Skip to content
DailyCRM
Legal Sign in Start free

Legal documents

  • Terms of Service
  • Acceptable Use Policy
  • Stock Images & Customer Content Policy
  • Privacy Policy
  • Data Processing Addendum
  • Cookie Policy

On this page

  1. 1. Our role: controller and processor
  2. 2. Information we collect
  3. 3. How we use information
  4. 4. AI Features
  5. 5. How we share information
  6. 6. Service providers (subprocessors)
  7. 7. International transfers
  8. 8. How long we keep information
  9. 9. Security
  10. 10. Your rights and choices
  11. 11. Privacy Officer (Canada, including Quebec Law 25)
  12. 12. Notice for US residents (including California)
  13. 13. Cookies
  14. 14. Children
  15. 15. Changes to this policy
  16. 16. Contact

Legal / Privacy Policy

Privacy Policy

Last updated
October 3, 2026
Version
2026-10-03
Contents
  1. 1. Our role: controller and processor
  2. 2. Information we collect
  3. 3. How we use information
  4. 4. AI Features
  5. 5. How we share information
  6. 6. Service providers (subprocessors)
  7. 7. International transfers
  8. 8. How long we keep information
  9. 9. Security
  10. 10. Your rights and choices
  11. 11. Privacy Officer (Canada, including Quebec Law 25)
  12. 12. Notice for US residents (including California)
  13. 13. Cookies
  14. 14. Children
  15. 15. Changes to this policy
  16. 16. Contact

This Privacy Policy explains how [OPERATOR LEGAL NAME] (“DailyCRM”, “we”) collects, uses, discloses and protects personal information in connection with the DailyCRM platform: our website dailycrm.net, the web application at app.dailycrm.net, our mobile apps, the website builder and related services (the “Services”). Capitalized terms not defined here have the meaning given in the Terms of Service.

1. Our role: controller and processor

  • Account and visitor information. For information about the people who sign up for and use DailyCRM (account owners and Authorized Users) and about visitors to dailycrm.net, DailyCRM decides how the information is used and is responsible for it (the “controller”, or the organization accountable under Canadian law).
  • Information our customers store about their clients and team. Businesses that use DailyCRM (our “Customers”) store information about their own clients, leads, website visitors and employees (“Customer Data”). For Customer Data, the Customer is the controller and DailyCRM processes it only on the Customer’s behalf and instructions, as a processor / service provider, under our Data Processing Addendum.
  • Customer websites. Websites built with DailyCRM are operated by our Customers and have their own privacy policies. If you are a client of a business that uses DailyCRM, or visited its website, please contact that business about your information; we will help it respond.

2. Information we collect

Information you give us

  • Account information: name, email address, company name, time zone and language, password (stored only as a salted hash), two-step verification settings, role and permissions.
  • Billing information: plan, billing history, billing address and tax details. Card payments are processed by Stripe; we receive only limited details (such as card brand, last four digits and expiry) and never store full card numbers.
  • Support and communications: messages, support tickets and attachments you send us, and feedback.
  • Legal acceptance records: which versions of our legal documents you accepted, when, and from which IP address and browser.

Information collected automatically

  • Device and usage information: IP address, browser and device type, operating system, pages and features used, sign-in times, active sessions, and audit logs of actions in an account (for security and so Customers can see who changed what).
  • Security signals: information processed by Cloudflare Turnstile and our rate limiting to detect bots and abuse.
  • Cookies and local storage: see our Cookie Policy.
  • Push notification tokens if you enable notifications in the browser or mobile app.

Customer Data we process for Customers

  • Clients and leads: names, phone numbers, email addresses, service addresses, job details, notes, photos and files, quotes, invoices and payment status, messages and reminders, reviews, and website form submissions.
  • Marketing attribution for Customer Sites, when the Customer enables it: pages visited, referrer, UTM parameters and advertising click identifiers (such as gclid, fbclid, msclkid), phone-click events and conversion events sent to advertising platforms.
  • Technician location: when a Customer uses job start/stop features, the mobile or web app records the device’s location (coordinates, accuracy and time) at those moments, on the Customer’s behalf. We do not track location continuously in the background.

