Privacy Policy
What Salesfresh does with personal data, why, who it is shared with, how long it is kept, and what you can ask us to do about it.
Effective from August 20, 2026
Privacy Policy
IDEASFRESH TECHNOLOGY PRIVATE LIMITED (CIN U72400TN2021PTC146933), referred to below as “we”, “us” or “Ideasfresh”, builds and operates Salesfresh — a customer relationship management platform covering leads, contacts, accounts, deals, quotes, contracts, service delivery, reporting and sales automation. This policy explains what personal data the platform handles, why, who it is shared with, how long it is kept, and what you can ask us to do about it.
It is written to be read, not to be survived. Where a statement describes something the product actually does, it describes the behaviour as built — not an aspiration. Where we make a commitment we cannot yet keep technically, we say so instead of implying otherwise.
This policy is issued in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000 together with the rules made under it. It applies to https://salesfresh.test, the Salesfresh web application, our browser extension, our APIs, and the email and telephony features that connect to them.
1. The two different roles we play
Almost every misunderstanding about CRM privacy comes from collapsing two very different relationships into one. We keep them separate, because your rights and our obligations differ in each.
| Data | Our role | What that means |
|---|---|---|
| Your own account and your organisation’s subscription — your name, work email, login credentials, billing details, support conversations | Data Fiduciary | We decide the purposes, we answer to you directly, and you exercise your DPDP rights against us. |
| The CRM records your team creates or imports — your leads, contacts, customers, their emails, phone numbers, call recordings and documents | Data Processor | Your organisation is the Data Fiduciary. We process this data only on your instructions and only to run the service. If one of your customers asks us to delete their record, we route that request to you rather than acting on it ourselves. |
We hold your details on that business’s behalf and have no independent relationship with you. Please contact that business directly. Write to us and we will forward your request to them and tell you we have done so, but we cannot amend or erase their records for them.
2. What we collect
This is the complete list, feature by feature. Several of these categories only come into existence if someone on your team switches the corresponding feature on.
2.1 Account and profile
- Email address and password. Passwords are stored only as a bcrypt hash — we cannot read, recover or tell you your password.
- Salutation, first and last name, and an optional short “about” description.
- Profile photo, if you upload one.
- Date of birth, country, calling code and mobile number, if you choose to fill them in. None of these are required to use the product.
- Your sign-in method, and the provider account identifier if you sign in with Google, Microsoft or LinkedIn instead of a password.
- Email verification status and the timestamp of verification.
2.2 Organisation, subscription and billing
- Company name, addresses, industry, currency, time zone and branding.
- GSTIN, PAN and place of supply, where you provide them — these are required to issue a compliant tax invoice.
- Plan, billing cycle, licensed user count, subscription status, invoices, credit notes and payment history.
- Payment mandate references and the last four digits and card type returned to us by our payment gateway.
Card numbers, CVVs, UPI credentials and net-banking logins are collected by Cashfree Payments on their own pages and infrastructure. They are never transmitted to, processed by, or stored on our servers. We receive only a payment result and a mandate reference.
2.3 The CRM records your team creates
This is content you supply, and it is by far the largest category. What is in it is entirely your team’s choice — we impose no schema on the substance of your records.
- Leads, contacts, accounts and their names, job titles, email addresses, phone numbers, postal addresses, social profiles and notes.
- Deals, pipelines, quotes, quote line items, products, price books and targets.
- Contracts and everything attached to them — approvals, milestones, obligations, SLAs, renewal terms, risk assessments and signatures.
- Assets, work orders, service appointments and service schedules.
- Tasks, meetings, meeting participants, calls, comments, tags and custom views.
- Files your team uploads against any of the above. These are held in our own object storage, not on a third-party file service.
- Data you import from spreadsheets or another CRM, including whatever personal data those files contain.
2.4 Mailbox contents, if a user connects a mailbox
Connecting a mailbox is optional, per-user, and always initiated by the user through the provider’s own consent screen. When a user connects one, we synchronise messages so that email appears on the CRM timeline. What we store is:
- Sender, recipients, cc and bcc, subject and date.
