MadagascarCRM← Back to home

Privacy Policy

Last updated June 27, 2026

This policy explains what information MadagascarCRM collects, how we use it, and the choices you have. It applies to our marketing site and the MadagascarCRM application (the “Service”).

MadagascarCRM (“we,” “us”) provides customer-relationship software for moving companies. We act as a data processor for the lead and customer information our business customers (“Companies”) store in the Service, and as a data controller for the account information of the people who sign in and use it. If you are an end customer of a moving company that uses MadagascarCRM, please direct privacy requests to that company.

Information we collect

Information you provide

  • Account data — your name, work email, password, company name, and role when you create an account.
  • Company & CRM data — leads, contacts, estimates, jobs, invoices, messages, and notes that you or your team enter or import.
  • Billing data — handled by our payment processor; we store a plan and a billing reference, never full card numbers.
  • Support data — messages you send us and their contents.

Information collected automatically

  • Usage & device data — log data, IP address, browser type, and pages viewed, used to operate and secure the Service.
  • Communications metadata — when calls or texts are made through the Service, we process the phone numbers, timestamps, and message contents needed to deliver and log them.

How we use information

  • Provide, maintain, and improve the Service.
  • Authenticate users and secure accounts.
  • Process payments and manage subscriptions.
  • Send calls, texts, and emails that you initiate through the Service.
  • Provide support and respond to your requests.
  • Detect, prevent, and address fraud, abuse, and security issues.
  • Comply with legal obligations.

We do not sell personal information, and we do not use your customers’ contact data to advertise to them.

Service providers (sub-processors)

We share data with vetted providers only as needed to run the Service. These currently include:

  • Supabase — database, authentication, and file storage.
  • Twilio — voice calling and SMS.
  • Stripe — payment processing.
  • Resend — transactional email.
  • Google — for Companies that connect Gmail or Google Calendar.
  • Vercel & Render — application hosting.

Each provider is bound by contract to protect the data and use it only to provide their service to us.

Google user data & Limited Use

If you choose to connect a Google account, MadagascarCRM requests only the narrowest Gmail permission needed to provide the feature you asked for, and we tell you what it is on the Google consent screen before you approve it.

  • Sending email on your behalf — used solely to send documents you explicitly choose to send (such as a quote) from your own email address, so your customer receives it from you and can reply directly to you. We send only when you take an action in the app that sends it.

We do not sell Google user data, use it for advertising, or transfer it to third parties except as needed to provide this feature, comply with law, or as part of a merger or acquisition. We do not use Google user data to train generalized AI or machine-learning models. Humans do not read your Google data except where you explicitly request support, where it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or where the data is aggregated and anonymized.

MadagascarCRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect your Google account at any time from Settings → Integrations, which revokes our access. You may also revoke access directly at myaccount.google.com/permissions.

Data retention

We retain Company and CRM data for as long as the account is active. When an account is closed, we delete or anonymize data within 90 days, except where we must retain it to comply with legal, tax, or accounting requirements.

Security

We encrypt data in transit and at rest, isolate each Company’s data with tenant scoping and row-level security, and restrict internal access on a need-to-know basis. See our Security overview for details. No method of transmission or storage is 100% secure, but we work hard to protect your information.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@mdgcrm.com. End customers of a moving company should contact that company, which controls the data.

Cookies

We use strictly necessary cookies to keep you signed in and to operate the Service. We do not use third-party advertising cookies.

International transfers

We are based in the United States and process data there. If you access the Service from outside the U.S., you consent to processing in the U.S. under this policy.

Children

The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.

Changes

We may update this policy from time to time. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, notify you in the app or by email.

Contact

Questions about this policy? Email privacy@mdgcrm.com.


This document is provided for transparency and does not constitute legal advice. We recommend having counsel review it for your jurisdiction before relying on it.