords or access tokens.