- A short preview snippet, plus the plain-text and HTML message bodies.
- Attachment metadata and the links found inside messages.
- Thread, folder and read/unread state, and drafts composed inside the product.
- A refresh token so synchronisation can continue without asking the user to sign in repeatedly. Tokens are revocable at any time, both from our settings screen and from the provider’s own security settings.
We request the narrowest set of permissions each provider offers for this to work: read, send and label-modify for Gmail plus basic profile and email address; the equivalent mail permissions for Microsoft Outlook; and message read, message create, account read and search for Zoho Mail. We do not request access to your files, contacts list or calendar beyond what is listed here.
Synchronised messages are scoped to the user who connected the mailbox and are visible to others only where your organisation’s own sharing and permission rules allow it. Connecting a personal mailbox will bring personal correspondence into the CRM, so we recommend connecting work mailboxes only.
2.5 Email engagement tracking
When your team sends email through the platform, we can record whether it was delivered, opened and clicked. This works by embedding a one-pixel transparent image in the message and by routing links through a redirect. We record delivery status, open count and time of first open, click count, the URLs clicked and when.
Open and click tracking observes the behaviour of the people your team emails. Whether that is lawful in a given jurisdiction, and whether notice or consent is required, is a decision for your organisation as the Data Fiduciary. We provide the capability; we do not assess the legality of your use of it.
2.6 Calls
If your organisation enables telephony, we store the numbers involved, direction, timestamps, duration, disposition and outcome notes, and a reference to the call recording where recording is switched on. Recordings themselves are held by our telephony provider and streamed to authorised users through the product. Recording a call may require notifying or obtaining the consent of the other party, and complying with applicable Do Not Call and telemarketing rules — again, your organisation’s call to make.
2.7 Public forms
For web forms your team publishes, we store the field values submitted, together with the submitter’s IP address, browser user agent, referring URL and any UTM campaign parameters present on the page. Forms are protected by Google reCAPTCHA to block automated submissions. Placing an appropriate collection notice on your own form is your organisation’s responsibility.
2.8 Product usage and audit trail
- An audit log of record changes — which record and table changed, what the operation was, which fields changed and their before and after values, who did it and when. This exists so your administrators can answer “who changed this, and when”.
- A record-view history noting which records a user opened and when, which powers the “recently viewed” lists.
- Session tokens, sign-in timestamps and device or browser information sufficient to keep sessions secure.
- Server logs, error traces and job queue records generated while serving requests.
2.9 Approximate location from IP address
For some records we look up an IP address against a third-party geolocation service to derive the organisation name, city, state, country and postal code. We keep the result so the same address is not looked up twice. This is coarse, city-level information inferred from network routing — it is not device GPS location, and we do not collect precise location from any device.
2.10 Browser extension
The Salesfresh browser extension helps a user capture a lead from a page they are already looking at — a LinkedIn profile, or a message in Gmail. It reads page content only on the page you are viewing and only when you invoke it; it does not run in the background across your browsing, and it sends nothing anywhere unless you press the button to save a record. It stores your session locally so you do not have to sign in on every page.
2.11 Support, sales and consent records
- Messages you send us, enquiry and demo request forms, and the correspondence that follows.
- A record of the consents and acknowledgements you give in the product — what you agreed to, which version of the document, on which application, and when. We keep these so we can demonstrate that consent was actually obtained.
3. Why we process it
Under the DPDP Act, personal data is processed either with your consent or for a certain legitimate use. This table sets out each purpose against the ground we rely on.
| Purpose | Ground |
|---|---|
| Creating your account, authenticating you and keeping you signed in | Performance of the service you signed up for; consent given at registration |
| Running the CRM — storing, indexing, searching and displaying your records | Processing on your organisation’s instructions as its processor |
| Sending transactional email — verification, password reset, invitations, notifications, reminders, invoices | Necessary to provide the service; you cannot opt out of these while your account is open |
| Billing, collections, tax invoicing and statutory accounting | Compliance with law and performance of the subscription contract |
| Optional features — mailbox sync, telephony, email tracking, integrations | Consent, given per feature by the user or administrator who enables it |
| Security — abuse prevention, rate limiting, audit logging, incident investigation | Legitimate use; also necessary to protect your data |
| Support you ask us for, including troubleshooting a specific record | Your request |
| Operational metrics — request volumes, error rates, storage and queue depth — to keep the platform sized and healthy | Legitimate use; these are infrastructure measurements, not analysis of what any individual does |
4. What we do not do
Stating the negative is often more useful than listing the positive. Each of the following is a description of how the platform is actually built.
