Privacy Policy
Last updated: 7 October 2026
This policy explains how WebPrims (“we”, “us”) collects and uses personal data when you use WebPrims CRM (the “Service”). It is written to meet India's Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Two kinds of data
- Account data — your name, email, phone, organization details and usage logs. We are the data fiduciary for this data.
- Google sign-in — if you choose “Continue with Google”, Google shares your name, email address and profile picture with us. We use them only to create and secure your account and never access your Gmail, contacts or other Google data.
- Customer data — leads, clients, invoices, notes and files you or your team add to the Service. Your organization is the data fiduciary; we process it only on your instructions to provide the Service.
2. How we use data
- To provide, secure and improve the Service, and to send service emails (invitations, password resets, reminders).
- To respond to support requests and prevent fraud or abuse.
- We do not sell personal data and we do not use your customer data for advertising.
3. AI features
When you use WebPrims AI (assistant, insights, drafting, Smart Add), the relevant CRM records are sent through our AI gateway, OpenRouter, to the model provider that generates the response (currently DeepSeek; we may also use Anthropic). The AI only sees records your role can already access. We choose provider settings that do not allow your data to be used for training where the provider offers that option. Workspace admins can turn AI off for their whole workspace in Settings.
4. Service providers
We use trusted processors to run the Service: Supabase (database and authentication), Vercel (hosting), Google (sign-in and email delivery), and OpenRouter with its model providers such as DeepSeek or Anthropic (AI features). Data may be processed outside India with appropriate safeguards.
5. Security
Data is encrypted in transit, isolated per organization with database row-level security, and every change to key records is written to an audit trail. No method of storage is 100% secure, but we work to protect your data and will notify affected users of a breach as required by law.
6. Retention
We keep data while your account is active. When an organization is deleted, its data is removed from the live database and from backups within 30 days, unless law requires us to keep it longer.
7. Your rights
You can access, correct, export (CSV) or delete your data from within the Service, withdraw consent, and nominate another person to exercise your rights. People whose data is stored by one of our customers should contact that business directly.
8. Contact & grievances
Grievance Officer: WebPrims — webprims@gmail.com. We respond within 30 days.