CRMLynk
  • Privacy
  • Terms
  • Contact Us

Privacy Policy

Last Updated: April 7, 2026

1. Overview

CRMLynk ("CRMLynk," "we," "us," or "our") provides managed OAuth integration services through our websites, applications, APIs, and related products and services (collectively, the "Platform"). This Privacy Policy describes how we collect, use, disclose, and protect your information when you use our Platform.

By accessing or using the Platform, you agree to this Privacy Policy. If you do not agree, please do not use the Platform.

2. Types of Information Collected

2.1 Personal Information

We may collect the following categories of Personal Information:

  • Account Information: Name, email address, business name, and billing details when you subscribe to our services.
  • Deployment Information: Your platform deployment URLs and configuration data necessary to route integration callbacks.
  • Communication Data: Information you provide when contacting us for support or inquiries.
  • Payment Information: Billing and transaction data processed through our third-party payment processor (Stripe). We do not store full payment card details.

2.2 Non-Personal Information

We may collect non-personal information including browser type, operating system, IP address, referring URLs, and usage patterns through standard web server logs.

2.3 Third-Party API Data

Our Platform routes OAuth authentication flows between third-party providers (including Google, Microsoft, Meta, and Zoom) and subscriber deployments. During this process:

  • We may temporarily process OAuth state parameters to determine the correct routing destination.
  • We do not access, store, or retain OAuth tokens, API credentials, or end-user data obtained through third-party APIs.
  • Authorization codes pass through our routing infrastructure in transit and are not persisted.

The following provider integrations are supported. Data accessed through these integrations is handled exclusively by the subscriber's deployment:

  • Google: Gmail, Google Calendar, Google Analytics, Google Ads, Google Business Profile, Google Sheets, Google Drive.
  • Microsoft: Outlook (email and calendar), Office 365, Microsoft Contacts, OneDrive.
  • Meta: Facebook Messenger, Instagram Direct Messages, Facebook Pages, Facebook Lead Ads.
  • Zoom: Zoom Meetings, Zoom Webinars, Zoom User Management.

3. How We Use Your Information

We use collected information to:

  • Provide, operate, and maintain the Platform and our integration services.
  • Authenticate and validate subscriber deployments.
  • Route OAuth callbacks to the correct subscriber deployment.
  • Process payments and manage subscriptions.
  • Communicate with you regarding your account, support requests, or service updates.
  • Detect, prevent, and address technical issues, fraud, or security incidents.

Google API Services Compliance: CRMLynk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do NOT retain Personal Information to develop, improve, or train generalized artificial intelligence or machine learning models, including user data provided via third-party APIs, including but not limited to Google Workspace APIs.

We do NOT use information received from Google APIs to:

  • Serve or target advertising.
  • Sell data to third parties, data brokers, or information resellers.
  • Make credit, lending, insurance, or employment decisions.
  • Develop profiles for the purpose of tracking or retargeting users.

4. YouTube API Services

If you choose to connect a YouTube or Google account through the Platform, this connection uses YouTube's API Services, and the Google Privacy Policy will apply to you.

If you have authorized us to access your information via YouTube API Services, in addition to our normal procedure for deleting stored data, you may revoke our access to your data via the Google Security Settings page.

5. Microsoft API Services

If you choose to connect a Microsoft account through the Platform, this connection uses the Microsoft identity platform and Microsoft Graph API. The Microsoft Privacy Statement will apply to you.

CRMLynk accesses Microsoft data solely to facilitate the integration between Microsoft services (Outlook, Calendar, Contacts, OneDrive) and subscriber platform deployments. We do not store, retain, or independently process Microsoft user data. CRMLynk's use of Microsoft Graph API data complies with the Microsoft APIs Terms of Use. You may revoke access at any time through your Microsoft Account Permissions page.

6. Meta Platform Data

If you choose to connect a Facebook or Instagram account through the Platform, this connection uses Meta's Graph API and related platform APIs. The Meta Privacy Policy applies to your use of Facebook and Instagram services.

CRMLynk facilitates the following Meta integrations on behalf of subscriber platform deployments:

  • Pages: Listing and managing Facebook Pages, subscribing to Page webhooks, reading and responding to Page comments and posts.
  • Messenger: Sending and receiving messages on behalf of connected Facebook Pages.
  • Instagram: Reading Instagram Business account profiles, sending and receiving Instagram Direct Messages.
  • Lead Ads: Receiving lead data from Facebook and Instagram lead ad forms.