3. How we use information

  • To provide the Services: create and manage accounts, host Customer Sites, deliver notifications, process payments, provide support, and perform actions you request (including AI Features).
  • To keep the Services secure: authenticate users, prevent fraud, spam and abuse, investigate incidents, enforce our Terms and Acceptable Use Policy.
  • To communicate with you: service and transactional messages (account, security, billing, changes to our terms) and, with your consent where required, product news. You can unsubscribe from marketing emails at any time; service messages are part of the Services.
  • To improve the Services: analyse usage in aggregated or de-identified form, fix bugs and plan features.
  • To comply with law and protect rights: meet legal, tax and accounting obligations, respond to lawful requests, and establish, exercise or defend legal claims.

We use Customer Data only to provide the Services to the Customer, as described in the Data Processing Addendum. We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use Customer Data to advertise to our Customers’ clients.

4. AI Features

When you use an AI Feature (for example, generating website texts or recognizing a receipt), we send the information needed for that request to the AI provider that performs it (see section 6). The providers process it to return a result under contract terms that, as of the date of this policy, do not allow them to use such data to train their models. We do not use Customer Data to train AI models for other customers. We do not make decisions that produce legal or similarly significant effects about individuals based solely on automated processing.

5. How we share information

  • Service providers (subprocessors) that host, secure and operate the Services for us, under contracts that limit their use of the information — see section 6.
  • At the Customer’s direction — for example, when a Customer connects Meta Conversions API, Google Ads or Microsoft Advertising tracking, Telegram notifications or a custom domain through Cloudflare, or sends emails to its clients.
  • Within a Customer’s account — other Authorized Users see information according to the roles and permissions the Customer sets.
  • DailyCRM staff may access an account to provide support or investigate problems; such access is limited, requires a reason and is logged.
  • Legal and safety: when required by law or a valid legal request, or to protect the rights, property or safety of DailyCRM, our users or others.
  • Business transfers: in connection with a merger, acquisition, financing or sale of assets, subject to confidentiality and to this policy.
  • With your consent or at your request.

6. Service providers (subprocessors)

ProviderPurposeLocation
[HOSTING PROVIDER — confirm]Application servers, databases, backups and file storage[DATA CENTRE LOCATION — confirm]
Cloudflare, Inc.Content delivery, DNS, DDoS and bot protection (Turnstile), TLS certificates and routing for custom domains (Cloudflare for SaaS); optionally object storage (R2)Global network; USA
Stripe, Inc. and affiliatesSubscription billing, payments, invoices and tax calculationUSA, Canada, Ireland
Resend (Plus Five Five, Inc.)Delivery of transactional emailsUSA
OpenAI, L.L.C.AI Features (text generation)USA
Anthropic, PBCAI Features (text generation)USA
DatalabRecognition of text in receipts and documents (OCR) on requestUSA
650 Industries, Inc. (Expo)Delivery of mobile push notificationsUSA
Apple, Google, Mozilla, Microsoft push servicesDelivery of browser and device notifications you enableUSA / global
Pixabay GmbHStock image search in the site editor (search terms only; no account data is sent)Germany
Telegram, Meta Platforms, Google, MicrosoftOnly when a Customer enables the related integration (notifications, Conversions API, Google Ads, Microsoft UET) — these providers act under their own terms with the CustomerUSA / global

We may update this list as our providers change. Customers who need advance notice of new subprocessors can rely on the process in the Data Processing Addendum.

7. International transfers

Our servers are located in [DATA CENTRE LOCATION — confirm], and several of our providers are located in or process data in the United States and other countries. Personal information may therefore be stored or processed outside your province, state or country, and may be accessible to courts and authorities there. We use contractual and other measures to protect personal information transferred across borders and, where required (for example, under Quebec law), assess the protection it will receive before transferring it.

8. How long we keep information

  • Account information and Customer Data: for as long as the account is active. After an account is closed or terminated, the Customer can export data for at least 30 days; we then delete or anonymize it, normally within 90 days, except as below.
  • Backups: deleted data may remain in backups until they are rotated (daily backups are kept for about 30 days and monthly backups for about 6 months).
  • Billing and tax records: as long as tax and accounting laws require (generally 6–7 years).
  • Security logs and audit logs: for a limited period appropriate to their purpose, generally up to [24 months — confirm].
  • Records of acceptance of our legal documents: for the life of the account and afterwards for as long as needed to establish or defend legal claims (generally the applicable limitation period).
  • De-identified or aggregated information may be kept longer.

