Effective: 26 August 2026 · Publisher: Deepliy · support@deepliy.com
The short version. Core CRM use is local-first. Optional Personal Sync, Google Drive backup, browser access and Team Workspace move only the relevant data directly between your devices and Google services. Deepliy does not operate a database that stores or can read your CRM records. A separate billing authority processes minimum pseudonymous purchase metadata for Google Play entitlement and fraud prevention. Analytics, diagnostics and user-submitted feedback are described below.
This policy covers the CRM: Customer & Sales Tracker Android app, its companion browser application and crmsalestracker.com. CRM records you enter remain yours. You decide what customer data to record and are responsible for having a lawful basis to use it.
Deepliy does not host or act as the storage provider for CRM record contents. Local records stay in app-private storage; optional cloud copies stay in a Google Drive account controlled by you or your Team manager. Google, Firebase and Google Play process the separate service data described in this policy under their own terms.
A separate billing authority verifies Personal Pro and Team Workspace purchases. It receives no CRM record or Drive business payload.
Local-first core: customers, appointments, sales, payments and other CRM records are stored in the app’s local Room database. Core editing, reports and reminders continue to work offline.
Personal Sync and browser: when you explicitly enable Personal Sync, supported CRM records and workspace configuration are encrypted on your device and stored in app-managed files in your own Google Drive. The companion browser communicates directly with Google and keeps an offline copy in browser storage. Use “forget this browser” on a shared computer to remove that browser copy.
Team Workspace: shared records are encrypted on participating devices and stored in the Team manager’s own Google Drive. Invited members who hold the workspace key can read the shared records. Removing access prevents future sync but cannot erase copies already obtained by a trusted member.
Backup: you can create local or Google Drive backups in JSON, ZIP or encrypted-container form. A ZIP or Drive backup can include attachment files when you choose that option. An unencrypted backup is readable by anyone who obtains the file; protect it accordingly.
Personal Sync and Team Sync are replication, not full backups. Supported reminder definitions, attachment metadata and encrypted attachment files are replicated when sync is enabled. Alarm scheduling and delivery checkpoints, notification state, local attachment cache paths and transfer-session state remain device-local. Keep a separate full backup.
Drive-based features request the drive.file and spreadsheets Google authorization scopes. The app uses them only for its workspace, recovery and backup files and the related spreadsheets; it does not scan your unrelated Drive content. OAuth access tokens stay in the Android app or browser client and are not sent to Deepliy.
The app and browser communicate directly with Google APIs. You can revoke access from your Google Account security settings. Revoking access stops future sync or backup but does not itself delete files already in your Drive.
Use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for advertising or transferred to an independent data broker.
When you verify or restore a purchase, the app or browser sends a Google identity token to the billing authority. The authority verifies issuer, audience, signature and expiry, derives a pseudonymous account binding, and does not use your email address as the entitlement key.
Contact access is optional and used only when you choose Import from Contacts. The selected name, phone number and email address are copied into a CRM record. Once imported, that record follows the Personal Sync, Team or backup options you enable; contact import itself does not upload your address book.
Notification and exact-alarm access is used for reminders. Widget and alarm state is maintained on the device. File-picker access is used for exports, imports and backups you initiate. WhatsApp, SMS, email and share actions open an app you choose; the CRM does not send those messages by itself.
The Android app uses Firebase Analytics and Firebase Crashlytics. They can receive a pseudonymous installation identifier and GA app-instance identifier; app version, build, language, theme and Team role; screen and feature events; device and operating-system details; crash stack traces; non-fatal errors; and technical breadcrumbs. We do not deliberately send customer names, phone numbers, notes, sale contents or other CRM record fields as analytics parameters.
The website and companion browser may use Google Analytics for aggregate usage measurement. CRM workspace contents are not sent to that analytics stream. The app removes the advertising-ID permission and contains no advertising SDK.
Firebase App Check with Play Integrity may provide app and device-integrity signals when feedback is submitted. These signals are used to protect the feedback endpoint, not to inspect CRM records.
Billing operations may record privacy-preserving events such as Play API success or error, verification latency, entitlement transition, RTDN duplicate, assertion rejection and reconciliation lag. Purchase tokens, order IDs, email addresses and CRM fields are not analytics parameters.
Feedback is sent only when you submit the form. Every submission contains your answers, app/version/language information and pseudonymous install identifiers so a report can be matched to relevant usage and crash diagnostics. A reply email is included only when you ask for a response and enter one.
Detailed device diagnostics are attached only when you enable that option. They can include device model and OS, screen and memory/storage state, battery and permission state, locale and time zone, counts of customers/sales/appointments, Team role and recent action-result labels. They do not include the content of CRM records. A failed submission may be queued locally and retried.
Google provides Firebase Analytics, Crashlytics, App Check, Play Integrity, Google Play billing/sign-in, Cloud Run, Firestore, Pub/Sub, Secret Manager, Drive and Sheets. Cloud services used by the billing authority process encrypted purchase tokens and minimum pseudonymous account, product, entitlement, expiry and verification metadata for app functionality and fraud prevention. Your own actions may also disclose data to apps or people you select through export, share, WhatsApp, SMS or email.
We do not sell CRM data or personal information. We may disclose feedback or diagnostic records when required by law, to protect the service against abuse, or to service providers that operate the feedback infrastructure under our instructions.
Synced record payloads are protected with AES-256-GCM before storage in Drive. Encryption keys remain with the participating devices, invitations and recovery material controlled through the user’s Google account. Deepliy cannot recover a lost workspace key or deleted Drive file.
Security also depends on your device lock, Google account, invited Team members, browser profile and backup choices. A local or browser copy can be read by someone who gains access to that device or browser profile. Encryption does not replace trusted-member and account security decisions.
Clearing app data or uninstalling removes the app’s local copy, but does not automatically delete Drive files, browser copies already stored elsewhere, shared-member copies, Google service records or feedback already submitted. Delete Drive files with your Google controls, use “forget this browser” for a browser copy and revoke Google authorization to stop future access.
Analytics and crash records are retained according to our Firebase/Google configuration and Google’s applicable controls. Feedback is retained as needed to answer, diagnose and improve the product. Contact support@deepliy.com for a privacy or deletion request and include the installation identifier shown in your support submission when available.
Billing metadata is retained while needed to verify, restore, reconcile and defend the purchase or meet legal/accounting and abuse-prevention obligations, then deleted or irreversibly detached according to the applicable retention process. Removing a CRM workspace does not by itself erase Google Play purchase records. You may request deletion of our pseudonymous billing record, subject to obligations that require limited retention.
The Service is a general business tool and is not directed to children. We do not knowingly solicit information from children through the app.
Business Profiles change labels, priorities and icons; they do not turn the Service into a regulated record system. In particular, the Clinic / Practitioner profile is for administrative customer, appointment, service and payment tracking and is not an EMR, diagnosis, prescription or medical-record system.
We may update this policy when the product or its service providers change. The effective date above identifies the current version. The English text is authoritative; translations are provided for convenience.
Questions and requests: support@deepliy.com. The current policy is available at https://www.crmsalestracker.com/privacy-policy.html.
Contact us about this policy or how the Service handles data: