Privacy policy
This policy covers the CRM: the web application, its mobile app, and its WhatsApp features. The CRM is provided by STAGIONE MEDIA LLP, trading as Cloud 9 Digital (“we”). Our marketing website has its own policy.
Who decides what happens to your data
Businesses (“organizations”) subscribe to the CRM to manage their leads, their team and their conversations. For the information an organization puts into the CRM, such as its leads, their messages and its staff’s records, the organization is responsible for it and we process it on the organization’s behalf and on its instructions. For the accounts of people who sign in, and for running and securing the service, we are responsible.
What we collect
- Accounts: name, email address, phone number, role, and sign-in records (time, device, IP address).
- Leads and customers: the contact details and notes an organization records, and the activity on each lead (calls logged, stage changes, follow-ups).
- WhatsApp messages: when an organization connects its WhatsApp Business number, the messages sent and received on it, who sent them, delivery and read status, and the files in them. Files are fetched from Meta when someone opens them and are not stored by us.
- WhatsApp Business app history: if an organization connects a number it also uses on the WhatsApp Business app and agrees in Meta’s window to share its chat history and contacts, we receive them. We add past chats only for people who are already leads in the CRM; the rest is kept for 30 days and then deleted.
- Emails: the emails the CRM sends on an organization’s behalf, and whether they were delivered.
- HR (when an organization uses it): attendance check-ins with the time, location and a selfie, leave requests, and timesheets.
- Mobile app: a notification token so we can send alerts. On Android, if a user turns on caller identification, the phone numbers of incoming calls are matched against their organization’s leads on the device.
- Assistant (when an organization turns it on): the questions people ask and the answers, and voice notes they send, which are transcribed.
Information from Meta
When an organization connects WhatsApp through the CRM, Meta gives us an access token for that organization’s WhatsApp Business account, and its business, account and phone number IDs. We use them only to send and receive that organization’s messages, manage its message templates, and show its number’s status. We keep the token encrypted. We do not use data from Meta for advertising, sell it, or share it with anyone except as described in this policy.
Why we use it
- To provide the CRM: storing an organization’s data, sending the messages and alerts it asks for, and showing its reports.
- To keep the service secure: sign-in checks, audit logs, and detecting abuse.
- To support organizations when they ask for help, with their permission.
- To bill organizations for their subscription and messages.
We do not sell personal data, and we do not use an organization’s data to train AI models.
Who we share it with
Only the service providers that run parts of the CRM for us, each for that purpose alone:
- Vercel (hosting) and Neon (database), where the CRM runs and its data is stored.
- Meta (WhatsApp Business Platform) and WATI, which deliver WhatsApp messages.
- Brevo, which delivers email.
- Upstash, which schedules reminders.
- Google Firebase, which delivers mobile notifications, and Google Maps, which shows attendance locations.
- OpenAI and Anthropic, which power the assistant and voice transcription, only for organizations that turn it on.
We may also disclose data where the law requires it.
How long we keep it
- An organization’s data is kept while its subscription is active, and deleted within 90 days after it ends or when it asks us to delete it.
- The raw notifications Meta sends us about WhatsApp messages are kept for 30 days.
- When an organization disconnects its WhatsApp number, we delete the access token at once.
- Backups roll over and are gone within 30 days of deletion.
Security
Data travels encrypted. Access tokens and other credentials are encrypted at rest. Each organization’s data is kept separate, and people see only what their role allows. Changes to settings and access are recorded in an audit log.
Your rights
You can ask to see, correct or delete your personal data, and withdraw consent where we rely on it. If you are a lead or customer of an organization that uses the CRM, contact that organization first, since it decides about your data; you can also write to us and we will pass your request on. People in India have these rights under the Digital Personal Data Protection Act, 2023. How to delete your data.
Children
The CRM is for businesses and their staff, not for children.
Changes
We will update this page when the way we handle data changes, and tell organizations about significant changes by email.
Contact
STAGIONE MEDIA LLP (Cloud 9 Digital), WorkFlo Hitex, Units 405–411, 4th Floor, Bizness Square, Jubilee Enclave, Madhapur, Hyderabad, Telangana 500081, India. Email hello@cloud9digital.in or call +91 88853 33635.