Privacy Policy

Last Updated: May 25, 2026

1. Overview

CRMown ("CRMown," "we," "us," and "our") respects your privacy and is committed to protecting it through compliance with this Privacy Policy. This Privacy Policy describes how we collect, use, disclose, and safeguard your Personal Information when you visit our website at crmown.com, use our SaaS platform at app.crmown.io, use our mobile applications, communicate with us, or we otherwise process your Personal Information (collectively, the "Platform").

Processor Role: This Privacy Policy does not apply to data subjects of our customers whose Personal Information we may receive pursuant to CRMown services we provide. Our customers use our platform to store and process their own customers' Personal Information, such as to: (i) manage contacts and sales pipelines; (ii) send electronic communications via email, SMS, WhatsApp, or other channels; (iii) create websites, forms, and landing pages; (iv) manage invoices, proposals, and financial records; and (v) otherwise collect, use, share, or process Personal Information. In these cases, we act as a processor and service provider. When you provide your data to one of our customers, our customer's privacy notice, rather than this Privacy Policy, will apply.

Self-Hosted ("Own") Customers: CRMown offers a perpetual license option where customers self-host the platform on their own servers. In this case, CRMown does not have access to, process, or store any data on the customer's self-hosted instance. The self-hosting customer is solely responsible for the privacy and security of data on their own infrastructure. This Privacy Policy applies only to data processed through CRMown's managed SaaS platform and marketing website.

By accessing or using the Platform, you agree and consent to this Privacy Policy. If you do not agree with our policies and practices, do not use the Platform.

2. Information We Collect

2.1 Information You Provide Directly

When you create an account, subscribe, make a purchase, request information, or contact us, we may collect:

2.2 Information from Third Parties

We may obtain information through marketing partners, advertising platforms, social media, data vendors, public databases, and event hosts. This may include your name, contact information, professional information, and publicly available content.

2.3 Information Collected Automatically

When you use our Platform, we automatically collect:

2.4 Information from Integrated Services

If you connect third-party services (email providers, calendar services, communication carriers via BYOC, social media, or payment processors), we may receive information from those services as authorized by you.

2.5 Google API Services — Limited Use Disclosure

CRMown's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Specifically:

3. Payment Processing for Booking Pages

This section describes how we process information related to payments collected through CRMown booking pages, including information about both Hosts (CRMown customers who accept payments) and Guests (third parties who pay for bookings).

3.1 What We Process

When a Host enables payment collection on a booking page and a Guest pays for a booking, we receive and process:

We do NOT receive, store, or process Guest payment card information. Payment card details are collected by Stripe through Stripe's hosted Checkout interface and never transit through CRMown's systems.

3.2 Stripe Connect Data Flow

For Hosts: when you authorize CRMown via Stripe Connect (Standard mode), Stripe shares your connected account identifier and a limited set of account status fields (charges enabled, payouts enabled, default currency, country, business email) with CRMown. CRMown does NOT receive your full Stripe account credentials and cannot access your bank account, payout history, or other Stripe data outside of what is necessary to facilitate booking payments.

For Guests: Stripe processes your payment as a sub-merchant transaction on behalf of the Host. Your payment data flows directly to Stripe under Stripe's own privacy policy (https://stripe.com/privacy). CRMown receives only the booking-related metadata described in §3.1.

3.3 Purpose of Processing

Payment-related information is processed solely to:

We do not use Guest information for marketing purposes without separate consent, and we do not sell Guest information to third parties.

3.4 Retention

Booking and payment metadata is retained for as long as the Host's account remains active, or as required by applicable financial-records laws (typically up to 7 years for tax purposes). Hosts may delete individual bookings through the CRMown dashboard, in which case Guest information associated with the booking is purged within 30 days, subject to legal retention requirements.

3.5 Guest Rights

Guests who do not have a CRMown account may still exercise privacy rights with respect to their booking information by contacting [email protected]. We will verify the identity of the requester (typically by matching the email address used at checkout) and respond within 30 days. Specifically, Guests may request:

Note: Guest information may also be retained separately in the Host's CRMown account under the Host's control. Deletion requests directed to CRMown do not automatically delete data from the Host's records; Guests who wish to have their data deleted from a Host's records should contact the Host directly.

