1. Introduction
Pointof-CRM (“Pointof-CRM”, “we”, “us”, or “our”) is a customer relationship management platform operated by Raheem Solutions. This Privacy Policy describes how we collect, use, store, and protect personal information when you use our website, web application, and related services (collectively, the “Services”).
We act as a data controller for information about your account and your use of the Services, and as a data processor for the customer data you and your team store inside Pointof-CRM (such as your contacts, companies, and deals). You remain the owner of that data at all times.
By creating an account or using the Services, you agree to the practices described in this policy.
2. Data we collect
We collect the following categories of information:
- Account information — your name, email address, password (stored securely as a salted hash via our authentication provider), profile details, organization name, and role.
- CRM data you provide — the records you create or import, including contacts, organizations, opportunities, tasks, notes, quotes, orders, invoices, products, and pipelines.
- Email & calendar data — if you connect Gmail or Outlook, we sync email threads, attachments, and calendar events so they can be logged against the relevant contacts and deals. We request only the scopes needed to provide these features.
- Meeting & messaging data — if you connect Zoom or WhatsApp, we process the meeting and message metadata needed to schedule, log, and surface that activity in your CRM.
- Billing information — when you subscribe, payments are processed by Stripe. We receive your plan, billing status, and the last four digits of your card; we do not store full card numbers.
- Usage & device data — log data such as IP address, browser type, pages viewed, and timestamps, used to keep the Services secure and reliable.
3. How we use your data
We use the information we collect to:
- Provide, operate, and maintain the Services.
- Authenticate users and secure accounts.
- Sync your email, calendar, and meeting activity into your CRM.
- Process payments and manage subscriptions.
- Send service-related notifications and respond to support requests.
- Detect, prevent, and address fraud, abuse, and security issues.
- Improve the Services and develop new features.
- Comply with legal obligations.
We do not sell your personal information, and we do not use the content of your CRM records or emails for advertising.
4. AI features
Pointof-CRM includes optional AI-powered features (such as data enrichment, summarization, and column mapping during imports). These features operate on a bring-your-own-key basis: you connect your own API key from a provider such as OpenAI, Anthropic, or Google.
When you use an AI feature, the relevant data is sent to your chosen provider under their terms to generate a response. We do not add a separate AI usage fee, and we do not use your data to train any AI models. If you do not configure an AI key, these features remain off.
6. Data security
We apply industry-standard safeguards to protect your data, including:
- Encryption at rest using AES-256.
- Encryption in transit using TLS.
- Role-based access control (RBAC) so users only see what they're permitted to.
- Audit logs and SSO available on Enterprise plans.
- Strict, least-privilege access controls for our own personnel.
No method of transmission or storage is ever completely secure, but we work continuously to protect your information and to notify affected users promptly in the event of a data breach, as required by law.
7. Data retention
We retain your information for as long as your account is active or as needed to provide the Services. When you delete a record, it is removed from your workspace. When you close your account, we delete or anonymize your personal data within a reasonable period, except where we are required to retain it to comply with legal, tax, or accounting obligations, or to resolve disputes.
You can export your CRM data at any time from the application before closing your account.
8. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your personal data (the “right to be forgotten”).
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
You can manage much of this directly from your account settings. For any other request, contact us at admin@pointofcrm.com and we will respond within the timeframe required by applicable law.
10. International data transfers
Pointof-CRM serves teams across the MENA region, South Asia, and beyond. Your data may be processed in countries other than your own, including by the sub-processors listed above. Where data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses to ensure it remains protected.
11. Children's privacy
The Services are intended for business use and are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you within the application or by email. Your continued use of the Services after changes take effect constitutes acceptance of the revised policy.
13. Contact us
If you have questions about this Privacy Policy or how we handle your data, we'd be glad to help.
See also our Terms of Service.