CRS CRM

CliqueUp Inc.

CRS CRM Privacy Policy

Effective July 24, 2026 · Last updated July 24, 2026

CRS CRM is a business application for content restoration and packout companies. It is operated by CliqueUp Inc. (“CliqueUp”, “we”, “us”) and made available to subscribing restoration businesses at app.crscrm.com. This policy explains what information the application handles, why, who it is shared with, and the choices available to you. Questions go to privacy@crscrm.com.

1. Our role, and who to contact

CRS CRM is multi-tenant business software. Each subscribing restoration business (a “Customer”) has its own isolated workspace and decides what records to put into it.

If you are a homeowner, policyholder, or insurance adjuster whose details appear in a restoration company’s workspace and you want to access, correct, or delete them, contact that restoration company directly — they control those records. You may also write to us at privacy@crscrm.com and we will route your request to them.

2. Information the application handles

Account and user data

For each application user: name, work email address, a salted hash of the password (never the password itself), a multi-factor authentication secret where MFA is enabled, the workspace and permission level assigned to them, interface and notification preferences, and session records. IP addresses are processed transiently to rate-limit sign-in and password-change attempts.

Business records entered by Customers

A Customer’s staff enter the information their restoration work requires. This can include:

Customers should enter only the information their work requires. CRS CRM is not intended for, and should not be used to store, medical records, government identification numbers, or payment card numbers.

Data received from connected systems

A Customer may connect third-party systems it already uses. When it does, we receive data from them for the purposes shown:

System What we receive or send
QuickBooks Online (Intuit) A read-only mirror of invoices, invoice lines, and payments, used for job costing and accounts-receivable tracking.
ContentsPal Inventory counts, box and tag counts, photo counts, and custody information for a job.
Google Calendar and Google Contacts See section 4.
Google Maps Platform A job’s service address is sent to calculate travel distance from the Customer’s warehouse for costing.
Airtable Read-only, at a Customer’s request, to import that Customer’s existing records into its workspace during onboarding.
Amazon Simple Email Service Used to deliver notification emails and calendar invitations that the application sends on a Customer’s behalf.

Cookies and technical data

The application sets one strictly necessary cookie: an HttpOnly, Secure session cookie that keeps you signed in. It is not used for advertising or tracking, and there is no way to use the application without it.

There are no advertising cookies, analytics trackers, session recorders, or third-party marketing tags in CRS CRM. Our servers keep operational logs (timestamps, request paths, error details) for security and troubleshooting.

3. How the information is used

What we never do: we do not sell personal information, we do not share it with data brokers, we do not use it for advertising or ad targeting, and we do not use Customer data or data obtained from Google APIs to develop, improve, or train generalized artificial intelligence or machine learning models.

4. Google user data

Connecting a Google account is optional and is initiated by the individual user or Customer administrator, never by us. Two separate features can use Google, and each is authorized separately.

Calendar sync

Requested scopes: https://www.googleapis.com/auth/calendar.events and https://www.googleapis.com/auth/calendar.calendarlist.readonly.

Caller-ID contact sync

Requested scope: https://www.googleapis.com/auth/contacts.

Tokens, retention, and revocation

When you authorize a connection, we store the resulting Google refresh token encrypted at rest, plus the minimum bookkeeping needed to keep the sync idempotent — the identifiers of the calendar events and contacts we created, and a hash used to detect changes. We never receive or store your Google password.

You can disconnect at any time in the application’s Settings. Doing so revokes the token with Google and deletes the stored mapping on our side. You can also revoke access directly at myaccount.google.com/permissions. Contacts already written to your Google account remain in your account after disconnection, under your control, and you can delete them there.

Limited Use. CRS CRM’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the user-facing features described above. It is not transferred to others except as necessary to provide those features, for security purposes, or to comply with applicable law. It is not used for advertising, and it is not used to train generalized AI or machine learning models. No human reads Google user data except with the user’s explicit consent, to resolve a specific support issue at the user’s request, for security purposes, or where required by law.

5. Who else handles the data

We do not sell or rent personal information. We share it only with service providers that help us run the application, each bound to handle it only for that purpose:

We may also disclose information if required by law or valid legal process, to protect our rights or the safety of others, or in connection with a merger or acquisition — in which case this policy continues to apply to the transferred data until it is superseded by a notice to you.

6. Where data is stored, and how it is protected

Data is stored in the United States (AWS us-east-1). Protections include: encryption in transit with TLS for all traffic, including between the application and its database; encryption at rest for the database, file storage, and stored third-party credentials; database-enforced row-level security so one Customer’s workspace cannot read another’s; multi-factor authentication for administrative logins; least-privilege access for the small number of personnel who administer the system; and automated database backups retained for seven days.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affecting personal information occurs, we will notify affected Customers without undue delay and cooperate with their own notification obligations.

7. How long data is kept

Business records stay in a Customer’s workspace for as long as that Customer keeps them and its subscription is active — restoration and insurance work often requires multi-year record retention, so the Customer sets the schedule. When a subscription ends, we delete or return the workspace data within 60 days of a written request, except where law requires longer retention. Account records and operational logs are kept only as long as needed for security, accounting, and legal purposes. Backups age out on the seven-day cycle above.

A Customer may also delete records itself at any time, and an administrator running a data import can replace a workspace’s records wholesale — an intentionally destructive action that requires typed confirmation.

8. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to object to or restrict certain processing. You will not be discriminated against for exercising them.

9. Children

CRS CRM is business software for use by restoration company staff. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child’s information reached us, write to privacy@crscrm.com and we will delete it.

10. Changes to this policy

If this policy changes, we will post the updated version at this address and change the effective date above. For changes that materially affect how personal information is used, we will make reasonable efforts to notify Customer administrators in advance, for example by email or an in-application notice.

11. Contact

CliqueUp Inc.
privacy@crscrm.com