Privacy Policy
This policy explains how NavCRM handles information when you use the NavCRM web and mobile applications.
Effective and last updated: 13 July 2026
Who we are
NavCRM is a multi-tenant customer relationship management service operated from India. In this policy, “NavCRM”, “we”, “us”, and “our” refer to the provider identified as NavCRM in the application and store listing. Questions or privacy requests can be sent to privacy@navcrm.in.
The organization that invited you to a NavCRM workspace may control the business records in that workspace. In that situation, you may also need to contact your organization for requests concerning those records.
Information we collect
- Account and profile data, such as name, work email address, phone number, role, tenant or company, team, department, and account identifiers.
- Authentication and security data, such as password-derived credentials, access and refresh tokens, activation or password-reset activity, permissions, and security or audit events.
- CRM and support content entered by users, including leads, opportunities, clients, tasks, meetings, notes, tickets, comments, estimates, visits, configuration, and operational logs.
- Files and media you choose to upload, such as documents, spreadsheets, images, camera captures, and support proof files.
- Precise or approximate location when you actively use a feature that requires it, such as meeting attendance or support visit check-in and check-out, or when you choose to add a precise map pin to a new sign-in security email. NavCRM requests device or browser permission before accessing location.
- App activity and diagnostics, including feature actions, error and crash information, timestamps, role or workspace context, app version, operating system, device model, network/API diagnostics, and performance information.
- Device and notification information, including a push-notification token and technical identifiers needed to deliver notifications and operate the service.
How we use information
- Provide, authenticate, secure, and support NavCRM.
- Display and synchronize workspace records across authorized users.
- Deliver notifications and user-requested files or exports.
- Process location-based attendance and visit workflows and optional sign-in security map pins.
- Diagnose crashes, prevent abuse, maintain audit trails, and improve reliability.
- Comply with legal obligations and enforce applicable agreements.
How information is shared
Workspace data is shared with users who are authorized by the same tenant, client, or operator context. Role and permission controls determine what each user can access.
We use service providers to host and operate NavCRM. These may include cloud hosting and storage providers and Google Firebase services for push notifications and crash reporting. Providers process information only to deliver their contracted services, subject to their own terms and our arrangements with them. We may also disclose information when required by law, to protect users or the service, or as part of a corporate transaction with appropriate safeguards.
NavCRM does not sell personal information or use it for third-party advertising.
Permissions and user choices
The Android and iOS apps may request notification and location permissions, and the web app may request browser location permission. Camera or document-picker access is initiated only when you choose to capture or upload a file. You can change Android permissions in device settings, although the related feature may stop working. You can control mobile display preferences. Development builds also expose a local diagnostic viewer; release builds report diagnostics in the background without showing raw developer logs in Settings.
Security and international processing
Production traffic is encrypted in transit using HTTPS. Mobile session credentials are stored using operating-system protected secure storage. We use access controls, tenant separation, logging, and operational safeguards designed to protect information. No method of storage or transmission is completely secure. Information may be processed where NavCRM and its service providers operate, subject to applicable legal safeguards.
Retention and deletion
We retain account and workspace information while it is needed to provide NavCRM, meet the customer organization’s instructions, maintain security and audit records, resolve disputes, or satisfy legal obligations. Retention periods can vary by data type and tenant requirements. Data that must be retained for security, fraud prevention, legal, or regulatory reasons may be isolated and retained for the required period.
To request deletion of your account and associated personal data, follow the steps on the NavCRM account deletion page. We will verify the request and explain any data that must be retained or is controlled by your organization.
Children
NavCRM is a business service and is not directed to children. Users must be authorized by their organization and legally able to use the service in their jurisdiction.
Changes to this policy
We may update this policy as NavCRM or applicable requirements change. We will post the revised policy here and update its effective date. If a change materially affects your rights, we will provide additional notice where required.