This Privacy Policy (“Policy”) describes how ZAMZILLA LLC, a limited liability company doing business as DashCRM (“Company,” “we,” “us,” or “our”), collects, uses, discloses, and protects information about you when you access or use the DashCRM platform and related services (collectively, the “Service”) available at https://apps.dashcrm.io.
By using the Service, you agree to the collection and use of your information as described in this Policy. If you do not agree with this Policy, please do not use the Service.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: Name, email address, password (hashed), phone number, company name, job title, and profile photo when you register for an account.
- Billing Information: Payment card details and billing address, processed and stored by our payment processor (Stripe). We do not store full payment card numbers.
- CRM Data: Contact records, lead information, pipeline data, notes, tasks, activities, call logs, support tickets, and any other data you input into the Service.
- Communications: Messages, feedback, support requests, and other communications you send to us.
- Uploaded Content: Documents, images, audio recordings, and other files you upload to the Service.
1.2 Information Collected Automatically
- Usage Data: Pages visited, features used, actions taken, timestamps, and session duration.
- Device and Browser Information: IP address, browser type and version, operating system, device identifiers, and screen resolution.
- Cookies and Similar Technologies: We use session cookies for authentication and functional cookies to remember your preferences. See Section 7 for details.
- Log Data: Server logs including IP addresses, request timestamps, error logs, and API call metadata.
1.3 Information from Third Parties
- Google OAuth: If you sign in using Google, we receive your Google account name, email address, profile photo, and a unique Google identifier. We do not receive your Google password.
- Integration Partners: If you connect third-party services (such as Twilio, WordPress, or Zapier), we may receive data from those services as part of the integration.
- Publicly Available Data: We may supplement your profile with publicly available professional information for lead enrichment features.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, maintain, and improve the Service.
- Create and manage your account and authenticate your identity.
- Process payments and manage subscriptions.
- Enable AI-powered features, including lead scoring, call transcription, and automated workflows.
- Send transactional emails and notifications (account confirmations, password resets, billing alerts).
- Respond to your support requests and communications.
- Monitor and analyze usage patterns to improve functionality and user experience.
- Detect, prevent, and address technical issues, security incidents, and fraudulent activity.
- Comply with legal obligations and enforce our Terms of Service.
- Send product updates, feature announcements, and marketing communications (you may opt out at any time).
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data under the following legal bases:
| Processing Purpose | Legal Basis |
|---|---|
| Account creation and service delivery | Contract performance |
| Payment processing | Contract performance |
| Security and fraud prevention | Legitimate interests |
| Analytics and service improvement | Legitimate interests |
| Marketing communications | Consent (opt-in) |
| Legal compliance | Legal obligation |
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
4.1 Service Providers
We share information with trusted third-party vendors who assist us in operating the Service, including:
- Stripe — payment processing
- Amazon Web Services (AWS) — cloud infrastructure and file storage
- Twilio — SMS and voice communications
- Google — OAuth authentication and AI services
- OpenAI — AI language model services
- Resend / Email providers — transactional email delivery
These providers are contractually obligated to use your data only as directed by us and in accordance with applicable privacy laws.
4.2 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.
4.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency).
4.4 With Your Consent
We may share your information for any other purpose with your explicit consent.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. When you close your account, we will delete or anonymize your personal information within 90 days, except where we are required to retain it for legal, regulatory, or legitimate business purposes (such as resolving disputes or complying with legal obligations).
CRM data (contacts, leads, activities, etc.) that you have input into the Service is retained for the duration of your subscription and for 30 days after termination, after which it is permanently deleted.
6. Data Security
We implement industry-standard technical and organizational security measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS/HTTPS.
- Encryption of sensitive data at rest.
- Multi-tenant data isolation to prevent cross-tenant data access.
- Role-based access controls limiting employee access to personal data.
- Regular security assessments and monitoring.
- Secure password hashing (bcrypt).
Despite these measures, no security system is impenetrable. We cannot guarantee the absolute security of your information. In the event of a data breach that affects your rights and freedoms, we will notify you and applicable authorities as required by law.
7. Cookies and Tracking Technologies
We use the following types of cookies:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Session (Authentication) | Keeps you logged in and maintains your session state | 1 year or until logout |
| Functional | Remembers your preferences (theme, language, sidebar state) | 1 year |
| Analytics | Helps us understand how the Service is used (aggregated, anonymized) | Up to 2 years |
You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Service, particularly authentication cookies.
8. AI Features and Data Processing
DashCRM includes AI-powered features that process your data to generate insights, automate tasks, and provide recommendations. Specifically:
- Call Transcription: Audio recordings may be processed by our AI transcription service (using Whisper API) to generate text transcripts. Transcripts are stored in your account.
- Lead Scoring: Contact and lead data is analyzed by AI models to generate scores and recommendations.
- AI Copilot: Your queries to the AI Copilot are processed by third-party AI providers (OpenAI, Google). These providers may process your data subject to their own privacy policies.
- No Training on Your Data: We do not use your Customer Data to train our AI models or those of our AI providers without your explicit consent.
9. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information (subject to legal retention requirements).
- Portability: Request a machine-readable export of your personal data.
- Objection / Restriction: Object to or request restriction of certain processing activities.
- Withdraw Consent: Withdraw consent for processing based on consent (e.g., marketing emails) at any time.
- California Residents (CCPA): You have the right to know what personal information we collect, the right to delete, the right to opt out of sale (we do not sell personal information), and the right to non-discrimination for exercising your rights.
To exercise any of these rights, please contact us at pr*****@*****rm.io. We will respond within 30 days (or within the timeframe required by applicable law).
10. International Data Transfers
ZAMZILLA LLC is based in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to this transfer.
For users in the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for transferring personal data to the United States.
11. Children’s Privacy
The Service is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected information from a child, please contact us at pr*****@*****rm.io.
12. Links to Third-Party Sites
The Service may contain links to third-party websites or services. This Policy does not apply to those third-party sites. We encourage you to review the privacy policies of any third-party sites you visit. We are not responsible for the privacy practices or content of third-party sites.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on this page and updating the “Effective Date” above. For significant changes, we may also send you an email notification. Your continued use of the Service after such changes constitutes your acceptance of the updated Policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Team:
ZAMZILLA LLC dba DashCRM
Privacy Team Email: pr*****@*****rm.io
General Email: le***@*****rm.io
Website: https://apps.dashcrm.io
If you are located in the EEA and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.
