Privacy Policy

Your Privacy
Matters to Us

We take data privacy seriously. This policy explains how we collect, use, and protect your information.

Last updated: January 28, 2026

TL;DR - Quick Summary

  • We collect only the data necessary to provide our services and improve your experience.
  • Your data is encrypted and stored securely. We never sell your information to third parties.
  • You own your data and can export or delete it at any time.
  • We're GDPR compliant and SOC 2 Type II certified.

Information We Collect

Account Information

When you create a Ghost CRM account, we collect your name, email address, company name, and payment information. This information is necessary to provide you with access to our services.

Usage Data

We automatically collect information about how you use our services, including features accessed, time spent, and interactions. This helps us improve our product and provide better support.

Customer Data

You may choose to store customer information, leads, opportunities, and other business data in Ghost CRM. You retain all rights to this data, and we act as a data processor on your behalf.

Technical Information

We collect device information, IP addresses, browser types, and operating systems to ensure security and optimize performance across different platforms.

How We Use Your Information

Service Delivery

We use your information to provide, maintain, and improve Ghost CRM services, including AI features, analytics, and integrations.

Communication

We may send you service-related emails, product updates, security alerts, and marketing communications (which you can opt out of at any time).

Product Improvement

We analyze usage patterns and feedback to enhance features, develop new functionality, and improve user experience.

Security and Compliance

We use your information to detect fraud, prevent abuse, ensure security, and comply with legal obligations.

Data Sharing and Disclosure

Service Providers

We share data with trusted third-party service providers who help us operate our business, including hosting, payment processing, and analytics providers. These providers are contractually required to protect your data.

Legal Requirements

We may disclose information when required by law, such as in response to subpoenas, court orders, or other legal processes.

Business Transfers

If Ghost CRM is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

With Your Consent

We may share your information with third parties when you explicitly consent to such sharing, such as when using integrations.

Data Security

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. We employ industry-standard security measures to protect your information.

Access Controls

We implement strict access controls and authentication mechanisms to ensure only authorized personnel can access systems and data.

Regular Audits

Our security practices are regularly audited by independent third parties. We are SOC 2 Type II certified.

Incident Response

We maintain an incident response plan and will notify affected users in the event of a data breach within 72 hours of discovery.

Your Rights and Choices

Access and Portability

You have the right to access your personal data and receive a copy in a structured, machine-readable format.

Correction and Deletion

You can update or delete your personal information at any time through your account settings or by contacting support.

Data Retention

We retain your data for as long as your account is active or as needed to provide services. After account deletion, data is retained for 90 days before permanent deletion.

Marketing Opt-Out

You can opt out of marketing communications at any time by clicking the unsubscribe link in emails or adjusting your account preferences.

International Data Transfers

Data Centers

We store data in secure facilities located in the United States and European Union. Data may be transferred between regions to provide our services.

GDPR Compliance

For European users, we comply with GDPR requirements and have implemented appropriate safeguards for international data transfers.

Privacy Shield

We adhere to data protection principles and maintain certifications for cross-border data transfers.

Cookies and Tracking

Essential Cookies

We use cookies necessary for the operation of our services, including authentication and security.

Analytics Cookies

We use analytics tools to understand how users interact with our platform. You can control cookie preferences in your browser settings.

Third-Party Cookies

Some integrations may use their own cookies. Please refer to their privacy policies for more information.

Children's Privacy

Age Restrictions

Ghost CRM is not intended for use by individuals under 16 years of age. We do not knowingly collect information from children.

Parental Notice

If we become aware that we have collected information from a child under 16, we will take steps to delete that information promptly.

Contact Us About Privacy

If you have questions about this Privacy Policy or our data practices, please contact us:

Email: privacy@boocrm.com

Address: Ghost CRM Inc., 123 Market Street, Suite 400, San Francisco, CA 94103

Data Protection Officer: dpo@boocrm.com

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a notice on our website. Continued use of our services after changes constitutes acceptance of the updated policy.