Plain-language note: This policy explains the information ReachHawks processes, why we use it, when service providers may receive it and how users can request access, correction or deletion. ReachHawks is operated by Email Verse, LLC.
1. Who we are
ReachHawks is an outbound and inbound sales-engagement software product operated by Email Verse, LLC. ReachHawks is treated as a separate product for branding, product and website purposes while Email Verse, LLC is the legal business entity behind the Service.
Sheridan, Wyoming 82801
United States
2. Scope
This Privacy Policy applies to visitors of the ReachHawks website, account holders, workspace owners, administrators and members, people who contact us, and individuals whose business information may be uploaded or processed by ReachHawks customers.
3. Customer and ReachHawks roles
For contact lists, inbound leads, campaign recipients, message content and CRM records submitted by a customer, the customer generally determines why and how the information is used. ReachHawks processes that data to provide the configured Service. For website analytics, account administration, security, billing and our own service communications, Email Verse, LLC may act as an independent controller or business.
4. Information we process
4.1 Account and workspace information
- Name, business email, authentication data, workspace name, role, permissions, plan, subscription status and settings.
- Invitations, workspace membership, support messages, feedback and account-management events.
4.2 Contacts, campaigns and CRM data
- Names, business emails, company information, job titles, LinkedIn URLs, tags, notes, list fields and CSV data.
- Campaign content, sequence steps, A/B variants, send events, bounce events, unsubscribe/suppression status, reply classifications and CRM stage activity.
4.3 Inbound and newsletter data
- Form submissions, webhook payloads, inbound messages, newsletter subscriber information and routing fields.
4.4 Hawk AI training and conversation data
- Website URLs or extracted business context, PDF/DOCX content you choose to upload, reply history, conversation context, suggested responses, approval decisions, meeting-booking context and training-confidence signals.
4.5 Connected-service data
- Configuration, tokens or credentials needed to connect supported mailboxes, SMTP providers, Slack, CRM systems, calendars, AI providers, LinkedIn integrations and automation tools.
- We treat access credentials and tokens as confidential operational data and limit their use to operating the connection you configure.
4.6 Technical and usage data
- IP address, browser/device information, timestamps, sessions, product usage, logs, queue events, error records, security events and feature interactions.
4.7 Billing data
- Plan, invoices, transaction identifiers, billing email, country and payment-status information. Complete card details are generally handled by the payment processor rather than intentionally stored on ReachHawks servers.
5. How we use information
- Operate accounts, workspaces, authentication and permissions.
- Send campaigns and newsletters, process inbound leads, maintain Unibox and CRM activity, and provide mailbox rotation, suppression, bounce and unsubscribe features.
- Run Hawk AI classification, reply suggestions, meeting scheduling, CRM actions and configured automation.
- Provide list verification when purchased or enabled.
- Operate integrations you authorize.
- Support users, troubleshoot errors, prevent abuse and maintain security and reliability.
- Administer subscriptions, add-ons and billing.
- Analyze aggregated usage and improve product quality.
- Comply with law, enforce our Terms and respond to lawful requests.
6. AI providers and subprocessors
When Hawk AI is enabled, relevant conversation text, training context and instructions may be sent to the AI provider you configure, such as OpenAI, Anthropic/Claude, Google Gemini or DeepSeek, or to a provider used by ReachHawks if you choose a ReachHawks-managed AI option. The selected provider’s terms and privacy practices also apply.
We may also use service providers for hosting, databases, email delivery, monitoring, payments, support, analytics, validation and infrastructure. We aim to share only the information reasonably needed for the provider’s function.
7. Connected mailboxes, calendars, CRM and other integrations
When you connect a third-party service, ReachHawks may access, transmit or store the minimum information reasonably required to perform the feature you enabled. Disconnecting a service may stop future synchronization but may not automatically delete historical data already stored in your workspace.
8. Legal bases and GDPR-informed practices
Where GDPR or similar laws apply, processing may rely on contract performance, legitimate interests, consent, legal obligations or customer instructions, depending on the context. We follow practices informed by GDPR principles such as transparency, purpose limitation, data minimization, accuracy, storage limitation and integrity/confidentiality.
ReachHawks does not currently claim ISO 27001 or SOC 2 certification and does not claim that every customer use case or configuration is automatically GDPR-compliant. Customers are responsible for determining their own lawful basis, notices, consent requirements and obligations for prospect or lead data.
9. Information sharing
We may share information with authorized workspace members, service providers needed to operate the Service, professional advisers, regulators or law-enforcement authorities where legally required, and successors in a merger, financing, restructuring or sale. We do not sell customer-uploaded contact lists or conversation data as a standalone database and do not authorize third parties to use Customer Content for their own independent marketing merely because it is processed through ReachHawks.
10. Data retention
We retain information only as long as reasonably necessary to provide the Service, maintain records, prevent abuse, comply with law and resolve disputes. Workspace data, contacts, campaign history, CRM records, message history and training materials may remain until deleted by an authorized user or according to product retention rules. Billing and security records may be retained longer where reasonably required.
11. Security
We use reasonable administrative, technical and organizational measures designed to reduce unauthorized access, misuse, loss or disclosure. These practices include encrypted HTTPS transport, authentication controls, role-based workspace permissions, limited administrative access, operational logging and protected handling of integration secrets. No online service can guarantee absolute security.
