Privacy Policy (VIP)

How ROSH™ Company Labs collects, uses, and protects information in BrainStorm™ CRM — with clear controls over your data.

Secure • Firebase-powered • Built for growth

Overview

Last updated: 2025 10 09

This Privacy Policy explains what data BrainStorm™ CRM collects and how it is used, shared, and protected. If you do not agree, please do not use the Service.

Data We Collect

Account Data

Name, email, and auth metadata provided via your chosen sign-in method (e.g., Google Sign-In).

Client & Order Data

Client contact details, orders, payments, debts, wishes, notes (including optional PROFIT annotations you add).

Usage & Device

General usage events and device/browser information necessary for functionality, security, and troubleshooting.

Generated Documents

Local PDFs you generate (delivery, debt reminders, etc.). These are produced client-side for privacy.

How We Use Data

  • Provide and improve the Service (features, performance, reliability).
  • Authenticate users and secure access.
  • Facilitate communications (WhatsApp, email templates, VIP support).
  • Analyze trends to guide product improvements and resolve incidents.
  • Comply with legal obligations and enforce terms.

Cookies

Essential Cookies

We may use strictly necessary cookies for sign-in, session continuity, and security. You can manage cookies in your browser, but core features may require them.

WhatsApp & Email

Communications

One-click WhatsApp and email templates are provided for your convenience. When used, your browser/app opens with prefilled content. You control what is sent and to whom.

Analytics & Logs

We may process anonymized or aggregated usage metrics and application logs to monitor performance, detect abuse, and improve functionality.

Data Retention

We retain data for as long as needed to provide the Service and comply with legal obligations. You may delete client/order data you control at any time from within your account (subject to your own policies).

Data Sharing

  • Service Providers: We may use reputable providers (e.g., hosting, authentication) under appropriate safeguards.
  • Legal & Safety: We may disclose data to comply with law, protect rights, or prevent harm.
  • No Selling: We do not sell personal data.

International Transfers

Where data is processed in other jurisdictions, we apply appropriate safeguards consistent with applicable laws.

Security

Technical & Organizational Measures

We rely on Firebase security controls, encryption in transit and at rest, and access rules. You are responsible for secure device practices and keeping credentials confidential.

Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, export, object to, or restrict certain processing. Contact us to exercise these rights where applicable.

Children’s Data

The Service is not intended for children under the age applicable by local law. We do not knowingly collect data from children for this Service.

Changes

We may update this Privacy Policy from time to time. Continued use after updates constitutes acceptance of the revised Policy.

Privacy questions? We can help.

Ask about data, compliance, or security. We’ll respond on WhatsApp or email.

  • GDPR-aligned practices
  • Data deletion/export guidance
  • Fast VIP response
We’ll never share your info. You can opt out anytime.