9. Security

We use administrative, technical and physical safeguards appropriate to the sensitivity of the information, including encryption in transit (TLS), database-level isolation of each Customer’s data, hashed passwords, optional and role-based mandatory two-step verification, role-based permissions, encryption of stored integration secrets, logging of staff access, malware scanning and metadata (GPS) stripping of uploaded files, and regular backups. No system is perfectly secure; you are responsible for keeping your credentials safe. If a breach of security safeguards creates a real risk of significant harm (or, under Quebec law, a risk of serious injury), we will notify affected individuals, regulators and Customers as required by law.

10. Your rights and choices

Depending on where you live, you may have the right to request access to your personal information, to correct it, to delete it, to withdraw consent, to receive it in a structured, commonly used technological format (data portability), to be informed about automated decisions, and to complain to a privacy regulator. Account owners can view, correct and export much of their information directly in the app.

To make a request, contact our Privacy Officer (section 11). We will verify your identity and respond within the time limits required by law (generally 30 days). If your request concerns Customer Data (for example, you are a client of a business that uses DailyCRM), we will refer it to that business, which is responsible for answering it, and help it as needed.

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner of Alberta or of British Columbia, or the privacy regulator where you live.

11. Privacy Officer (Canada, including Quebec Law 25)

The person in charge of the protection of personal information at DailyCRM is: [PRIVACY OFFICER NAME, TITLE], [OPERATOR LEGAL NAME], [OPERATOR ADDRESS], email [PRIVACY EMAIL].

12. Notice for US residents (including California)

This section supplements the policy for residents of US states with consumer privacy laws, including the California Consumer Privacy Act as amended (CCPA). For Customer Data, we act as a service provider / processor to our Customers.

  • Categories collected in the last 12 months: identifiers (name, email, IP address, account ID); customer records and commercial information (company, billing and plan details); internet or other electronic network activity (usage and log data); geolocation data (approximate location from IP address; precise device location at job start/stop when a Customer uses that feature); professional information (role, employer); and inferences limited to product usage.
  • Sources: you, your employer (the Customer), your devices, and our service providers.
  • Purposes: the business purposes described in section 3.
  • Disclosures: to service providers and as described in section 5. We do not sell or share personal information for cross-context behavioural advertising, and we have no actual knowledge of selling or sharing personal information of consumers under 16.
  • Sensitive personal information (account log-in credentials, precise geolocation) is used only to provide the Services, secure accounts and as otherwise permitted by law — not to infer characteristics about you.
  • Your rights: to know/access, delete, correct, opt out of sale/sharing (not applicable — we do not sell or share), limit the use of sensitive personal information (we already limit it), and not to be discriminated against for exercising your rights. You may use an authorized agent; we may ask for proof of authorization and verify your identity. We honour Global Privacy Control signals on dailycrm.net as an opt-out request where applicable.
  • To exercise your rights, email [PRIVACY EMAIL].

13. Cookies

We use only cookies and similar technologies needed to run and secure the Services and remember your preferences. See the Cookie Policy.

14. Children

The Services are for businesses and are not directed to children. Users must be at least 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us and we will delete it.

15. Changes to this policy

We may update this policy. The “Last updated” date and version at the top show the current version. If changes are material, we will notify account owners by email or in the app before they take effect and, where required, ask for consent or acceptance.

16. Contact

Questions or requests: [PRIVACY EMAIL] · [OPERATOR LEGAL NAME], [OPERATOR ADDRESS].

This document is written in English. Any translation is provided for convenience only; if there is a conflict, the English version governs to the extent permitted by law.

DailyCRM

CRM and website for cleaning and home-service companies.

Product

How it worksWebsite builderFeaturesPricing

Account

Sign inCreate accountFAQ

Legal

Terms of ServiceAcceptable Use PolicyStock Images & Customer Content PolicyPrivacy PolicyData Processing AddendumCookie Policy
© 2026 DailyCRM All legal documents