CRM Dost is a customer relationship management platform operated by IT SPAR (OPC) Private Limited ("CRM Dost", "we", "us"). It is offered as a web app, an Android app, an iOS app, a public website at crmdost.com, and public pages that our customers publish (property listings, web forms and chat widgets).
This policy explains what information we collect, why, who we share it with, how long we keep it and what choices you have. It applies to everyone who visits our website, creates an account, uses a workspace as a team member, or interacts with a CRM Dost customer through a form, a chat widget, a listing page, an email or a WhatsApp conversation.
1. Who is responsible for your data
CRM Dost plays two different roles, and your rights depend on which one applies.
- For your own account, your billing details, your use of our website and apps, and our product analytics, CRM Dost decides how the data is used. We are the "data fiduciary" under India's Digital Personal Data Protection Act, 2023 and the "controller" under laws such as the GDPR.
- For the data a customer enters into its workspace — its leads, contacts, employees, attendance records, messages, listings and documents — that customer decides how the data is used and we process it on the customer's instructions. The customer is the fiduciary or controller and CRM Dost is the processor. If you are a lead, a contact or an employee of a CRM Dost customer and want your data corrected or deleted, contact that customer first; we will help them honour your request.
2. What we collect
Account and sign-in. Your name, email address, phone number, profile photo if you add one, and a sign-in identity. Sign-in is provided by Firebase Authentication with email and password, Google Sign-In or Sign in with Apple; we store the identifier those services give us, never your Google or Apple password. Your email address is verified before a workspace can be joined or created.
Workspace and organisation data. The company name, industry, country, time zone, currency, office locations and settings of each workspace, the roles and permissions of its members, invitations sent to join it, and the plan it is on.
Customer data you enter (leads and contacts). Everything a workspace records about its leads and customers: names, phone numbers, email addresses, addresses, source, status and pipeline stage, deal values and currencies, notes, tags, call and meeting logs, follow-up dates, documents and images, lead history, and assignments to team members. CRM Dost stores it so the workspace can use it; we do not use it for our own purposes.
Team, attendance and payroll data. For workspaces that use the Team and Attendance modules: employee profiles, reporting managers, designations, shifts and rosters, check-in and check-out times, the GPS coordinates captured at the moment of a punch, the office geofence the punch was judged against, work-from-home and field-visit declarations, leave requests and balances, holidays, regularisation and approval records, and the monthly attendance figures used for payroll. A selfie or photo is stored only where the workspace has switched that on.
Communications data. Messages exchanged with leads through the WhatsApp inbox (via the WhatsApp Business Platform), emails composed and sent from the email workspace and their delivery status, website chatbot conversations, web form submissions, and any attachments in those conversations.
Connected mailboxes and domains. If a workspace connects its own mailbox to send email: SMTP host, port and username with the password encrypted at rest; or, for a Gmail or Microsoft 365 account connected with OAuth, the mailbox address and an encrypted refresh token; or, for an authenticated sending domain, the domain name and the DNS records we asked the customer to publish. See section 6.
Email engagement data. For each email sent through the workspace: a per-recipient tracking token, whether and when the email was opened (a one-pixel image), which links were clicked and when, unsubscribe requests, and bounce or complaint notices returned by mail servers. Opens and clicks record the recipient's browser or mail client identifier ("user agent"); we do not record the recipient's IP address with them.
Payment and billing data. The plan chosen, billing currency, invoices, transaction and subscription identifiers from Razorpay or Stripe, the last four digits and brand of a card when the gateway reports them, GST or tax identifiers if you give them, and AI credit purchases. Card numbers, CVV codes and bank credentials are entered on the payment gateway's pages and never reach CRM Dost.
Device and usage data. The device model, operating system and version, app version and build, language, a push-notification token when you allow notifications, an install identifier used for live updates of the app, IP address, the screens and pages you open, the actions you take (for example "lead created" or "email sent" — never the content), performance timings, and crash reports. Session replays used to diagnose problems mask everything you type.
Support and correspondence. Emails, chat messages and feedback you send us, and notes about how we resolved them.
Website visitors. On crmdost.com we collect standard server logs, analytics events, and the details you submit through contact, demo or sales forms.
