Privacy Policy

Last updated: September 14, 2026

ReactionData, Inc. (“Reaction,” “we,” “us,” or “our”) operates the Reaction platform and related services (collectively, the “Service”), accessible at https://reactiondata.com. This Privacy Policy explains how we collect, use, store, share, and protect information when you use the Service, including when you choose to connect third-party accounts such as Google Gmail, Google Calendar, Microsoft Outlook / Teams, and LinkedIn (personal profile and company page).

By using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.

1. Who We Are

Company: ReactionData, Inc.

Address: 1415 E 840 N, Orem, UT 84097, United States

Website: https://reactiondata.com

Privacy contact: privacy@reactiondata.com

2. Information We Collect

2.1 Information you provide

When you register for or use the Service, we may collect:

– Name and contact information (such as email address and phone number)

– Account credentials and organization membership details

– CRM data you or your organization enter (contacts, accounts, notes, tasks, and related records)

– Communications you send through the Service

2.2 Information collected automatically

When you use the Service, we may automatically collect:

– Device and browser information

– IP address and general usage data (pages viewed, actions taken, timestamps)

– Session and authentication cookies necessary to operate the Service

2.3 Information from Google when you connect Gmail or Calendar

If you choose to connect your Google account through Integrations, we access Google user data only after you complete Google’s OAuth consent flow. Depending on the permissions you grant, we may access:

– Basic profile information (name, email address, and profile identifier) via openid, email, and profile scopes

– Gmail data via gmail.readonly and gmail.send, including message metadata (such as subject, sender, recipients, and date), message snippets or previews, and message body content when needed to display threads or send replies from the Communication Log

– Google Calendar data via calendar.events.owned including event titles, descriptions, locations, start and end times
on your primary Google Calendar

– Google Contacts data via contacts.readonly, including contact names, email addresses, phone numbers, and company or organization names from your Google Contacts when you use Import Contacts. This access is read-only; we do not create, edit, or delete contacts in Google

We access Google data only for the connected user who authorized the connection. We do not request access to Google data you have not authorized through Google’s consent screen.

2.4 Information from LinkedIn when you connect

If you choose to connect LinkedIn through Integrations, we access LinkedIn data only after you complete LinkedIn’s OAuth consent flow. Depending on the connection and the permissions you grant, we may access:

– Basic profile information for the person who connected (name, profile identifier, and email address on a member connection) via openid, profile, and email
– Company Pages the connected person administers, including Page identifiers and names, via rw_organization_admin and r_organization_social
– Permission to create and manage posts as that member (w_member_social) and/or as a Page (w_organization_social / r_organization_social)
– Content you compose in Reaction to publish on LinkedIn, including post text, hashtags, destination URLs (including UTM parameters we append), link-card title and description, and attached images, documents, videos, or thumbnails

When LinkedIn has granted our application Community Management access (and the connected account has authorized the relevant scopes), we may also access:

– Page analytics for posts published as a company Page (for example impressions, clicks, reactions, comments, and reposts)
– Member post analytics for posts published as a connected personal profile, when LinkedIn grants r_member_postAnalytics (impressions and related totals LinkedIn makes available for that member; some metrics LinkedIn does not offer for personal profiles)
– Comments, reactions, and related social activity on posts your organization published through the Service, including identifiers for people who engaged and, when LinkedIn returns them, display name, headline, and profile URL

We access LinkedIn data only for connections your organization authorized. We do not request scopes you have not approved on LinkedIn’s consent screen.

3. How We Use Information

We use information to:

– Provide, operate, maintain, and improve the Service

– Authenticate users and manage accounts and organizations

– Enable CRM, workflow, survey, and related product features you use

– Provide customer support and respond to inquiries

– Protect the security and integrity of the Service

– Comply with legal obligations

3.1 How we use Google user data

When you connect Google Gmail or Calendar, we use Google user data solely to provide user-facing features in the Service, including:

– Displaying email history between your connected mailbox and CRM contacts in the Communication Log

– Sending email to CRM contacts from your connected Gmail mailbox when you choose to send a message

– Syncing events from your primary Google Calendar into your CRM calendar, and creating, updating, or deleting events on that primary calendar when you save CRM calendar events

– Retrieving your Google Contacts when you choose Import Contacts in Integrations → Gmail so you can review them and create or merge them into your organization’s CRM contact records. Import is user-initiated; we do not automatically or continuously sync your Google address book

– Maintaining your connection (including refreshing OAuth tokens) so these features continue to work until you disconnect

We do not use Google user data to:

– Serve advertisements, including retargeting or interest-based advertising

– Sell, rent, or license Google user data to data brokers or information resellers

– Determine creditworthiness or for lending purposes

– Train generalized machine learning or artificial intelligence models unrelated to your use of the Service

– Build user profiles for unrelated marketing purposes

3.2 How we use Microsoft/Teams call data

When your organization enables Teams call history sync, we use Microsoft Graph call record metadata solely to show phone and video calls between Outlook-connected Reaction users and CRM contacts in the Communication Log. We only create a log entry when a connected Reaction user participated in the call and another participant matches a CRM contact by email or phone number. 

