Privacy notice for the Sales Bench
Version of 25 September 2026. This page shows the date of the current version.
The Sales Bench is the working software of Heartful GTM, a line of business of Heartful Services Ltd. This notice is for people who sign in to it: people who work for Heartful Services, and the staff of our clients. It explains what the Sales Bench holds about you, why, and what you can do about it.
Who is responsible
Heartful Services Ltd is the controller of the account data described on this page.
Heartful Services LtdSummit House, 4-5 Mitchell Street
Edinburgh, EH6 7BD
United Kingdom
Registered in Scotland, company number SC638807.
Privacy contact: alex at heartful-services dot com
How you sign in
You sign in with your Google account. The Sales Bench has no passwords of its own and stores none.
When you sign in, your browser goes to Google, and Google sends you back with a one-time code. The Sales Bench exchanges that code directly with Google. It asks Google only for your basic profile and email address, and from Google's answer it keeps four facts: your Google account identifier, your email address, your name, and whether Google has verified your email address.
You can only get in if a Heartful director or CSO has invited you first. The invitation creates your account under the email address you were invited with, and your first sign-in links it to your Google account. A sign-in without an invitation is refused and creates nothing.
What is stored about you
- Your account: your Google account identifier, the provider (Google), your email address, your name, whether you hold the platform role "director", your residency zone, your account status, when the account was created and when you last signed in. Your name and the time of your last sign-in are updated each time you sign in.
- Your access to each client: which role you hold in which client's workspace, who invited you, when you joined and, if your access was withdrawn, when.
- Your residency zone is used for one check: a person in the role "cso" or "operator" can only be given access to a client whose data must stay in a zone that admits theirs. For the other roles it is not checked.
- Access keys you create for the browser extension or other tools: the name you gave the key, its permissions, its expiry, when it was last used and whether it was revoked. The key itself is never stored, only a one-way hash of it. The extension keeps your key, the Sales Bench address and its own counters in your browser's local storage on that device only.
- Your work in a client's workspace: if you send outreach, a sender seat with your display name, your LinkedIn member identifier if recorded, your time zone and your send window. Each recorded touchpoint, draft, assignment and profile look-up names the person who prepared, performed, assigned or requested it. If you use the extension's connections scan, the connections it reads from your own LinkedIn connections list (name, headline and profile address of each) are stored against your account in that client's workspace.
- An audit trail of certain actions, such as creating or changing a client or its branding, moving a contact to another stage, reassigning work, recording a capture from the extension, starting a connections scan, and reporting who performed a touchpoint. Each entry records who did it and when.
Other people with access to the same client's workspace can see your name next to work you did there, within what their role allows.
The databases that hold this data are kept in Cloudflare's EU jurisdiction. Your account is kept while you have access. When access to a client is withdrawn, the record of that access is marked as ended rather than deleted, and the audit trail keeps who did what.
Cookies and sign-in state
The Sales Bench sets one cookie for your session, __Host-sb_session. It holds your account identifier, a random identifier for this session, the host name you signed in on, and when the session started and ends, signed so it cannot be altered. It lasts 12 hours. It is marked HttpOnly, Secure and SameSite=Lax, and it is valid only on the exact host that set it.
Signing out clears the cookie in your browser and records the random session identifier on the server as ended, so that a copy of the cookie stops working too. That record holds the random identifier and nothing else: not your account identifier, not your name, not the host. It is deleted when the session would have expired, at most 12 hours later. It is kept in Cloudflare's key-value store, which is not limited to the EU.
While a sign-in is in progress, a short-lived record (which provider, a one-time verifier, a one-time value that ties Google's answer to this sign-in, the host, and the page to return to) is kept for at most 10 minutes and deleted when the sign-in completes. A second cookie, __Host-sb_signin, holds that one-time value in your browser for the same 10 minutes, so that the sign-in can only be completed in the browser that started it. It is cleared when the sign-in completes.
The Sales Bench uses no analytics and no advertising cookies, and it loads no scripts, fonts or images from third parties.
Logs
The Sales Bench runs on Cloudflare Workers, with Cloudflare's Workers Logs switched on for every request. For each request Cloudflare records a log entry with details of the request and the response, such as the address requested, the time and the outcome, together with technical details Cloudflare holds about the request. Those details can include the network (IP) address the request came from and the headers your browser sent. Cloudflare keeps these logs for 7 days.
The Sales Bench's own log lines name people by internal identifier, not by name or email. When something fails, the technical details of the error go to the log and not to your screen.
Why, and on what legal basis
We use your data to let you sign in, to give you the access your role requires and nothing more, to keep a record of who did what for accountability to our clients, and to keep the service secure.
We process your account data because it is necessary for our legitimate interests in providing the Sales Bench securely to our clients and our team, and in keeping a record of who did what (Article 6(1)(f) UK GDPR). Where you work for Heartful Services under a contract with us, it is also necessary to perform that contract (Article 6(1)(b) UK GDPR).
Your rights
You have the right to access the data held about you, to have it corrected or erased, to restrict its processing, to object to processing based on our legitimate interests, and, where the processing rests on a contract with you, to receive your data in a portable form.
To use any of these rights, or to object, email alex at heartful-services dot com. Heartful Services handles every request.
You also have the right to complain to the Information Commissioner's Office (ICO), the supervisory authority in the United Kingdom, at ico.org.uk.