This Privacy Policy explains how Hanse Performance UG (haftungsbeschränkt) ("we", "us") processes personal data when you install and use the QuickClick app for Pipedrive ("the App"). We are the data controller for the processing described here.
QuickClick adds a panel with configurable action buttons to the detail view of your Pipedrive deals, contacts and organizations. When a user presses a button, the App triggers a webhook URL that you have configured, so you can start your own automations.
When you install the App, you grant it access through Pipedrive's OAuth 2.0 with the following read-only scopes:
The App never has write access to your Pipedrive data.
On our servers we store only what is needed to run the App:
What we do not store: We do not copy or retain the contents of your deals, contacts or organizations. When a button is pressed, your browser sends the current record's type, ID, the acting user's ID and a timestamp directly to the webhook URL you configured. That payload does not pass through, and is not stored by, our servers.
The webhook URLs you enter point to services that you control (for example n8n, Make, Zapier or your own API). Any data sent to those destinations is processed under your responsibility and the privacy terms of those services. You are responsible for ensuring you are permitted to send that data there.
We process this data to perform our contract with you (Art. 6(1)(b) GDPR) and on the basis of our legitimate interest in operating and securing the App (Art. 6(1)(f) GDPR).
Data is stored on servers located in Germany, operated by Hetzner Online GmbH (Gunzenhausen, Germany) acting as our processor. Data is processed within the EU.
We keep your configuration and tokens for as long as the App is installed. When you uninstall QuickClick from your Pipedrive account, Pipedrive notifies our server and we automatically delete your OAuth tokens and all stored configuration for your account. You may also request deletion at any time by emailing info@hanseperformance.de.
OAuth tokens are stored server-side and are not exposed to the browser. Every request from the panel to our API is verified using a short-lived, signed token (JWT) issued by Pipedrive. Traffic is encrypted via HTTPS.
The App does not use advertising or tracking cookies. Each session is authenticated with the signed token provided by Pipedrive.
Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, and to object to processing. You also have the right to lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at info@hanseperformance.de.
We may update this Privacy Policy from time to time. The current version is always available at this URL, with the effective date shown above.