Privacy Policy
Last updated September 26, 2026
This policy explains what violet[XX]M collects and why, across our website (violetxxm.com) and the violetCRM service: the web app at crm.violetxxm.com, its REST API and MCP server, and the Deal Rooms that sellers share with their buyers.
The short version
- We collect what we need to run violetCRM and nothing more.
- The app's cookies exist only to keep you signed in and secure. We don't use advertising or cross-site tracking cookies, and there are none on the website.
- We don't sell your personal information or use it for advertising.
- The records your organization keeps in violetCRM belong to your organization. We process them to provide the service.
Information we collect
On the website
The website has no accounts and no forms. We count page views with Vercel Web Analytics, which doesn't use cookies and doesn't identify individual visitors. If you email us, we use your message and email address only to reply.
Your violetCRM account
When you sign in, we receive your name and email address from Google, your organization's single sign-on provider, or the email address you type in for a sign-in code. We keep your profile (name, email, role, manager, and admin settings), when you last signed in, and the personal access tokens and connected AI apps you set up. We never see a password; violetCRM doesn't have them.
Data your organization puts into violetCRM
This is the heart of the service: accounts, contacts (which can include names, email addresses, phone numbers, and job titles of people your organization works with), opportunities, activities, notes, attachments, custom fields and objects, go-to-market knowledge, and Deal Room content. Your organization controls this data and decides who in it can see what. We process it only to provide violetCRM to your organization.
Deal Room visitors
When a seller shares a Deal Room with you, we record your visits so the seller can see how the room is being used: when you visited, which sections you viewed, your device type, operating system, and browser, and your email address if the room asks you to verify it. We store a one-way hash of your IP address, never the address itself, and we don't use any of this to follow you anywhere else.
Technical and usage data
We count how often each part of the service is used (per month, per feature) to operate and improve it, and we record errors so we can fix them. Error reports don't include your name or email. Our hosting providers also log standard connection data such as IP addresses, request times, and browser details, for security and reliability.
Cookies and browser storage
The website sets no cookies. The violetCRM app and Deal Rooms set only the cookies they need to work, all first-party:
violetcrm_session: keeps you signed in to the app.violetcrm_csrf: protects your account from forged requests.-
violetcrm_oauth_stateandvioletcrm_oidc_txn: short-lived, used only while you sign in with Google or single sign-on. dsr_room_session: keeps a Deal Room visitor's access to that room.
Both the website and the app also keep a few preferences in your own browser's storage, such as light or dark theme, navigation layout, pipeline view, and which introduction panel the sign-in page shows next. These stay on your device and are never sent to us. Blocking cookies will stop you from signing in to violetCRM.
How we use information
- To provide violetCRM: sign-in, storing and showing your data, email sign-in codes, and notifications you set up.
- To keep it secure: detecting abuse, enforcing access controls, and investigating problems.
- To operate and improve it: fixing errors and understanding which features are used.
- To reply when you contact us, and to meet legal obligations.
AI features
Some features use AI: extracting knowledge from documents in violetGTM, and drafting Deal Room content. When you use them, the content involved, which can include deal and contact details, is sent to Google's Gemini API to produce the result. If your organization connects an AI assistant such as Claude to violetCRM, that assistant receives the data it asks for, limited to what the person who connected it can see, under its provider's own terms.
Service providers
We rely on these providers to run violetCRM. Each handles data only to provide its service to us:
- Vercel: hosting and cookie-free analytics.
- Cloudflare: network delivery and protection for the website.
- Supabase: database and file storage.
- Upstash: sign-in sessions and background job delivery.
- Google: Google sign-in, and the Gemini API for AI features.
- Mailgun: sign-in codes, Deal Room verification, and automation emails.
- Sentry: error reports.
- Firecrawl: loading public web pages you ask violetGTM to read.
Sharing
We don't sell or rent personal information, and we don't share it for advertising. Beyond the providers above, we share information only when your organization or you direct us to (for example, a Deal Room you publish, or a webhook your admin sets up), when the law requires it, to protect people's safety or our service, or as part of a merger or acquisition, in which case this policy continues to apply.
Security
Data is encrypted in transit, and our database provider encrypts it at rest. Each organization's data is kept separate both in the application and by database-level access rules, and sensitive credentials such as single sign-on and webhook secrets are encrypted. No system is perfectly secure, but we work to protect your information and will tell affected customers promptly about a breach that affects their data.
How long we keep information
We keep your organization's data for as long as its account is active. When something is deleted in violetCRM, it can be restored for a short recovery window, then it's permanently removed along with its attachments. Database backups may keep copies for a limited time after that. If your organization closes its account, we delete its data on request.
Your choices and rights
You can update your profile in violetCRM, and your organization's admins can edit, export (through the REST API), or delete its data at any time. To access, correct, or delete personal information, email us. If your information is in violetCRM because an organization you work with added it, we'll help that organization handle your request. Depending on where you live, you may have further rights under laws such as the GDPR or the California Consumer Privacy Act. We don't sell or share personal information as the CCPA defines those terms, and we won't treat you differently for exercising your rights.
Children
violetCRM is a business tool and isn't meant for anyone under 18. If we learn we have a child's information, we'll delete it.
International transfers
Our providers may process data in the United States and other countries, which may have different data protection laws than where you live.
Changes to this policy
If we change this policy, we'll update the date above, and we'll tell customers about significant changes before they take effect.
Contact
Questions or requests about privacy: [email protected]