Privacy Policy
Last updated: July 15, 2026
Who we are
TidyCRM (“we”, “us”) provides auditing and cleanup tooling for CRM accounts. This policy explains what we collect, why, and the choices you have. Questions: privacy@tidycrms.com.
What we collect
Account data. Your name, email address, and password hash (or Google sign-in identifier), plus workspace and team membership details.
CRM connection data. The Private Integration Tokens you provide are encrypted at rest with AES-256-GCM and used only to call the CRM API on your behalf. During audits we process metadata about your sub-accounts — names, statuses, and timestamps of funnels, workflows, contacts, campaigns, forms, calendars, opportunities, tags, and media files — to produce your report. Findings (entity names and the reason flagged) are stored so you can review them.
Billing data. Payments are processed by Stripe. We never see or store full card numbers — only your subscription status and plan.
Usage data. Standard server logs (IP address, browser, pages) used for security and debugging.
What we do NOT do
We do not sell your data. We do not use your CRM data for advertising or model training. We do not modify or delete anything in your CRM account without an explicit approval action taken by you or a teammate with the Admin role.
How we share
Only with the processors required to run the service: our hosting provider (Vercel), database provider (Neon), background-job provider (Inngest), email provider (Resend), and payment provider (Stripe) — each bound by their own data-processing terms. We may disclose data if required by law.
Retention & deletion
Audit findings are retained while your account is active so keep-safe decisions persist between audits. Deleting a connection deletes its stored token and discovered locations immediately. Deleting your workspace deletes all associated data within 30 days. Email privacy@tidycrms.com to request export or erasure at any time.
Security
Tokens are encrypted at rest (AES-256-GCM). Traffic is encrypted in transit (TLS). Sessions expire after at most 7 days and rotate regularly. Access to production systems is limited and logged.
Your rights
Depending on your region (including GDPR and CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Contact us and we will honor verified requests within the legally required window.
Changes
We will notify you by email about material changes to this policy before they take effect.