Privacy Policy
Last updated: 6 July 2026 · Versions: Australia and United States / International
CatchaCRM ("we", "us") provides a cloud-based CRM platform for trade and field-service businesses (the "Service"). This policy explains how we collect, hold, use and disclose personal information. For Australia, we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including the Notifiable Data Breaches scheme.
1. Two kinds of data
- Account data — information about you and your users (we act as the data controller).
- Customer Data — information you store about your customers inside the Service (we act as a processor / service provider on your instructions; your business is the controller).
2. What we collect — by module
The Service is modular. What we hold depends on the modules you use:
| Module | Typical data processed |
|---|---|
| Account & billing | Name, business name, ABN/tax ID, address, email, phone, credentials, role assignments, plan and payment records (card details are processed by Stripe — we never store full card numbers) |
| Sales CRM | Your customers' contact details, company details, deal values, notes, tasks, calendar events, communication history |
| Quoting, Invoicing & Subscriptions | Quote/invoice line items, amounts, tax details, payment status, public pay-link tokens, credit notes, recurring billing schedules |
| Payments, Banking & AP | Payment records, imported bank transaction lines, reconciliation matches, supplier and bill details, expenses |
| Jobs & Field Dispatch | Job details and site addresses, dispatch coordinates and zones, crew and equipment rosters, checklist/SWMS records, site photos, customer digital signatures |
| Inventory & Procurement | Product/service catalogs, stock levels, warehouse bin locations, purchase orders, RFQs, supplier quotes |
| Marketing & Growth | Campaign lists and send logs, review invitations and responses, referral codes and rewards, inbound form/chat/calculator submissions |
| Support Desk | Tickets, SLA timing, message threads, knowledge-base usage |
| Comms Hub | Connected email account threads, email/SMS message content and delivery metadata, call records via the softphone, team chat messages, templates and sequences |
| AI Tools | Prompt text and generated drafts (processed via third-party AI providers to produce the output) |
| Automation | Workflow rules, webhook payloads you configure, execution logs |
| Security & platform | Login history, IP addresses and restrictions, audit trails, field history, import/export logs, device/usage data, crash reports |
3. How we use information
To provide, secure, support and improve the Service; process billing; send service communications; prevent fraud and abuse; and meet legal obligations. We use aggregated, de-identified usage data to improve the platform. We do not sell personal information.
4. Disclosure & sub-processors
We disclose information only to operate the Service: cloud hosting and database infrastructure (Supabase/AWS, Vercel, Hostinger), payments (Stripe, PayPal), SMS and voice carriers, email delivery providers, AI model providers (Google) for AI Tools, and automation infrastructure (n8n) — plus disclosures required by law or made with your consent. Each provider is bound by contractual data-protection obligations.
Some providers store or process data outside Australia (including the United States, India and Singapore). We take reasonable steps consistent with APP 8 to ensure overseas recipients handle personal information in accordance with the APPs.
5. Security
Multi-tenant isolation enforced with database row-level security, encrypted transport (TLS), role-based access scopes (own/team/all), IP restrictions, login history and immutable audit logs. No system is perfectly secure — use strong passwords and manage user access carefully.
6. Retention
Account data is kept while your account is active and as required for legal/tax purposes. Customer Data is retained while your subscription is active; after termination it remains exportable for at least 30 days, then is deleted from production systems in the ordinary course. Data-retention policies can also be configured per workspace.
7. Cookies & tracking
The website and app use strictly necessary cookies (session, security, region preference). We do not run third-party advertising trackers.
8. Your rights (Australia)
You may request access to or correction of your personal information at any time via hello@catchacrm.com. We will respond within a reasonable period. If you are unsatisfied with our handling of a complaint, you may contact the Office of the Australian Information Commissioner (OAIC, oaic.gov.au). Eligible data breaches will be notified to affected individuals and the OAIC under the Notifiable Data Breaches scheme.
9. Children
The Service is for business use and not directed to children under 16. We do not knowingly collect children's personal information.
10. Changes & contact
Material changes to this policy will be notified in-app or by email. Privacy questions, requests and complaints: hello@catchacrm.com.