3. How we use information
- To provide the service: create and secure your account, run your workspace, sync data across the web and mobile apps, send notifications you have asked for, and deliver messages and emails on your behalf.
- To operate attendance and location features the workspace has enabled: judge a punch against the office geofence, record work-from-home or field visits, calculate hours, leave and payroll figures, and show them to the people the workspace has authorised.
- To bill you: process subscriptions, renewals, upgrades, AI credit purchases and refunds, issue invoices and comply with tax law.
- To support you: answer questions, investigate problems, and, with your consent or when strictly needed to resolve a support case, view your workspace in the way you see it ("impersonation" by our support staff, which is logged).
- To keep the service safe: detect abuse, spam, fraud and security incidents, enforce sending limits, and honour unsubscribe, bounce and complaint signals.
- To improve the product: understand which features are used and where people get stuck, measure performance and fix crashes. We use aggregated and pseudonymous analytics for this and never sell it.
- To communicate with you: service announcements, security notices, billing messages, and, if you opt in, product news. Every marketing email has an unsubscribe link.
- To meet legal obligations and to establish, exercise or defend legal claims.
Where the GDPR applies, our legal bases are performance of the contract with you, our legitimate interests in running, securing and improving the service, your consent where we ask for it (for example location, notifications, marketing and connected mailboxes), and compliance with law.
4. AI features (CRMDostAI)
CRMDostAI powers optional features such as drafting emails, generating web forms and answering website chat visitors. When you use one, the relevant text (for example your instructions, the lead's name and context, or a visitor's question and the conversation so far) is sent to an AI model provider to produce a response. Our current provider is OpenAI; we may add or change providers and will list them in section 10.
- AI features are switched off for the whole platform by default and are enabled by CRM Dost per feature; a workspace uses them only when it chooses to.
- Providers process the text to generate the response under their API terms, which prohibit using API data to train their models.
- We do not send your whole database to a provider — only what the feature needs for that request.
- AI output can be wrong. Review a draft before you send it, and a generated form before you publish it. The chatbot is clearly presented as automated to visitors, and hands over to a person when it cannot help.
- For each AI request we record usage metadata for billing and reliability (which feature, tokens used, model, duration, cost in credits) but never the prompt or response text in our analytics.
5. WhatsApp, chatbot and web forms
WhatsApp. The WhatsApp inbox uses Meta's WhatsApp Business Platform. Messages you send and receive pass through Meta and are stored in your workspace so your team can read and reply to them. Meta processes the messages under its own terms and privacy policy. Customers must have the recipient's consent to message them on WhatsApp, use approved message templates where Meta requires them, and stop messaging anyone who asks.
Website chatbot and web forms. A customer can embed a chat widget or a form on its own website. What a visitor types is collected on behalf of that customer and becomes a lead or a conversation in the customer's workspace. The widget stores a session identifier in the visitor's browser so the conversation continues across pages; a phone number given in the chat may be verified with a one-time code. The customer is responsible for telling its visitors that it uses CRM Dost and for its own privacy notice.
Public property pages. Listings a customer publishes are shown on a public website. Enquiries submitted there go to the customer. A listing the customer marks as sold, rented or draft is no longer shown.
6. Connected email accounts and email tracking
Emails you write in CRM Dost are sent from your own address, never from a CRM Dost address, using one of three methods you choose in Settings.
- SMTP mailbox: you give us your mail server details and an app password. The password is encrypted at rest and used only to hand your emails to your mail server.
- Gmail or Microsoft 365 connected with OAuth: you sign in with Google or Microsoft and grant CRM Dost permission to send email as you. For Gmail we request only the gmail.send permission. We use it solely to send the emails you compose through the Gmail API; we never read, list, search or modify your messages, labels, contacts or settings, and we request no other Gmail permission. For Microsoft 365 we request the Mail.Send permission with the same restriction. The refresh token we receive is stored encrypted and is used only to obtain a short-lived access token at the moment of sending. You can disconnect the mailbox at any time under Settings, or from your Google Account or Microsoft account permissions page, after which we delete the token.
