Bad HubSpot data costs deals and forecast trust.Start free audit
Revenue Hub LatamHubSpot Audit
Back

Privacy Policy

Last updated: 4 October 2026

Overview

HubSpot Audit is operated by Revenue Hub Latam SpA ("Revenue Hub Latam"), based in Santiago, Chile, at www.revenuehublatam.com/hubspot-audit. This policy explains what data we access when you connect a HubSpot portal, what we store, who can see it and how we protect it.

Revenue Hub Latam is responsible for your account data. For the data we read from your HubSpot portal, the company that owns the portal decides what is processed, and we process it on its behalf to provide the service.

The short version: we store your audit results, including the examples from your CRM that support each finding, so you can come back to them. They are stored securely and, within HubSpot Audit, only your account can see them; our team and the providers that run the service access them only as described below. We do not sell your data.

Data We Access

When you connect a HubSpot portal with OAuth and run an audit, HubSpot Audit reads the following through the official HubSpot API, within the permissions you approve:

  • Contacts, companies, deals, line items and tickets, with the properties the checks need (for example names, email addresses, owners, stages, amounts and dates)
  • Activities (calls, meetings and tasks): counts, dates, outcomes and owners
  • Portal configuration: properties, pipelines and stages, workflows, forms, lists, marketing emails, custom objects and associations, and campaigns when your HubSpot permissions allow it
  • HubSpot users, owners, teams and seats, including names, email addresses, roles and last login dates
  • Conversation threads and message timestamps, to measure response times, and the number of customer survey responses
  • Account information such as portal ID, name, time zone and currency, plus API usage, login history, audit logs and security activity (such as data exports and app installs) when your HubSpot plan provides them

Audits run only when you request them: HubSpot Audit does not keep a continuous sync of your CRM. The audit only reads. When you connect, HubSpot also lists optional write permissions for contacts, companies, deals, lists and users; only the paid action tools use them, and each change asks for your confirmation first.

How We Protect Your Data

  • Your HubSpot access and refresh tokens are encrypted with AES-256 before they are stored. The encryption key is kept as a server environment variable, separate from the database.
  • Tokens are used only to call the HubSpot API on your behalf. We do not write them to logs, send them to your browser or share them with the AI provider or any other third party.
  • Passwords are stored only as bcrypt hashes. Your session uses a secure, httpOnly cookie that expires after 7 days.
  • Every request for saved results is checked against your signed-in account and the selected portal. Report files sit in private storage, behind download links that expire after one hour.
  • Data is encrypted in transit (HTTPS) and, at our database provider Supabase, at rest.
  • Session recordings in our analytics tools hide the text shown in the dashboard, so they do not capture your audit results.
  • You can revoke access at any time by uninstalling the app in HubSpot (Settings, Integrations, Connected Apps; its HubSpot listing name is currently Portal Audit).

What We Store

We store the following in our database and private file storage, hosted by Supabase:

  • Account data: your name, email address, username, language, whether you are an agency or the company that owns the portal, and the optional profile details you add (company, phone, company size, industry and the purpose of your audit), plus your password as a bcrypt hash.
  • HubSpot connection: portal ID and name, the permissions HubSpot granted and your encrypted access and refresh tokens.
  • Audit results: the latest result of each audit section for each portal you connect, so you can come back to your findings and generate reports. Results contain scores, counts and findings, and the examples from your CRM that support each finding: names of properties, pipelines, stages, workflows, forms, lists and campaigns; names and subject lines of marketing emails; names, email addresses and login activity of HubSpot users and owners; HubSpot audit-log and security events (who did what and when); and a limited number of example records per finding, such as the name and email address of a contact or the name, stage and amount of a deal. Running a section again replaces its previous result.
  • Operating context: the answers you give to the context questions for each portal, including any notes you type.
  • Reports: the AI-written executive narrative, saved with your audit results, and a copy of each generated PowerPoint report, kept in private storage. Excel, YAML and JSON exports are generated when you download them and are not kept.
  • White-label settings: only if you buy the white-label add-on: your company name, logo and website, and the contact name, email address and phone shown on your reports.
  • Activity logs: which audits and actions you ran and when, including the IDs of HubSpot records changed by an action you confirmed and a short description of the change.
  • Payments: what you bought, the amount and the Stripe references. Stripe handles your card details; we never see or store them.

Who Can See Your Data

Your audit results are stored securely and only you can view them in HubSpot Audit: the user who connected the portal, after signing in. HubSpot Audit does not have shared team workspaces. If a colleague connects the same HubSpot portal from their own account, they get their own separate results, and results and reports are not shared between accounts.

Keep your password confidential, as the Terms of Service require: anyone who signs in with it can see your results.

