Effective date: September 3, 2026 · Operator: Gigadev
This policy explains what NinjaProspecting CRM ("the service", "we") collects, how we use it, where it is stored, and with whom it is shared. NinjaProspecting CRM is business software: our customers are companies ("workspaces") whose staff ("users") use it to manage their sales relationships. The LinkedIn Capture browser extension has its own policy, which supplements this one. Looking for how we handle Google data? Jump to section 3.
Account information. Your name, work email address, role, and workspace membership, provided when your administrator invites you or when your company signs up. Sign-in is handled by Supabase Auth (an emailed sign-in code) or, where enabled, "Continue with LinkedIn"; we store the resulting account identifier, never a password.
Workspace data you enter. Contacts, companies, deals, notes, tasks, files, custom fields, and anything else your team records about its business relationships. This includes personal data about third parties (your prospects and customers) that your company is responsible for collecting lawfully.
Connected-account data. When a user connects a Gmail, Outlook, Google Calendar, or Outlook calendar account we receive mail and calendar data from that account, as described in sections 3 and 4.
LinkedIn data captured by the optional extension, described in its own policy.
Usage and technical data. Server logs (request paths, timestamps, IP address, browser user-agent), an audit log of who created, changed, or deleted which record and when, and error reports. We do not use analytics or advertising trackers.
We do not sell personal data, use it for advertising, share it with data brokers, or use it to train artificial-intelligence or machine-learning models.
This section describes how NinjaProspecting CRM handles data received from Google APIs when a user connects a Google account. It applies in full to every Google permission we request.
| Google permission | Why we ask for it | When it is used |
|---|---|---|
openid, email | To know which Google account was connected and show it in Settings. | At connection. |
gmail.readonlyRead your email messages and settings | To file the mail you send and receive onto the matching contact’s timeline and into your workspace inbox. | Periodically in the background while the mailbox stays connected. |
gmail.sendSend email on your behalf | To send a reply or a new email from your own mailbox when you click Send (or schedule one for later) in the CRM. | Only on your explicit action. |
calendar.readonlySee your calendars | To show your existing calendar events next to CRM meetings so you don’t double-book. | When you open a scheduling view. Requested for read-only calendar connections. |
calendar.eventsView and edit events on your calendars | To create, update, or delete the calendar events that correspond to meetings you schedule in the CRM. | When you create, move, or delete such a CRM meeting. Requested only if you choose two-way sync at connection. |
Starting from the time you connect (with a 24-hour look-back), we periodically read messages in your mailbox, excluding Spam and Trash, and store for each: sender and recipient addresses and names, subject, date, Gmail thread and message identifiers, Gmail labels, a short snippet, the message body as plain text, truncated to 50 KB, and the names and sizes of attachments. We do not download or store the attachment files from your mailbox. Each stored message is linked to the contact records whose email address matches a sender or recipient; messages that match no contact are still stored in your workspace so they can be linked later. When you send from NinjaProspecting CRM, we store the sent message (including its HTML) and any file you attached in the composer.
Calendar events are read live when you open a scheduling view and are not stored; we only display them. For meetings you create in the CRM with two-way sync on, we store the identifier of the Google event we created so we can update or remove it when the CRM meeting changes.
The access and refresh tokens Google issues are stored encrypted (AES-256-GCM) in our database and decrypted only in memory to make the API calls above. Disconnecting an account in Settings deletes the tokens immediately and stops all access.
Mail filed onto a contact and calendar-derived CRM meetings are visible to the members of your workspace, like every other record in it. Your workspace's administrators control membership. Gigadev staff do not read your Google data except to investigate a support request you have made, to address a security incident, or where required by law.
We do not transfer Google user data to any other application or third party except the infrastructure providers in section 5, who process it on our behalf to run the service. We do not use it for advertising, do not sell it, and do not use it to build or train AI/ML models.
NinjaProspecting CRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Stored messages stay in your workspace so your team's history is complete; disconnecting a mailbox stops collection and revokes our access but keeps what was already filed — the same way removing a mailbox from your phone keeps the contacts you saved from it. Your administrator can delete any filed message or contact at any time. A workspace's data is deleted when the customer ends service or on request (section 6). Database backups are retained for a short rolling window (currently 7 days) and then expire.
Settings → Email or Settings → Calendar in NinjaProspecting CRM, or at Google Account → Security → Third-party apps & services.
Outlook mail and calendar connections work the same way as section 3 with the equivalent Microsoft Graph permissions (Mail.Read, Mail.ReadWrite, Mail.Send, Calendars.Read or Calendars.ReadWrite, offline_access) and the same storage, encryption, visibility, retention, and revocation rules. Access can also be revoked at Microsoft account → Privacy → App access.
NinjaProspecting CRM runs on infrastructure providers acting as our processors:
Every workspace's data is isolated at the database layer (row-level security) so one customer can never read another's.
Users can view and edit their own profile in the app. Workspace administrators can correct or delete any record, remove members, and disconnect mailboxes and calendars. For access, correction, deletion, or export requests that you cannot complete in the app — including deletion of an entire workspace — contact support@ninjaprospectingcrm.com. Because NinjaProspecting CRM processes data on behalf of the customer that operates your workspace, we may refer requests about third-party contact data to that customer.
TLS for all traffic; encryption at rest; encrypted OAuth tokens; per-workspace row-level isolation enforced by the database; audit logging of every create, change, and delete; role-based permissions within a workspace; daily backups.
NinjaProspecting CRM is business software and is not directed at children under 16.
We will post changes on this page and update the effective date. Material changes will be announced in the application.
Privacy questions or requests: support@ninjaprospectingcrm.com. The service is operated by Gigadev (scott.shepherd@gigadev.net).