Privacy policy

Shuttio moves CRM data into Attio. This policy explains what personal data that involves, what we keep afterwards, and what you can ask us to do with it.

Last updated: 24 September 2026

Who we are

Shuttio (shuttio.com) is operated by Venturise OÜ, a private limited company registered in Estonia under registry code 17064180, with its registered address at Ruunaoja tn 3, 11415 Tallinn, Estonia. For the account data described below, Venturise OÜ is the controller under the EU General Data Protection Regulation (GDPR).

For anything in this policy, write to support@shuttio.com. We have not appointed a Data Protection Officer; the same address reaches the person responsible for data protection.

Two roles: your account, and your CRM data

We hold two different kinds of personal data, and our role differs between them.

  • Your account. Your email address, your sign-in details and the settings of your migrations. We decide how this is used, so we are its controller.
  • The records you migrate. Contacts, companies, deals, notes, tasks, meetings and list memberships in your source CRM or CSV. You (or your organisation) remain the controller of that data. We process it only on your instructions, to move it into the Attio workspace you connect, which makes us your processor. Business customers who need a data processing agreement under Article 28 GDPR can request one at support@shuttio.com.

What we collect

Account data

  • Your email address, and your name and profile picture if Google provides them.
  • If you sign up with a password: a salted scrypt hash of it. We never store the password itself.
  • If you sign in with Google: your Google account identifier and the sign-in tokens Google returns for it.
  • Single-use tokens for confirming your address (valid 24 hours) and resetting your password (valid 1 hour), stored only as a SHA-256 hash.
  • Rate-limit counters for failed sign-ins, sign-ups and account emails, keyed by email address or IP address, so the sign-in form cannot be brute-forced.

Business profile

Shuttio no longer asks questions about your business. If you answered the earlier intake questionnaire (company name, business type and the rest of that form), those answers are still stored with your account, but nothing reads or uses them.

Connections to Attio and your source CRM

When you connect Attio, HubSpot, Pipedrive or Salesforce we receive an OAuth access token (and, where the provider issues one, a refresh token). Affinity has no OAuth, so it takes an API key you paste in. Each of these is encrypted before it is stored: sealed under its own data key, which is itself wrapped by a master key held outside the database. We also keep non-secret details that identify the connection, such as the Attio workspace name and id, the HubSpot portal domain, the Pipedrive company name, the Salesforce username or the Affinity tenant name. Each connection belongs to the one migration you made it for; no other migration can use it.

Migration data

For each migration you create, we keep the bookkeeping that makes it re-runnable and reversible:

  • its settings: source, object, sample size and status (and, for older migrations, the row filter and target list);
  • the structure mirrored from your source (or, for older migrations, proposed for you) and the version you approved;
  • the field mapping you reviewed, including any names and types you changed (and, for older migrations, any value rewrites);
  • a ledger of every object, attribute, option, record, note, task, meeting and list entry the migration created in Attio, identified by Attio id;
  • a map from each source record id to the Attio record id it became;
  • a per-record receipt for every row that failed or was skipped, with the reason. A reason can quote the value Attio rejected, such as a malformed email address or phone number;
  • run counts and a summary of the outcome;
  • the field list the Fields step read from your source and your destination, with up to three example values per field. It is encrypted, used for at most 24 hours, and deleted within 48 hours by a daily purge, together with the migration's credentials.

What we do not keep

  • Your records. Rows from HubSpot, Pipedrive, Salesforce or Affinity are read from the source and written to Attio inside the migration job. They are not stored in our database, apart from the three example values per field described above. When you ask to look up a failed row in the results view, we fetch it live from the source and do not save it.
  • Your uploaded CSV. A CSV imports in full, with no sample. The file is deleted when the import finishes or you roll it back. A run that is paused or stopped on an error keeps it until you resume, retry or roll back. A CSV sample started before CSV imports ran in full keeps its file for up to 30 days; then it is deleted.

Why we use it, and our legal basis

  • To provide the service (Art. 6(1)(b) GDPR, performance of a contract): creating your account, connecting your systems, mirroring your structure and mapping, running, pausing, resuming and rolling back migrations, and emailing you when one finishes.
  • To keep the service secure (Art. 6(1)(f), legitimate interests): confirming email addresses, rate-limiting sign-in attempts, and investigating errors.
  • To give you support(Art. 6(1)(b) and (f)): a small number of Venturise OÜ staff can view your account email and a migration's settings, status and failure receipts in an internal admin view when helping you or diagnosing a failure. They cannot see your credentials in readable form.

We do not sell personal data, use it for advertising, or use your records to train any model. Shuttio loads no analytics or advertising trackers.

