LiveCRM Privacy Policy

Last updated September 25, 2026.

This policy describes the personal information LiveCRM collects, how we use it, who receives it, how long we keep it, and the choices you have.

1. Who we are #

LiveCRM, Inc. is a Delaware corporation. Our postal address is 7201 Lighthouse Lane NE, Olympia, WA 98506, United States. You can reach us about privacy at privacy@livecrm.ai.

2. Scope #

LiveCRM handles personal information in two different roles, and this policy treats them separately.

LiveCRM as a controller. We decide how to handle the information we need to run our own business: the accounts of the people who sign in to LiveCRM, the records of how our service is used, what visitors send us through our website, and our correspondence with you. Section 3 lists that information, and the rest of this policy covers how we use, share, keep and protect it.

LiveCRM as a processor. When a customer connects its CRM, LiveCRM processes the records in it, and the personal information those records contain, on that customer's behalf and on its instructions. For that information the customer is the controller and LiveCRM is its processor and service provider. Our Data Processing Addendum at livecrm.ai/dpa governs that processing, and it forms part of our Master Subscription Agreement at livecrm.ai/msa. Section 4 describes what that processing involves so that the people in those records can understand it. If you are one of those people and want to exercise a right over your information, contact the company whose CRM holds it. If you contact us instead, we will direct you to that company, as the Data Processing Addendum requires.

3. What we collect about our users and visitors #

Account information. When you sign up or sign in we collect your email address and the name and account identifier your Google account provides if you sign in with Google. We record your role in your company's account, whether your account is active, when it was created, and when you last signed in. For your company's account we record the company name, its email domain, its plan, and its trial dates and usage allowance. If a colleague invites you, we record your email address, the invitation's role and who sent it.

Sign-in information. You sign in with Google or with a one-time link sent to your email. We do not store passwords. For a one-time link we store your email address and a one-way hash of the link, never the link itself. Signing in with Google does not give us access to your Google account beyond your email address, name and account identifier, and we do not store the access token Google issues.

Agreement records. When you create an account for your company, we record that you accepted our Master Subscription Agreement: your email address, the version you accepted and a fingerprint of its text, the time, the method you used to sign up, the IP address your request came from and your browser's user agent string.

AI client authorizations. When you connect an AI client to LiveCRM through our Model Context Protocol server, we store the client's registration details, such as its name and the address it returns to after authorization, and the permissions you approved. We store only one-way hashes of the tokens we issue, and we record when each token was issued, when it expires, and when it was last used.

Usage information. For each request an AI client makes through our Model Context Protocol server, we record which account and which authorization made it, which operation it called, whether it succeeded, how many records it involved, how long it took, and when it happened. We do not record the request's contents or the data we returned in that record. We also count the changes the service makes to your CRM, because your plan is measured in them.

Console conversations. If you use the Console, the chat assistant inside LiveCRM, we store the conversation: your messages and the assistant's replies.

Operational logs. Our servers keep logs of the requests they handle, including the time, the address requested and the result. Our logs may include IP addresses, email addresses and record identifiers.

Billing. We do not currently collect payment information. Paid plans will be billed through a payment processor, which we will add to our subprocessors page before it receives any data, and we will update this policy at that time.

Demo requests and contact. If you request a demo on our website, the form sends us your name, work email address, role, the CRM you use, an approximate record count and anything you write about your needs. It reaches us by email and is not stored in our database. After you submit it we send you to Calendly to book a time, and your name and email address are passed to Calendly so you do not have to enter them again. If you email us, we keep the correspondence.

4. Customer CRM data we process on a customer's behalf #

This section describes processing we perform as a processor. The customer's own privacy notice and our Data Processing Addendum govern it.

