Privacy Policy
This Privacy Policy explains how IonkoCRM (“IonkoCRM”, the “Service”), operated by [OPERATOR LEGAL NAME, e.g. IonkoCRM LLC] (“we”, “us”, “our”), collects, uses, shares, and protects personal information. It applies to our public website and to the IonkoCRM web application.
Our guiding philosophy is to collect as little personal information as possible, to avoid advertising and third-party tracking, and to give you meaningful control over your data.
Contents
1. Information we collect
Information you provide when you create and use an account
- Account details: your name (or username), email address, and a password. Passwords are stored only as a salted one-way hash — we never store or can see your actual password.
- Plan information: which plan tier your account is on (for example, free or business).
- Business profile you choose to add: business name, address, phone number, email, website, logo, and invoicing preferences such as currency and numbering prefixes.
- Email-sending settings: if you choose to send emails to your clients through the Service, you may provide your own outgoing mail (SMTP) server credentials. These are used solely to send mail on your behalf.
- Communications: messages you send us for support or other inquiries.
Information collected automatically
- Security and login data: your IP address and timestamps of sign-in attempts. We record recent failed sign-in attempts to protect accounts against automated attacks (rate limiting and abuse prevention). This data is short-lived and used only for security.
- Essential cookies: a session cookie to keep you signed in and a token to protect forms against cross-site request forgery. See Section 3.
- Email confirmation and password-reset tokens: temporary, single-purpose tokens we generate to verify your email and let you reset your password.
Content you store in the Service
When you use IonkoCRM to run your business, you enter and upload content — for example, your clients’ names, email addresses, phone numbers, and addresses; notes; invoices, quotes, and ledger/payment records; emails you send to clients (recipient, subject, and body); and files you upload. We store this content so we can provide the Service to you. See Section 10 for how this content is treated.
We do not intentionally collect special categories of data (such as health, biometric, or government-ID numbers), and we ask that you not store such data in free-text fields unless it is necessary and lawful for your business.
2. How we use information
- To provide, maintain, and operate the Service and your account.
- To authenticate you and keep your account and our systems secure (including fraud and abuse prevention, and rate-limiting sign-in attempts).
- To send you essential service emails — email confirmation, password resets, and important account or security notices. These are transactional; we do not send marketing email unless you have separately opted in.
- To send emails to your clients when you use the email feature, using the outgoing mail settings you provide.
- To respond to your support requests.
- To maintain, troubleshoot, and improve the reliability and features of the Service.
- To comply with legal obligations and enforce our Terms & Conditions.
We do not sell your personal information, and we do not use it for third-party advertising or cross-context behavioral advertising.
3. Cookies and tracking
We use only the cookies necessary to make the Service work securely. We do not use analytics, advertising, or social-media tracking cookies.
- Session cookie — keeps you signed in during your visit.
- CSRF token — protects forms against cross-site request forgery.
- Security challenge (Cloudflare Turnstile) — on sign-in and registration, after repeated failed attempts, we may show a “are you human?” challenge provided by Cloudflare to block automated attacks. Cloudflare may set its own cookie for this purpose. This is a privacy-respecting alternative to traditional CAPTCHAs and is used only for security.
Because these cookies are strictly necessary to provide a service you request, they do not require consent under most cookie rules; you can still block cookies in your browser, but the Service may not function.
4. Legal bases (where applicable)
Where data-protection law requires a legal basis, we rely on: performance of a contract (to provide the Service you sign up for); legitimate interests (to secure our systems and prevent abuse); consent (where we ask for it, such as optional communications); and legal obligation (to comply with applicable law).
5. How we share information
We share personal information only in these limited situations:
- Service providers that host and operate the Service on our behalf, under confidentiality obligations — see Section 6.
- Legal and safety: when required by law, legal process, or to protect the rights, property, or safety of our users, the public, or us.
- Business transfer: in connection with a merger, acquisition, financing, or sale of assets, your information may be transferred, subject to this policy.
- With your direction: for example, sending an email to a recipient you choose through the email feature.
We do not sell or rent personal information, and we do not share it for others’ advertising.
6. Service providers
We rely on a small number of trusted providers to run the Service:
- Hostinger — website and application hosting, database storage, and sending of our own transactional emails (such as confirmation and password-reset messages).
- Cloudflare — the Turnstile security challenge used to protect sign-in and registration from automated abuse.
- Your outgoing mail provider — if you configure the email feature with your own SMTP credentials, your chosen mail provider transmits the emails you send to your clients. That provider’s handling of those messages is governed by your agreement with them.
7. Data retention
We keep your account information and the content you store for as long as your account is active. You can delete individual records at any time within the Service. Security logs, such as recent sign-in attempts, are kept only for a short period needed for their security purpose and are then removed.
If you close your account or ask us to delete it, we will delete or de-identify your account information and content within a reasonable period (generally within [30–90] days), except where we must retain certain information to comply with legal obligations, resolve disputes, or enforce our agreements. Residual copies may persist briefly in routine backups before being overwritten.
8. How we protect information
We use reasonable technical and organizational measures to protect personal information, including: storing passwords only as salted hashes; encrypting traffic in transit (HTTPS); isolating administrative access; limiting and monitoring failed sign-in attempts; and protecting forms against cross-site request forgery. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to respond promptly to any incident.
9. Your privacy rights
Consistent with our privacy-first approach, we offer the following rights to all users, and, for California residents, as provided by the California Consumer Privacy Act (CCPA/CPRA):
- Access / know — request a copy of the personal information we hold about you and how we use it.
- Correction — ask us to correct inaccurate information (much of which you can also edit directly in your account).
- Deletion — ask us to delete your personal information.
- Portability — request an export of your data in a portable format.
- Opt out of sale/sharing — we do not sell or share personal information for advertising, so there is nothing to opt out of, but you may confirm this with us.
- Non-discrimination — we will not deny service or charge different prices for exercising your rights.
To exercise any right, email us at omniplexdesign@gmail.com. We will verify your request (typically by confirming control of your account email) and respond within the timeframe required by applicable law. You may use an authorized agent where the law permits.
10. Data about your clients
When you add information about your own customers and clients to IonkoCRM, you control that data and are responsible for it. You are responsible for collecting and using it lawfully — including providing any notices and obtaining any consents your customers are entitled to, and for complying with applicable email and marketing laws when you use the email feature.
We process your clients’ data only to provide the Service to you and on your instructions. If one of your clients contacts us about their data, we will refer them to you as the responsible business, and we will reasonably assist you in responding to their requests.
11. Children
The Service is a business tool intended for adults. It is not directed to children, and you must be at least 18 years old to use it. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. Where data is processed
The Service is operated from and hosted in the United States. If you access the Service from outside the United States, you understand that your information will be processed in the United States, where privacy laws may differ from those in your location. Where required, we take appropriate steps to protect information transferred internationally.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide a more prominent notice. This page is always the current version. Your continued use of the Service after an update means you accept the revised policy.
14. Contact us
Questions, concerns, or privacy requests? Contact us at omniplexdesign@gmail.com.