01Who we are
Photon CRM (“Photon,” “we,” “us,” or “our”) is a software-as-a-service customer relationship management platform operated by [LEGAL ENTITY NAME], a company organized under the laws of [JURISDICTION]. This Privacy Policy applies to the Photon CRM web application, related applications, APIs, and websites that link to it (collectively, the “Service”).
For the purposes of the EU and UK General Data Protection Regulation (GDPR), [LEGAL ENTITY NAME] acts as a data controller for account and usage data, and as a data processor when handling the customer records, communications, and contacts you bring into the Service on behalf of your organization.
02Information we collect
We collect the following categories of information:
Account information
When you create an account, we collect your name, email address, organization, role, and authentication identifiers. If you sign in with Google, we receive your basic profile and verified email address from Google in place of a separate password.
Customer & relationship data
As a CRM, Photon stores the business records you and your team enter or import — contacts, companies, deals, notes, tasks, and the communications associated with them. You control this data; we process it to provide the Service to you.
Google user data
With your explicit authorization, we access certain data from your Google account through Google APIs. This is described in detail in Section 3.
Usage & device data
We collect technical information such as IP address, browser type, device identifiers, pages viewed, feature usage, and timestamps. We use strictly necessary cookies for authentication and session management, and (with consent where required) limited analytics to improve the Service.
03Google user data & scopes
Photon requests access to your Google data only after you grant consent on Google’s OAuth screen. You can decline any scope or revoke access at any time (see Section 12). We access the following:
openid email profilegmail.readonly gmail.sendcalendar.eventsdrive.filecontacts.readonlyGmail and Drive are classified by Google as restricted scopes; Calendar and Contacts are sensitive scopes. We request the minimum scopes required for each feature and request them incrementally, in context, rather than all at once.
04How we use information
We use the information we collect to:
- Provide, operate, and maintain the Photon CRM Service and its features.
- Authenticate you and secure your account.
- Sync your Google email, calendar, contacts, and selected files to the relevant CRM records, as you direct.
- Generate the user-facing intelligence features of the Service — such as activity timelines, suggested next steps, and forecasting — operating on your own data to deliver results to you.
- Provide customer support and respond to your requests.
- Detect, prevent, and address security incidents, fraud, and abuse.
- Comply with legal obligations and enforce our agreements.
We do not use your data for advertising, and we do not sell your personal information.
05Google API Services — Limited Use disclosure
Required affirmation
Photon CRM’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
For data obtained through restricted and sensitive scopes, we specifically commit that:
- We limit our use of Google user data to providing and improving the user-facing features that are prominent in the Photon interface and for which you granted access.
- We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with appropriate notice.
- We do not use Google user data for serving advertisements, including personalized, retargeted, or interest-based advertising.
- We do not allow humans to read your Google user data unless we have your affirmative consent for specific messages, it is necessary for security or to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
06AI & automated processing
Photon is an AI-native platform. Our AI features — such as summarization, drafting assistance, win-probability scoring, and forecasting — process your data to produce results for you and your organization within your own workspace.
We do not use Google user data obtained through restricted or sensitive scopes (Gmail, Drive, Calendar, Contacts) to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models. Where AI is applied to this data, it is solely to deliver the feature you requested, on your data, to you.
Some AI features may rely on third-party model providers. When data is sent to such providers for processing, it is transmitted under contractual terms that prohibit using your data to train their models and require its deletion after processing. We provide details of our subprocessors on request.
08Data retention & deletion
We retain personal data only as long as needed to provide the Service and for legitimate, documented business or legal purposes. Synced Google data is retained for as long as your integration remains connected and is removed in line with your settings and our retention schedule.
You can delete records within the Service, disconnect Google integrations, or request deletion of your account at any time. On account deletion or verified request, we delete or irreversibly de-identify your personal data within a defined period, except where retention is legally required. Our architecture supports cryptographic erasure (“crypto-shredding”) so that encrypted data can be rendered permanently unrecoverable when keys are destroyed.
09Data security
We protect your data with encryption in transit (TLS) and at rest, strict access controls and least-privilege practices, tenant isolation, audit logging, and ongoing monitoring. Access to production data is limited to authorized personnel and is logged. No method of transmission or storage is perfectly secure, but we work continuously to protect your information and will notify affected users and authorities of qualifying incidents as required by law.
10International data transfers & residency
Photon may process data in countries other than where you are located. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses. We support regional data residency for eligible plans so that customer data can be hosted within a designated region.
11Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent at any time.
EU / UK (GDPR)
You have the rights described above and may lodge a complaint with your local supervisory authority. Our legal bases for processing include performance of a contract, legitimate interests, consent, and legal obligation.
California (CCPA/CPRA)
You have the right to know, delete, correct, and limit the use of sensitive personal information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined under California law, and we do not discriminate against you for exercising your rights.
To exercise any right, contact us at [CONTACT EMAIL]. We will verify your request and respond within the timeframes required by applicable law.
12Revoking Google access
You can revoke Photon’s access to your Google account at any time:
- Within Photon, disconnect the Google integration in your account settings; or
- From your Google Account, visit Google Account → Security → Third-party access and remove Photon CRM.
Revoking access stops further syncing. Data already synced into your CRM is handled per Section 8; you may delete it separately.
13Children’s privacy
Photon is a business tool not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
14Changes to this policy
We may update this policy to reflect changes to the Service or legal requirements. We will revise the “Effective” date above and, for material changes, provide additional notice. Continued use of the Service after changes take effect constitutes acceptance.
Contact us
Questions about this policy or your data? Reach our privacy team: