CRM Gem privacy
Privacy Policy
How CRM Gem handles personal data when providing its website, application, and services.
- Effective:
- 27 July 2026
- Last updated:
- 27 July 2026
1. Scope and privacy roles
This Privacy Policy describes how CRM Gem, a service operated under the SmartBizToolls brand, handles personal data. It covers website visitors, account holders, Professional Setup customers, and people whose information users store in CRM Gem.
CRM Gem determines how information is used for account administration, billing, security, support, and service operations. For client or customer information entered by an account holder, that user generally decides why and how it is used, while CRM Gem processes it to provide the software service. Exact legal roles may vary by location and context.
Read this policy with the Terms of Service and Refund, Cancellation & Subscription Renewal Policy.
2. Information we collect
Account and identity data
Name, email address, authentication identifiers, profile information, and login or security records. When Google sign-in is used, CRM Gem receives the account information required by the configured sign-in flow.
Business information
Business name and contact details, branding, logo, brand colour, document footer, payment settings, business preferences, and other profile information.
CRM and customer records
Information users enter about clients, customer contacts, projects, notes, supported tasks or reminders, invoices, quotations, proposals, line items, payments, public-link status, proposal responses and comments, and recurring-document settings.
Files and communications
Uploaded files, attachments, logos, generated document content, email content and recipients, delivery events, support messages, feedback, and Professional Setup information. Generated PDFs are handled as needed for document workflows; this policy does not claim that every PDF is permanently stored.
Billing and payment information
For CRM Gem Pro, this may include plan, billing interval, PayPal subscription identifiers, status, paid-period dates, cancellation state, and payment or reconciliation information.
For customer invoice payments, this may include invoice payment status, amount, currency, PayPal order or capture references, merchant matching and verification information, and payment activity. CRM Gem does not need users to email PayPal passwords, full card numbers, or secret credentials, and does not claim to store complete card details.
Technical and usage data
Infrastructure may process IP address, browser or device information, request and error information, authentication or session information, and security, fraud-prevention, and diagnostic data. When analytics is enabled, page visits, interactions, referrals, and campaign information may also be processed.
3. How information is collected
Information may come directly from account holders; through CRM Gem forms and workflows; from clients interacting with public documents; from PayPal; from Supabase authentication; from support and Professional Setup communications; and automatically through hosting, security logs, cookies, sessions, and analytics where enabled.
4. How information is used
- Create, authenticate, secure, and maintain accounts.
- Provide CRM functions and generate, send, and share documents.
- Process or verify payments and manage subscriptions.
- Send transactional emails, recurring invoices, and reminders.
- Provide support and Professional Setup and enforce plan limits.
- Prevent abuse, fraud, and security incidents and diagnose service errors.
- Meet legal, tax, accounting, security, and dispute obligations.
- Improve usability using appropriately limited analytics and communicate service or policy changes.
CRM Gem does not sell users’ personal data or provide user CRM records to advertisers.
5. Legal grounds
Depending on location and context, processing may rely on performance of the service agreement, user instructions, legitimate operational or security interests where permitted, consent where required, legal obligations, or the establishment, exercise, or defence of legal claims. Consent is not necessarily the legal ground for every activity.
6. Your responsibility for customer data
Users decide what client information they enter and must have permission or another lawful basis, provide required privacy notices, and respond to their clients’ applicable access, correction, deletion, restriction, or objection requests.
Avoid unnecessary sensitive data, unlawful surveillance, spam, deceptive billing, and unauthorized collection. Verify document recipients and public links. Further responsibilities appear in the Terms of Service.
7. Public document links
Public invoice, quotation, and proposal links use access tokens. Anyone possessing a valid link may be able to view the linked document. Share links only with intended recipients and avoid unnecessary sensitive information.
CRM Gem may log interactions needed for document responses or payment functions. Search indexing is not intended for tokenized customer documents. Contact support if invalidation is required and no self-service option exists. A submitted deletion request does not instantly invalidate every public link.
8. Cookies, sessions, and local storage
CRM Gem uses authentication cookies or session storage needed to keep accounts signed in and secure. Preference storage may remember settings such as interface theme. These functions are used to provide requested application behavior.
When Google Analytics is enabled, Google may use cookies or similar identifiers for analytics. CRM Gem does not currently present a dedicated analytics-consent choice. Whether one is legally required depends on the locations served and should be assessed before broader launch.
9. Google Analytics
Google Analytics loads only in production when a valid measurement ID is configured. When enabled, it may collect page views, interaction information, browser or device information, approximate location, and referral or campaign information according to Google’s configuration.
