CliqueUp Inc.
CRS CRM Privacy Policy
CRS CRM is a business application for content restoration and packout
companies. It is operated by CliqueUp Inc. (“CliqueUp”, “we”, “us”)
and made available to subscribing restoration businesses at
app.crscrm.com. This policy explains what information the
application handles, why, who it is shared with, and the choices
available to you. Questions go to
privacy@crscrm.com.
1. Our role, and who to contact
CRS CRM is multi-tenant business software. Each subscribing restoration business (a “Customer”) has its own isolated workspace and decides what records to put into it.
- For account information — the user accounts, authentication data, and subscription records we need in order to run the service — CliqueUp is the controller.
- For the business records inside a workspace — jobs, the property owners and insurance contacts attached to them, notes, costing, invoices — the Customer is the controller and CliqueUp acts as its service provider (processor), handling that data only to operate the application, on the Customer’s instructions.
If you are a homeowner, policyholder, or insurance adjuster whose details appear in a restoration company’s workspace and you want to access, correct, or delete them, contact that restoration company directly — they control those records. You may also write to us at privacy@crscrm.com and we will route your request to them.
2. Information the application handles
Account and user data
For each application user: name, work email address, a salted hash of the password (never the password itself), a multi-factor authentication secret where MFA is enabled, the workspace and permission level assigned to them, interface and notification preferences, and session records. IP addresses are processed transiently to rate-limit sign-in and password-change attempts.
Business records entered by Customers
A Customer’s staff enter the information their restoration work requires. This can include:
- Property owner / customer details — name, service address, phone number, email address, and an optional alternate contact’s name, phone, and email.
- Insurance and claim details — insurance company, claim number, and adjuster name, phone, and email.
- Job records — services performed, schedules, tasks, crew and communication notes, activity history, referral source, and job costing figures.
- Financial records — invoices, payments, accounts receivable status, and subcontractor invoices.
- Business directories — restoration company and vendor contacts (business name, contact name, phone, website, notes).
Customers should enter only the information their work requires. CRS CRM is not intended for, and should not be used to store, medical records, government identification numbers, or payment card numbers.
Data received from connected systems
A Customer may connect third-party systems it already uses. When it does, we receive data from them for the purposes shown:
| System | What we receive or send |
|---|---|
| QuickBooks Online (Intuit) | A read-only mirror of invoices, invoice lines, and payments, used for job costing and accounts-receivable tracking. |
| ContentsPal | Inventory counts, box and tag counts, photo counts, and custody information for a job. |
| Google Calendar and Google Contacts | See section 4. |
| Google Maps Platform | A job’s service address is sent to calculate travel distance from the Customer’s warehouse for costing. |
| Airtable | Read-only, at a Customer’s request, to import that Customer’s existing records into its workspace during onboarding. |
| Amazon Simple Email Service | Used to deliver notification emails and calendar invitations that the application sends on a Customer’s behalf. |
Cookies and technical data
The application sets one strictly necessary cookie: an
HttpOnly, Secure session cookie that keeps
you signed in. It is not used for advertising or tracking, and there is
no way to use the application without it.
There are no advertising cookies, analytics trackers, session recorders, or third-party marketing tags in CRS CRM. Our servers keep operational logs (timestamps, request paths, error details) for security and troubleshooting.
3. How the information is used
- To provide, secure, and support the application.
- To compute the things the application exists to compute — job status, schedules, costing, accounts receivable, reports.
- To send transactional email a Customer’s users have opted into: notifications about their jobs and calendar invitations they choose to send.
- To synchronize data with the systems a Customer or user has explicitly connected, in the direction described in this policy.
- To detect and prevent abuse, unauthorized access, and fraud, and to meet legal obligations.
What we never do: we do not sell personal information, we do not share it with data brokers, we do not use it for advertising or ad targeting, and we do not use Customer data or data obtained from Google APIs to develop, improve, or train generalized artificial intelligence or machine learning models.
4. Google user data
Connecting a Google account is optional and is initiated by the individual user or Customer administrator, never by us. Two separate features can use Google, and each is authorized separately.
Calendar sync
Requested scopes:
https://www.googleapis.com/auth/calendar.events and
https://www.googleapis.com/auth/calendar.calendarlist.readonly.
- Why: so scheduled jobs created in CRS CRM appear on the connected Google Calendar. The read-only calendar list scope is used solely to let you choose which of your calendars events should be written to.
