Privacy Policy
Effective Date: July 11, 2026 · Last Updated: July 11, 2026
Also see: Terms of Service · Cookie Policy
This Privacy Policy explains how [Company Legal Name] ("SmartLite", "we", "us") collects, uses, and protects information when you use SmartLite CRM (the "Service"). It covers both information about you as a user of the Service, and how we handle "Customer Data" — the business records your organization stores in the Service, which may include personal data about your own customers and contacts.
1. Information We Collect
Account & Usage Information
- Registration details: name, work email, organization name, and password (stored hashed, never in plain text).
- Login and session activity, including timestamp, IP address, and device/browser information, for security and audit purposes.
- Support communications, if you contact us.
Customer Data
Data your organization enters into the Service — records, attachments, custom objects, and configuration — is "Customer Data." Your organization controls what Customer Data is collected and is responsible for having appropriate legal grounds (e.g. consent, contract) for any personal data of third parties (your customers, leads, contacts) entered into the Service. We act as a data processor for Customer Data; your organization is the data controller.
2. How We Use Information
- To provide, operate, and maintain the Service, including tenant isolation, authentication, and permission enforcement between organizations.
- To communicate with you about your account, service changes, and (if you opt in) product updates.
- To monitor for security issues, abuse, and to enforce our Terms of Service.
- To provide optional AI-assisted features, only where your organization's administrator has explicitly enabled and configured an AI provider — content sent to an AI provider in that case is scoped to your organization and never shared across tenants.
3. Data Storage & Security
- Each organization's data is logically isolated from every other organization at the application layer; access requires a valid session scoped to that organization.
- Passwords are hashed (never stored in plain text); optional two-factor authentication (TOTP) is available.
- File attachments are stored in encrypted object storage, accessed only via short-lived, tenant-scoped signed URLs.
- We use industry-standard infrastructure providers for hosting, database, and object storage; no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
4. Who We Share Data With
We do not sell your data. We share information only with:
- Infrastructure sub-processors that host, store, and run the Service on our behalf (hosting, database, object storage, email delivery).
- AI providers — only for organizations that have explicitly enabled and configured one, and only for the content that feature is scoped to.
- Legal authorities, where required by law, subpoena, or to protect the rights, property, or safety of SmartLite, our users, or the public.
- A successor entity, in the event of a merger, acquisition, or asset sale — you'll be notified before Customer Data becomes subject to a different privacy policy.
[List your specific hosting/database/storage/email sub-processors by name here once finalized — most privacy policies name them explicitly.]
5. Data Retention
We retain account and Customer Data for as long as your organization's account is active. If you close your account, we retain data for a limited period to allow export or reactivation, after which it is deleted or anonymized, except where we're required to retain it longer for legal or security purposes (for example, security audit logs).
6. Your Rights (Including GDPR)
Depending on your location, you may have rights under data protection law (including the EU/UK GDPR and similar laws) to access, correct, export, or request deletion of your personal data. SmartLite CRM includes built-in tooling for this:
- Erasure — an organization administrator can initiate erasure of a specific record from within the Service.
- Access / export — contact us at support@smartlite.app to request a copy of your personal data or a full organization data export.
- Correction — account information can be updated directly in the Service; Customer Data corrections go through your organization administrator.
If your organization's Customer Data includes personal data of your own end customers, requests from those individuals should generally be directed to your organization (the data controller) in the first instance; we support your organization in fulfilling them.
7. Cookies & Local Storage
See our Cookie Policy for details on what we use today and why.
8. International Data Transfers
Your information may be processed in a country other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for international transfers. [Confirm your hosting region(s) and add specifics once your infrastructure footprint/regions are finalized.]
9. Children's Privacy
The Service is intended for business use by adults and is not directed at children under 16. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice before they take effect.
11. Contact Us
For privacy questions or to exercise your data rights, contact us at support@smartlite.app. [If GDPR applies to you and you're required to designate a Data Protection Officer or EU/UK representative, name them here.]