Crazy CRM
CRAZY CRM
מערכת ניהול קשרי לקוחות

מדיניות פרטיות

עודכן לאחרונה: 25 בספטמבר 2026

Crazy CRM ("המערכת", "אנחנו") היא מערכת לניהול קשרי לקוחות (CRM). מדיניות זו מסבירה אילו נתונים אנו אוספים, כיצד אנו משתמשים בהם, וכיצד אנו מגנים עליהם - לרבות נתונים מ-Google.

עדכון 28 בספטמבר 2026: עוזר ה-AI בוואטסאפ שקרא נתוני יומן ומסמכי Drive הוסר מהמערכת. מהמועד הזה נתונים מיומן Google וממסמכי Drive אינם נשלחים לשום מודל AI. הנתיב היחיד שבו מידע שמקורו ב-Google מגיע למודל הוא ניקוד לידים אופציונלי, כשהלקוח מריץ אותו על ליד שנוצר מטופס Google, וגם הוא חסום ממפתח Gemini שלא אושר כמפתח בתשלום. סירוב נרשם ביומני המערכת.

איזה מידע אנו אוספים

כיצד אנו משתמשים בנתונים מ-Google

אנו מבקשים את ההרשאות הבאות ומשתמשים בכל אחת מהן אך ורק למטרה שלשמה נדרשה:

איננו קוראים, אוספים או משתמשים בנתונים האלה לשום מטרה אחרת. הנתונים אינם נמכרים אינם מושכרים ואינם משמשים לפרסום או לאימון מודלים.

בינה מלאכותית (AI) ונתונים מ-Google

המערכת כוללת עוזר AI ופיצ'רים מבוססי AI כמו ניקוד לידים וניסוח הודעות. אין לנו מודל משלנו ואיננו מריצים מודל מקומי. הפיצ'רים האלה עובדים עם מפתח API של הלקוח עצמו (BYOK) מול אחד משלושה ספקים: Google Gemini API, Anthropic Claude API, OpenAI API. הקריאות יוצאות ישירות לנקודות הקצה של הספק בלי מתווך, gateway או aggregator באמצע.

שיתוף מידע

איננו מוכרים את המידע שלך. אנו משתפים אותו רק עם ספקי תשתית הכרחיים המפעילים את השירות: Google Firebase (אחסון ואימות), ובכפוף להסכמתך - ספקי תקשורת (Twilio/Green API ל-WhatsApp) וסליקה (Morning/PayMe). כל אחד מהם כפוף למדיניות הפרטיות שלו.

שמירה ומחיקת מידע

אנו שומרים את הנתונים שלך כל עוד חשבונך פעיל. ניתן לנתק את חיבור Google Calendar בכל עת מתוך מסך היומן במערכת (כפתור "נתק יומן") - פעולה זו מוחקת מיידית את אסימוני הגישה שלנו.

מחיקת חשבון: בעל החשבון יכול למחוק את החשבון וכל הנתונים בכל עת, באופן עצמאי, דרך הגדרות → עסק → "אזור מסוכן - מחיקת חשבון". המחיקה כוללת את כל נתוני ה-CRM ואת כל חשבונות המשתמשים בצוות, והיא בלתי הפיכה. לחלופין ניתן לפנות אלינו בכתובת המייל למטה ונבצע את המחיקה עבורך.

אבטחה

אסימוני הגישה ל-Google נשמרים בצורה מאובטחת בצד-שרת (Google Cloud), מבודדים לפי משתמש ולפי עסק, ולעולם אינם נחשפים לצד-הלקוח. כל הגישה מוגנת באמצעות Firebase Authentication וכללי הרשאה רב-דייריים. הנתונים מאוחסנים בתשתית Google Cloud / Firebase, עם הצפנה בתעבורה (TLS) ובמנוחה (at-rest), בידוד מלא בין עסקים, ויומני ביקורת (audit log) לפעולות רגישות.

זכויות נושא המידע (GDPR / תיקון 13)

בהתאם לחוק הגנת הפרטיות התשמ"א-1981 ותיקוניו (כולל תיקון 13) ולעקרונות תקנת ה-GDPR, עומדות לכל אדם שמידע עליו מנוהל במערכת הזכויות הבאות, אותן ניתן לממש מול בעל העסק שאיתו הוא בקשר:

בעלי עסקים מבצעים בקשות אלו ישירות מתוך המערכת - בכרטיס הלקוח קיימים כפתורי "ייצוא מידע הלקוח" ו-"מחיקת כל המידע" (תחת אזור "פרטיות (GDPR)"). פעולת המחיקה מתועדת ביומן הביקורת.

Google API Limited Use - הצהרת תאימות

Crazy CRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements. Google user data is never used to create, train, fine-tune or improve any foundational or generalized machine learning or artificial intelligence model, whether ours or a third party's. It is never sold, never used for advertising, and never transferred to any party other than the infrastructure and AI providers strictly required to deliver a feature the user asked for.

AI/ML processing. Crazy CRM has no proprietary model and no self-hosted model. AI features run on the tenant's own API key (BYOK) against one of three providers, called directly with no aggregator, gateway or model hub in between: Google Gemini API (a billing-enabled paid-tier key is required), Anthropic Claude API, and OpenAI API. Under their commercial terms none of the three trains on API inputs or outputs. Voice-note transcription (OpenAI and ElevenLabs) processes WhatsApp audio only and never receives Google user data. The in-app assistant that used to read calendar events and Drive documents was removed from the product on 28 September 2026, so no Google Workspace data reaches any model through it. The one remaining path is optional AI lead scoring, which a user runs on a single lead; when that lead originated in Google Forms the backend withholds it from a Gemini key that has not been attested as paid-tier, and logs the refusal. Gmail access is send-only: no mailbox content is ever read, and therefore none can ever reach a model.

We request the minimum scopes required for the features the user enables: Calendar (calendar.readonly, calendar.events) for two-way calendar sync, gmail.send to send mail the user composes, drive.file for CRM backups the app itself writes, drive.metadata.readonly for file pickers, Google Forms read scopes to turn form responses into CRM leads, and the Google Ads adwords scope for read-only campaign metrics in the dashboard (not Workspace data). Human access to Google user data occurs only with the user's explicit consent, for security purposes, or as required by law.

יצירת קשר

לשאלות בנושא פרטיות או למחיקת נתונים: elchaifinn@gmail.com