- Direction: one-way, from CRS CRM to Google. The application creates, updates, and removes the calendar events it created for CRS CRM job schedules. It does not read the contents of your existing calendar events and does not copy your personal calendar into the application.
Caller-ID contact sync
Requested scope:
https://www.googleapis.com/auth/contacts.
- Why: so an incoming call from a job customer shows that customer’s name on the staff member’s phone instead of an unknown number. This replaces a manual copy-paste workflow.
- What is written: for the active (non-lost) jobs in the user’s workspace, the customer’s and alternate contact’s name, phone number, and address, placed in a dedicated “CRS Customers” contact group and labeled as such.
- Scope of change: the application creates, updates, and deletes only the contacts it created for this purpose. It does not read, alter, or delete your other Google contacts, and it does not copy your existing contacts into the application.
-
Why the broad scope: Google’s People API does not
offer a narrower write permission than
contacts. We use it only as described here.
Tokens, retention, and revocation
When you authorize a connection, we store the resulting Google refresh token encrypted at rest, plus the minimum bookkeeping needed to keep the sync idempotent — the identifiers of the calendar events and contacts we created, and a hash used to detect changes. We never receive or store your Google password.
You can disconnect at any time in the application’s Settings. Doing so revokes the token with Google and deletes the stored mapping on our side. You can also revoke access directly at myaccount.google.com/permissions. Contacts already written to your Google account remain in your account after disconnection, under your control, and you can delete them there.
Limited Use. CRS CRM’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the user-facing features described above. It is not transferred to others except as necessary to provide those features, for security purposes, or to comply with applicable law. It is not used for advertising, and it is not used to train generalized AI or machine learning models. No human reads Google user data except with the user’s explicit consent, to resolve a specific support issue at the user’s request, for security purposes, or where required by law.
5. Who else handles the data
We do not sell or rent personal information. We share it only with service providers that help us run the application, each bound to handle it only for that purpose:
- Amazon Web Services — hosting, database, storage, and email delivery, in the United States.
- Google LLC — only for the calendar, contacts, and travel-distance features described above, and only for Customers and users who connect them.
- Intuit, ContentsPal, and Airtable — only where a Customer has connected that system to its own workspace.
We may also disclose information if required by law or valid legal process, to protect our rights or the safety of others, or in connection with a merger or acquisition — in which case this policy continues to apply to the transferred data until it is superseded by a notice to you.
6. Where data is stored, and how it is protected
Data is stored in the United States (AWS us-east-1).
Protections include: encryption in transit with TLS for all traffic,
including between the application and its database; encryption at rest
for the database, file storage, and stored third-party credentials;
database-enforced row-level security so one Customer’s workspace cannot
read another’s; multi-factor authentication for administrative logins;
least-privilege access for the small number of personnel who
administer the system; and automated database backups retained for
seven days.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affecting personal information occurs, we will notify affected Customers without undue delay and cooperate with their own notification obligations.
7. How long data is kept
Business records stay in a Customer’s workspace for as long as that Customer keeps them and its subscription is active — restoration and insurance work often requires multi-year record retention, so the Customer sets the schedule. When a subscription ends, we delete or return the workspace data within 60 days of a written request, except where law requires longer retention. Account records and operational logs are kept only as long as needed for security, accounting, and legal purposes. Backups age out on the seven-day cycle above.
A Customer may also delete records itself at any time, and an administrator running a data import can replace a workspace’s records wholesale — an intentionally destructive action that requires typed confirmation.
8. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to object to or restrict certain processing. You will not be discriminated against for exercising them.
- Application users: your workspace administrator can correct or remove your account, and you can update your own profile and notification settings in the application. You can disconnect any Google or QuickBooks connection you authorized.
- People whose details appear in a workspace: contact the restoration company handling your job, as described in section 1.
- Either way: write to privacy@crscrm.com. We respond within 30 days, or tell you why we need longer.
9. Children
CRS CRM is business software for use by restoration company staff. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child’s information reached us, write to privacy@crscrm.com and we will delete it.
10. Changes to this policy
If this policy changes, we will post the updated version at this address and change the effective date above. For changes that materially affect how personal information is used, we will make reasonable efforts to notify Customer administrators in advance, for example by email or an in-application notice.
11. Contact
CliqueUp Inc.
privacy@crscrm.com