Legal
Privacy Policy
Effective date: June 1, 2026
1. Who We Are
Obriym CRM — the CRM and e-commerce management platform available at this domain — is operated by a Ukraine-registered sole proprietor (ФОП), who is the controller of your personal data. Full legal requisites are listed on the Legal details page. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use the Service.
Questions or requests regarding your personal data: crm@obriym.com
2. Information We Collect
Account information
When you register, we collect your name, email address, and password stored as a secure hash. Invited team members provide only what is required to create their account.
Workspace data
Data you enter into your workspace, including leads, contacts, companies, deals, orders, and related records, is your data. We store it to provide the Service and do not use it for advertising or share it with third parties for their own purposes.
Usage and technical data
We collect standard server logs including IP addresses, request paths, timestamps, and response codes. This data is used for security, debugging, and Service reliability. We do not use it to build user profiles.
Email communications
We send transactional emails: account verification, password reset, team invitations, and daily activity digests if enabled. We do not send marketing emails without explicit opt-in.
3. How We Use Your Information
- To provide, operate, and improve the Service
- To authenticate users and enforce role-based access
- To send transactional notifications you have requested
- To investigate abuse, security incidents, and technical issues
- To comply with legal obligations
We do not sell your personal data. We do not use your workspace data for machine learning or advertising.
4. Data Storage and Security
Your data is stored in a Neon Postgres database hosted in the EU/US region. We apply encryption in transit (TLS) and at rest. Access to production data is restricted to authorized personnel.
Workspace data is fully isolated. No cross-workspace data access is possible through the application layer.
Workspace API tokens and widget keys are stored only as one-way SHA-256 hashes — never in plaintext, and never logged. Third-party integration credentials (OAuth and webhook tokens) and two-factor-authentication secrets are stored encrypted at rest so the connections you enable can operate; they are never written to application logs.
5. Data Retention
Your data is retained as long as your workspace exists. When you delete your workspace, data is permanently deleted within 30 days. You may export your workspace data at any time before deletion.
Amazon SP-API is a stricter exception: the integration does not request buyer names, addresses, contact details or messages. Its non-personal order, item, amount, status and listing-link records are automatically deleted after 18 months. A pending OAuth state expires after 10 minutes, and disconnecting the Amazon adapter immediately erases its stored OAuth token and connection settings.
Server logs are retained for 90 days. Audit activity logs within your workspace are retained for 1 year.
6. Your Rights (GDPR / CCPA)
Depending on your location, you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data (right to be forgotten)
- Export your data in a portable format
- Object to or restrict certain processing
To exercise any of these rights, contact us at crm@obriym.com. We will respond within 30 days.
7. Third-Party Services
We use the following third-party services to operate the platform:
- Neon - Postgres database hosting
- Vercel - application hosting and blob storage for uploaded files such as product images and record attachments
- Resend - transactional email delivery
- Google Analytics - website usage analytics — loaded only after you accept the analytics cookie category
- Vercel Analytics - privacy-friendly, cookieless traffic measurement — loaded only after you accept the analytics cookie category
- Sentry - error monitoring; personal data is scrubbed from error reports before they are sent
- Upstash - rate limiting and durable delivery of webhooks and background jobs
- Anthropic - AI assistant features; it does not receive raw customer personal data imported from your integrations
Each service processes only the data necessary for its function and operates under its own privacy policy. A current list of subprocessors is published at /subprocessors. We do not sell your personal data or protected customer data, and we do not share it with advertising brokers.
Separately from these services, you can connect your own accounts on third-party platforms — marketplaces, messengers, delivery carriers, and payment gateways. Those platforms are not Obriym subprocessors: they act as independent data controllers under their own privacy policies, and data only moves along the sync directions you have enabled. The platform categories and data flows are described at /subprocessors.
8. Cookies
We use a required session cookie to keep you signed in. Analytics cookies (Google Analytics and Vercel Analytics) load only after you accept the analytics category in our cookie banner; you can change or withdraw your choice anytime via 'Cookie settings' in the footer. We do not use advertising or cross-site tracking cookies.
9. Children
The Service is not directed at children under 16. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy. We will notify workspace owners by email at least 14 days before material changes take effect. The effective date at the top of this page reflects the latest revision.
11. Contact
Privacy questions or data requests: crm@obriym.com