What reaches the AI model

Shuttio uses Anthropic's Claude for two things. First, when you upload a CSV, it guesses what each column holds (an email, a date, a choice from a list). For each column it receives the column name, at most three sample values, each truncated to 80 characters, and, for a column with 25 or fewer distinct values, how many there are. Those sample values can contain personal data from your file. Second, the help chat: when you use it, Claude receives our product documentation, the messages you type (the conversation is kept in your browser, not on our servers) and, on a migration page, a summary of that migration made of counts, statuses, option choices and error groups, never a record value, name, email or source id. Nothing from a connected CRM's records reaches the model: its structure is mirrored from the CRM's own schema by code, and the record stream never passes through the model either. Anthropic processes these requests as our subprocessor under its commercial terms: it does not use API inputs or outputs to train its models, and it deletes them within 30 days.

Subprocessors

These are the only third parties that process personal data on our behalf.

Subprocessor
Vercel Inc.Hosts the application and its server functions, and keeps request and function logs.
Neon (Databricks, Inc.)Postgres database that stores everything described in this policy.
Inngest Inc.Runs migrations as durable background jobs. It receives a migration id only, never credentials or records.
Anthropic PBCClaude guesses the type of each column in a CSV you upload, as described below.
ResendSends account emails (address confirmation, password reset) and, when enabled, migration completion notices.
Google LLCGoogle sign-in, if you choose it.

Attio, HubSpot, Pipedrive, Salesforce and Affinity are not our subprocessors: they are the systems you connect, under your own agreements with them. We read from your source and write only to the Attio workspace you authorise.

International transfers

Several of our subprocessors are based in the United States, so personal data may be processed outside the European Economic Area. Where it is, we rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses.

Our database (Neon) and application servers (Vercel) run in the United States (AWS US East). Vercel, Databricks (Neon), Anthropic, Resend and Google are certified under the Data Privacy Framework. Inngest receives no personal data, only a migration id.

How long we keep it

  • Import packages for Odoo: an import package is kept encrypted and deleted 7 days after it is built, or when you finish the load guide, whichever comes first. Its download links work for 24 hours, and only for you.
  • The Odoo app: if you use our Odoo app, the records waiting for your Odoo are kept encrypted, and deleted as soon as your Odoo confirms them, and after 24 hours at most. The app's access is stored only as a fingerprint, and you can disconnect it from Odoo or from Shuttio at any time.
  • Uploaded CSV files: deleted when the import finishes or you roll it back; a paused or failed run keeps it until you resume, retry or roll back. A CSV sample started before CSV imports ran in full keeps its file for up to 30 days.
  • Credentials:each belongs to one migration and is deleted 14 days after the migration finishes (done, failed or rolled back), and revoked with the provider where the provider allows it. A migration that is running or paused keeps its access. If you need the migration again later, you reconnect it on the migration's page.
  • Values that could not be written: When a single value could not be written to your destination (a malformed email, a number that is not a number), the migration's Errors tab lists it with the object, the field, the source record's id, our own explanation, the destination's error code and HTTP status, and up to 200 characters of the value. The destination's error message is never stored. The value is deleted 14 days after the migration finishes, at the same time as its credentials; the rest of the line stays with the migration.
  • Account, business profile and migration data: for as long as your account exists, so you can re-run or roll back a migration later. When your account is deleted, all of it is deleted with it. We do not delete inactive accounts automatically; you can ask us to delete yours at any time.
  • Sign-in rate-limit counters and email links: rate-limit counters are cleared when you next sign in successfully. Email confirmation links expire after 24 hours and password-reset links after 1 hour, and each is deleted once used.
  • Server logs: our application logs record ids and counts, not your records or credentials, and our hosting provider keeps them for no more than 3 days.

Cookies

We use only cookies that the service needs to work:

  • a session cookie that keeps you signed in;
  • short-lived cookies (ten minutes) that protect an OAuth connection against forgery and remember which page to return you to afterwards.

Because they are strictly necessary, they do not require consent.

Security

Credentials are encrypted at rest under envelope encryption, and only one module in the codebase can decrypt them. Background jobs carry a migration id and nothing else. Every request re-checks that you own the migration it touches. The full detail is on our security page.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • have your data deleted;
  • restrict or object to processing based on legitimate interests;
  • receive your data in a portable format;
  • withdraw any consent you have given, without affecting earlier processing.

Access to your systems ends on its own 14 days after the migration finishes; email us if you want it ended sooner. To exercise any other right, including deleting your account, email support@shuttio.com from the address on your account. We answer within one month.

Deleting your Shuttio account does not remove records a migration already created in your Attio workspace; those belong to you. Roll the migration back first if you want them gone. We delete our copy of each token 14 days after the migration finishes and revoke it where the provider allows; you can also remove Shuttio in your Attio, HubSpot, Pipedrive or Salesforce settings at any time.

If you believe we have handled your data unlawfully, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or to the supervisory authority where you live.

Children

Shuttio is a business tool and is not intended for anyone under 16.

Changes to this policy

If we change how we handle personal data, we will update this page and the date at the top. For material changes we will also email account holders before they take effect.

Contact

Venturise OÜ, Tallinn, Estonia · support@shuttio.com