3.6 Sharing

Payment-related information may be shared with:

We do not share Guest payment information with marketing partners, advertising platforms, or any third party not listed above.

4. How We Use Your Information

Platform Functionality. To provide, operate, personalize, and improve the Platform, including diagnostics, security, data analysis, and product development.

AI Features. Some features leverage artificial intelligence (Anthropic Claude API and customer-selected providers) for lead scoring, message drafting, analytics, and automation. We do not use your data to train generalized AI models. AI processing is limited to the specific service invocation.

Customer Support. To provide technical support, respond to inquiries, and resolve issues.

Business Operations. For accounting, auditing, billing, and contractual obligations.

Communications. To send service messages, notifications, security alerts, marketing materials, and promotional content per your preferences.

Security. To detect, prevent, and respond to fraud, abuse, and security incidents.

Advertising and Marketing. To deliver personalized content, verify promotional eligibility, and measure campaign effectiveness.

Affiliate Program. To track referrals, calculate commissions, and administer the built-in affiliate program.

Analytics. To compile statistics, identify trends, and improve the Platform experience.

Legal and Compliance. To comply with legal, regulatory, tax, and reporting requirements.

Legal Basis (EEA, UK, Brazil)

We process Personal Information where we have: (a) your consent; (b) a contract to perform; (c) a legal obligation; or (d) legitimate interests not overridden by your rights. CRMown is the Data Controller for information collected through the Platform, except where we act as a Processor for our customers.

5. How We Protect Your Information

We implement appropriate administrative, technical, and organizational security measures including:

No technology is 100% secure. If you believe your interaction with us is no longer secure, please contact us immediately at [email protected].

6. When We Share Your Information

Affiliates and Subsidiaries. For purposes consistent with this policy.

Service Providers. Including AWS ECS (hosting), Stripe (subscription payments), Stripe Connect (booking-page payments), Postmark/Amazon SES (email), and CRMown (AI).

Communication Carriers (BYOC). Your communication data flows through your selected carrier (Twilio, Plivo, Telnyx). CRMown facilitates the connection but does not control the carrier's data practices.

Affiliate Partners. Limited information (name, email, plan) for commission tracking if you arrived via a referral link.

Advertising and Marketing Partners. To deliver and measure advertising content.

Connected Third-Party Services. When you connect social media, calendar, or marketplace integrations.

Client Portal Users. Data shared through the Client Portal is controlled by the CRMown customer, not CRMown.

Hosts (Booking Page Operators). Guest booking and contact information is shared with the Host, who owns the booking page; the Host's separate use of that information is governed by the Host's own privacy practices.

Sales, Mergers, Acquisitions. As part of corporate transactions.

Legal Purposes. To comply with legal obligations or protect rights and safety.

With Your Consent. Where you direct us to disclose information.

We do NOT share your phone number or opt-in consent with third parties without your express written consent.

7. Data Retention

We retain Personal Information only as long as reasonably necessary. CRMown customers may configure data retention periods at the organization level. When retention periods expire, data is flagged for deletion per the configured policy. You may request deletion as described in §11.

Booking and payment metadata is subject to the retention rules described in §3.4.

8. Information from Children

We do not knowingly collect information from children under 16. If we learn we have collected such information, we will delete it promptly. Contact us if you become aware that a child has provided us with Personal Information.

9. Links to Other Websites

The Platform may link to third-party websites and services we do not control. We are not responsible for their privacy practices and encourage you to review their policies.

10. Do Not Track

The Platform does not currently respond to browser DNT signals.

11. Your Legal Rights

European Privacy Rights (GDPR, UK GDPR, Swiss nFADP)

U.S. State Privacy Rights

Residents of California and other states with privacy laws may have rights to opt out of sale/sharing/targeted advertising, access, correct, delete data, non-discrimination, and appeal decisions. CRMown does not sell Personal Information for monetary consideration.

Sensitive Data: We limit processing of sensitive information to authorized uses or as required by law.

Automated Profiling: We do not engage in automated profiling that produces legal or similarly significant effects.