12. Your rights and choices
Depending on your location and whether an applicable privacy law covers the relevant processing, you may have rights to request access, correction, deletion, restriction, portability, objection, withdrawal of consent or information about how personal information is used. You may also have rights relating to direct marketing, targeted advertising, sale or sharing of personal information, profiling or automated processing. Requests can be sent to hello@reachhawks.com. We may need to verify identity and may retain information where required for legal, billing, fraud-prevention or security reasons.
13. Account and data deletion
Authorized account holders may request account or workspace deletion through available in-app controls or by contacting us. Deletion requests are subject to verification, workspace authority, legal retention requirements, backups and records we are required to retain.
14. Cookies and similar technologies
We may use cookies, local storage and similar technologies for authentication, security, session continuity, preferences, embedded scheduling, performance measurement and, if enabled, analytics. We distinguish between technologies that are strictly necessary to provide a service requested by the user and technologies that are not strictly necessary.
14.1 EU and UK visitors
Where EU ePrivacy rules or UK PECR require consent, non-essential cookies and similar technologies should not be placed or accessed before the visitor gives an affirmative choice. Strictly necessary technologies may be used without consent where the applicable exemption permits it. When non-essential analytics, advertising or similar technologies are enabled, ReachHawks will use consent controls designed to let EU and UK visitors accept or reject those technologies before they load, and to change or withdraw their choice later.
14.2 United States visitors
For U.S. visitors, cookie and tracking choices are provided as required by applicable state law. Many U.S. state privacy laws focus on opt-out rights for sale, targeted advertising or certain forms of sharing or profiling rather than requiring prior consent for ordinary non-sensitive processing. Rights and requirements vary by state, and affirmative consent may still be required for certain sensitive-data processing or other regulated uses.
14.3 Browser and consent signals
You may also restrict cookies through browser controls. Where applicable law requires us to recognize a legally valid universal opt-out preference signal, we will honor that signal for the processing to which it applies. Blocking strictly necessary technologies may prevent parts of the Service from functioning correctly.
15. Marketing communications
You may opt out of ReachHawks marketing emails using the unsubscribe mechanism provided or by contacting us. Transactional messages, security alerts, billing notices and material service-policy updates may still be sent where necessary.
16. International processing and transfers
Email Verse, LLC is based in the United States, and ReachHawks and its service providers may process personal information in the United States and other countries. Where a transfer from the European Economic Area to a country without an applicable adequacy decision requires an Article 46 safeguard, our primary contractual transfer mechanism is the European Commission's 2021 Standard Contractual Clauses for international transfers, as applicable to the parties and processing. Where a restricted transfer from the United Kingdom requires an appropriate safeguard, we use the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as applicable. We may also rely on another lawful transfer mechanism where the law permits it.
ReachHawks does not currently claim certification under the EU-U.S. Data Privacy Framework. A transfer mechanism, contractual safeguard or provider certification is not a substitute for the other privacy, security and transparency obligations that may apply to the processing.
17. EU and UK visitors and customers
If the GDPR or UK GDPR applies to your personal information, the rights available to you may include access, correction, erasure, restriction, portability, objection and withdrawal of consent where consent is the legal basis. You may also have the right to complain to the competent supervisory authority. These rights are subject to legal conditions and exceptions.
Where ReachHawks processes Customer Content on behalf of a customer acting as controller, ReachHawks generally acts as a processor or service provider for that processing. A Data Processing Addendum (DPA) covering applicable processor obligations and, where relevant, international-transfer safeguards can be made available on request by contacting hello@reachhawks.com.
Customers remain responsible for determining the lawful basis and direct-marketing rules that apply to their own prospecting, recipient lists and campaigns, including GDPR, UK GDPR, the EU ePrivacy framework, UK PECR and any country-specific electronic-marketing rules. ReachHawks provides workflow controls such as unsubscribe and suppression handling, but the Service does not make a customer's outreach lawful by itself.
18. U.S. state privacy rights
Residents of certain U.S. states may have privacy rights under laws such as the California Consumer Privacy Act as amended by the CPRA and other comprehensive state privacy laws. Which law applies, and which rights are available, depends on the state, the type of data and whether the applicable statutory thresholds and exemptions are met.
Where applicable, rights may include the right to know or access personal information, correct inaccuracies, request deletion, obtain a portable copy, opt out of sale, targeted advertising or certain profiling, limit certain uses of sensitive personal information, and exercise rights without unlawful discrimination. Some states also provide a right to appeal a denied request.
California disclosure: ReachHawks does not sell personal information and does not share personal information for cross-context behavioral advertising as the terms “sell” and “share” are defined by the CCPA/CPRA. We also do not sell customer-uploaded contact lists or conversation data as a standalone database. If our practices change, we will update this Policy and provide legally required choices before using personal information in a materially different way.
Privacy requests may be submitted to hello@reachhawks.com. We may verify the requester's identity and authority before acting on a request. Where applicable, an authorized agent may submit a request on your behalf, subject to legally permitted verification. We will respond within the time required by the applicable law.
19. Children and sensitive information
ReachHawks is intended for professional and business use and is not designed for children. Do not intentionally upload highly sensitive information such as government IDs, passwords, biometric data, health records, financial account credentials or children’s data unless the processing is lawful, necessary and specifically authorized.
20. Changes to this policy
We may update this policy as ReachHawks changes. The “Last updated” date identifies the current version. Material changes may be communicated through the website, app, email or another reasonable channel.
21. Contact
For privacy questions, access requests, deletion requests, DPA requests or security concerns, contact hello@reachhawks.com.
