Privacy Policy

Effective July 20, 2026

1. What we collect

Account data — your name, email, and password hash when you sign up (or your Google profile basics if you sign in with Google). Workspace data — the CRM records your team stores: contacts, companies, deals, notes, documents, messages, invoices. Usage data — logs of requests and errors needed to operate and secure the Service, including IP addresses.

2. How we use it

To provide and improve the Service, secure accounts, send transactional email (invites, receipts, reminders, trial notices), and provide support. We do not sell personal data, and we do not use your workspace data to train AI models or for advertising.

3. Who processes it (subprocessors)

We rely on a small set of infrastructure providers: Vercel (hosting), Supabase (database), Stripe (payments), Resend (email delivery), Twilio (SMS delivery, when you connect it), and Google (sign-in, Gmail sending, and Calendar, when you connect them). Each receives only what it needs to perform its function.

4. Google user data

When you connect a Google account, AliveMindCRM requests only the minimum scopes needed for the features you choose to use:

  • Send email on your behalf (gmail.send) — so you can send individual, one-to-one emails to your own contacts from inside the CRM, sent as you. We use this only to transmit messages you compose and send. We do not read, search, download, or store the contents of your mailbox. AliveMindCRM has no Gmail read access of any kind.
  • Calendar events (calendar.events) — so AliveMindCRM can create and update the meetings you schedule through the app and show them on your calendar. We do not read unrelated calendars.
  • Basic profile (openid, userinfo.email, userinfo.profile) — your name and email address, used to identify the connected account.

Google account data is used solely to provide these features at your direction. It is never sold, never used for advertising, never used to train AI or machine-learning models, and never transferred to anyone except as needed to deliver the feature you requested or where required by law. OAuth tokens are stored encrypted (AES-256-GCM), and you can disconnect a Google account at any time from Settings, which revokes our access.

AliveMindCRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Your contacts' data

Workspace owners are the controllers of the contact records they store; we process that data on their behalf. Marketing emails sent through AliveMindCRM include an unsubscribe link, and opt-outs are enforced automatically. If you believe an AliveMindCRM customer holds your data, contact them directly or email us and we will pass the request along.

6. Retention and deletion

Workspace data is retained while the workspace is active. Deleted workspaces are held for 30 days (in case of accidental deletion) and then permanently destroyed. You can export your data (CSV) at any time from the app. To delete your account entirely, contact us.

7. Security

Data is encrypted in transit (TLS) and at rest. Connected provider credentials (e.g. Stripe, Twilio) are stored encrypted with AES-256-GCM. Passwords are hashed with bcrypt. Access to production systems is restricted and logged.

8. Cookies

We use only essential cookies: your session cookie (to keep you signed in) and security tokens. No third-party advertising or analytics cookies are set.

9. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data. Email us and we'll respond within 30 days.

10. Contact

Privacy questions: [email protected]. See also our Terms of Service.