Privacy Policy
Last updated: 31 August 2026
This policy explains what wCRM does with personal data. The service is operated by Karina Loaiza, which is the data controller for the information described below. Write to privacy@wcrm.app with any question or request.
What we collect
Your account. When you sign in with Google we receive your email address, your name and your Google account identifier. We do not receive or store your Google password, and we do not request access to your Gmail, Drive or calendar.
What you put into the service. The contacts you create — names, phone numbers, email addresses, companies and notes — plus your proposal templates and the proposals you send, including their subject, body and whether they carried an attachment.
Technical data. A session cookie that keeps you signed in, and server logs with IP address, date and requested route, which we keep for a short period for security and troubleshooting. We do not use advertising or analytics trackers.
Why we use it
- To run the service you signed up for: showing your board, sending your proposals, applying the limits of your plan.
- To keep the service secure: detecting abuse, investigating incidents, preventing unauthorized access.
- To bill you, once paid plans begin.
- To contact you about the service itself — outages, changes to these policies, security notices. We do not send marketing email unless you ask for it.
Where the GDPR applies, our legal basis is the performance of the contract between us for running the service and billing, and our legitimate interest in keeping the service secure and in communicating about it.
The contacts you add
Most of the personal data in wCRM is not yours: it belongs to the people you store as contacts. For that data you are the controller and we are the processor — we handle it under your instructions, to provide the service, and for nothing else. You are responsible for having a lawful basis to store it and for answering requests from those people. If one of them contacts us directly, we will refer them to you.
Who else sees the data
We do not sell personal data and we do not use it to train machine learning models. We share it only with the providers needed to operate:
- Google — sign-in only, so we can verify who you are.
- Resend — delivery of the proposals you send. Resend receives the recipient, subject, body and any attachment.
- Hostinger — the server where the application and its database run.
- Our payment provider — once paid plans begin. It acts as merchant of record and receives your billing details directly; we never see your card number.
We may also disclose data if the law requires it, after checking that the request is valid.
Where it is stored and for how long
Data is stored on a server we rent from Hostinger in Boston, United States, and is isolated per account at the database level, so one account cannot read another's rows. Backups are kept for 14 days.
If you are in the European Union, the United Kingdom or another country with data transfer rules, this means your data — and the data of the contacts you add — is transferred to and processed in the United States. By using wCRM you acknowledge that transfer.
We keep your data for as long as your account is open. If you close it, we delete the data within 30 days, except records we must keep for accounting or legal reasons.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or limit how we use it, and you can object to a particular use. Write to privacy@wcrm.app and we will answer within 30 days. If you are in the European Union or the United Kingdom and you think we have handled your data badly, you may also complain to your local data protection authority.
Video on our website
Our home page includes a presentation video hosted on YouTube. Nothing is loaded from YouTube until you click play: until then the page only shows a still image. If you do play it, YouTube receives your request and may set its own cookies, under Google's privacy policy. We do not receive any information about who watches it.
Cookies
wCRM sets one cookie, which stores your session so you stay signed in. It is not used for advertising or tracking, and deleting it simply signs you out.
The browser extension
wCRM Contact Capture is an optional Chrome extension that adds the contact of the WhatsApp Web chat you have open to your wCRM board. It is not required to use wCRM, and installing it changes nothing about how the rest of the service handles your data.
When it reads anything. Only at the moment you click its toolbar icon. It does not run in the background, it has no standing access to any website, and it does nothing at all until you click.
What it reads. Two values from the page you are looking at: the contact name shown in the chat header, and the phone number shown in the contact panel. It does not read the messages in the conversation, your chat list, or any other part of the page.
Where those values go. Into your own wCRM account, and nowhere else. The extension opens wcrm.app in a tab with the new contact form prefilled, and nothing is stored until you review it and save. There is no server belonging to the extension, and the values are not sent to us, to any analytics service, or to any other third party.
What it stores on your computer. One value: the identifier of the wCRM tab it opened, so that capturing several contacts in a row reuses the same tab. It is cleared when you close the browser and it contains no personal data.
Removing the extension from Chrome removes it completely. The contacts you already saved stay in your wCRM account, and you can delete them there like any other contact.
Children
wCRM is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.
Changes
If we change this policy in a way that materially affects you, we will notify you by email or inside the application before the change takes effect.
