Legal
Privacy Policy
Effective date: August 24, 2026
Who we are
Opulent CRM is operated by Opulent Mass LLC (“we”, “us”). For the account data of the people who subscribe to and sign in to Opulent CRM — names, work emails, authentication and usage records — Opulent Mass LLC is the data controller and decides how that data is used.
For the CRM records a subscribing organization enters about its own customers, contacts and partners, that organization is the controller and Opulent Mass LLC is a processor acting on its instructions. Privacy questions and requests can be sent to privacy@opulentcrm.app.
Who this covers
Two groups: the organizations that subscribe to the platform and their users (administrators, managers, representatives, portal users), and the business contacts those organizations store in their own workspace. Each subscribing organization is the controller of the contact records it enters; we process them on that organization's instruction.
What is collected
Account data: name, work email, organization membership, role, authentication metadata.
CRM data entered by the organization: accounts, contacts, opportunities, notes, activities, tasks, appointments, products, orders, imports and files.
Location data: business addresses geocoded for mapping and routing, and — only where a user grants device permission — the device position used to verify a visit check-in.
Communication data: emails sent through the platform and their delivery, open, bounce, complaint and unsubscribe events; manually logged calls and texts.
Operational data: audit logs, error reports and usage counts used for billing and cost accounting.
Location-data consent
Device location is requested only for visit check-in and route execution, only while those screens are in use, and only after the browser permission prompt is accepted. Declining does not block CRM access; the check-in is recorded without verification.
How it is used
To operate the service the organization subscribed to, authenticate users, send transactional and user-initiated email, calculate seats and invoices, monitor cost and reliability, and investigate abuse or security incidents.
Customer CRM data is not sold, rented, or used to train third-party models.
Who can see it
Within an organization, access is limited by active membership and role. External professional portal users see only their own business profile, availability, requests, messages and orders. Our staff have no implicit access; access requires an explicit, audited grant.
Legal basis for processing
We process account, CRM and operational data to perform our contract with the subscribing organization. We rely on legitimate interests for security, fraud prevention, abuse investigation, service improvement and cost accounting; on consent for device location and for any marketing email we send you about Opulent CRM; and on legal obligation where we must retain records for tax, accounting or law-enforcement purposes.
Who we share data with
Merchant of Record. Our order process is conducted by our online reseller Paddle.com, which is the Merchant of Record for all our orders. Paddle.com handles checkout, subscription management, payments, tax compliance, invoicing and refunds, and processes the billing details you enter at checkout under its own privacy notice. We do not receive or store full card details.
Service providers. Hosting, database and application infrastructure; transactional and marketing email delivery; mapping, geocoding and route optimization; AI features used to summarize or query your own CRM data; and error and performance monitoring. These providers process data only on our instructions and are bound by confidentiality obligations.
Professional advisers and authorities. Legal and accounting advisers where needed, and public authorities where we are legally required to disclose.
Some of these providers operate in the United States and other countries. Where data moves out of the UK or EEA, we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision. Customer CRM data is not sold or rented.
Marketing-email consent
Bulk or marketing email sent by an organization requires that organization to hold and record consent from each recipient. The platform stores consent and unsubscribe state per contact, honors unsubscribes, and separates marketing sending from transactional and authentication email.
Cookies and similar storage
The application stores a strictly necessary session token so you stay signed in, plus local preferences such as your chosen navigation app. Our checkout uses cookies set by Paddle.com to process the order and prevent fraud. We do not use advertising or cross-site tracking cookies, so there is nothing to opt out of; you can clear or block cookies in your browser, though signing in will stop working without the session cookie.
Retention, export and deletion
Data is retained while the subscription is active. After cancellation, data is retained for a defined window so it can be exported, then deleted. Organizations can export their records at any time; individual export, correction and deletion requests can be made to privacy@opulentcrm.app.
Retention periods: CRM and account data are kept while the subscription is active and for 30 days after cancellation, after which they are deleted or anonymised. Email delivery and engagement events are kept for 24 months. Audit and security logs are kept for 12 months. Billing and tax records are kept for 7 years where law requires it. Backups roll off within 30 days of deletion.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable format, withdraw consent you have given, and — for UK/EEA residents — complain to your supervisory authority. We respond to requests within one month.
If your data was entered into a subscribing organization's workspace, that organization controls it; we will forward your request to them and support them in answering it.
Security
Access controls are enforced in the database per organization, and credentials are held server-side. We describe our practices on the Security page and make no claims about certifications or compliance programs we have not completed.
Contact
Privacy requests: privacy@opulentcrm.app. General support: support@opulentcrm.app.