- We do not sell personal data, and we do not rent, trade or otherwise monetise it. There is no arrangement under which any third party pays us for access to it.
- We do not use your data for advertising, and we do not build advertising profiles or audience segments from it.
- We run no third-party analytics or advertising trackers in Salesfresh. There is no Google Analytics, no Tag Manager, no advertising pixel, no session-replay tool and no behavioural analytics SDK anywhere in the application.
- We do not train AI models on your data. Nothing your team writes into the CRM is used to train, fine-tune or evaluate any model, ours or anyone else’s.
- We do not read your CRM records. Access by our staff is restricted, logged and only occurs where you have asked us to look at something or where we must to investigate a security incident.
- We do not send you marketing email you did not ask for, and every optional message we do send carries a working unsubscribe.
5. How the AI features work
Salesfresh includes AI assistance — sentiment analysis on incoming messages, grammar checking, writing suggestions, suggested replies, and extracting structured details out of an email so a lead can be created from it.
The language models behind these features are open-weight models that we host ourselves, on the same infrastructure as the rest of the platform. Your text is not sent to OpenAI, Google, Anthropic, or any other external AI provider — there is no such integration in the product. Nothing is retained by a model after a request is answered, and nothing is used for training.
AI output is a suggestion and can be wrong. It is offered to speed up drafting and triage, not to make decisions. Do not rely on it for anything with legal, financial or contractual consequence without a person checking it first.
7. Where your data is held
The platform runs on infrastructure we own and operate in India. The primary database, the cache, the object storage holding your attachments and the AI service all sit on our own hardware, under our own administration — not on a rented public cloud tenancy.
The processors listed in section 6 are international services and may process the specific data they receive outside India. Where that happens, the transfer is governed by our contract with that processor and is limited to the narrow slice of data described in the table. We do not transfer your CRM records in bulk to any jurisdiction outside India.
8. How we protect it
- All traffic to the platform is encrypted in transit over TLS. Plain HTTP is redirected, not served.
- Passwords are stored only as bcrypt hashes. Reset tokens are single-use and expire within minutes.
- Sessions are signed tokens that are checked against a live server-side session register on every single request. That register is what makes revocation immediate — disabling an account or a role change takes effect at once, rather than whenever the token would have expired.
- Every record carries the identity of the organisation that owns it, and every query is scoped to it. A user cannot reach another organisation’s data.
- Within your organisation, access is governed by roles, module permissions and record-sharing policies that your administrators define. We enforce these on the server, not merely in the interface.
- Record changes are written to an immutable audit log, so unauthorised or mistaken changes can be traced.
- Administrative access to production infrastructure is limited to a small number of personnel and requires key-based authentication over a private network. It is not reachable from the public internet.
- Access tokens for mailboxes and integrations are encrypted at rest with AES-256-GCM under a key held separately from the database, so the stored value is useless to anyone who obtains the data on its own. They are decrypted only in memory at the moment a request to that provider is made, are never returned to your browser or included in any API response, and are revoked at the provider as soon as you disconnect the integration.
No system is immune. If a breach affects your personal data, we will notify you and the Data Protection Board of India as the DPDP Act requires, describing what happened, what data was involved, what we have done and what we recommend you do. We will not delay notification to finish an investigation first.
