Crazy CRM ("המערכת", "אנחנו") היא מערכת לניהול קשרי לקוחות (CRM). מדיניות זו מסבירה אילו נתונים אנו אוספים, כיצד אנו משתמשים בהם, וכיצד אנו מגנים עליהם - לרבות נתונים מ-Google.
אנו מבקשים את ההרשאות הבאות ומשתמשים בכל אחת מהן אך ורק למטרה שלשמה נדרשה:
calendar.readonly - לקרוא את רשימת היומנים והאירועים שלך כדי להציג אותם בלוח השנה של המערכת ולבדוק זמינות לפני קביעת פגישה.calendar.events - ליצור, לעדכן ולמחוק אירועים שאתה מנהל דרך המערכת ולשמור סנכרון דו-כיווני.gmail.send - לשלוח הודעות מהמערכת מכתובת האימייל שלך. זו הרשאת שליחה בלבד. אין למערכת הרשאת קריאה לתיבת הדואר שלך והיא אינה קוראת ממנה דבר.drive.file - לכתוב גיבוי של נתוני ה-CRM שלך לדרייב שלך. ההרשאה מוגבלת לקבצים שהמערכת עצמה יצרה ואינה נותנת גישה לשאר הקבצים בדרייב.drive.metadata.readonly - להציג רשימת קבצים לבחירה בעת חיבור טופס או תיקייה. שמות קבצים בלבד ולא תוכן.forms.body.readonly ו-forms.responses.readonly - לקרוא את שאלות הטופס שחיברת ואת התשובות שנשלחו אליו כדי ליצור מהן לידים בתוך ה-CRM.adwords - לקרוא נתוני ביצועים של הקמפיינים שלך ב-Google Ads כדי להציג אותם בדשבורד של המערכת. קריאה בלבד. אלה אינם נתוני Workspace.איננו קוראים, אוספים או משתמשים בנתונים האלה לשום מטרה אחרת. הנתונים אינם נמכרים אינם מושכרים ואינם משמשים לפרסום או לאימון מודלים.
המערכת כוללת עוזר AI ופיצ'רים מבוססי AI כמו ניקוד לידים וניסוח הודעות. אין לנו מודל משלנו ואיננו מריצים מודל מקומי. הפיצ'רים האלה עובדים עם מפתח API של הלקוח עצמו (BYOK) מול אחד משלושה ספקים: Google Gemini API, Anthropic Claude API, OpenAI API. הקריאות יוצאות ישירות לנקודות הקצה של הספק בלי מתווך, gateway או aggregator באמצע.
איננו מוכרים את המידע שלך. אנו משתפים אותו רק עם ספקי תשתית הכרחיים המפעילים את השירות: Google Firebase (אחסון ואימות), ובכפוף להסכמתך - ספקי תקשורת (Twilio/Green API ל-WhatsApp) וסליקה (Morning/PayMe). כל אחד מהם כפוף למדיניות הפרטיות שלו.
אנו שומרים את הנתונים שלך כל עוד חשבונך פעיל. ניתן לנתק את חיבור Google Calendar בכל עת מתוך מסך היומן במערכת (כפתור "נתק יומן") - פעולה זו מוחקת מיידית את אסימוני הגישה שלנו.
מחיקת חשבון: בעל החשבון יכול למחוק את החשבון וכל הנתונים בכל עת, באופן עצמאי, דרך הגדרות → עסק → "אזור מסוכן - מחיקת חשבון". המחיקה כוללת את כל נתוני ה-CRM ואת כל חשבונות המשתמשים בצוות, והיא בלתי הפיכה. לחלופין ניתן לפנות אלינו בכתובת המייל למטה ונבצע את המחיקה עבורך.
אסימוני הגישה ל-Google נשמרים בצורה מאובטחת בצד-שרת (Google Cloud), מבודדים לפי משתמש ולפי עסק, ולעולם אינם נחשפים לצד-הלקוח. כל הגישה מוגנת באמצעות Firebase Authentication וכללי הרשאה רב-דייריים. הנתונים מאוחסנים בתשתית Google Cloud / Firebase, עם הצפנה בתעבורה (TLS) ובמנוחה (at-rest), בידוד מלא בין עסקים, ויומני ביקורת (audit log) לפעולות רגישות.
בהתאם לחוק הגנת הפרטיות התשמ"א-1981 ותיקוניו (כולל תיקון 13) ולעקרונות תקנת ה-GDPR, עומדות לכל אדם שמידע עליו מנוהל במערכת הזכויות הבאות, אותן ניתן לממש מול בעל העסק שאיתו הוא בקשר:
בעלי עסקים מבצעים בקשות אלו ישירות מתוך המערכת - בכרטיס הלקוח קיימים כפתורי "ייצוא מידע הלקוח" ו-"מחיקת כל המידע" (תחת אזור "פרטיות (GDPR)"). פעולת המחיקה מתועדת ביומן הביקורת.
Crazy CRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements. Google user data is never used to create, train, fine-tune or improve any foundational or generalized machine learning or artificial intelligence model, whether ours or a third party's. It is never sold, never used for advertising, and never transferred to any party other than the infrastructure and AI providers strictly required to deliver a feature the user asked for.
AI/ML processing. Crazy CRM has no proprietary model and no self-hosted model. AI features run on the tenant's own API key (BYOK) against one of three providers, called directly with no aggregator, gateway or model hub in between: Google Gemini API (a billing-enabled paid-tier key is required), Anthropic Claude API, and OpenAI API. Under their commercial terms none of the three trains on API inputs or outputs. Voice-note transcription (OpenAI and ElevenLabs) processes WhatsApp audio only and never receives Google user data. The in-app assistant that used to read calendar events and Drive documents was removed from the product on 28 September 2026, so no Google Workspace data reaches any model through it. The one remaining path is optional AI lead scoring, which a user runs on a single lead; when that lead originated in Google Forms the backend withholds it from a Gemini key that has not been attested as paid-tier, and logs the refusal. Gmail access is send-only: no mailbox content is ever read, and therefore none can ever reach a model.
We request the minimum scopes required for the features the user enables: Calendar
(calendar.readonly, calendar.events) for two-way calendar sync,
gmail.send to send mail the user composes, drive.file for CRM
backups the app itself writes, drive.metadata.readonly for file pickers,
Google Forms read scopes to turn form responses into CRM leads, and the Google Ads
adwords scope for read-only campaign metrics in the dashboard (not Workspace
data). Human access to Google user data occurs only with the user's explicit consent, for
security purposes, or as required by law.
לשאלות בנושא פרטיות או למחיקת נתונים: elchaifinn@gmail.com