CRM Goalie holds two kinds of sensitive information: the key that lets us read and write your CRM, and the lead records we judge on your behalf. Here is exactly how each is handled. No marketing language; if something below changes, this page changes first.
Encrypted at rest, decrypted only in the engine
Your CRM key is encrypted with AES-256-GCM the moment you paste it. It is decrypted in memory only when the engine talks to your CRM, and never shown again in the dashboard, logs, or emails.
One client can never read another's records
Every row in the database carries your workspace ID and is protected by row-level security enforced by the database itself, not just by our application code.
Encrypted in transit, everywhere
All traffic between your browser, our servers, your CRM, and our providers uses TLS. Intake URLs carry a per-client secret token; the lead mailbox address is unguessable.
Our downtime never loses your lead
If any part of CRM Goalie is unavailable, leads pass through to your CRM unchecked and are logged for review. Worst case is one junk lead through, never one real lead lost.
Every verdict is reversible
Rejected leads are parked with their evidence and restored with one click. The ledger is append-only; we do not edit or delete decision history.
We prove the lead landed
After every delivery we read the record back from your CRM and keep a receipt. A lead that fails that check raises an alert to our team within seconds.
Least privilege, named people
Production access is limited to the people who operate the service. Sign-in to your dashboard is by single-use magic link; there are no passwords to leak.
A short, named list of subprocessors
Vercel (hosting), Supabase (database and authentication), Stripe (billing), Resend (email), a phone-lookup provider (Telnyx, IPQualityScore, or Twilio), and Anthropic for optional message screening (message text only, no contact details).
01Retention
Lead records and the decision ledger stay for the life of your account, because the ledger is your permanent record. After cancellation your data remains exportable for 90 days, then is deleted. CRM credentials are deleted the moment a connection is removed.
02Incidents
If we learn of a breach affecting your data, we notify you without undue delay with what happened, what was affected, and what we did. Engine incidents that could affect lead flow are fixed the same day and reported in your weekly digest.
03Roadmap
Independent SOC 2 assessment is planned once client volume justifies the audit. Until then, this page is the commitment and the Privacy Policy and Terms are the contract.