Privacy Policy
Last updated: July 3, 2026
1. Privacy Officer
17297394 Canada Inc. ("toncrm.io") is responsible for the protection of personal information collected through the toncrm.io platform and the toncrm.io website.
Privacy Officer: The President, 17297394 Canada Inc., Quebec, Canada.
Email: privacy@toncrm.io
Our roles: for the information of our direct clients (account, billing, usage data), toncrm.io acts as the data controller. For the information our clients store about their own contacts, toncrm.io acts as a processor: the client business remains the controller, and those individuals exercise their rights with that business. This role is governed by our data processing agreement (DPA), available in the application.
2. Information We Collect
We collect the following information:
- Registration information: name, email address, phone number
- Billing information: address, payment details (processed by Stripe)
- Usage data: pages visited, features used, activity logs
- CRM contact data: information you enter into your toncrm.io account
- Communications: emails and messages exchanged through the platform
3. Purpose of Collection
Your information is collected and used to:
- Provide and improve toncrm.io services
- Process payments and billing
- Communicate with you regarding your account and our services
- Ensure security and prevent fraud
- Comply with our legal obligations
4. Data Hosting and Retention
toncrm.io infrastructure is hosted on Hetzner Cloud (Germany and Finland, European Union). A privacy impact assessment (PIA) was completed on July 3, 2026 for communications outside Quebec. It is available on request at privacy@toncrm.io. Hetzner Cloud operates under the European GDPR, which provides an equivalent or higher level of protection. Some processing services are located in the United States (see Sub-processors below).
Information is retained as long as your account is active. Upon a deletion request, your account is deleted within 30 days. Data of a closed organization is purged 30 days after closure. Backups are retained for 7 days. Logs are retained according to applicable legal obligations. Bank transactions imported through a bank connection are retained as long as the account is active and deleted when the bank is disconnected or the account is closed.
5. Sub-processors
We use the following third-party services to operate toncrm.io. All sub-processors are bound by data processing agreements. The up-to-date list is available in the application and on request at privacy@toncrm.io.
| Service | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application, database, backups, and file storage | European Union (Germany / Finland) |
| Cloudflare, Inc. | Network proxy, CDN, and DNS in front of the application | United States / global |
| Anthropic, PBC | Generative AI models (assistants, copilot, analysis) | United States |
| OpenAI, L.L.C. | Embeddings for semantic search and AI memory | United States |
| Twilio Inc. | SMS, MMS, and phone calls | United States |
| ElevenLabs Inc. | Voice synthesis for AI agents (if enabled) | United States |
| Resend, Inc. | Delivery of transactional and marketing emails | United States |
| Stripe, Inc. | Payment processing | United States / Canada |
| Plaid Inc. | Bank connection and transaction import (if connected) | United States |
| Google LLC | Gmail / Contacts / Calendar OAuth connection; text-to-speech (TTS), mapping (Places), and Google Ads conversion measurement (if connected) | United States |
| Microsoft Corporation | Outlook / Microsoft 365 OAuth connection (if connected) | United States |
| Bunny.net (BunnyWay d.o.o.) | CDN for delivery of uploaded media | Slovenia (European Union) |
| Recall AI, Inc. (Recall.ai) | Video meeting capture (bot that records and transcribes), if meeting recording is enabled | European Union (Germany) |
| ipapi.co | Approximate IP-based geolocation (punch clock) | United States |
| Intuit Inc. (QuickBooks Online) | Accounting import (if connected) | United States |
| Square (Block, Inc.) | Invoice import (if connected) | United States |
| PayPal, Inc. | Invoice import (if connected) | United States |
| Hunter (Hunter.io) | B2B lead enrichment (if enabled) | United States |
Providers marked "if connected" or "if enabled" only receive data when your organization activates the corresponding feature.
The virtual assistant's voice is a synthetic voice generated by ElevenLabs.
6. Information Sharing
We never sell your personal information. We may share it only with the sub-processors listed above, solely for the purposes described.
7. Your Rights (Quebec Law 25 / PIPEDA)
Under Quebec's Act respecting the protection of personal information in the private sector (Law 25) and federal PIPEDA, you have the right to:
- Access your personal information
- Request correction of inaccurate information
- Request deletion of your information
- Withdraw your consent to collection or use of your information
- Obtain data portability in a structured format
- Request that the dissemination of your information cease or that it be de-indexed (s. 28.1)
- File a complaint with the Commission d'accès à l'information du Québec (CAI) (s. 90)
- Be notified of any privacy incident
To exercise these rights, contact us at privacy@toncrm.io. We will respond within 30 days.
8. Security
We implement technical and organizational security measures to protect your information, including:
- Encryption in transit (TLS 1.2+)
- Encryption of sensitive secrets (email connection tokens, telephony credentials)
- Encrypted off-site backups
- Generalized encryption at rest currently being rolled out
- Two-factor authentication available
- Role-based access control (RLS)
- Continuous security review and automated testing
Card payments are processed by Stripe, PCI-DSS certified; toncrm.io never stores any card number.
9. Electronic Communications (CASL)
toncrm.io allows its clients to send commercial electronic messages (SMS and email) to their contacts. In compliance with Canada's Anti-Spam Legislation (CASL):
- Consent: No commercial messages are sent without explicit (active opt-in) or implied consent (existing business relationship, max 2 years).
- Unsubscribe: Every marketing message includes a functional unsubscribe mechanism. Unsubscribe requests are processed immediately for SMS (STOP keyword) and within 10 business days for email.
