Privacy
Last updated · June 22, 2026 (added product analytics disclosure + opt-out section)
The short version
Your CRM data lives in our cloud database so it can sync across your devices. We hold it for you, but we don't sell it, share it for advertising, or look at it for any purpose other than supporting the service you're paying for. You can export the whole thing as JSON at any time, and we delete it after you close your account.
What we collect about you (not your CRM data)
Independent of your CRM data, we collect:
- Your email address — for signup, signin, and the handful of transactional emails we send (welcome, password reset, trial ending, payment failed, etc.).
- Your phone number — required at signup. We text you a 6-digit verification code through Twilio Verify (Twilio's managed verification service) to confirm you can receive SMS at the number you provided. We store the verified number on your account and use it to enforce our one-free-trial-per-phone policy (so a single person can't cycle through trials with new emails). We do NOT use your number for marketing or call you outside of system functions.
- Billing details — collected by our payment processor (Stripe), not by us. We see the last four digits, brand, and expiration of your card so we can show them in the billing screen; we never see the full card number.
- A small amount of session metadata — IP address, browser/device fingerprint, last sign-in time. Used to invalidate stolen sessions and to show you a list of where you're signed in.
- Usage logs for SMS, voice, and transcription — for activity history shown on contact detail pages and for service reliability. Not used for billing (Twilio bills you directly), not analyzed for marketing.
Service providers we use
The product relies on third-party infrastructure. We share only the data necessary for these providers to do their job; none are permitted to use your data for their own purposes (including training models, marketing, or resale).
- Cloud database & application infrastructure — stores your CRM data and runs the auth, API, and background sync services. Data is encrypted in transit and at rest.
- Payment processor — handles subscription billing. We see card brand, last four digits, and expiration; never the full card number.
- Twilio (your connected account) — Twilio is your own connected account, not a Groundbase subprocessor. Message and call content flows from Twilio to your contacts under your own agreement with Twilio. Groundbase only orchestrates the API calls using your encrypted Twilio credentials; we never see your Twilio bill.
- Twilio Verify (Groundbase's account) — separate from your BYO Twilio: we use Twilio Verify on our own master Twilio account to send the SMS code at signup. Twilio receives the phone number and the verification code request, and bills us (not you) for that single SMS. Twilio's privacy terms apply to that transmission.
- Resend (your connected account) — when you connect Resend for email campaigns, mail traffic flows directly from Resend to your recipients under your own agreement with Resend. Groundbase orchestrates the API calls using your encrypted Resend API key.
- Transactional email — sends the small set of system emails Groundbase generates (welcome, password reset, trial reminders). Doesn't handle the email you send from your own inbox connection.
- AI transcription — voicemail and call transcription. Audio is sent to a speech-to-text API for transcription only; the provider's terms prohibit training their models on this data. Disable transcription in Settings → Voice if you'd rather it not happen.
- Your email provider — if you connect Gmail, Outlook, or any IMAP account, the actual mail traffic flows directly between Groundbase and your provider. We hold an encrypted copy of your password server-side so the IMAP/SMTP connection can run from our background sync.
What we don't do
- We don't sell your data. To anyone. Ever.
- We don't share your data with advertisers or data brokers.
- We don't embed third-party trackers, ads, or analytics inside the signed-in app.
- We don't train any model on your CRM data.
Google Workspace APIs — Limited Use
When Groundbase connects to a Google account (for example, to sync Google Calendar or read mail from a connected Gmail inbox), the use and transfer of any data received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What that means in practice:
- Google user data is used only to provide or improve features the user has signed in for (e.g. showing your calendar events alongside Groundbase tasks).
- Google user data is not transferred to any third party except as necessary to provide or improve those features, comply with applicable law, or as part of a merger / acquisition / sale of assets with appropriate notice.
- Google user data is not used for serving advertisements, and we do not allow humans to read it except where you have given affirmative consent, where required for security purposes (such as investigating abuse), to comply with applicable law, or where the data has been aggregated and anonymized.
- Google user data is not used to develop, improve, or train generalized AI or ML models.
How we protect sensitive data
CRM data — and especially the categories that lean sensitive (contacts' phone numbers, SMS/email content, voicemail recordings and transcripts, Google account tokens) — is protected by the following mechanisms:
- Encryption in transit. All API traffic between your browser/app and our backend, and between our backend and every subprocessor (Cloud DB, payments, SMS/voice, transcription, email provider), uses TLS 1.2 or higher.
- Encryption at rest. The cloud database storing your CRM data encrypts all customer data at rest using AES-256. Backups inherit the same encryption.
- OAuth tokens, IMAP/SMTP passwords, and Twilio API keys are stored with an additional layer of application-level encryption on top of the database's at-rest encryption. They are decrypted only at the moment of use to make an authenticated call to the relevant provider.
- Authentication. Sessions are bearer-token (JWT) based, 30-day rolling, and can be revoked from any session at any time. Time-based one-time-password (TOTP) MFA is available under Settings → Security — we recommend turning it on.
- Access controls. Production data access is restricted to the small set of operators (currently: the founder) who need it to support the service. Access is gated behind the same MFA-protected account credentials, never shared, and audit-logged. No third party has direct database access.
- Retention. Active CRM data is retained while your subscription is active. When you cancel, data persists through the 30-day reactivation window and is then deleted. Voicemail recordings older than 90 days are pruned automatically unless you star them. SMS/email content stays as long as the contact does — deleting a contact removes their conversation history.
- Subprocessor scope. Each subprocessor receives only the data it needs to do its job (e.g. the transcription provider receives audio files; the payment processor never sees CRM data). Twilio is your own connected account rather than a Groundbase subprocessor — phone numbers and message bodies flow to Twilio under your own agreement with them. None of our subprocessors are permitted to use the data for their own purposes.
- Incident response. In the unlikely event of a breach affecting your data, we will notify affected users by email within 72 hours of confirmation, including the nature of the incident and what data was involved.
Product analytics
We measure aggregate product usage — how many people complete signup, finish onboarding, or get stuck along the way — so we can find rough spots and fix them. We use PostHog for this.
We do NOT capture the content of your CRM data — contacts, messages, deals, notes, emails, or anything you type into form fields. That stays inside your account.
You can turn analytics off at any time in Settings → General → Help improve Groundbase. When off, no further events are sent for your account.
Cookies & local storage
The web app stores a JSON Web Token (JWT) in your browser's local storage to keep you signed in across page refreshes. It expires after 30 days of inactivity or when you sign out. No third-party cookies are set by the app.
Your rights over your data
- Export — Settings → Backup & Export gives you a full JSON dump of every CRM table.
- Correct or delete individual records — built in to the app.
- Reset to empty — Settings → Backup & Export → Reset to empty database wipes all your CRM records (contacts, deals, tasks, messages, calls, etc.).
- Delete your account — email
support@groundbasecrm.comfrom your account email and we'll close the account and remove your data within 7 business days. If you cancel your subscription instead, your account closes automatically after the 30-day reactivation window expires.
Data residency
Your data is currently hosted in the United States, and some processors are located in the United States and process data subject to U.S. law. If you have a data residency requirement that needs a specific region, email us and we'll see what we can do.
Contact
Questions about anything here? Email support@groundbasecrm.com.