Privacy policy.

Effective 9 September 2026 · Last updated 9 September 2026

1. Who we are

Boulton (“Boulton,” “we,” “us”) operates a business-to-business software platform for outbound client acquisition. Boulton is operated by BayRise Capital Partners LLC d/b/a Boulton AI, a Florida limited liability company.

Contact: privacy@boulton.ai
Mailing address: 16703 Early Riser Ave, Land O Lakes, FL 34638

This policy explains what information we collect, why, how we use it, who we share it with, how long we keep it, and how to stop being contacted or have your information removed.

2. Who this policy covers

Boulton serves business customers. Three groups of people appear in this policy:

  • Client users — people at our business customers who log into Boulton.
  • Prospects — business contacts our clients choose to reach out to using Boulton.
  • Website visitors — anyone visiting our public site.

If you received a message and want it to stop, go straight to our do-not-contact page.

3. Information we collect

3.1 From client users

Name, business email address, business phone, job title, company, login credentials, and activity within the platform (pages viewed, actions taken).

3.2 From clients about their prospects

Our clients load, or direct us to compile, business contact information about the companies and people they want to reach. This is typically: name, job title, business email address, employer, company website, company size, industry, LinkedIn profile URL, and publicly available business information.

We obtain this information from our clients directly, and from commercial business-data providers and public web sources. Clients determine who is targeted. Clients are responsible for their lawful basis to contact those prospects.

3.3 From connected accounts (Google, Calendly)

See Section 5 — this is disclosed separately and in detail.

3.4 Automatically

IP address, browser type, device information, and usage logs, for security and to operate the service.

3.5 Payment information

Payments are processed by Stripe. We do not store card numbers, card brands, or any part of a card number. We store a Stripe customer identifier, a subscription identifier, and subscription status. All payment card data is held by Stripe, not by us.

4. How we use information

  • To provide, operate, secure, and support the platform.
  • To send outbound messages at our clients’ direction, from our clients’ own sending accounts.
  • To classify, route, and summarize replies our clients receive.
  • To enrich and verify business contact data so messages reach valid recipients.
  • To bill clients and prevent fraud.
  • To meet legal obligations.

We use artificial intelligence and large language model providers to draft message copy, classify replies, and generate campaign strategy. See Sections 5.4 and 7.

We do not sell personal information. We do not use personal information for advertising or ad targeting. We do not use tracking pixels in outbound messages by default.

5. Google user data — access, use, storage, sharing, and Limited Use

This section governs data obtained through Google APIs and takes precedence over any general statement elsewhere in this policy.

5.1 What we access

When a Boulton user chooses to connect their Google Calendar, we request the following OAuth scopes:

ScopeWhat it permitsWhy Boulton requests it
https://www.googleapis.com/auth/calendar.freebusy Read busy/free intervals To determine when the user is free, so the platform can offer a prospect real open times.
https://www.googleapis.com/auth/calendar.events Create and manage calendar events To create the meeting event on the user’s calendar when a prospect books a time.
https://www.googleapis.com/auth/calendar.readonly Read calendars and events To identify which calendars the account holds, and the user’s primary calendar and time zone, at the point of connection.

We request no Gmail scopes, no Drive scopes, and no Contacts scopes.

5.2 What we do with it

  • Read: We query free/busy intervals on the connected calendar to compute available meeting slots to offer a prospect. We do not read the titles, descriptions, or attendees of the user’s existing events.
  • Write: We create a calendar event only when a meeting is agreed, and only on the connected user’s own calendar.
  • We do not modify or delete events Boulton did not create.

5.3 What we store

We store the OAuth access and refresh tokens, encrypted at rest, so the connection persists between sessions. We store the identifier and start/end time of events Boulton creates. We do not store the contents, attendees, titles, or descriptions of the user’s pre-existing calendar events.

5.4 What we do not do

  • We do not use Google user data for advertising of any kind, including retargeting or personalized advertising.
  • We do not sell or transfer Google user data to third parties, data brokers, or information resellers.
  • We do not use Google user data to train, develop, or improve any generalized or non-personalized artificial intelligence or machine learning model.
  • We do not send the contents of your calendar events to our AI providers. Availability — open time slots computed from your calendar’s busy/free information — is provided to the model that drafts the reply, solely so that it can offer meeting times to a prospect.
  • We do not allow humans to read Google user data, except: (a) with the user’s explicit prior agreement, for support; (b) where necessary for security purposes such as investigating abuse or a bug; (c) where required by law; or (d) where the data is aggregated and de-identified for internal operations.

5.5 Limited Use affirmation

Boulton’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5.6 Revoking access

A user may disconnect their calendar at any time within Boulton, or revoke Boulton’s access directly at their Google account permissions page. On disconnection or revocation we revoke the token with Google and delete our stored copy. To request deletion of remaining associated data, email privacy@boulton.ai.

6. Prospect information — notice to recipients

If you received a message sent through Boulton and want to know why:

  • The message was sent by our client, not by Boulton. Boulton is the software platform our client used.
  • Your business contact information was obtained from publicly available business sources or commercial data providers, and the decision to contact you was made by our client.