What we copy. To work on a customer's CRM quickly and consistently, LiveCRM keeps a copy of the records the customer connects and keeps it current from the CRM's own change notifications. For Salesforce that covers accounts, contacts, leads, opportunities, cases and the CRM's user list. For HubSpot it covers companies, contacts and deals. The copy includes the standard fields of those records, such as names, job titles, email addresses, telephone numbers, postal addresses, ownership and status, and it also includes every custom field the customer's integration user can read. The information in the copy is whatever the customer has put in its CRM.

What else we keep. Before LiveCRM changes a record in a customer's CRM, it records the values it is about to change and the values it writes, so that the change can be reversed. When LiveCRM merges duplicate records, it keeps a snapshot of the records it merges. When a customer runs an enrichment using its own data provider account, we send that provider the details it needs to find a match, which can include a person's name, company, email address and company website, and we hold the provider's answers for up to 30 days while the customer reviews them. When a customer connects its Slack workspace, we keep a copy of the workspace's member list, including each member's name and email address, so that each alert reaches the person who owns the record.

Where it is stored. We store customer CRM data in a managed PostgreSQL database on Amazon Web Services in the United States (us-east-1). Each customer's data is separated from every other customer's by row-level security enforced in the database. The database is encrypted at rest and accepts only encrypted connections. The message queue that carries work between parts of the service is encrypted at rest and holds each message for up to 14 days.

Credentials. The authorization tokens for Salesforce, HubSpot and Slack, the credentials for a customer's data provider, and any Anthropic key a customer supplies are stored in AWS Secrets Manager, encrypted with a key managed by AWS, under a path unique to that customer. They are not stored in our database.

5. AI clients and the Model Context Protocol #

When a customer's AI client connects to LiveCRM, we receive only the tool calls it makes: the name of each tool and the arguments the client sends with it. We do not receive the conversation between you and your AI client, its instructions, or anything else it holds. When the client identifies itself as it connects, we do not store that description.

We do not log the arguments or the results of tool calls. We keep the usage record described in section 3, and anything a tool call creates or changes becomes part of your account like the same action taken in the LiveCRM app: a run it creates, a plan it saves, and the record of every change it makes to your CRM.

The data a tool call returns goes to the AI client you chose, under your agreement with that client's provider. That provider is not LiveCRM's subprocessor.

We do not use customer data to train or fine-tune any AI model. Our Master Subscription Agreement and Data Processing Addendum also commit us not to permit our AI subprocessors to do so.

The Console, the chat assistant inside LiveCRM, works differently from an outside AI client. It sends your conversation, and the CRM records it reads to answer you, to Anthropic for processing. It uses your company's own Anthropic key if you have connected one. It uses LiveCRM's Anthropic account if you have not, and also if your key is missing or rejected and your company allows that fallback.

6. How we use information #

We use the information in section 3 to create and secure your account, sign you in, provide and support the service, send you sign-in links and account notices, measure usage against your plan, respond to your requests, detect and prevent abuse and security incidents, and comply with the law. We use usage information to operate and improve the service, as our Master Subscription Agreement allows, without disclosing customer data or identifying you. We use customer CRM data only to provide the service on the customer's instructions.

We do not sell personal information or share it for cross-context behavioral advertising.

7. Sharing and subprocessors #

The companies that process data on our behalf, what each one does and where, are listed at livecrm.ai/subprocessors. We update that list, and notify customers who have subscribed to notifications, at least 30 days before a new subprocessor begins processing customer data.

A customer's own services are not our subprocessors. The CRM it connects, the data provider it uses on its own contract, the Slack workspace it connects, the Anthropic key it supplies, and the AI clients it authorizes all receive data under that customer's own agreements with them.

Our website loads its fonts from Google Fonts, so your browser sends Google its IP address and user agent when you visit. If you request a demo, Calendly receives your name and email address as described in section 3.

We may also disclose information when the law requires it, to protect the rights and safety of our customers or others, or to a successor in a merger, acquisition or sale of our business, which would remain bound by this policy.

8. Retention and deletion #

Your account information stays for as long as your company's account exists.