9. How long we keep it
| Data | Retained for |
|---|---|
| Your CRM records and attachments | As long as your account is open. Deleting a record removes it from the application immediately and it can no longer be reached by anyone in your organisation. It is then permanently erased from our database and file storage 30 days later. |
| Your account and your organisation’s data after account deletion | Access ends immediately for everyone. The data is held for 30 days so the deletion can be reversed if it was a mistake, and is permanently erased after that. |
| Synchronised mailbox content | Until the user disconnects the mailbox or the account is deleted. Disconnecting revokes our token and stops further synchronisation. |
| Call recordings | For the period configured by your organisation, subject to our telephony provider’s own retention |
| Audit logs | For the life of the account — their purpose is accountability, which a short retention would defeat |
| Invoices, credit notes and tax records | Eight years from the end of the relevant financial year, as Indian tax and companies law requires. These survive account deletion because we are not permitted to destroy them. |
| Consent records | For as long as needed to demonstrate that consent was obtained, and to defend a claim about it |
| Server and security logs | Rolling window, typically 90 days |
| Support correspondence | Three years from the close of the conversation |
We keep backups so we can recover the service from a failure, and those backups are held on a rolling 30-day cycle. That means data erased from the live system can persist in a backup for up to a further 30 days before the backup containing it is itself rotated out. Backups are never used to answer a query, restore an individual record, or bring deleted data back into the product — they exist only for disaster recovery. If you need a hard confirmation that every copy is gone, allow 60 days from your deletion request.
Deleting an entire organisation removes access for everyone in it, so the action is restricted to the person who created the account and is confirmed by a one-time code sent to their email. Other users can delete their own profile, which removes them from the organisation; the records they created remain with the organisation, since those belong to it rather than to them.
10. Your rights
As a Data Principal under the DPDP Act, in relation to the data for which we are the Data Fiduciary, you have the following rights.
| Right | How to use it |
|---|---|
| Access — a summary of the personal data we hold about you and how it is processed | Most of it is visible in your profile and settings. For a formal summary, write to us. |
| Correction, completion and updating | Edit your profile directly, or ask us and we will correct it. |
| Erasure | Delete your profile from settings, or ask the account owner to delete the organisation. We will erase what we are not legally required to keep, and tell you what we must retain and why. |
| Withdraw consent | Disconnect any integration, turn off any optional feature, or unsubscribe from optional email. Withdrawal applies going forward and does not undo processing already lawfully carried out. |
| Nominate someone to exercise your rights if you die or become incapacitated | Write to us with the nominee’s details. |
| Grievance redressal | Raise it with our Grievance Officer, in section 14. We will respond substantively, not with an acknowledgement and silence. |
We will respond to a rights request within 30 days. We may ask you to verify your identity first — we would rather ask an extra question than hand your data to someone impersonating you. Exercising a right costs nothing, and we will not treat you differently for exercising one.
If our response does not satisfy you, you may complain to the Data Protection Board of India. Please give us the chance to fix it first; it is usually faster.
12. Children
Salesfresh is a business tool. It is not directed at children, and we do not knowingly collect personal data of anyone under 18. If you believe a child’s data has reached us, tell us and we will delete it. Where your organisation’s CRM records happen to concern a child, the DPDP Act’s additional obligations — verifiable parental consent, and a prohibition on tracking or targeted advertising directed at children — fall on your organisation as the Data Fiduciary.
13. Changes to this policy
We will update this policy when the product changes or the law does. The effective date at the top always reflects the current version. For any change that materially affects how we handle personal data, we will give you notice by email and in the product at least 30 days before it takes effect, so you have time to review it and decide what you want to do. We will not make a material change quietly and rely on you not noticing.
14. Contact and grievance redressal
For any privacy question, rights request or complaint, contact our Grievance Officer. Please include enough detail to identify your account and describe what you are asking for.
- Entity
- IDEASFRESH TECHNOLOGY PRIVATE LIMITED
- CIN
- U72400TN2021PTC146933
- Registered office
- 558, Kollai Mettu Street|Valapandal, Ranipet District|Tamil Nadu, India - 632318
- Privacy matters
- privacy@salesfresh.com
- Grievance Officer
- grievance@salesfresh.com
- Product support
- support@salesfresh.com
- Phone
- +91 8189981738
We acknowledge every privacy request within 72 hours and aim to resolve it within 30 days.