How to stop being contacted

There are two different things you can ask for, and they are not the same:

What you wantHowWhat happens
Stop hearing from this one sender Reply to the message and say so We suppress you for that client only. Other Boulton clients may still contact you.
Stop hearing from anyone using Boulton Our do-not-contact page We add you to our platform-wide do-not-contact list. No client using Boulton can message you again.

Replying to one sender does not remove you from the platform. If you want to be gone entirely, use the second row.

To ask what information we hold about you, or to have it removed, see Section 10.

7. Who we share information with

We share information with service providers who help us run the platform. They are bound to use it only to provide services to us.

Some of these are our providers. Others are accounts our clients own and connect themselves. The distinction matters, so we state it.

7.1 Our service providers

  • Hosting and infrastructure: Railway (backend), Vercel (frontend), Neon (database), and a managed job queue.
  • Artificial intelligence / model providers: Anthropic, OpenAI. Used to draft message copy, classify replies, extract information from client materials, and generate strategy.
  • Contact data sourcing, enrichment and verification: AI Ark, LeadMagic, MillionVerifier, Enrichley.
  • Website content: Firecrawl (public company websites — no personal data).
  • Sending infrastructure: ScaledMail (domains and mailboxes), Spaceship (domain registration — no personal data).
  • Billing: Stripe.
  • Transactional email: Resend.
  • Error monitoring: Sentry. Configured with personal data collection disabled and event scrubbing enabled.
  • Internal operations alerting: Slack.

7.2 Accounts our clients connect themselves

These are our clients’ own accounts, under their own contracts. We act on them at the client’s direction; they are not our subprocessors:

PlusVibe · Instantly · HeyReach (LinkedIn) · GoHighLevel · Notion · Google Calendar · Calendly

7.3 EmailBison — either, depending on the client

EmailBison is used for email sequencing and delivery. Depending on the client, either Boulton provides the account (in which case EmailBison is our service provider) or the client connects their own EmailBison account (in which case it is theirs). Clients can determine which applies to them in their workspace settings.

The full list, with the purpose and data category for each provider, is maintained in the Subprocessors section of our Terms of Service, which carries its own last-updated date. Processing locations are available on request.

We may also disclose information where required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets.

8. Data retention

We are specific about this because a stated retention period we did not honor would be worse than saying nothing.

  • Contact and company information. Business contact records — name, job title, employer, business email, and similar factual business information — are retained as part of our ongoing business database. We do not delete them on a fixed schedule. This is factual business information that we also source independently from commercial data providers. See Section 10 for how to have your own information removed.
  • Client user accounts. Retained for the life of the account.
  • Client campaign data (targeting, message content, campaign records). Available to the client for export for 30 days after termination, and retained thereafter except where we are required to delete it.
  • Do-not-contact and opt-out records. Retained indefinitely and deliberately — we cannot keep honoring your request not to be contacted unless we remember that you made it. This is the one category we will not delete.
  • Google OAuth tokens. Deleted when you disconnect or revoke access.
  • Security and audit logs. Retained for operational and security purposes. We do not currently operate a fixed deletion schedule for these.

We do not currently run automated deletion on a schedule. Where you ask us to remove your information, we handle that on request — see Section 10.

9. Security

We encrypt data in transit and encrypt credentials and access tokens at rest. Access to production systems is limited to personnel who need it. We do not currently hold a SOC 2 or ISO 27001 certification. We will describe our current security posture honestly on request.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to processing. To exercise them, email privacy@boulton.ai, or use our do-not-contact page. We will respond within the time required by applicable law.

If you ask us to remove you, here is exactly what we do:

  1. We add you to our platform-wide do-not-contact list, so that no client using Boulton can message you again. This is checked before any message is sent.
  2. We delete the personal information we hold about you.
  3. We keep the minimum record needed to keep honoring your request — because we cannot refuse to contact you in future if we do not remember that you asked. That record exists only to keep your request working. It is never used to contact you and it is not used for anything else.

One limitation, stated plainly: we obtain business contact information from third-party data providers. A record about you may therefore be supplied to us again in future by one of them. Our do-not-contact list is checked before any message is sent, so you will not be contacted — but we cannot promise that no record about you will ever re-enter our systems.

Where Boulton processes prospect information at a client’s direction, that client is the controller and we are the processor. We will refer your request to them and assist them in responding.

California residents: We do not sell or share personal information as those terms are defined under the CCPA/CPRA.

11. International transfers

We are based in the United States and our service providers are primarily located in the United States. If you are outside the United States, your information will be transferred to and processed in the United States.

12. Children

Boulton is a business tool and is not directed to anyone under 18. We do not knowingly collect information from children.

13. Changes to this policy

If we change how we use Google user data, we will update this policy and prompt affected users to consent before the new use takes effect. For other changes, we will update the date at the top and, where the change is material, notify clients.

14. Contact

BayRise Capital Partners LLC d/b/a Boulton AI
16703 Early Riser Ave
Land O Lakes, FL 34638
privacy@boulton.ai