CRMLynk may receive webhook notifications from Meta containing message content, user identifiers, and Page activity data. This data is routed to the appropriate subscriber deployment in transit and is not persisted by CRMLynk.

Data Deletion: You may request deletion of any Facebook or Instagram data associated with your use of the Platform by contacting us at [email protected]. CRMLynk also provides a Data Deletion Request callback endpoint to Meta. When Meta processes a user's data deletion request, CRMLynk will propagate the deletion to all affected subscriber deployments and return a confirmation code. You may also remove CRMLynk's access through your Facebook Business Integrations settings.

7. Zoom API Services

If you choose to connect a Zoom account through the Platform, this connection uses Zoom's OAuth and REST APIs. The Zoom Privacy Policy applies to your use of Zoom services.

CRMLynk facilitates the following Zoom integrations on behalf of subscriber platform deployments:

  • User Profile: Reading Zoom user display name and email for account linking.
  • Meetings: Creating, reading, and updating Zoom meetings from scheduling interfaces.
  • Webinars: Reading webinar details and registration data.

CRMLynk may receive webhook notifications from Zoom containing meeting event data and user identifiers. This data is routed to the appropriate subscriber deployment in transit and is not persisted by CRMLynk.

Deauthorization: When a user uninstalls or disconnects CRMLynk from their Zoom account, Zoom notifies CRMLynk via a deauthorization webhook. CRMLynk will propagate the deauthorization to the affected subscriber deployment and confirm data handling compliance with Zoom. You may also revoke access through your Zoom Installed Apps page.

CRMLynk's use of Zoom API data complies with the Zoom Marketplace Developer Agreement.

8. Webhook Data in Transit

CRMLynk receives webhook notifications from third-party providers (Meta, Zoom, and others) and routes them to the appropriate subscriber deployment. During this routing process:

  • Webhook payloads may contain end-user data such as message content, user identifiers, meeting event details, and lead form submissions.
  • This data passes through CRMLynk's infrastructure in transit only and is forwarded to the subscriber deployment in real time.
  • We do not persist, log, index, or independently process the contents of webhook payloads.
  • We maintain routing mappings (such as Facebook Page IDs and Zoom account IDs mapped to subscriber deployment URLs) in order to deliver webhooks to the correct destination.

9. How We Protect Your Information

We implement industry-standard security measures to protect your information, including:

  • TLS 1.2+ encryption for all data in transit.
  • Encryption at rest for stored subscriber data.
  • Constant-time comparison for API key and webhook signature verification to prevent timing attacks.
  • Strict input validation and URL verification on all endpoints.
  • Least-privilege access controls on infrastructure.

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

10. When We Share Your Information

We do not sell, rent, or trade your Personal Information. We may share your information only in the following circumstances:

  • Service Providers: With trusted third-party service providers who assist in operating the Platform (e.g., payment processing, infrastructure hosting), subject to confidentiality obligations.
  • Legal Requirements: When required by law, regulation, legal process, or governmental request.
  • Safety and Security: To protect the rights, property, or safety of CRMLynk, our users, or the public.
  • Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, with notice to affected users.
  • With Your Consent: When you have given explicit consent to share your information.

10.1 Text Messaging

We do NOT share your phone number or text messaging opt-in consent with third parties unless we have received your express written consent to do so. All categories described above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties, excluding aggregators and providers of text messaging services.

11. Data Retention and Deletion

We retain Personal Information only for as long as reasonably necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.

You may request deletion of your Personal Information at any time by contacting us at [email protected]. Upon receiving a verified deletion request, we will delete or de-identify your data within 30 days, except where retention is required by law.

When a subscriber's account is deactivated or terminated, we will delete associated deployment and account data within 30 days.

12. Cookies and Tracking Technologies

The CRMLynk Platform (the OAuth proxy service) does not use cookies, web beacons, or similar tracking technologies. Our proxy infrastructure processes requests statelessly and does not set cookies on end-user browsers.

Our marketing website at crmlynk.com may use essential cookies for basic functionality (such as session management). We do not use advertising cookies, analytics tracking pixels, or third-party tracking scripts.

13. Children's Privacy

The Platform is not directed at individuals under the age of 16. We do not knowingly collect Personal Information from children under 16. If we become aware that we have collected Personal Information from a child under 16, we will take steps to delete that information promptly. If you believe a child under 16 has provided us with Personal Information, please contact us at [email protected].

14. Links to Other Websites and Services

The Platform may contain links to or integrations with third-party websites and services, including but not limited to Google, Microsoft, Meta (Facebook, Instagram), and Zoom. This Privacy Policy applies only to CRMLynk. We are not responsible for the privacy practices of third-party services. We encourage you to review the privacy policies of any third-party service you interact with.

