Privacy Policy
Effective July 23, 2026
IronVail CRM ("IronVail", "we", "us") is operated by Ironvail Holdings LLC. This policy describes what we collect, why, and the choices you have. The short version: your CRM data is yours, we don't sell it, and every workspace is isolated from every other.
What we collect
Account data — your name, email address, and password hash when you create an account.
Workspace data — the accounts, contacts, deals, notes, tasks, and email content you and your team put into your workspace. This data belongs to your workspace and is processed only to provide the service.
Connected services — if you connect a mailbox (e.g. Microsoft 365) we store OAuth tokens, encrypted at rest, and use them solely to send email you compose and to detect replies to that email. If you connect Apollo, we store your API credential encrypted and use it only to import the leads you request. We read mail in a mailbox you connect, and nothing beyond what the feature you enabled requires, and disconnecting removes our access.
Usage data — standard server logs (IP address, browser type, pages requested) used for security and debugging.
Feature counts — for each workspace, each day, which parts of IronVail were used and roughly how many people used them. That is the whole record: no record identifiers, no search terms, no text you typed, and no timing finer than a day. We use it to decide what to build and what to remove, and we delete it after 180 days.
What is stored on your device
So that IronVail keeps working when your phone or laptop loses its connection — or when you navigate away mid-sentence — three things are kept in your browser's local storage on the device you are signed in on:
Notes you write offline — anything you log without a connection is saved on the device and uploaded when you reconnect. It stays there until it uploads, so that losing signal never loses your work. Signing out does not delete it, because it is your unsaved work; you are told how much is waiting and can choose to sign out anyway.
Unsaved drafts — while you are typing a note, a message or a post, a copy is kept on the device so that closing the tab or moving to another page does not lose it. It is offered back the next time you open the same field, is never uploaded on your behalf, and is deleted as soon as you save. Anything still unsaved is removed after seven days. Signing out does not delete it, for the same reason as above — it is your unsaved work, and you are told how much is waiting.
A copy of your account, contact and opportunity names — names and identifiers only, so you can file a note against the right record with no connection. This is deleted when you sign out.
Both live in ordinary browser storage, which is not encrypted beyond whatever encryption the device itself uses. If you are working on a shared or borrowed device, sign out when you are finished.
How we use it
To provide and improve the service, to send transactional email (invites, password resets, billing receipts), and to keep the platform secure. We do not sell personal data, and we do not use your workspace data to train models or for advertising.
Email you send through IronVail
You are the sender of campaigns and sequences you create. Every bulk email includes an unsubscribe link; suppression lists are enforced automatically. You are responsible for having a lawful basis to contact your recipients.
Sub-processors
We use Supabase (database and authentication), Vercel (hosting), Stripe (payments — we never see full card numbers), Resend (email delivery), and Sentry (error diagnostics). Each processes data only as needed to provide their service to us.
Sentry receives error reports so we can fix faults, and we deliberately limit what reaches it: no session recording, no request bodies, no cookies, and no URL query strings — so a search you type is not transmitted. Error messages are filtered for credentials and email addresses before they leave our servers. Workspace and user identifiers are included so we can tell whether a fault affects one customer or everyone.
Security & retention
Workspaces are isolated with database-level row security. Credentials and tokens are encrypted at rest. Data is retained for as long as your workspace exists; when you delete your account or workspace, associated data is deleted within 30 days, excepting records we must keep for legal or billing reasons.
Your rights
You can access, correct, export, or delete your personal data. Contact us at support@ironvailcrm.com and we'll respond within 30 days. EU/UK residents may also lodge a complaint with their supervisory authority.
Contact
Ironvail Holdings LLC
418 Broadway #10114, Albany, NY 12207
support@ironvailcrm.com — privacy and legal
security@ironvailcrm.com — security reports
We'll post any material changes to this policy here and update the effective date above.