- Authenticated domain: you publish DNS records that let our delivery service (Amazon SES) sign email from your domain. We store the domain name, the records and their verification status.
CRM Dost's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Information obtained through a connected Google account is used only to provide the email-sending feature you connected it for, is not used for advertising, and is never sold or shared with third parties except as necessary to provide that feature or as required by law.
Tracking. When a workspace switches on open or click tracking, each email carries a one-pixel image and rewritten links that pass through CRM Dost. The recipient's mail client fetching the image or the link records an open or a click against that recipient. Every bulk email carries an unsubscribe link and the one-click List-Unsubscribe header; a recipient who unsubscribes is added to the workspace's suppression list and is not emailed by that workspace again. Addresses that bounce permanently or complain of spam are suppressed automatically.
7. Location, notifications and device permissions
- Location is requested only when you check in or out, or use a feature that needs it (a field visit, the lead map). Coordinates are captured at that moment, not continuously, and are visible to the people in your workspace who manage attendance. You can refuse the permission; the workspace may then ask you to punch from the office network or with an approval instead.
- Notifications are sent only after you allow them. The push token identifies your device to Firebase Cloud Messaging; you can turn notifications off in the app or in your device settings at any time.
- Camera and photo library access is used only when you choose to attach a picture or document. Files are uploaded to our storage and shown to the workspace members allowed to see them.
- The apps may update their own screens in the background ("live updates") by downloading a newer version of the app's web layer from our storage. This sends us the install identifier, app version and platform so we can count adoption and roll back a faulty release; it does not read anything on your device.
8. Analytics, cookies and similar technologies
We use PostHog for product analytics, error tracking and session replay across the website and the apps, and Firebase Analytics, Crashlytics and Performance Monitoring in the mobile apps. These record which screens are opened, which actions are taken, how long requests take and where the app crashed. They are keyed to a pseudonymous identifier and, once you sign in, to your CRM Dost user identifier, workspace identifier and role — never to your name, email, phone number or the content you enter.
- Session replay masks every input field and never records passwords, messages or lead details.
- The mobile apps do not use advertising identifiers, and we do not run advertising networks in the product.
- crmdost.com uses cookies and browser storage for the website analytics above and to remember your preferences. Our apps use browser storage to keep you signed in and to remember settings such as the last tab you opened.
- You can block cookies in your browser; the website still works. Analytics in the apps can be limited through your device's privacy settings.
9. Who we share information with
We do not sell personal data and we do not share it with advertisers. We share it only as described here.
- Within your workspace: with the members and roles the workspace owner has given access. Permissions decide who can see leads, deal values, attendance records and reports.
- With the people you contact: when you send an email or a WhatsApp message, the recipient sees your name, address or number and the content.
- With sub-processors that run the service, listed in section 10, under contracts that bind them to protect the data.
- With payment gateways to take payment and issue refunds.
- With authorities where the law requires it, or to protect the rights, safety and property of CRM Dost, our customers or the public.
- In a merger, acquisition or sale of assets, where the acquirer takes on this policy's obligations; we will tell you before your data is transferred.
10. Sub-processors
These companies process data on our behalf. We review them before use and update this list when it changes.
- Amazon Web Services (Asia Pacific – Mumbai region): file and image storage, database backups, and email delivery for authenticated domains (Amazon SES).
- Google Firebase and Google Cloud: sign-in (Authentication), push notifications (Cloud Messaging), app analytics, crash reporting and performance monitoring, web hosting.
- Google Maps Platform: maps, geocoding and place search in address and location features.
- PostHog: product analytics, error tracking and session replay.
- Meta Platforms (WhatsApp Business Platform): sending and receiving WhatsApp messages.
- OpenAI: AI model provider for CRMDostAI features.
- Razorpay: payments and subscriptions billed in Indian rupees.
- Stripe: payments and subscriptions billed in US dollars.
- Google and Microsoft: when you connect a Gmail or Microsoft 365 mailbox, your emails are sent through their APIs.
- Our application and database hosting providers, and our transactional email provider for the emails CRM Dost itself sends you (verification, password reset, invoices, notifications).
