Privacy Policy
Last updated: October 2026
1. Introduction
eCRM ("we", "our", or "us") operates the eCRM email outreach platform at email-crm.app. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. It covers both our customers (the people who sign up and use eCRM) and the contacts our customers email through eCRM.
2. Information We Collect
Account information: your name, email address, company name, chosen plan, and the date you accepted our Terms and this Policy.
Connected mailbox credentials: when you connect a Gmail or Microsoft Outlook account we store the OAuth access and refresh tokens Google or Microsoft issue to us. For SMTP/IMAP accounts we store the server details, username and password you enter. All of these are encrypted before being stored in our database. We never see or store your Google or Microsoft password.
Email content from connected mailboxes: we read messages in your connected mailbox that are replies to emails eCRM sent, or bounce notifications about them, and store the sender, subject, date and body of those replies so you can read and answer them in eCRM's inbox. We do not store or index the rest of your mailbox. See section 4 for details.
Lead data: contact information you import or enter (such as name, email address, company, job title, phone and custom fields), campaign content, and the emails eCRM sends to those contacts.
Engagement data: when eCRM sends an email it may include a small tracking image and rewrite links so we can record when the email is opened or a link is clicked, along with the time, IP address and user agent of the request. We also record replies, bounces and unsubscribes.
Billing information: payments are processed by Stripe. We receive your subscription status and a customer reference; we never receive or store your full card number.
Usage and log data: IP address, browser type, and server logs used for security and troubleshooting.
3. How We Use Your Information
- To provide and operate the eCRM service
- To send the campaign emails you configure through your connected sender accounts
- To detect replies and bounces, stop follow-ups to contacts who replied, and show replies in your inbox
- To run email warmup for accounts you enrol in it (section 5)
- To report campaign performance (opens, clicks, replies, bounces)
- To authenticate users, secure accounts, and prevent abuse
- To process payments and send account, billing and support emails
We do not sell personal data, use it for advertising, or use your mailbox or lead data to train AI or machine-learning models.
4. Google and Microsoft Account Data
eCRM requests only the permissions it needs for the features you use:
- Sending accounts (Gmail):
gmail.sendto send emails you schedule, andgmail.modifyto find replies and bounce notifications for those emails and, if you turn on warmup, to mark warmup emails read, move them out of spam and file them under a "Warmup" label, plus your basic profile (email,profile) to identify the account. - Sending accounts (Outlook):
Mail.Send,Mail.ReadWriteandoffline_access, used for the same purposes. - Warmup accounts (Gmail):
gmail.sendandgmail.modify, used only to send and reply to warmup emails, mark them read, move any that landed in spam out of spam, and file them under a "Warmup" label so they stay out of the main inbox. These actions are applied only to messages created by the eCRM warmup network.
We use data obtained through these permissions only to provide the features described above to you. Humans at eCRM do not read your mailbox content, except with your explicit permission for support, where required for security (for example investigating abuse), or to comply with the law.
Limited Use disclosure: eCRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as needed to provide the service, for security purposes, to comply with law, or as part of a merger or acquisition with notice to you. We do not use it for advertising.
You can revoke eCRM's access at any time by disconnecting the account in eCRM or from your Google account permissions or Microsoft account settings.
5. Email Warmup
If you enrol a mailbox in warmup, eCRM sends a small number of automatically generated emails between it and other mailboxes in the eCRM warmup network, replies to some of them, marks them read, moves them out of spam, and files them under a "Warmup" label. Every warmup email carries a short tag so it can be identified and filtered. Warmup emails contain generic text, not your campaign or lead data. Other warmup participants' mailboxes will receive emails from your address, and yours will receive theirs. You can remove a mailbox from warmup at any time.
6. Lead Data and Your Role
You own the lead data you upload and decide how it is used. For that data you are the controller and eCRM acts as your processor, processing it only on your instructions to provide the service. You are responsible for having a lawful basis to email your contacts and for honouring their requests. If you are a contact who received an email sent through eCRM and want your data removed, please contact the sender directly or email us and we will pass your request on.
7. Service Providers
We share data only with providers that help us run eCRM, under contracts that restrict their use of it:
- DigitalOcean: server hosting and database (data centre in Bangalore, India)
- Stripe: payment processing
- Resend: delivery of our own account emails (verification, password reset, notifications)
- Google and Microsoft: sending and reading email through the mailboxes you connect
We may also disclose data where required by law or to protect the rights, safety and security of eCRM and its users.
8. Data Storage, Transfers and Security
Our servers are located in India. If you are in another country, your data will be transferred to and processed there. We protect data with HTTPS for all traffic, encryption of mailbox credentials and tokens in the database, hashed passwords, role-based access within your organisation, rate limiting, and restricted server access.
9. Data Retention and Deletion
- Account, lead and campaign data is kept while your account is active.
- When you disconnect a sender account, its stored tokens and credentials are deleted immediately.
- When you delete a workspace, its leads, campaigns and stored replies are deleted.
- When your account is closed, your data is deleted within 30 days, except records we must keep for legal, tax or accounting reasons.
You can ask us to delete your account and data at any time by emailing privacy@data-info.app.
10. Your Rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict its processing, and to complain to your local data protection authority. To exercise these rights, contact us at privacy@data-info.app. We will respond within 30 days.
11. Cookies and Local Storage
eCRM uses your browser's local storage to keep you signed in and remember preferences. We do not use advertising or third-party tracking cookies. Stripe may set cookies on its checkout pages for fraud prevention.
12. Children
eCRM is a business service and is not intended for anyone under 18.
13. Changes to This Policy
We may update this Policy from time to time. If we make material changes we will update the date above and notify account owners by email or in the app.
14. Contact
For privacy questions or requests, contact us at privacy@data-info.app.