Groundbase

Privacy

Last updated · September 8, 2026 (removed a promise that cancelled accounts close and delete themselves after 30 days — nothing did that; deletion is by request, which is what this page now says)

The short version

Your CRM data lives in our cloud database so it can sync across your devices. We hold it for you, but we don't sell it, share it for advertising, or look at it for any purpose other than supporting the service you're paying for. You can export the whole thing as JSON at any time, and we delete it after you close your account.

What we collect about you (not your CRM data)

Independent of your CRM data, we collect:

Service providers we use

The product relies on third-party infrastructure. We share only the data necessary for these providers to do their job; none are permitted to use your data for their own purposes (including training models, marketing, or resale).

What we don't do

Google Workspace APIs — Limited Use

When Groundbase connects to a Google account (for example, to sync Google Calendar or read mail from a connected Gmail inbox), the use and transfer of any data received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What that means in practice:

How we protect sensitive data

CRM data — and especially the categories that lean sensitive (contacts' phone numbers, SMS/email content, voicemail recordings and transcripts, Google account tokens) — is protected by the following mechanisms:

Product analytics

We measure aggregate product usage — how many people complete signup, finish onboarding, or get stuck along the way — so we can find rough spots and fix them. We use PostHog for this, in their US region.

What is sent: your account's internal ID, named product events (signup, onboarding step completed, first campaign sent), and the page paths you visit inside the app.

What is not sent: your email address, and the content of your CRM data — contacts, messages, deals, notes, emails, or anything you type into form fields. Text is masked by default before any event leaves your browser.

One honest caveat: page paths include record identifiers, so a page view of a contact reads as /contacts/<id>. That tells us a record was opened; it carries nothing about who the contact is or what the record contains.

This is pseudonymous, not anonymous — the account ID is stable, so events from one account group together, and we could match that ID back to your account if we had reason to.

You can turn analytics off in Settings → General → Help improve Groundbase on web and desktop. The setting applies to the device you set it on. The mobile app does not currently expose this toggle — if you want analytics off everywhere, email support@groundbasecrm.com and we'll disable it for your account.

Cookies & local storage

The web app stores a JSON Web Token (JWT) in your browser's local storage to keep you signed in across page refreshes. It expires after 30 days of inactivity or when you sign out.

Our product-analytics tool also sets a first-party cookie on groundbasecrm.com so a visit to the marketing site and a later session in the app are counted as one person rather than two. No advertising cookies are set, and no third party can read these from another site. Turning analytics off (below) stops it.

Your rights over your data

Data residency

Your data is currently hosted in the United States, and some processors are located in the United States and process data subject to U.S. law. If you have a data residency requirement that needs a specific region, email us and we'll see what we can do.

Contact

Questions about anything here? Email support@groundbasecrm.com.