1. Overview & Principles
At scratchly ("Scratchly", "we", "us", or "our"), privacy is not an afterthought; it is built into the architecture of our CRM. We believe that your pipeline, contact histories, and deal intelligence belong solely to your organization.
2. Information We Collect
We collect information in three specific contexts:
- Account & Waitlist Information: Your full name, work email address, team size, role, and custom survey feedback provided during registration or early pass generation.
- Workspace & Customer Data: Contact records, sales opportunities, deal values, company tags, and communication summaries you create or import.
- Technical & Telemetry Data: Browser type, operating system, IP address, and platform usage metrics collected strictly to optimize application performance.
3. Protection of CRM Data
All data stored in Scratchly is protected using enterprise-grade security protocols:
TLS 1.3 encryption across all client-to-server and API communication channels.
AES-256 bit encryption on all underlying database volumes and backup snapshots.
4. AI Copilot & Model Isolation
When you interact with the Scratchly Deal Copilot or automated timeline summarization tools, inference is conducted through isolated enterprise endpoints. Your deal memos and executive communications are never stored in third-party public training corpora.
6. Your Rights (GDPR & CCPA)
Regardless of your geographical location, Scratchly grants all users the following fundamental privacy rights:
- Right to Access & Portability: Export all workspace records in standard CSV or JSON format at any time.
- Right to Rectification: Edit or update any contact or personal details directly from your settings.
- Right to Erasure ("Right to be Forgotten"): Request complete, permanent deletion of your account and all associated pipeline data within 30 days.
7. Retention & Deletion
We retain account data only as long as your workspace remains active. When an account is terminated, all primary database records and automated backups are permanently purged within 30 days.
8. Contact Our Data Privacy Officer
For questions regarding this policy or to exercise your GDPR/CCPA rights, contact us at:
privacy.scratchly@gmail.com