1. Introduction
SalePro CRM ("SalePro CRM", "we", "us", "our") is a customer-relationship-management platform built for sales professionals and project managers in the construction and remodeling industry. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over it.
By using SalePro CRM, you agree to the practices described in this policy. Questions about anything below can be sent to support@saleprocrm.com.
2. Information We Collect
We collect the following categories of information when you create an account or use the platform:
- Account information — name, email address, password (stored hashed), profile photo, role, time zone, country, and contact phone number.
- Company / business information — company name, branding (logo, colors), business address, phone, website, bank or payment details added to quotes, and any team-member records you create.
- CRM data — leads, contacts, projects, quotes, payment stages, change orders, notes, tasks, attached documents, and message history that you create or upload.
- Communication data — emails, SMS messages, WhatsApp messages, and meeting records sent or logged through the platform.
- Calendar and email integration data — when you connect Google Workspace, the OAuth tokens needed to access Gmail and Google Calendar on your behalf, plus the messages and events you fetch or send through the integration.
- Payment and subscription data — plan selection, billing interval, subscription status, invoice history, and the Stripe customer identifier associated with your account. Card numbers are handled directly by Stripe and are never stored on our servers.
- Device, log, usage, and IP data — IP address, browser, operating system, pages visited, request timestamps, and product-analytics events used to operate, secure, and improve SalePro CRM.
- Cookies and similar technologies — see Section 7.
3. How We Use Information
We use the information we collect to:
- Provide and operate the SalePro CRM service for you and your workspace.
- Manage your account, workspace members, and subscription.
- Process payments and issue invoices through Stripe.
- Sync Gmail and Google Calendar only when you explicitly connect those integrations.
- Send transactional notifications (account verification, password resets, receipts, security alerts, important account notices).
- Improve product performance, reliability, and stability.
- Run internal analytics and gather product-usage insights so we can prioritize improvements.
- Detect, investigate, and prevent fraud, abuse, and security incidents, and meet our legal and compliance obligations.
- Send marketing emails (product updates, onboarding tips, occasional announcements) only if you opt in during signup or in your account settings. You can unsubscribe at any time.
We do not sell personal data, and we do not use your CRM content or Google user data to train machine-learning models.
4. Google API Limited Use Disclosure
SalePro CRM's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only use Google user data to provide user-requested CRM functionality (such as syncing Calendar events into your CRM, or sending and reading email tied to a lead).
- We do not sell Google user data.
- We do not use Google user data for advertising purposes.
- We do not allow humans to read Google user data, except where necessary for support (with your permission), to investigate a security incident, to comply with legal obligations, or with your explicit consent for specific messages.
You can disconnect your Google account at any time from Settings → Integrations, which revokes our access. You can also revoke access directly at myaccount.google.com/permissions.
5. Third-Party Services
We rely on a small number of third-party service providers to operate SalePro CRM. The categories include:
- Hosting and database providers — to run the application and store your data.
- Payment processors — such as Stripe, to handle subscription billing and process card payments.
- Email providers — to deliver transactional and (opt-in) marketing emails.
- Google APIs — for Gmail and Google Calendar integration when you connect your Google account.
- Calendar integrations — for syncing scheduled events with your CRM workflow.
- E-signature providers — such as DocuSign, when used to collect signatures on quotes or contracts.
- Analytics and error-monitoring tools — to measure feature usage and detect product errors.
Each provider only receives the data needed to perform its specific function and is bound by its own terms and privacy commitments.
6. Data Sharing
We share your information only as needed to operate the platform, and only in the following limited ways:
- We do not sell personal data.
- We share data with the third-party service providers listed in Section 5, strictly for the purposes described.
- We may disclose information if required by law, valid legal process, or government request, or to protect our rights, property, or the safety of our users.
- In connection with a business transfer (such as a merger, acquisition, or sale of assets), with notice to you when reasonably possible.
7. Cookies
We use cookies and similar technologies in two categories:
- Essential cookies are required to operate the platform — for login, session management, and security (CSRF and rate-limit protection). These cannot be turned off without breaking core functionality.
- Non-essential cookies may be used for analytics, product-usage insights, and marketing measurement. These are only set after you give consent through our cookie banner.
You can accept or reject non-essential cookies at any time. Choosing "Reject Non-Essential" still allows the platform to function — only essential cookies will be set.
8. Data Retention
- Your data is kept for as long as your account is active.
- Some records (such as billing history, audit logs, and consent records) may be retained for legal, accounting, security, or compliance reasons even after an account is canceled.
- When you cancel or delete an account, your CRM content may be removed after a reasonable period, allowing time for export and any business or legal obligations.
- Encrypted backups may temporarily retain data after deletion until they are rotated out (typically within 30 days).
9. Security
We use reasonable technical and organizational safeguards to protect your data, including TLS for data in transit, encrypted storage at rest, hashed passwords, least-privilege access for engineers, rate limiting, and security headers.
No system is 100% secure. While we work hard to protect your data, we cannot guarantee absolute security and will notify you promptly if a breach affects your account.
10. User Rights
Depending on where you live, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Deletion — request that your data be deleted.
- Opt out of marketing — unsubscribe from marketing emails at any time, either from any marketing email or from Settings → Notifications.
- California privacy rights (CCPA / CPRA) — California residents have the right to know, delete, correct, and limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising.
- GDPR-style rights — where applicable, and as a forward-looking practice, you may also have the right to data portability, to restrict or object to certain processing, to withdraw consent, and to lodge a complaint with your local data-protection authority.
To exercise any of these rights, email support@saleprocrm.com. We will respond within the timeframe required by applicable law.
11. Children's Privacy
SalePro CRM is intended for business use by adults. The service is not intended for users under the age of 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact us so we can delete it.
12. Changes to Policy
We may update this Privacy Policy from time to time. When we do, we will revise the Last Updated date at the top of the policy and, for material changes, notify you by email or through the app before the change takes effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.
13. Contact
For questions about this policy or your data, contact us at: