This policy explains what information CRM Goalie ([LEGAL ENTITY NAME]) collects, how we use it, and the choices you have. It covers our website, dashboard, and lead-intake endpoints (the “Service”). It is written for two audiences: the contractors who are our clients, and the consumers whose lead information our clients process through the Service.
01Information we collect
From clients (account holders): business name, your name and email, sign-in activity, the CRM credentials you connect (stored encrypted), your service-area ZIP codes, trades, vendor list and per-lead costs, and billing details handled by our payment processor. We never see or store full card numbers.
Lead records processed for clients: the fields a lead source sends, typically name, phone, email, street address, ZIP, the service requested, and any message the consumer wrote, along with the vendor it came from and the time it arrived. We also record the verdict, the reason, and the evidence for that verdict.
Technical data: request logs, IP addresses of systems delivering leads, and error diagnostics needed to run the Service reliably.
02How we use it
- To judge each lead against the client’s rules and deliver or hold it accordingly.
- To show the client a ledger of decisions with evidence, source-quality statistics, and monthly reports.
- To prepare credit-request packets for marketplace leads the client is entitled to dispute.
- To detect problems: for example, a vendor feed that has gone silent or a CRM connection that has stopped working.
- To bill clients, provide support, and secure the Service.
We do not sell personal information. We do not use lead records to market to consumers, and we do not build profiles of consumers across clients.
03Our role for consumer lead data
For lead records, our client is the business that receives the lead and decides how to use it; we process that data on the client’s instructions as a service provider. Consumers who have questions about how a particular contractor uses their information should contact that contractor. Where a consumer contacts us directly, we will forward the request to the relevant client and assist as needed.
04Automated decisions
The Service applies rules configured by each client (duplicate detection, existing-customer matching, service area, trade, phone and email validity) and, when a client enables it, an automated review of a lead’s message text to flag messages that are not service requests. These decisions determine whether a lead is delivered to the client’s active pipeline or held for review; they do not deny any consumer a service, and a client can reverse any decision at any time. Evidence for every decision is recorded and visible to the client.
05Who we share data with
We use a small set of infrastructure providers to run the Service, each bound by their own contractual and security commitments:
- Hosting and database: Vercel (application hosting) and Supabase (database and authentication), located in the United States.
- Payments: Stripe, for client billing.
- Email delivery: Resend, for account and report emails to clients.
- Phone-number intelligence: a carrier-lookup provider (Telnyx, IPQualityScore, or Twilio) that receives a lead’s phone number to confirm it is a working number and its line type.
- Message screening: Anthropic, when a client has enabled automated review of lead message text. Only the message text is sent, without the consumer’s name or contact details.
- The client’s CRM: the system you connect (for example GoHighLevel, HubSpot, JobNimbus, ServiceTitan, Housecall Pro, Salesforce, or Pipedrive) receives the lead records and verdicts you direct us to write there.
We may also disclose information when required by law or to protect the rights and safety of our clients, consumers, or the public.
06Retention
- Lead records and the decision ledger are retained for as long as the client’s account is active, because the ledger is the client’s permanent record of what was intercepted and why.
- After a client cancels or stops paying, their workspace is paused and its data retained for 90 days for export, then deleted.
- CRM credentials are deleted immediately when a connection is removed or an account is closed.
- Technical logs are kept for a limited period for security and debugging.
07Security
CRM credentials are encrypted at rest with keys held only by the Service. Each client’s data is isolated at the database level so one client can never read another’s records. Access to production systems is limited to the people who operate the Service. All traffic is encrypted in transit. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.
08Your choices and rights
- Clients can view, correct, export, and delete their account data and ledger from the dashboard or by contacting us, and can disconnect a CRM at any time.
- Consumers may ask what information about them a client has processed through the Service, or ask that it be corrected or deleted, by contacting the contractor who received the lead or by contacting us at the address below; we will route the request to the client and help fulfil it. Where state privacy laws grant additional rights, we honor them.
- We do not respond to browser “do not track” signals because the Service does not track visitors across other websites.
09Cookies
The dashboard uses a single, essential session cookie to keep you signed in. The marketing website does not use advertising cookies or third-party trackers.
10Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect information from children.
11Changes and contact
We will post any changes to this policy here and, for material changes, notify clients by email. Questions or requests: [LEGAL ENTITY NAME], [MAILING ADDRESS], privacy@crmgoalie.com.