15. Do Not Track

Our Platform does not currently respond to "Do Not Track" signals. We do not engage in cross-site tracking of our users.

16. Your Legal Rights

Depending on your location, you may have the following rights regarding your Personal Information:

  • Access: Request a copy of the Personal Information we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your Personal Information.
  • Portability: Request your data in a structured, machine-readable format.
  • Objection: Object to processing based on legitimate interests.
  • Restriction: Request restriction of processing in certain circumstances.
  • Withdraw Consent: Where processing is based on consent, withdraw that consent at any time.

To exercise any of these rights, contact us at [email protected]. We will respond to requests within 30 days (or as required by applicable law).

17. European Privacy Rights

If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, the following additional provisions apply:

Data Controller and Processor: CRMLynk is the Data Controller of Personal Information collected through the Platform (such as account and billing information). With respect to data processed on behalf of our subscribers through the integration services, CRMLynk acts as a Data Processor.

Legal Bases for Processing: We process Personal Information under the following legal bases:

  • Contract: Processing necessary to perform our agreement with you.
  • Legitimate Interests: Processing necessary for our legitimate business interests, such as security and fraud prevention.
  • Consent: Where you have provided explicit consent.
  • Legal Obligation: Processing required to comply with applicable law.

International Transfers: Your data may be transferred to and processed in the United States. We rely on appropriate safeguards for such transfers, including Standard Contractual Clauses approved by the European Commission.

Supervisory Authority: You have the right to lodge a complaint with your local data protection supervisory authority.

18. Data Privacy Framework

CRMLynk adheres to the principles of the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of Personal Information transferred from the EEA, UK, and Switzerland to the United States.

CRMLynk commits to resolve complaints about our collection or use of your Personal Information. Individuals with inquiries or complaints should first contact us at [email protected]. We will respond within 45 days. If we are unable to resolve the matter directly, you may submit your complaint to JAMS (jamsadr.com/DPF-Dispute-Resolution) as an independent recourse mechanism, at no cost to you.

CRMLynk is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC). In certain circumstances, you may invoke binding arbitration through the Data Privacy Framework Panel.

19. California Privacy Rights

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your Personal Information.

Categories of Information

CategoryCollectedDisclosedSold
Identifiers (name, email, IP address)YesYes (service providers)No
Commercial information (subscription history)YesYes (payment processor)No
Internet or network activity (usage logs)YesNoNo
Geolocation data (approximate, from IP)YesNoNo
Inferences (usage patterns)YesNoNo
Sensitive Personal InformationNoNoNo

Your Rights: You have the right to know, delete, correct, and opt-out of the sale of your Personal Information. We do not sell Personal Information. To exercise your rights, contact [email protected].

We will not discriminate against you for exercising your CCPA rights.

20. Virginia Privacy Rights

If you are a Virginia resident, the Virginia Consumer Data Protection Act (VCDPA) provides you with rights to access, correct, delete, and obtain a copy of your Personal Information. You also have the right to opt out of the processing of your data for targeted advertising, sale, or profiling. We do not engage in any of these activities.

To exercise your rights, contact [email protected]. If we decline your request, you may appeal by contacting us at the same address.

21. Colorado Privacy Rights

If you are a Colorado resident, the Colorado Privacy Act (CPA) provides you with rights to access, correct, delete, and obtain a portable copy of your Personal Information. You may opt out of targeted advertising, sale, or profiling. We do not engage in any of these activities.

To exercise your rights, contact [email protected].

22. Connecticut Privacy Rights

If you are a Connecticut resident, the Connecticut Data Privacy Act (CTDPA) provides you with rights similar to those described in the Virginia and Colorado sections above. To exercise your rights, contact [email protected].

23. Utah Privacy Rights

If you are a Utah resident, the Utah Consumer Privacy Act (UCPA) provides you with rights to access and delete your Personal Information, and to opt out of the sale of your data or targeted advertising. We do not sell data or engage in targeted advertising. To exercise your rights, contact [email protected].

24. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last Updated" date at the top of this page indicates when the policy was last revised. Continued use of the Platform after changes constitutes acceptance of the revised policy.

25. How to Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

CRMLynk
Email: [email protected]
Mail: CRMLynk, Virginia, United States

For data protection inquiries from EEA/UK residents, please use the email address above with "GDPR Request" in the subject line.

© 2026 CRMLynk. All rights reserved.
  • Privacy Policy
  • Terms of Service
  • Contact