It is not enabled in every environment by default. Browser privacy controls, content blockers, or Google’s available opt-out tools may limit analytics collection.
10. Service providers and disclosure
Information may be processed by providers required to operate CRM Gem:
- Supabase — authentication, database, and storage.
- Vercel — hosting and application delivery.
- PayPal — CRM Gem subscription billing and connected customer invoice-payment processing.
- Brevo — transactional email delivery.
- Google Analytics — analytics only when enabled.
Information may also be disclosed at a user’s instruction, to public-document recipients, to personnel who need it for support or service delivery, when legally required, to protect rights and security, or in a future business reorganization with appropriate safeguards. Providers have their own terms and privacy practices, and CRM Gem cannot control every aspect of their systems.
11. PayPal roles
PayPal processes recurring CRM Gem Pro subscription authorization and connected invoice payments. A customer paying an invoice pays the CRM Gem account owner or issuing business. CRM Gem is not the merchant of record, seller, or service provider for the underlying invoiced goods or services and does not claim to store complete card details.
12. International processing
Providers and infrastructure may process information outside a user’s country, where privacy protections may differ. CRM Gem seeks to use contractual, technical, and organizational safeguards appropriate to the service but does not claim that one particular international-transfer mechanism applies in every case.
13. Data retention
Account and CRM data is generally retained while an account remains active. Subscription, payment, fraud, dispute, and accounting records may be retained longer where reasonably needed. Support records may be retained to resolve issues and maintain service history, while security and technical logs may be retained for limited operational periods.
Backups may retain deleted information temporarily until overwritten. Public records and links may remain until removed, invalidated, or the underlying information is deleted. Retention may be extended for legal obligations, disputes, fraud prevention, or security. CRM Gem aims not to retain personal data longer than reasonably necessary for its stated purpose, subject to operational and legal requirements.
14. Account-deletion requests
The current Settings action submits a deletion request for review; it does not immediately erase the account or all related records.
CRM Gem may verify identity and account ownership. Active subscriptions should be cancelled before deletion where possible. Processing a request may require stopping recurring processes, disabling reminders, invalidating public links, removing files, and closing the account.
Some information may be retained for payments, taxes, fraud prevention, security, legal claims, and disputes, and backups may take additional time to expire. The process does not automatically cancel PayPal billing or immediately clean every storage object. Save required records before requesting deletion and contact support@smartbiztoolls.com with questions.
15. Access, correction, and copies
Users can update certain profile and business information in Settings and manage supported CRM records in the application. You may contact support to request access, correction, or a copy of personal data, subject to identity verification.
Requests may be limited by another person’s privacy, security needs, legal obligations, lawful exceptions, or technical feasibility. CRM Gem does not currently promise a complete self-service “download all my data” workflow.
16. Privacy rights
Depending on applicable law and circumstances, rights may include access, correction, deletion, restriction, objection, withdrawal of consent, complaint, review of certain automated decisions, and data portability where legally required and technically applicable.
Rights vary by location. Identity verification may be required, and requests may be denied or limited where lawful. Contact support to make a request. You may also complain to an appropriate privacy regulator where applicable.
17. Security
CRM Gem uses reasonable administrative, technical, and organizational safeguards. These may include authentication, access controls, row-level security, secure server-side functions, and provider protections. Secret or payment credentials are intended to remain server-side where that handling is required.
No storage or transmission method is guaranteed completely secure. Users are responsible for protecting account credentials and choosing public-link recipients carefully. Promptly report suspected security incidents.
18. Data incidents
CRM Gem will investigate suspected personal-data incidents and may notify affected users or authorities when legally required. Report suspected incidents to support@smartbiztoolls.com. This policy does not promise a fixed notification deadline.
19. Children
CRM Gem is intended for users aged at least 18 or the age of legal majority in their location, whichever is higher. It is not intended for children and does not knowingly invite children to create business accounts. Contact support if information is believed to have been submitted by a child without appropriate authorization.
20. Automated processing
CRM Gem uses ordinary automation for functions such as plan-limit enforcement, recurring workflows, reminders, and security controls. These functions do not generally make decisions producing legal or similarly significant effects about individuals. CRM Gem does not claim to use advanced profiling or AI decision-making for those purposes.
21. Changes to this policy
CRM Gem may update this policy and will show the updated date. Reasonable notice will be provided for material changes where practical. Continued use may indicate acceptance where legally permitted, and explicit consent will be requested where applicable law requires it.
22. Contact
Privacy questions or requests may be sent to support@smartbiztoolls.com.