Privacy Policy
Last updated: July 23, 2026
This Privacy Policy explains how Marketing Simplified ("we," "us," "our") collects, uses, and shares information in connection with Marketing Simplified CRM (the "Service"). By using the Service, you agree to this Policy.
1. Information We Collect
- Account information — name, email, phone, business name, and password when you sign up.
- Contact & lead data — the contacts, notes, custom fields, tags, messages, call recordings/transcripts, and appointments you create or import into the Service.
- Communications — the content and metadata of SMS, emails, and calls sent or received through the Service.
- Payment information — handled by our payment provider, Whop. We do not store your full card details; we receive subscription status and limited billing data.
- Usage & device data — log data, IP address, browser type, and how you interact with the Service, collected to operate and secure it.
2. How We Use Information
- To provide, maintain, and improve the Service;
- To send SMS, email, and place calls on your behalf when you instruct the Service to;
- To process subscriptions and payments;
- To provide support and respond to your requests;
- To secure the Service, prevent abuse, and comply with legal obligations.
Google user data is an exception to the general uses above: it is used only as described in Section 4 ("Google User Data") — to provide and improve the user-facing calendar and scheduling features you see in the Service, and for nothing else.
3. Service Providers & Sharing
We share information with trusted subprocessors only as needed to run the Service. We do not sell your personal information. Key providers include:
- Supabase (database, authentication) and Vercel (hosting) — store and serve your data;
- Twilio — voice calls and SMS; SendGrid — email delivery;
- Google and Microsoft — calendar sync, if you connect them (Google user data is handled per Section 4);
- Whop — subscription billing; OpenAI — optional call transcription.
We may also disclose information if required by law or to protect the rights, safety, and security of our users or the Service.
4. Google User Data
If you choose to connect a Google account, the Service accesses Google user data through Google's APIs with your explicit OAuth consent, limited to the openid, email, and Google Calendar (https://www.googleapis.com/auth/calendar) scopes. This section governs all Google user data, and takes precedence over anything else in this Policy for that data.
- What we access. Your Google account email (to label the connection) and your Google Calendar: free/busy times, calendar events, and the ability to create, update, and delete the specific events that correspond to appointments booked through the Service.
- How we use it. Solely to provide and improve the Service's user-facing calendar and scheduling features: showing your real availability, blocking times you are busy so you don't get double-booked, and keeping appointments booked in the Service in sync with your calendar. We do not use Google user data for advertising, and we do not use it for any purpose other than providing or improving these user-facing features.
- How we store it. OAuth tokens are encrypted at rest (AES-256-GCM). Free/busy and event data is fetched transiently when availability is computed and is not retained beyond what is needed to operate the feature; for appointments the Service books on your calendar, we store the event's identifier so we can update or cancel that same event later.
- How we share it. We do not sell Google user data, transfer it to advertisers or data brokers, or use it for credit or lending purposes. It is shared only with the infrastructure subprocessors necessary to run the Service (hosting and database, per Section 3), and only to provide the features above.
- AI/ML. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use Google user data — raw, aggregated, or derived — to create, train, or improve any machine learning or artificial intelligence models, whether ours or a third party's. Where a user-facing scheduling feature is assisted by AI (for example, suggesting currently-open appointment times in a conversation), Google-derived availability information is processed transiently at inference time only to provide that feature, and is not used for model training by us or by our AI providers.
- Human access. No human reads your Google Calendar data except with your explicit permission (e.g., a support request), where necessary for security purposes such as investigating abuse, or where required by law.
- Revoking access. You can disconnect your Google account at any time in the Service (Calendars → Connections), which deletes the stored tokens, or from your Google Account security settings. You may also request deletion of connection data at team@marketingsimplifiedcrm.io.
5. Your Contacts' Data (Controller / Processor)
For the contact and lead data you put into the Service, you are the "controller" and we act as a "processor" on your behalf. You are responsible for having a lawful basis and any required consent to collect and contact those individuals, and for responding to their privacy requests. We process that data only per your instructions and this Policy.
6. Cookies
We use strictly necessary cookies to keep you signed in and to operate the Service. We do not use them for third-party advertising.
7. Data Retention
We retain your data for as long as your account is active and as needed to provide the Service. After account closure, we delete or anonymize your data within a reasonable period, except where retention is required by law.
8. Security
We use industry-standard measures — including encryption in transit, access controls, and tenant isolation — to protect your information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at team@marketingsimplifiedcrm.io. You can also export or delete much of your data directly within the Service.
10. International Transfers
Your information may be processed in the United States and other countries where our providers operate. We take steps to ensure appropriate safeguards for such transfers.
11. Children
The Service is not directed to children under 18, and we do not knowingly collect their personal information.
12. Changes to This Policy
We may update this Policy from time to time. Material changes will be posted here with an updated date, and we will take reasonable steps to notify you.
13. Contact
Questions or requests about your privacy? Contact us at team@marketingsimplifiedcrm.io.