Privacy Policy

Last updated: March 18, 2026

1. Introduction

Tektrify LLC ("we", "us", or "our") operates CRMlet ("Service"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use CRMlet.

By using CRMlet, you consent to the data practices described in this policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Information You Provide

When you use CRMlet, you provide:

  • Account Information: Email address, password (hashed), business name
  • Onboarding Data: Industry/niche, business description, target audience, service offerings, location
  • Profile Information: Headshot, hero images, logo, business photos
  • Funnel Content: Headlines, copy, testimonials, pricing, calendar links
  • Payment Information: Processed by Stripe (we do not store credit card details)
  • Custom Domain: Domain name for Pro plan users

2.2 Automatically Collected Information

  • Usage Data: Pages viewed, features used, time spent, interactions
  • Device Information: Browser type, operating system, IP address, device identifiers
  • Cookies: Session cookies for authentication, preference cookies for settings
  • Analytics: Page views, user flows, feature adoption (anonymized when possible)

2.3 Lead and Customer Data

If you use CRMlet's outreach features, you may upload or import:

  • Lead Information: Names, email addresses, phone numbers, business details
  • Email Enrichment Data: Email addresses obtained via Hunter.io API
  • Engagement Metrics: Email opens, clicks, responses, booking events

Important: You are the data controller for lead/customer data you upload. You must have legal rights to use this data and comply with CAN-SPAM, GDPR, and other regulations.

3. How We Use Your Information

We use collected information to:

3.1 Provide the Service

  • Create and host your funnel/landing pages
  • Generate AI-powered content (headlines, copy, testimonials)
  • Process payments and manage subscriptions
  • Store and display your uploaded content (images, text)
  • Connect third-party services (Calendly, custom domains)
  • Send transactional emails (account confirmations, password resets, receipts)

3.2 Improve the Service

  • Analyze usage patterns to improve features
  • Identify and fix bugs
  • Develop new features based on user behavior
  • Optimize performance and user experience

3.3 Communicate with You

  • Provide customer support
  • Send service updates and announcements
  • Notify you of new features
  • Send marketing emails (you can opt out anytime)

3.4 Legal and Security

  • Enforce our Terms of Service
  • Prevent fraud and abuse
  • Comply with legal obligations
  • Protect our rights and property

4. Data Storage and Security

4.1 Where We Store Data

  • Firebase/Firestore: Account data, onboarding responses, funnel content (Google Cloud, US region)
  • Firebase Storage: Uploaded images (headshots, hero images, logos)
  • Vercel: Application hosting and deployment (US region)
  • Stripe: Payment processing and subscription management (PCI-compliant)

4.2 Security Measures

  • Passwords hashed with bcrypt (industry-standard, 10 salt rounds)
  • HTTPS encryption for all data transmission
  • JWT-based session authentication with secure, HttpOnly cookies
  • Regular security audits and dependency updates
  • Access controls and role-based permissions
  • Automated backups and disaster recovery

Note: No method of internet transmission or electronic storage is 100% secure. While we implement industry best practices, we cannot guarantee absolute security.

4.3 Data Retention

  • Active Accounts: Data retained as long as your account is active
  • Deleted Accounts: Data deleted within 30 days of account deletion
  • Legal Requirements: Some data may be retained longer to comply with legal obligations
  • Backups: Backup copies deleted within 90 days

5. Third-Party Services

CRMlet integrates with third-party services. When you use these features, those services may collect data according to their own privacy policies:

5.1 Payment Processing

Stripe: Handles all payment processing. We do not store credit card details. See Stripe's Privacy Policy.

5.2 Email Services

Resend: Sends transactional and marketing emails on our behalf. See Resend's Privacy Policy.

5.3 Email Enrichment

Hunter.io: Provides email lookup and verification services. When you use email enrichment, business names and domains are sent to Hunter.io. See Hunter.io's Privacy Policy.

5.4 AI Content Generation

Google Gemini AI: Generates funnel content based on your onboarding responses. Your business information is sent to Gemini API for processing. See Google AI Principles.

5.5 Calendar Booking

Calendly: If you connect Calendly, appointment data is managed by Calendly. See Calendly's Privacy Policy.

5.6 Hosting and Infrastructure

Vercel: Hosts the CRMlet application. See Vercel's Privacy Policy.
Firebase/Google Cloud: Stores data and images. See Firebase Privacy Policy.

6. Cookies and Tracking

6.1 Cookies We Use

  • Essential Cookies: Required for authentication and security (cannot be disabled)
  • Preference Cookies: Remember your settings and choices
  • Analytics Cookies: Help us understand how you use CRMlet (anonymized)

6.2 Managing Cookies

Most browsers allow you to control cookies through settings. Disabling essential cookies may affect functionality. Learn more: All About Cookies

7. Your Rights and Choices

7.1 Access and Portability

You can access your account data anytime from the dashboard. To request a copy of all your data in a portable format, email us at privacy@crmlet.com.

7.2 Correction and Deletion

You can edit most information from your dashboard. To delete your account and all associated data, go to Settings → Delete Account. Deletion is permanent and cannot be reversed.

7.3 Marketing Communications

You can opt out of marketing emails by clicking "Unsubscribe" in any marketing email or by adjusting preferences in your account settings. Transactional emails (receipts, password resets) cannot be disabled.

7.4 Do Not Track

CRMlet respects Do Not Track (DNT) browser signals. When DNT is enabled, we do not set analytics cookies.

8. Regional Privacy Rights

8.1 GDPR (European Users)

If you are in the European Economic Area (EEA), UK, or Switzerland, you have additional rights under GDPR:

  • Legal Basis: We process your data based on contract performance, consent, and legitimate interests
  • Data Minimization: We collect only necessary data for the Service
  • Right to Object: You can object to processing based on legitimate interests
  • Right to Restrict: You can request temporary restriction of processing
  • Right to Erasure: You can request deletion ("right to be forgotten")
  • Supervisory Authority: You can lodge complaints with your local data protection authority

To exercise GDPR rights, email gdpr@crmlet.com.

8.2 CCPA (California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request disclosure of data collected and how it's used
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: We do not sell personal information
  • Non-Discrimination: We will not discriminate for exercising CCPA rights

To exercise CCPA rights, email privacy@crmlet.com or call 1-800-CRMLET (placeholder - update with actual number if available).

9. Children's Privacy

CRMlet is not intended for users under 18 years old. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us immediately at privacy@crmlet.com and we will delete it.

10. International Data Transfers

CRMlet is operated from the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US.

By using CRMlet, you consent to the transfer of your data to the US. We implement appropriate safeguards (encryption, secure hosting) to protect data during international transfers.

11. Data Breach Notification

In the unlikely event of a data breach affecting your personal information, we will:

  • Notify affected users via email within 72 hours of discovery
  • Provide details about the breach and what data was affected
  • Explain steps we're taking to mitigate harm
  • Offer guidance on protecting your account
  • Notify relevant authorities as required by law

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Changes will be posted on this page with an updated "Last updated" date.

Material changes will be communicated via email or prominent notice in the app. Continued use of CRMlet after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your data:

Email (General): privacy@crmlet.com

Email (GDPR): gdpr@crmlet.com

Email (Support): support@crmlet.com

Website: crmlet.com

Mailing Address:
Tektrify LLC
Attn: Privacy Officer
[Address to be added]
Puyallup, WA [ZIP]

This Privacy Policy was last updated on March 18, 2026. We encourage you to review this policy periodically for any changes.