1. Who This Policy Covers, and Our Role

This Privacy Policy explains how TechZarInfo Software Solutions PVT LTD (“TZI-CRM,” “we,” “us”) collects, uses, stores, and shares information through the TZI-CRM customer relationship management platform (the “Service”), including its web application, APIs, and any connected mobile clients.

TZI-CRM is a multi-tenant B2B SaaS product. Each customer organization that signs up (“Tenant,” “Customer,” “you,” if you are a Tenant Admin) creates an account and invites its own employees (“Users”) to use the Service. Because of this structure, we act in two different roles:

  • Data controller — for account-level information about Tenants and Users: names, work emails, login credentials, device/session records, billing contacts, and support communications. We decide why and how this data is processed to operate and secure the Service.
  • Data processor (service provider)— for the business data a Tenant’s Users enter about the Tenant’s own customers and contacts: leads, deals, invoices, proposals, messages, and similar records (“Customer Data”). Here, the Tenant is the controller and determines what data is collected and why.

Tenant Admins are responsible for having a lawful basis to collect and process their end-customers’ personal data within the CRM, including obtaining any consents required under the DPDP Act or other applicable law.

If you are an end-customer whose details were entered into TZI-CRM by one of our Tenants (for example, a lead or contact), your relationship is with that Tenant, not with us. Please direct data requests to them; we will assist our Tenant in fulfilling such requests as their processor.

2. Information We Collect

2.1 Account and Tenant Data

When a Tenant signs up and invites Users, we collect names, work email addresses, phone numbers, role/designation, password hashes, and organization details (company name, industry, team size).

2.2 Customer Data

Leads, deals/pipeline records, contacts, tasks, targets, calendar events, proposals, and invoices that Users create within the Service. This is Customer Data as defined in our Terms & Conditions and belongs to the Tenant, not to us.

2.3 Communications Data

Messages sent and received through the Service’s messaging features, including WhatsApp, Instagram, Facebook, and connected Gmail accounts (see Sections 3 and 4 for specifics), and internal notes/comments Users attach to records.

2.4 Usage and Log Data

IP addresses, browser/device type, pages and features accessed, timestamps, and error/diagnostic logs, collected automatically to operate, secure, and improve the Service.

3. Meta Platform Data (WhatsApp, Instagram, Facebook)

If a Tenant connects a WhatsApp Business, Instagram, or Facebook Page account, the Service uses Meta’s Graph API and WhatsApp Cloud API to access and store:

  • Messages, comments, and media (images, documents, etc.) exchanged through the connected channel;
  • Sender contact information (name, phone number, or social handle) attached to those messages;
  • Page/business access tokens necessary to keep the connection authenticated; and
  • Records automatically created from incoming messages, such as new Leads generated from a chat or comment.

This data is used solely to provide messaging and CRM functionality within the connecting Tenant’s account — for example, so a sales rep can see and reply to a WhatsApp conversation from inside the CRM. It is not sold, and is not shared with third parties beyond what is necessary to operate the integration (i.e., with Meta itself, as the platform the message passed through) and standard service sub-processors described in Section 9.

You may request deletion of Meta Platform Data associated with your account as described in Section 12 (Requesting Deletion of Your Data).

4. Gmail / Google Account Data

If a User connects a Gmail account, the Service requests the following Google API scopes to power the CRM’s Email Chat feature: reading messages, composing and sending messages, and modifying message state (e.g., marking as read, labeling) on the connected mailbox. Access and refresh tokens are stored to keep the connection active.

We access, use, store, and share information received from Google APIs in accordance with the Google API Services User Data Policy, including the Limited Use requirements:

  • Gmail data is used only to display, send, and organize your email within the Service’s Email Chat feature — never for advertising or ad-related purposes;
  • Gmail data is not transferred to third parties except as necessary to provide or improve user-facing features of the Service, to comply with law, or as part of a merger/acquisition (with continued protection of the data);
  • No human at TZI-CRM reads Gmail content except (a) with your affirmative consent for a specific support request, (b) for security purposes such as investigating abuse, or (c) to comply with applicable law.

You can disconnect your Gmail account at any time from your account settings, which revokes the stored token; Google account permissions can also be revoked directly at myaccount.google.com/permissions.

5. Location Data

If a Tenant enables the Live Team Locations feature (available on eligible plans), the Service collects the GPS coordinates of a User’s device approximately every 30 seconds while that User is logged in and the feature is active. This data is used solely to let the Tenant’s Admin(s) view the real-time location of field/sales staff within that Tenant’s account, and is displayed only to Admins within the same Tenant — it is never visible to other Tenants or shared outside your organization.

Location data is retained on a rolling basis and purged automatically after 90 days, except where a longer period is required for legal or dispute purposes.

If you are a Tenant Admin enabling this feature, you are responsible for notifying your employees that location tracking will occur and for obtaining any consent required under applicable labor and privacy law before turning it on. TZI-CRM will prompt Users for their device’s native location permission, but does not independently verify that an employer has met its own notice/consent obligations.

