1. Two roles: our data vs. your data
Account & site data (your registration, login, billing, support and usage of our website): we are the controller.
Customer Data (the clients, contacts, notes, sales, cases, documents and messages your company stores in its workspace): your company is the controller and we are the processor: we only handle it on your instructions to provide the Service. Individuals whose details are held in a customer's workspace should direct privacy requests to that customer; we will assist them.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Registration & contact | Company name, your name, email, phone, business address, current CRM, plan and deployment choices, acceptance of the Terms (time + version) | You (invite request form) |
| Account & login | Email, hashed password, role, workspace membership, login timestamps | You / your administrator |
| Billing | Plan, seats, invoices, usage counts (e.g. SMS sent, database size); payment card details are handled by our payment processor, not stored by us | Your use of the Service |
| Licensing & devices | License key, a hashed machine fingerprint (hardware identifiers), OS/platform, app version, check-in times | Desktop application |
| Technical & diagnostics | IP address, browser/user-agent, pages requested, error reports and stack traces (with personal data scrubbed where possible) | Automatic |
| Communications with us | Support requests, contact-form messages, emails | You |
| Customer Data | Whatever your company chooses to store in its workspace, including messages sent to your clients via the Service | Your company (processor role) |
3. How we use it
- Provide, operate, secure and support the Service and your workspace.
- Provision accounts and send transactional email (invitations, password links, invoices, usage and trial notices).
- Bill for plans and add-ons; prevent fraud and abuse; enforce our Terms and license.
- Diagnose errors, monitor performance and improve the product (aggregate, de-identified where possible).
- Respond to your requests and, with your consent or where permitted, tell you about product updates. You can opt out of marketing at any time.
- Comply with legal obligations.
Legal bases (where GDPR applies): performance of a contract, our legitimate interests (running and securing the Service), consent (marketing, non-essential cookies if any), and legal obligation. We do not sell personal information and do not use Customer Data for advertising or to train models.
4. Who we share it with (sub-processors)
We use a small number of service providers to run TechieCRM. They may process personal information only on our instructions:
| Provider | Purpose |
|---|---|
| Railway (hosting) | Application hosting, PostgreSQL and MongoDB databases, backups |
| Our email provider (SMTP) | Sending transactional email from admin@techiecrm.com |
| Twilio | SMS numbers and message delivery (only if your workspace enables the SMS add-on) |
| Error monitoring (e.g. Sentry) | Crash and error reports for reliability |
| Payment processor | Card processing for subscriptions (when online payments are enabled) |
| Domain / DNS registrar | Serving techiecrm.com |
We may also disclose information if required by law, to protect rights and safety, or as part of a merger or acquisition (with notice). We will update this list as providers change.
5. Where data is stored
Our production systems are hosted in data centres in the United States (US-West). If you are outside the US your information is transferred there; we rely on our providers' contractual safeguards. Customers requiring in-country hosting can choose the local-server or desktop deployment options, where Customer Data stays on infrastructure you control.
6. Retention
- Registration requests that are not provisioned: up to 12 months, then deleted.
- Account and billing records: for the life of the account and as required for tax/accounting (typically 7 years for invoices).
- Customer Data: while your workspace is active, plus 30 days after termination for export, then deleted from live systems; backups roll off on their schedule (daily/weekly/monthly, up to ~90 days).
- Logs and diagnostics: short rolling windows (typically ≤ 90 days).
7. Security
All traffic is encrypted in transit (HTTPS/TLS; HSTS enabled). Passwords are stored hashed. Each customer workspace is an isolated database. Credentials your workspace stores for its own integrations (e.g. your outbound email account) are encrypted at rest. Access to production is limited to authorised personnel. Managed database backups run daily/weekly/monthly. No system is perfectly secure; if we become aware of a breach affecting your information we will notify you as required by law.
8. Your rights & choices
Depending on where you live you may have the right to access, correct, export, restrict or delete your personal information, to withdraw consent, and to complain to a privacy regulator (in Canada, the Office of the Privacy Commissioner). To exercise these rights email admin@techiecrm.com. Workspace administrators can update most account details directly in the Service. For information held in a customer's workspace, contact that customer; we will support them in responding.
9. Cookie notice
TechieCRM uses only strictly necessary cookies:
| Cookie | Purpose | Lifetime |
|---|---|---|
sessionid | Keeps you signed in to the portal | Session / up to 2 weeks |
csrftoken | Protects forms against cross-site request forgery | 1 year |
tc_cookie_notice (local storage) | Remembers that you dismissed the cookie notice | Persistent |
We do not use advertising or third-party tracking cookies. Because these cookies are essential, they do not require consent; you can block them in your browser but the portal will not work without them. Session storage is used to remember UI state (e.g. which menu sections are open).
10. Email & SMS communications
We send transactional messages needed to run your account (invitations, password links, invoices, usage notices). Product or marketing emails are optional and include an unsubscribe link. Messages your company sends to its clients through the Service (email from your own identity, SMS via your rented number) are your responsibility, including consent and opt-out handling under CASL/TCPA and similar laws; the Service records those messages in your workspace.
11. Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect their personal information.
12. Changes
We may update this policy. Material changes will be announced to workspace administrators by email or in-app before they take effect; the "last updated" date above always reflects the current version.
13. Contact
Privacy questions or requests: admin@techiecrm.com or via our contact page.