Call record data we may store includes:

– Call start and end times

– Call type (for example audio or video)

– Participant display names and identifiers needed to match CRM contacts

– A stable reference to the Microsoft call record for deduplication

We do not store Teams call recordings, transcripts, or full meeting content. We do not use Microsoft call data for advertising, selling data, credit decisions, or training unrelated machine learning models.

 

3.3 How we use LinkedIn data

When you connect LinkedIn, we use LinkedIn data solely to provide user-facing features in the Service, including:

– Connecting and displaying the LinkedIn member profile and/or company Page your organization authorized
– Composing, scheduling, and publishing posts to LinkedIn as that member or Page
– Storing draft and published post content in your organization’s Reaction account so you can review, edit (where allowed), and see status
– Showing performance of those posts (counts such as reactions and comments; and, with Community Management, impressions, clicks, reposts, and engagement rate where LinkedIn provides them)
– Displaying comments on those posts in the Service and sending a reply you compose
– Maintaining your connection (including refreshing OAuth tokens) until you disconnect

We do not use LinkedIn data to:

– Serve advertisements, including retargeting or interest-based advertising
– Sell, rent, or license LinkedIn data to data brokers or information resellers
– Build a database of LinkedIn members across unaffiliated customers
– Identify sales or recruiting prospects, create leads, or enrich CRM profiles from people who commented, reacted, or otherwise engaged (unless that person connected their own LinkedIn account, or your organization entered the information itself)
– Train generalized machine learning or artificial intelligence models unrelated to your use of the Service

4. How We Store Third-Party User Data

4.1 OAuth tokens

When you connect Google, we store OAuth access and refresh tokens, granted scope information, and your connected mailbox address in our application database so the integration can operate on your behalf until you disconnect.

4.2 Gmail content

Gmail messages are primarily retrieved from Google when you view the Communication Log or related features. We may also store certain email metadata in your organization’s CRM communication log records (such as subject lines, dates, sender and recipient information, and message previews) to support CRM workflows. We do not operate a separate public email archive outside your organization’s Reaction account.

4.3 Calendar content

Events from your primary Google Calendar synced into Reaction are stored in your organization’s CRM calendar data so they can be displayed and managed within the Service according to your permissions.

4.4 Google Contacts and imported CRM Data

Your Google Contacts are retrieved from Google when you run Import Contacts. We do not maintain a separate copy of your full Google address book outside your organization’s Reaction account. Contact fields you choose to import (such as name, email, and phone number) are stored in your organization’s CRM contact records. Granted OAuth scopes, including contacts.readonly, are stored with your connection as described in section 4.1.

4.5 Security

We use industry-standard safeguards designed to protect data in transit and at rest, including HTTPS for data transmitted over public networks and access controls limiting employee and system access to production data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

4.6 Microsoft Outlook and Teams call metadata

When you connect Microsoft Outlook, we store OAuth tokens, granted scopes, your mailbox address, and your Microsoft Entra user identifier so we can match you to Teams call participants. When your organization enables Teams call sync, we store organization-level subscription state and call log metadata in your CRM communication log records as described in section 3.2. Application permissions for call records are granted separately from mailbox permissions via your organization’s Microsoft admin consent.4.1

3.3 How we use LinkedIn data

When you connect LinkedIn, we use LinkedIn data solely to provide user-facing features in the Service, including:

– Connecting and displaying the LinkedIn member profile and/or company Page your organization authorized
– Composing, scheduling, and publishing posts to LinkedIn as that member or Page
– Storing draft and published post content in your organization’s Reaction account so you can review, edit (where allowed), and see status
– Showing performance of those posts (counts such as reactions and comments; and, with Community Management, impressions, clicks, reposts, and engagement rate where LinkedIn provides them)
– Displaying comments on those posts in the Service and sending a reply you compose
– Maintaining your connection (including refreshing OAuth tokens) until you disconnect

We do not use LinkedIn data to:

– Serve advertisements, including retargeting or interest-based advertising
– Sell, rent, or license LinkedIn data to data brokers or information resellers
– Build a database of LinkedIn members across unaffiliated customers
– Identify sales or recruiting prospects, create leads, or enrich CRM profiles from people who commented, reacted, or otherwise engaged (unless that person connected their own LinkedIn account, or your organization entered the information itself)
– Train generalized machine learning or artificial intelligence models unrelated to your use of the Service

5. How We Share Information

We do not sell your personal information, Google user data, or LinkedIn data.

