Privacy Policy
1. Absolute Data Ownership
At VEXCRM, we operate on a fundamental design principle: your databases, your customer records, and your operational workflows belong 100% to you.
Unlike monthly subscription-based CRM platforms that hold your datasets hostage in multi-tenant environments, VEXCRM instances are completely segregated. The data you store on your dashboard—including lead lists, employee attendance logs, invoices, customer support tickets, and sales reports—is hosted on your own isolated Firestore databases and server configs. VEXCRM has zero backend access to your data tables, nor do we monitor, profile, or query your files.
2. Compliance Enablement & Data Control
VEXCRM is designed to provide the necessary data architecture, database segregation, and user administration controls to support your compliance with global privacy regulations:
GDPR & CCPA Enablement
Our single-tenant architecture ensures that your data partitions are isolated. This enables your system administrators to execute granular data rights requests—such as 'Right to Be Forgotten' purges, data access queries, and structured JSON record exports—directly from your dashboard controls without relying on third-party cloud aggregators.
HIPAA Compatibility
For health technology and medical operators, VEXCRM's code is designed to support the implementation of necessary technical safeguards. When hosted on Google Cloud Platform / Firebase infrastructure (which signs Business Associate Agreements - BAAs - for HIPAA-eligible resources), you can establish complete operational controls over patient records with zero external data telemetry leakage.
3. Information We Collect
We do not collect customer database records. The only information VEXCRM collects consists of technical parameters needed to facilitate your software updates and license validations:
- License Verification Data: Your designated business email and lifetime product license key, checked securely upon database initialization.
- System Telemetry (Optional): Critical runtime error exceptions and system crashes, transmitted anonymously to diagnose code discrepancies (can be disabled in dashboard settings).
- Support Communications: Inquiries, emails, and attachments sent directly to our support desk to resolve technical issues.
4. Security & Encryption Standards
To protect enterprise databases from malicious actors, VEXCRM relies on bank-grade security protocols implemented directly within your infrastructure:
Data at Rest & in Transit
- Encryption at Rest: All databases, documents, and storage buckets run on enterprise cloud databases encrypted using AES-256 standard.
- Encryption in Transit: Access to the dashboard is protected by TLS 1.3 encryption (HTTPS). Third-party webhook syncs must utilize secure OAuth 2.0 or SHA-256 encrypted headers.
- Granular Security Rules: Database authorization is strictly enforced via Firestore Security Rules, restricting employees from reading payroll, settings, or database logs unless explicitly authorized by the Super Admin.
5. Third-Party Integrations & APIs
VEXCRM connects to external tools (such as WhatsApp API, Stripe/PayPal payment modules, or custom webhooks) to automate client operations. When using these APIs, the data exchanged is direct:
For example, when VEXCRM fires WhatsApp notifications (e.g., lead allocation alerts, payment updates), the message payload goes directly from your private Firestore database to the official Meta WhatsApp API gateway. VEXCRM servers do not proxy, inspect, or log the content of these messages.
You are solely responsible for ensuring your API keys are configured securely and that third-party platforms align with your company's privacy requirements.
6. Data Retention & Rights
Since the database is yours, you have complete control over data retention times. You can wipe, clean, archive, or backup your files at any point through the cockpit interface without requesting permission or experiencing latency. VEXCRM does not keep copies of deleted databases.
For questions or requests regarding VEXCRM licenses, updates, or custom modifications, contact our compliance team at compliance@vexfore.com.