To run and support the service, our team can see account details such as your name, email address, connected portal names and activity. We open your audit results only when you ask us for help, when it is needed to keep the service secure and working, or when the law requires it.

AI Processing

When you generate the executive report, HubSpot Audit asks an AI model from DeepSeek to write its narrative. Our servers send DeepSeek a summary of your audit: scores, counts and findings; pipeline totals and amounts at risk; your operating-context answers, including any notes you typed; the countries or regions HubSpot logins came from; and a limited set of names taken from the findings: names and email addresses of HubSpot users and owners, names of pipelines, stages, properties, workflows, forms and lists, up to three stuck deal or ticket names per pipeline, and the contact names on the five longest-unanswered conversations.

We do not send your full CRM records, the email addresses of example contacts or your HubSpot tokens. The narrative is saved with your audit results. It is written by AI and can contain errors, so review it before you share it.

DeepSeek is based in China and processes and stores what it receives on servers in the People's Republic of China. Its privacy policy allows it to keep that data and to use it to train and improve its models; our requests do not include any setting that limits that retention or use.

Service Providers

We use these providers to run HubSpot Audit and share with each one the data it needs for its job:

  • Supabase: database, private file storage and the server functions that run the audits. It holds everything listed under What We Store.
  • Netlify: hosts the web application and its server functions.
  • DeepSeek (China): writes the AI narrative from the audit summary described above.
  • Stripe: processes payments; it receives your email address and the HubSpot portal ID the purchase is for.
  • Resend: sends account emails, such as email confirmation and password reset.
  • Slack: notifies our team when someone creates an account or makes a purchase (name, email address, account type, and product and amount for purchases).
  • Analytics: Google Analytics and Microsoft Clarity (through Google Tag Manager), PostHog, and the tracking code of Revenue Hub Latam's own HubSpot account record how the product is used. When you sign in, we link this activity in PostHog to your email address and to the ID and name of the HubSpot portal you selected, and your email address and first name are added as a contact in Revenue Hub Latam's own HubSpot account. PostHog and Clarity can record sessions. In the dashboard, recordings hide the text on screen and PostHog does not keep the text of the elements you click, so your audit results are not captured; PostHog also hides what you type into form fields.

These providers process data outside Chile and possibly outside your country. Supabase stores our database and files in the United States, PostHog processes analytics in the United States and DeepSeek processes the AI summary in China. We transfer data to these countries only to run the service.

How We Use Your Information

We use your account details to run the service, send account emails such as email confirmation and password reset, answer your support requests and understand how the product is used. We use the data we read from your HubSpot portal to produce your audit, your reports and the actions you confirm. Our analytics receive your audit scores and the number of findings, not the findings or the CRM records behind them.

Cookies

HubSpot Audit sets its own cookies only to keep you signed in and to secure the step where you connect HubSpot. Google Analytics, Microsoft Clarity, PostHog and HubSpot set their own cookies to measure how the product is used. You can block analytics cookies in your browser settings; the service does not need them to work.

What We Never Do

  • Sell your data or your HubSpot data.
  • Share your HubSpot data with other customers or with third parties, beyond the service providers listed above, except when the law requires it.
  • Use your HubSpot data for advertising or to contact the people in your CRM.
  • Store your HubSpot tokens or your password in plain text.
  • Change anything in HubSpot without your explicit confirmation.

Data Retention and Deletion

We keep your account data and audit results while your account is active, until you delete them or ask us to.

  • Removing a portal in HubSpot Audit deletes, for your user, its stored connection, its saved audit results and AI narrative, and the PowerPoint reports generated for it. Activity logs for that portal are kept until you delete your account or ask us to delete them.
  • Uninstalling the app in HubSpot revokes our access to the portal, but does not delete what is already stored. Remove the portal in HubSpot Audit as well, or ask us to delete it.
  • If you administer a HubSpot portal and want us to delete everything stored about it, from every HubSpot Audit account that connected it, email us from an address in that HubSpot account.

To delete your account, or to get a copy of your data, email us at roberto@revenuehublatam.com. We delete your data from HubSpot Audit's database and file storage and ask our analytics providers to delete your profile. We complete deletion requests within 30 days and confirm by email. We only keep what the law requires us to keep, such as payment records. Deleted data can remain in our database provider's backups for a limited time, until they are overwritten.

Your Rights

You can ask us to access, correct, delete or export your personal data, or object to its use, by emailing roberto@revenuehublatam.com. We reply within 30 days. You can also complain to the data protection authority in your country.

Security Incidents

If a security incident affects your data, we will notify you and HubSpot without undue delay.

Changes to This Policy

We will post changes to this policy on this page and update the date at the top. For significant changes, we will email account holders before they take effect.

Contact

Questions about this privacy policy? Write to roberto@revenuehublatam.com.