When a CRM is disconnected, LiveCRM stops syncing it and deletes the stored credential. AWS keeps the deleted credential recoverable for 7 days, and earlier versions of the credential are removed when the account is deleted. The records already copied, and the history of changes, stay in the account.

When a trial ends, nothing is deleted. The service stops making changes to your CRM and the data stays in the account until your company asks us to delete it, as our Master Subscription Agreement states.

Your company's account administrator can ask us in writing, at privacy@livecrm.ai or jaime@livecrm.ai, to delete the account. We verify the request, and we complete the deletion within 30 days of it. When we delete an account, we revoke LiveCRM's access to the connected CRM and Slack workspace, delete the stored credentials, which AWS keeps recoverable for 7 days, and delete the account's data from our database: the copied CRM records, runs, rules, plans, the review queue, Console conversations, usage records, the account's users, and the record of every change LiveCRM made to the customer's CRM, including the values before and after each change and the snapshots kept to reverse merges.

One record is kept. The record that your company accepted our Master Subscription Agreement, including the IP address and browser user agent described in section 3, is kept for six years after the account is deleted, as evidence of the contract, and is then deleted.

Other records have their own retention periods. Records of one-time sign-in links are removed about a day after the link expires. The registration details of an AI client are removed once 90 days pass in which none of its tokens was used and it holds no unexpired token. Console conversations are kept until the account is deleted.

Copies outside the database expire on their own schedules: database backups after 7 days, queued messages after 14 days, application logs after 30 days, and load balancer logs, which record request addresses and IP addresses, after 90 days. Logs are shared across accounts and cannot be deleted for a single account before they expire.

Changes LiveCRM made in a customer's CRM remain in that CRM after the account is deleted.

9. Security #

We protect personal information with measures described at livecrm.ai/security, including encryption in transit and at rest, database-level separation between customers, and sign-in without passwords. We do not currently hold a SOC 2 report or ISO 27001 certification.

10. Cookies and similar technologies #

Our website, livecrm.ai, sets no cookies and loads no analytics or advertising scripts. Our network provider, Cloudflare, adds a small script to our pages that hides email addresses from automated harvesting; it is served from our own domain and sets no cookies.

The LiveCRM app and our API use only the cookies they need to work, and none is used for analytics or advertising:

livecrm_session keeps you signed in for up to 7 days, or until you sign out.

oauth_state protects the Google sign-in step against forgery and lasts 10 minutes.

login_next remembers the AI client authorization you were completing when you were asked to sign in, and lasts 10 minutes.

terms_acceptance carries your acceptance of our agreement through the Google sign-in step, and lasts 10 minutes.

sf_oauth_pkce and slack_oauth_state protect the steps that connect Salesforce and Slack, and each lasts 10 minutes.

The app also stores two small preferences in your browser so that notices you dismiss stay dismissed.

11. Your rights #

Depending on where you live, you may have the right to ask for access to the personal information we hold about you, to have it corrected, to have it deleted, to object to or restrict how we use it, and to receive a copy of it. To exercise any of these rights for the information in section 3, email privacy@livecrm.ai. We will verify your request, answer it within 30 days, and not treat you differently for making it.

For information in a customer's CRM, the customer is the controller, so contact that company. If you contact us, we will direct you to it.

If you are in the European Economic Area, the United Kingdom or Switzerland, you may also complain to your data protection authority.

12. International transfers #

We store data in the United States. Our network provider, Cloudflare, handles traffic to our service at locations around the world, including outside the United States. If you use LiveCRM from the European Economic Area, the United Kingdom or Switzerland, the account information we hold about you as a controller is transferred to the United States because that transfer is necessary to provide the service you asked for. For customer CRM data subject to European, UK or Swiss law, our Data Processing Addendum provides the Standard Contractual Clauses.

13. Changes to this policy #

We will post any change to this policy on this page with a new date. We will email account administrators about a material change at least 30 days before it takes effect.

14. Effective date #

This policy is effective as of September 25, 2026.