Australian Privacy Rights

Australian residents may request correction of and access to their Personal Information. We respond within 30 days. Complaints may be directed to the Office of the Australian Information Commissioner.

Canadian Privacy Rights (PIPEDA)

Canadian residents may request correction and access. We respond within 30 days. Consent may be withdrawn at any time. Quebec residents may have additional rights per Section 10.1.

Guest Rights (Booking Page Payments)

Guests who pay for bookings through CRMown without creating an account have specific rights described in §3.5, available regardless of account status and exercisable by contacting [email protected].

12. Marketing Choices

Opt out of marketing by clicking "unsubscribe" in emails, updating Settings, using the public preference center, or contacting us. Service-related messages may still be sent.

13. Cookies

We use cookies and similar technologies to operate the Platform, analyze usage, and deliver advertising. CRMown customers may embed tracking pixels on their own sites — that tracking is controlled by the customer.

14. International Data Transfers

Data may be transferred to the United States. For transfers from the EEA/UK/Switzerland, we use Standard Contractual Clauses or other recognized mechanisms. Self-hosted customers control their own data jurisdiction.

15. AI and Data Processing

16. Consent Management

CRMown provides built-in consent management tools including per-contact consent tracking, Do Not Contact functionality, public preference center, consent audit log, GDPR/CCPA mode toggles, double opt-in, and data export/deletion capabilities. Customers are responsible for their own compliance obligations.

17. How to Contact Us

CRMown
Email: [email protected]
Website: crmown.com

We respond to privacy inquiries within 30 days (or sooner where required by law).

18. CRMown Capture Browser Extension

If you install the CRMown Capture browser extension (available from the Chrome Web Store and Microsoft Edge Add-ons), it interacts with CRMown only through the CRMown API, authenticated by an API key that you generate in CRMown → Settings → Developer. The sub-sections below describe what the extension reads, what it sends, where your API key lives, and how to disable it.

18.1 Where the Extension Activates

The extension only runs on five supported websites:

It cannot see or read any other website you visit. Site-specific content scripts are scoped via Manifest V3 host_permissions to those five domains only. The extension does not request <all_urls> or any broader access.

18.2 What the Extension Reads

On a supported page, the extension reads only the public profile, post, comment, or review information visible on that page: the captured person's name, headline, job title, company, social URLs, and (if you select it, or it is the page's main body) the post or comment text. The extension does not read cookies from the source site, does not traverse your other tabs, does not record your browsing history, and does not load any analytics or third-party SDKs.

18.3 What the Extension Sends, and Where

Each capture is a single HTTPS POST to your configured CRMown API base URL (default https://app.crmown.io/api, editable for self-hosted instances). The request body contains:

Your CRMown API key is sent in the Authorization: Bearer header of that POST. No cookies from the source site, no browser fingerprint, no third-party calls.

18.4 Where Your API Key Lives

The extension stores your API key in chrome.storage.local (or the browser-equivalent local-storage area). This means:

18.5 What Happens Once a Capture Reaches CRMown

After the POST reaches the CRMown API, the captured contact is processed the same way as any other contact created in CRMown — see §7. Data Retention for retention and deletion, and §6. When We Share Your Information for the list of sub-processors that may participate in best-effort enrichment of the captured fields. Server-side enrichment is asynchronous, best-effort, and uses only the third-party providers disclosed in §6; no additional vendors are introduced by the extension itself.

18.6 How to Disable or Revoke

You can stop the extension from capturing at any time by either of these actions:

18.7 Permissions the Extension Declares

PermissionWhy It Exists
activeTab Reads the current tab's URL and title only when you explicitly open the popup, right-click, or hit the shortcut.
contextMenus Adds a single “Capture to CRMown” right-click entry, scoped to the five supported sites only.
storage Stores your API key and a small set of preferences in chrome.storage.local on this browser profile.
Host permissions Limited to the five supported sites — no <all_urls> and no access to any other domain.

Questions about CRMown Capture's data handling? See §17. How to Contact Us.

19. Policy Updates

We may update this Privacy Policy at any time. Material changes will be notified as required by law. Continued use of the Platform after changes constitutes acceptance.

CRMown AI
Ask anything about CRMown
Powered by CRMown AI