Privacy Policy
Last updated: July 19, 2026
Who this covers
This policy covers the 9DollarCRM marketing website (9dollarcrm.com) and the 9DollarCRM application (app.9dollarcrm.com). It explains what personal data we collect, why we collect it, and the choices you have. If you have any question this page does not answer, email us at hello@9dollarcrm.com.
Data we collect
We collect five kinds of data, and nothing more:
- Account data. When you sign up we collect your name, email address, and business name so we can create and secure your workspace.
- The records you create. Customers, leads, jobs, quotes, invoices, notes, and files you add to your workspace. You control this data: you decide what goes in, and you can export or delete it.
- Form submissions on this website. If you use our contact or newsletter form, we receive the name, email, and message you type, plus any campaign tags (such as utm_source) in the link you arrived from.
- Usage and device metadata. Server logs, IP address, browser type, and approximate location derived from IP. We use this to keep the service running and secure, not to profile you.
- Billing data. Payments are handled by payment processors (Stripe, Razorpay, or PayPal). We never see or store your full card number; the processor does, under its own privacy policy.
How we use it
We use personal data to operate the service, answer support requests, bill subscriptions, improve the product, and keep accounts secure (including maintaining an audit log of sensitive actions). We send service emails about your account, such as invoices and security notices. We send marketing emails only if you asked for them, and every one includes an unsubscribe link that we honor immediately. We never sell personal data.
Your customers’ data, and our role as processor
The records a business creates in its workspace belong to that business. For that data we act as a processor: we handle it only on the business’s instructions and under our Data Processing Agreement. Every workspace is isolated from every other with database row-level security, so one business can never read another’s records. If you are a customer of a business that uses 9DollarCRM and you have a question about your data, that business is the controller; contact them first, and we will help them respond.
Subprocessors and sharing
We share data with service providers only where needed to run a feature, and most only activate when you connect them yourself. We never sell data to anyone.
- Payments: Stripe, Razorpay, PayPal.
- Email delivery: Resend, SendGrid, Amazon SES, or Gmail/SMTP where you configure them.
- SMS, voice, and WhatsApp: Twilio and Meta (WhatsApp), where connected.
- Calendar: Google Calendar and Microsoft/Outlook, where connected.
- Meetings: Zoom and Webex, where connected.
- Accounting: QuickBooks (Intuit), where connected.
- AI features: OpenAI, Anthropic, Google Gemini, or OpenRouter. When you use an AI feature, the content you run through it is sent to the provider you selected in order to generate the response. If you never use AI features, nothing is sent.
- Hosting and infrastructure: the cloud providers that run our servers and store workspace files.
Retention
We keep account data for as long as your account exists. If you cancel, your workspace becomes read-only and remains exportable for a reasonable period so you can take your data with you, after which it is deleted. Security and audit logs are retained for as long as needed to investigate and prevent abuse.
Your rights
You can access, export (one-click CSV export is built in), correct, and delete your personal data. Use the in-app privacy controls for data subject access requests, or email hello@9dollarcrm.com. We respond within the timescales required by applicable law. Depending on where you live (for example under the GDPR or similar regimes), you may also have rights to restrict or object to processing, and to complain to your local data protection authority.
Security
Workspaces are isolated with row-level security, data is encrypted in transit, accounts support multi-factor authentication, and sensitive actions are recorded in an append-only audit log. The full picture is on our security overview.
Children
9DollarCRM is a business tool and is not directed to children. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.
International transfers
Some of the subprocessors above may process data in countries other than yours. Where they do, transfers are covered by the safeguards in their terms and data processing agreements.
Changes and contact
If we make a material change to this policy, we will update the date above and notify account holders by email. Questions, requests, or concerns: hello@9dollarcrm.com.
Related: Terms of Service · Cookie Policy · Data Processing Agreement · Security overview