- Identification: Every message identifies the sending business (name, contact information).
- Audit trail: All consent changes are recorded in an immutable audit log for legal evidence.
9.1 SMS A2P 10DLC Program (US Carriers)
For SMS messages sent to US phone numbers (10DLC), toncrm.io is registered as an «Independent Software Vendor (ISV)» with The Campaign Registry (TCR) and US mobile carriers (AT&T, Verizon, T-Mobile). The following rules apply specifically to A2P SMS messaging:
- No sharing of mobile phone numbers for third-party marketing : Mobile phone numbers, SMS opt-in data, and any information related to SMS consent are NEVER sold, rented, shared, or disclosed to third parties for marketing or promotional purposes. No affiliates, advertising partners, or third parties receive this data.
- Message frequency : Frequency varies based on each customer's usage. Recipients may request a reduced frequency at any time by replying directly to the sender.
- Message and data rates : Message and data rates may apply based on your mobile plan. toncrm.io and its customers never charge directly for received SMS messages.
- Required keywords : Reply «STOP», «CANCEL», «UNSUBSCRIBE», «END», or «QUIT» to immediately unsubscribe. Reply «HELP» or «INFO» for contact and assistance information.
- Supported carriers : AT&T, Verizon, T-Mobile, US Cellular, and other North American carriers.
- SMS message categories : appointment notifications, reminders (payments, follow-ups), transaction confirmations, occasional promotions, satisfaction surveys. No regulated content (gambling, alcohol, cannabis, high-interest loans, adult content, firearms) is permitted on toncrm.io's A2P program.
- Access to mobile opt-in data : Only the operator of the customer business (the toncrm.io account holder who collected the consent) has access. toncrm.io stores this data in an organization-segmented database hosted at Hetzner Cloud (European Union). A privacy impact assessment (PIA) was completed on July 3, 2026 for communications outside Quebec.
For any questions regarding the processing of your mobile opt-in data within the A2P 10DLC program, contact privacy@toncrm.io.
10. Cookies and Tracking Technologies
On our website, a consent banner is shown on first visit. Analytics cookies (Google Analytics) are only loaded after your acceptance. No advertising cookies are used.
- Strictly necessary cookies for platform operation (session, preferences)
- Analytics cookies (Google Analytics), set only after consent
- Partner attribution cookie (crm_ref, 60 days), set after consent when you arrive via a partner link
- Cookieless internal analytics (self-hosted)
- Emails sent through the platform may contain an open-tracking pixel and measured links (open and click statistics)
- The website chat uses a session identifier stored in your browser's local storage (localStorage) to maintain the conversation; exchanges are processed by our AI providers
You can change your choice at any time via the "Cookie preferences" link in the footer.
11. Google User Data (Google API Services User Data Policy)
When a user connects their Google account (Gmail, Google Calendar, Google Business Profile, Google Ads, YouTube) to toncrm.io, toncrm.io's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide and improve the service features the user connects: email sync (Gmail), including automatic triage and classification of inbound emails (suggestions, AI memory), calendar sync (Google Calendar), Google Business Profile management, Google Ads reporting, YouTube publishing.
- We do not transfer Google user data to third parties except as necessary to provide the requested service, or to comply with applicable law. Specifically, some features activated by the user (email triage, summaries, semantic search) have the content of synced Gmail emails processed by our AI providers (Anthropic, OpenAI) acting as sub-processors, in compliance with the Limited Use requirements; these providers do not train their models on this data.
- We do not use Google user data for advertising purposes.
- We do not use Google user data to train, develop, or improve any artificial intelligence or machine learning models, including large language models (LLMs).
- Users can revoke access at any time via toncrm.io integration settings, or directly at https://myaccount.google.com/permissions.
Google user data is scoped per authenticated user and per organization (strict multi-tenant isolation). No cross-organization access is possible.
11.1 Microsoft User Data
When a user connects their Microsoft account (Outlook / Microsoft 365) to toncrm.io via Microsoft Graph, the synced data (emails, contacts, signatures) is used only to provide the features activated by the user. As with Gmail, the content of synced Outlook emails may be processed by our AI providers (Anthropic, OpenAI) for triage, summaries, and semantic search, without any model training. It is never sold, used for advertising, or used to train AI models. Access can be revoked at any time from toncrm.io integration settings or from the Microsoft account portal.
12. Automated Decisions
The service may make decisions based on automated processing of personal information: sorting and prioritizing incoming calls, filtering incoming emails, automatic answering-machine detection on outbound calls, communication journeys triggered by interactions, and actions of the Oracle assistant.
In accordance with section 12.1 of Quebec's Act respecting the protection of personal information in the private sector, you have the right to be informed of such a decision, to submit observations to a member of our staff who can review the decision, to know the main factors and parameters that led to the decision, and to have the information used corrected. Contact privacy@toncrm.io.
13. Employee Data of Our Clients
Our clients may use workforce features: time punching with optional geolocation (GPS can be declined; an approximate IP-based fallback is then used), attendance confirmation photos if enabled by the employer (no facial recognition), and time and payroll data.
If your employer uses toncrm.io, your employer is responsible for informing you of this processing. Location data and photos are purged according to the retention schedule.
14. Minors
The service is intended for businesses. A user must be at least 14 years old; under Quebec law, consent for a minor under 14 rests with the holder of parental authority. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
15. Changes
We may update this policy from time to time. Significant changes will be communicated by email or via an in-app notification. The last updated date is indicated at the top of this page.
16. Contact
For any questions about this privacy policy, contact us at privacy@toncrm.io.