6. Device and Session Data

To keep accounts secure, we record information about each login session: device type (web or mobile), a device identifier generated on that device, a human-readable device label, IP address, and session status. New devices go through an approval flow — an existing Admin must approve a “Device Login Request” before a new device can access the account — and we log who approved or rejected each request and when.

7. How We Use Information

  • To provide, operate, and maintain the Service (e.g., rendering your pipeline, sending messages, syncing email);
  • To authenticate Users, secure accounts, and detect/prevent fraud or unauthorized access;
  • To provide customer support and respond to inquiries;
  • To send service-related communications (billing, trial/plan status, security alerts);
  • To monitor, diagnose, and improve platform performance and reliability;
  • To comply with legal obligations and enforce our Terms & Conditions.

We do not use Customer Data, Meta Platform Data, or Gmail data to train third-party AI/ML models, nor do we sell personal data.

8. Legal Basis and India’s DPDP Act, 2023

TZI-CRM is governed by the laws of India. Where the Service processes personal data of individuals located in India (“Data Principals”), we process that data consistent with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), including by:

  • Processing account-level data (Section 2) on the basis of the contract necessary to provide the Service to our Tenants, and legitimate business purposes such as security and support;
  • Relying on Tenants, as controllers of the Customer Data they enter, to establish their own lawful basis (typically consent or legitimate use) for processing their end-customers’ personal data;
  • Providing Data Principals the rights described in Section 13 below and a channel to raise grievances (Section 17).

9. How We Share Information

We do not sell personal data. We share information only with the following categories of recipients:

RecipientPurpose
Meta Platforms, Inc.Delivers WhatsApp/Instagram/Facebook messages via their Graph API and WhatsApp Cloud API (Section 3)
Google LLCGmail API access for the Email Chat feature (Section 4)
Transactional email provider (SMTP)Delivers account, billing, and security notification emails
Cloud hosting / database providerHosts application infrastructure and per-tenant databases
Professional advisors, auditors, or successorsOnly as necessary for legal compliance, or in connection with a merger, acquisition, or asset sale (with continued protection of the data)
Law enforcement / regulatorsOnly where required by applicable law or valid legal process

10. Data Retention

Data typeRetention
Customer Data (leads, deals, contacts, invoices, etc.)For the life of the Tenant’s subscription; exportable for 60 days after cancellation, then deleted within 90 days of cancellation unless a longer period is required by law
Meta Platform Data (messages, comments, media)Same as Customer Data above, or until you request earlier deletion (Section 12)
Gmail data (via Email Chat)Retained only as long as the Gmail connection remains active; deleted upon disconnection
Location dataRolling 90-day window, then purged automatically
Device/session and security logsUp to 12 months after account closure, for security and fraud-investigation purposes
Account data (Tenant/User records)For the life of the account; deleted or anonymized within 90 days of account closure, subject to legal holds

The periods above are TZI-CRM’s recommended defaults; confirm against actual operational practice before publishing.

11. Data Security and Multi-Tenant Isolation

We use industry-standard technical and organizational measures to protect information, including encryption in transit, access controls, and device-approval requirements for login (Section 6). Each Tenant’s data is stored in a separate, physically isolated database rather than in shared tables filtered by tenant ID — providing strong isolation between customers’ data at the infrastructure level.

No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

12. Requesting Deletion of Your Data

You may request deletion of your personal data, including data collected via WhatsApp, Instagram, Facebook, or Gmail integrations, by:

  • Emailing sales@techzarinfo.comwith the subject line “Data Deletion Request”; or
  • If you are a Tenant Admin, using the relevant deletion controls in your account settings (where available).

We will verify the request and complete deletion within a commercially reasonable time, except where we are required to retain certain data for legal, tax, or security purposes. If you contacted us through a connected Meta account, we will also honor deletion requests submitted via Meta’s own data-deletion request flow, where applicable.

13. Your Rights as a Data Principal

Subject to applicable law (including the DPDP Act), you may have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Request erasure of your data, subject to Section 10;
  • Withdraw consent, where processing is based on consent;
  • Raise a grievance with our Grievance Officer (Section 17) and, if unresolved, with the Data Protection Board of India.

To exercise these rights, contact us using the details in Section 17. If you are an end-customer of one of our Tenants, we recommend contacting that Tenant directly, as they control the data; we will support them in responding to your request.

14. Payment Information

TZI-CRM does not currently process online card payments. Subscriptions are billed manually via invoice, and we do not collect or store credit card, debit card, or other card numbers. If online payment processing is introduced in the future, this section will be updated to name the payment processor used and confirm that full card numbers are tokenized by that processor and never stored by TZI-CRM directly.

15. Children’s Privacy

The Service is intended for business use by adults acting on behalf of their employer. It is not directed to, and we do not knowingly collect personal data from, individuals under the age of 18.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email to Tenant Admins or an in-app notice at least 15 days before taking effect. The “Last updated” date at the top of this page reflects the most recent revision.

17. Contact Us and Grievance Officer

TechZarInfo Software Solutions PVT LTD
No.3D, M.S Tower, 4th Floor, Convent Rd, Cantonment, Tiruchirappalli – 620001, Tamil Nadu, India
Sales inquiries & General/support inquiries: sales@techzarinfo.com