How we protect your data
This page is maintained by the GI CRM team to answer common security and privacy questions about GI CRM. It is not an independent certification or audit report.
Authentication & access
Sign-in is required for all CRM data. Accounts are managed through our hosted authentication provider, supporting email/password sign-in and OAuth providers we explicitly enable.
Inside the application, access is enforced server-side using role-based rules (admin, manager, marketing, sales, sales_admin). Users can only see and modify the records their role and assignments allow.
Encryption in transit
All traffic to the application, the API, and the database is served over HTTPS/TLS. Webhook endpoints require shared secrets or signature verification before any data is accepted.
Data storage & isolation
Customer and lead data is stored in a managed PostgreSQL database with row-level security policies. Sensitive operational secrets (webhook secrets, API tokens) are not readable by ordinary users and are accessed only by trusted server functions.
Staff contact details such as email and phone are restricted to the profile owner and administrators.
Shared responsibility
GI CRM relies on Lovable Cloud (hosting, database, authentication) for platform security capabilities. Configuration choices inside the application — roles, workflows, integrations, exports — are the responsibility of the GI CRM team and the customer's administrators.
Data handling & retention
We store only the data needed to operate the CRM: leads, conversations, contracts, tasks, and the activity logs that explain how they changed. Customers can request export or deletion of their workspace data by contacting us.
We do not sell customer data. Third-party integrations (advertising, messaging, email) are activated only when an administrator explicitly enables them.
Reporting a security issue
If you believe you have found a vulnerability or have a security question, please contact the GI CRM administrator for your workspace. We will acknowledge the report and work with you on remediation.
This page reflects current product behavior and is updated as the product evolves. It is editable project content, not an independent attestation.