Privacy Policy
Last updated: July 20, 2026
CRM Aide ("we," "our," or "us") operates the CRM Aide customer relationship management application (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service.
1. Information we collect
We may collect the following types of information:
- Account information — name, email address, password (stored hashed), role, profile settings, and theme preferences.
- CRM data — records you create or manage (leads, contacts, deals, invoices, notes, attachments, and related business data).
- Authentication data — session tokens and, if enabled, Google OAuth identifiers when you sign in with Google.
- Email integration data — if you connect Gmail, we store OAuth tokens and sync email metadata and content necessary to display messages and associate them with CRM records.
- Usage and technical data — IP address, browser type, device information, and application logs for security and troubleshooting.
2. How we use your information
We use collected information to:
- Provide, operate, and maintain the Service
- Authenticate users and enforce role-based access controls
- Process CRM workflows (conversions, payments, payroll, email sync)
- Improve security, prevent fraud, and troubleshoot errors
- Comply with legal obligations
3. Google services
If you use Google Sign-In or connect a Gmail account, your use is also subject to Google's Privacy Policy. We request only the scopes needed for authentication and mail features (read/send Gmail where enabled). You may disconnect Gmail at any time from the Email page in the application.
4. Data sharing and disclosure
We do not sell your personal information. We may share data:
- With your organization's administrators who manage the CRM instance
- With service providers that host or support the application (under confidentiality obligations)
- When required by law, court order, or to protect rights, safety, and security
- In connection with a merger, acquisition, or sale of assets (with notice where required)
5. Data retention
CRM records are retained until deleted by authorized users. Soft-deleted records may remain in the Recycle Bin for up to 60 days before permanent removal. Account and authentication data are retained while your account is active and as needed for legal or operational purposes thereafter.
6. Security
We implement reasonable administrative, technical, and organizational measures to protect your data, including encrypted passwords, token-based API authentication, and role-based access controls. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
7. Your rights
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete personal information we hold about you
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Request a copy of your data in a portable format
Contact your organization administrator or us using the details below to exercise these rights.
8. Cookies and local storage
The Service may use browser local storage to persist authentication tokens, theme preferences, and UI settings. These are necessary for core application functionality.
9. Children's privacy
The Service is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect the latest revision. Continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact us
For privacy-related questions, contact your CRM administrator or email crm@aide247.com.