Privacy Policy
Effective September 4, 2026
This Privacy Policy explains how Totalscapes Qld Pty Ltd (ABN 20 696 605 580) ("CRM-007", "we", "us", "our"), trading as CRM-007, an Australian company registered in Queensland, Australia, collects, uses, and protects personal information through our website and CRM platform (together, the "Service").
This policy covers two different groups of people, and it's worth being upfront about the distinction:
- Customers — the businesses and individual users who sign up for and use CRM-007 directly ("you" in most of this policy).
- Website visitors identified through a customer's tracking snippet — people who visit one of our customers' websites, where our customer (not us) decides what data to collect and why. For that group, our customer is the data controller and we act as their data processor. If you're such a visitor and have a privacy question, please contact the business whose website you visited — we don't have a direct relationship with you and can't act on your data without instructions from our customer.
1. Information we collect from customers
Account and billing information. Company name, subdomain, your name, email address, and a hashed password when you sign up. If you choose a paid plan, our payment processor Stripe collects your payment details directly — we only receive your subscription status, plan, and billing history, never your full card number.
Content you put into the Service. Contacts, companies, deals, messages, notes, and any files or images you upload.
Provider keys you choose to add. If you connect your own Anthropic, xAI, OpenAI, Twilio, or SMTP credentials, we store them encrypted at rest and use them only to make requests on your behalf, as you've configured.
Usage and device information. Log data such as IP address, browser type, pages visited, and timestamps, collected automatically when you use our website or dashboard.
Communications. If you contact us — support tickets, the contact form, email — we keep a record of that correspondence.
2. Information collected on a customer's behalf (the tracking snippet)
When a customer installs our JavaScript tracking snippet on their own website, it collects the visiting device's IP address, page views, referrer, session duration, and similar browsing signals. We use that IP address to attempt to match the visit to a company (via third-party IP intelligence providers), and, at the customer's discretion, to further enrich that company's contact details. Visits that don't resolve to a company still appear in the customer's dashboard as anonymous sessions — nothing is silently discarded.
We process this data only under instruction from the customer who installed the snippet, for their own sales and marketing purposes. We don't use it for our own purposes, sell it, or combine it across customers.
3. Cookies
Our own marketing site and dashboard use strictly necessary cookies to keep you signed in and remember which login mode (customer or admin) applies to your session. We don't use third-party advertising cookies on our own site. The tracking snippet described above may set its own cookie or use similar client-side storage on our customers' websites, to recognize a returning visitor within a browsing session — that's governed by the customer's own cookie/privacy notice on their site, not this one.
4. How we use information
We use the information above to:
- Provide, maintain, and secure the Service;
- Process payments and manage subscriptions;
- Respond to support requests and communicate about your account;
- Detect, investigate, and prevent fraud, abuse, or security incidents; and
- Comply with our legal obligations.
Where GDPR applies (see Section 8), our legal bases for these uses are: performance of our contract with you (providing the Service you signed up for), our legitimate interests (security, fraud prevention, improving the Service), and, where relevant, your consent or compliance with a legal obligation.
5. Who we share information with
We share information with the following categories of service providers, each acting as our processor and bound by their own data protection obligations:
- Stripe — payment processing and billing;
- Our hosting provider — application hosting and infrastructure;
- IP intelligence providers (e.g. ipapi.is, ip-api.com) — resolving a visitor's IP address to a company, for the visitor-identification feature;
- Anthropic, xAI, or OpenAI — only if you or a customer supplies your own API key for one of these providers, in which case content is sent directly to that provider under your account with them, not ours; and
- Twilio — only if you or a customer supplies their own Twilio credentials, for sending SMS.
We don't sell personal information, and we don't share customer data across tenants — each customer's data lives in its own isolated database. We may disclose information if required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets, in which case we'll require the successor to honor this policy.
6. International data transfers
We're based in Australia, and our infrastructure and service providers may be located in other countries, including the United States. Where we transfer personal information subject to GDPR outside the European Economic Area or United Kingdom, we rely on appropriate safeguards such as Standard Contractual Clauses with our processors.
7. Data retention and deletion
We keep customer account data for as long as your account is active. If you close your account, we delete your tenant database and associated files within a commercially reasonable time, except for billing records we're required to retain by law. You can request deletion or an export of your data at any time by emailing privacy@crm007.com.
8. Your rights
If you're in the European Economic Area or United Kingdom (GDPR/UK GDPR): you have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to lodge a complaint with your local data protection authority.
If you're a California resident (CCPA/CPRA): you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of any sale or sharing of personal information — we don't sell personal information, so there's nothing to opt out of on that front.
If you're in Australia: we handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth), including your right to access and correct information we hold about you.
To exercise any of these rights, email privacy@crm007.com. We'll respond within the timeframe required by the applicable law.
9. Security
Each customer's data is stored in its own isolated database, not a shared table filtered by an ID. Passwords are hashed, not stored in plain text, and sensitive configuration such as API keys is encrypted at rest. No method of transmission or storage is completely secure, so we can't guarantee absolute security, but we work to protect your information using industry-standard practices.
10. Children's privacy
The Service isn't directed at children, and we don't knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we'll delete it.
11. Changes to this policy
We may update this policy from time to time. If we make a material change, we'll notify you by email or an in-app notice before it takes effect.
12. Contact us
Questions about this policy or how we handle your information? Email privacy@crm007.com or use our contact page.