11. Where data is stored and international transfers
Our primary storage is in India (the AWS Mumbai region and our database hosting). Some sub-processors, such as Google, Meta, OpenAI, PostHog and Stripe, process data in the United States, the European Union or other countries. Where data leaves the country you are in, we rely on the transfer safeguards available under the applicable law, including the sub-processor's standard contractual clauses and certifications, and we transfer only what the feature needs.
12. How we protect information
- All traffic between your device and CRM Dost is encrypted (HTTPS/TLS), and so is traffic to our sub-processors.
- Passwords are handled by Firebase Authentication and are never visible to us. Mailbox passwords, OAuth tokens and WhatsApp access tokens are encrypted at rest with keys held separately from the database.
- Every request is scoped to the signed-in user's workspace on the server, so one customer's data cannot be reached from another's account. Role-based permissions limit what each member sees.
- Public pages (listings, forms, chat widgets, tracking links, unsubscribe pages) carry only random tokens, never account identifiers, and are rate-limited.
- Access by our staff is limited to what is needed to operate and support the service, is logged, and is reviewed.
- We keep encrypted backups so data can be restored after a failure.
- If a security incident affects your data, we will tell you and any authority we are required to notify without undue delay, and describe what happened and what we are doing about it.
No system is perfectly secure. Keep your password private, use a strong one, sign out on shared devices, and tell us at security@crmdost.com if you believe your account has been compromised.
13. How long we keep information
- Account data: for as long as your account exists. When you delete your account, we remove your profile within 30 days unless a workspace you own still holds data that must be transferred first.
- Workspace data (leads, messages, attendance, listings, documents): for the life of the subscription and 90 days after it ends, so the workspace can export or reactivate. After that it is deleted, except where the customer has asked for earlier deletion or the law requires longer retention (for example payroll and tax records the customer must keep).
- Email engagement events and suppression lists: for the life of the workspace, because an unsubscribe must be honoured for as long as the workspace can send.
- Billing records and invoices: for the period tax law requires, currently eight years in India.
- Server logs, analytics events and crash reports: up to 12 months, then deleted or aggregated.
- Backups: rotated on a fixed schedule, so deleted data leaves backups within 35 days.
14. Your rights and choices
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, to withdraw consent, and to complain to a supervisory authority. We honour these rights for everyone, wherever they are.
- Access and correction: most of your data is visible and editable in your profile and workspace settings.
- Export: a workspace owner can export leads, attendance and payroll data from the app; email us for anything else.
- Deletion: use the "Delete account" page on crmdost.com or write to privacy@crmdost.com. A workspace owner can also delete the whole workspace.
- Marketing: unsubscribe from any marketing email with the link in it; service and billing messages continue while you have an account.
- Connected accounts: disconnect a Gmail or Microsoft 365 mailbox, a WhatsApp number or an authenticated domain from Settings at any time.
- Permissions: location, notifications, camera and photos can be revoked in your device settings.
- If you are a lead, contact or employee of a CRM Dost customer, ask that customer; if they do not respond, contact us and we will help.
Under the Digital Personal Data Protection Act, 2023 you may also nominate another person to exercise your rights if you are unable to. Requests are answered within 30 days. We may ask you to verify your identity first.
15. What our customers must do
Because customers decide how the data in their workspace is used, they must:
- collect leads' and contacts' data lawfully and tell those people how it will be used;
- have consent or another lawful basis before sending marketing email or WhatsApp messages, honour every unsubscribe and opt-out, and not import purchased or scraped lists;
- tell employees what attendance and location data is collected and why, and keep it only as long as employment and payroll law require;
- give the people whose data they hold a way to exercise their rights, and pass on requests that reach us;
- keep their team members' access limited to what each needs, and remove members who leave.
Where a customer needs a written data processing agreement, we provide one on request at privacy@crmdost.com.
16. Children
CRM Dost is a business tool for adults. We do not knowingly collect personal data from anyone under 18, and an account may only be created by someone who is 18 or older. If you believe a child has given us data, contact us and we will delete it.
17. Changes to this policy
We update this policy when the product or the law changes. The date at the top shows the current version. For significant changes we notify workspace owners by email or with a notice in the app before the change takes effect. Continued use after that date means you accept the updated policy.