We may share information only in these circumstances:

– Within your organization: Data you add to Reaction, including synced communication log and calendar data, CRM contacts you import from Google, LinkedIn posts, and LinkedIn performance and comments shown in the Service, is visible to other users in your organization according to your organization’s roles and permissions

– Service providers: We use trusted infrastructure and service providers (such as cloud hosting providers) that process data on our behalf under contractual obligations to protect it and use it only to provide services to us

– Legal and safety: When required by law, legal process, or to protect rights, safety, and security

– Business transfers: In connection with a merger, acquisition, or sale of assets, subject to applicable law and, where required, notice to you

We do not transfer Google user data to third parties except as permitted by the Google API Services User Data Policy, including to provide or improve user-facing features you request, for security purposes, to comply with applicable law, or as part of a merger or acquisition after obtaining your consent where required.

We do not transfer LinkedIn member data to third parties except as needed to operate the LinkedIn features you requested (including sending content to LinkedIn to publish or reply), to our infrastructure providers, for security, to comply with law, or as part of a merger or acquisition where required. We do not export LinkedIn Member Data to your organization as a standalone data feed or to any other customer.

6. Human Access to Google User Data

Our employees and contractors do not read Google user email, calendar, or contacts content, or LinkedIn posts and comments, except:

– When you request support and explicitly authorize us to access specific data to resolve your issue

– When necessary for security purposes (such as investigating abuse or a security incident)

– When required to comply with applicable law

– When data is aggregated and anonymized for internal operations in compliance with applicable law

7. Your Choices and Data Deletion

7.1 Disconnect Google in Reaction

You can disconnect Gmail at any time from Integrations → Gmail → Disconnect. Disconnecting removes your stored OAuth tokens and connection record from Reaction.

7.2 Revoke access in Google

You can revoke Reaction’s access to your Google account at any time through your Google Account permissions page at https://myaccount.google.com/permissions.

7.3 Delete synced and imported CRM data

Communication log entries, calendar events, and CRM contacts previously synced or imported through the Google integration may remain in your organization’s CRM records until deleted by authorized users in your organization or until your organization deletes the relevant records. Disconnecting Gmail or revoking access in Google stops future imports but does not remove CRM records already created. To request deletion of your account or personal data, contact privacy@reactiondata.com.

7.4 Account deletion

If your organization or account is deleted, we delete or de-identify associated data in accordance with our retention practices and applicable agreements, except where retention is required by law.

7.5 Disconnect LinkedIn in Reaction

You can disconnect LinkedIn at any time from Integrations → LinkedIn. Disconnecting removes stored OAuth tokens and the connection record. Posts already created in Reaction remain in your organization’s account until your organization deletes them. Disconnecting does not delete the post on LinkedIn.

7.6 Revoke access in LinkedIn

You can revoke Reaction’s access in your LinkedIn account’s permitted services or authorized apps settings. That stops new API access; it does not by itself delete Reaction records. On request from your organization or from LinkedIn, we delete stored LinkedIn Marketing Data we hold on your behalf within ten (10) days, except where we are required to retain it by law.

8. Google API Services User Data Policy (Limited Use)

Reaction’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Policy URL: https://developers.google.com/terms/api-services-user-data-policy

In particular:

– We limit our use of Google user data to providing or improving user-facing features that are prominent in the Service

– We access only the Google OAuth scopes needed for those features

– We do not use Google user data for prohibited transfers or uses described in Google’s policies

9. LinkedIn Marketing API and Community Management

Our use of LinkedIn APIs and LinkedIn data complies with the LinkedIn Marketing API Terms (https://www.linkedin.com/legal/l/marketing-api-terms), LinkedIn’s developer documentation, and LinkedIn’s Marketing API data storage requirements. We use Community Management and related LinkedIn products only for the use cases we requested: managing posts on connected Pages and member profiles, monitoring engagement on those posts in the Service, and displaying Page (and, where LinkedIn allows, member) post analytics.

10. Data Retention

We retain personal information, Google connection data, and LinkedIn connection data for as long as your account or organization uses the Service and as needed to provide features you enable. When you disconnect Google or LinkedIn, we delete stored OAuth tokens promptly. LinkedIn Marketing Data is retained according to the limits in section 4.7. Other CRM records may be retained according to your organization’s settings and applicable law.

11. Healthcare and HIPAA

Some customers use Reaction in healthcare or other regulated contexts. Where Reaction acts as a business associate to a covered entity, use of protected health information is governed by applicable business associate agreements and regulatory requirements in addition to this Privacy Policy. This Privacy Policy describes our general platform practices; your organization may have separate contractual terms governing regulated data.

12. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us at privacy@reactiondata.com.

13. International Users

Reaction is operated in the United States. If you access the Service from outside the United States, you understand that your information may be processed in the United States and other countries where we or our service providers operate.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes to how we use Google user data or LinkedIn data, we will update this policy and, where required, provide notice and obtain your consent before using that data in a new way.

The “Last updated” date at the top of this page indicates when this Privacy Policy was last revised. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.

15. Contact Us

Questions about this Privacy Policy or our handling of Google or LinkedIn data:

– Email: privacy@reactiondata.com

– Mail: ReactionData, Inc., 1415 E 840 N, Orem, UT 84097, United States