Legal · Data Protection

Privacy Policy

Effective [EFFECTIVE DATE] Operated by [LEGAL ENTITY NAME] photoncrm.ai

In short

Photon CRM is an AI-native customer relationship management platform. This policy explains what data we collect, how we use it, and the rights you have over it. It includes specific disclosures about the Google user data we access (Gmail, Calendar, Drive, Contacts, and profile) and our commitment to Google’s Limited Use requirements. We do not sell your data, and we do not use your Google data to train generalized AI models.

01Who we are

Photon CRM (“Photon,” “we,” “us,” or “our”) is a software-as-a-service customer relationship management platform operated by [LEGAL ENTITY NAME], a company organized under the laws of [JURISDICTION]. This Privacy Policy applies to the Photon CRM web application, related applications, APIs, and websites that link to it (collectively, the “Service”).

For the purposes of the EU and UK General Data Protection Regulation (GDPR), [LEGAL ENTITY NAME] acts as a data controller for account and usage data, and as a data processor when handling the customer records, communications, and contacts you bring into the Service on behalf of your organization.

02Information we collect

We collect the following categories of information:

Account information

When you create an account, we collect your name, email address, organization, role, and authentication identifiers. If you sign in with Google, we receive your basic profile and verified email address from Google in place of a separate password.

Customer & relationship data

As a CRM, Photon stores the business records you and your team enter or import — contacts, companies, deals, notes, tasks, and the communications associated with them. You control this data; we process it to provide the Service to you.

Google user data

With your explicit authorization, we access certain data from your Google account through Google APIs. This is described in detail in Section 3.

Usage & device data

We collect technical information such as IP address, browser type, device identifiers, pages viewed, feature usage, and timestamps. We use strictly necessary cookies for authentication and session management, and (with consent where required) limited analytics to improve the Service.

03Google user data & scopes

Photon requests access to your Google data only after you grant consent on Google’s OAuth screen. You can decline any scope or revoke access at any time (see Section 12). We access the following:

Profile & email
Your name, profile picture, and verified email address — used to create and identify your account and to enable Google Sign-In.
openid email profile
Gmail
Read and send email so that Photon can sync relevant correspondence to the right contacts and deals, and let you send tracked messages from within the CRM. gmail.readonly gmail.send
Calendar
Read and write calendar events to log meetings against contacts and deals and to schedule activities from within Photon. calendar.events
Drive
Access files you explicitly attach or select so they can be linked to CRM records. We request the narrowest scope sufficient for this purpose. drive.file
Contacts
Read your Google Contacts to help you import and keep CRM contact records up to date. contacts.readonly

Gmail and Drive are classified by Google as restricted scopes; Calendar and Contacts are sensitive scopes. We request the minimum scopes required for each feature and request them incrementally, in context, rather than all at once.

04How we use information

We use the information we collect to:

We do not use your data for advertising, and we do not sell your personal information.

05Google API Services — Limited Use disclosure

Required affirmation

Photon CRM’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

For data obtained through restricted and sensitive scopes, we specifically commit that:

06AI & automated processing

Photon is an AI-native platform. Our AI features — such as summarization, drafting assistance, win-probability scoring, and forecasting — process your data to produce results for you and your organization within your own workspace.

We do not use Google user data obtained through restricted or sensitive scopes (Gmail, Drive, Calendar, Contacts) to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models. Where AI is applied to this data, it is solely to deliver the feature you requested, on your data, to you.

Some AI features may rely on third-party model providers. When data is sent to such providers for processing, it is transmitted under contractual terms that prohibit using your data to train their models and require its deletion after processing. We provide details of our subprocessors on request.

07How we share information

We share information only in these limited circumstances:

We do not sell or rent your personal information, and we do not share it for cross-context behavioral advertising.

08Data retention & deletion

We retain personal data only as long as needed to provide the Service and for legitimate, documented business or legal purposes. Synced Google data is retained for as long as your integration remains connected and is removed in line with your settings and our retention schedule.

You can delete records within the Service, disconnect Google integrations, or request deletion of your account at any time. On account deletion or verified request, we delete or irreversibly de-identify your personal data within a defined period, except where retention is legally required. Our architecture supports cryptographic erasure (“crypto-shredding”) so that encrypted data can be rendered permanently unrecoverable when keys are destroyed.

09Data security

We protect your data with encryption in transit (TLS) and at rest, strict access controls and least-privilege practices, tenant isolation, audit logging, and ongoing monitoring. Access to production data is limited to authorized personnel and is logged. No method of transmission or storage is perfectly secure, but we work continuously to protect your information and will notify affected users and authorities of qualifying incidents as required by law.

10International data transfers & residency

Photon may process data in countries other than where you are located. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses. We support regional data residency for eligible plans so that customer data can be hosted within a designated region.

11Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent at any time.

EU / UK (GDPR)

You have the rights described above and may lodge a complaint with your local supervisory authority. Our legal bases for processing include performance of a contract, legitimate interests, consent, and legal obligation.

California (CCPA/CPRA)

You have the right to know, delete, correct, and limit the use of sensitive personal information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined under California law, and we do not discriminate against you for exercising your rights.

To exercise any right, contact us at [CONTACT EMAIL]. We will verify your request and respond within the timeframes required by applicable law.

12Revoking Google access

You can revoke Photon’s access to your Google account at any time:

Revoking access stops further syncing. Data already synced into your CRM is handled per Section 8; you may delete it separately.

13Children’s privacy

Photon is a business tool not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

14Changes to this policy

We may update this policy to reflect changes to the Service or legal requirements. We will revise the “Effective” date above and, for material changes, provide additional notice. Continued use of the Service after changes take effect constitutes acceptance.

Contact us

Questions about this policy or your data? Reach our privacy team:

Entity [LEGAL ENTITY NAME]
Data Protection [DPO EMAIL]
Address [MAILING ADDRESS]