Legal Documentation
Privacy Policy for OVERTON CRM SOLUTIONS LLP
Effective Date: August 5, 2026 • Last Updated: August 5, 2026
1. How Accounts Work
Understanding our account model is important to understanding this policy.
- Organization registration is web-only.A builder or business (“Organization”) registers for OVERTON CRM SOLUTIONS LLP through our web portal. Registration is not offered in the mobile application.
- Employee accounts are provisioned, not self-created. Accounts for employees are created and assigned roles exclusively by the Organization's Admin or Director through the web portal.
- The mobile application is login-only. It does not offer account registration by any method, including Google Sign-In or Apple Sign-In. Signing in with Google or Apple using an email address that has not been provisioned by an Organization will return an error and will not create an account.
2. Controller and Processor Roles
- Your Organization is the data controller for its workspace. This includes all employee account records and all lead, customer, and prospect records stored in that workspace.
- OVERTON CRM SOLUTIONS LLP is the data processor. We process that data on the Organization's instructions in order to provide the Services.
- Lead and customer records (names, email addresses, phone numbers, form responses and related notes) are supplied to us by the Organization or its integrations. We do not independently collect this data, and we do not use it for any purpose other than delivering the Services to that Organization.
- If you are a lead or customer whose details appear in an OVERTON CRM SOLUTIONS LLP workspace and you wish to exercise your rights over that data, please contact the Organization that holds the record. If you do not know which Organization that is, contact us at support@overton.in and we will assist in routing your request.
3. Information We Collect
We collect the following types of information:
A. Information You or Your Organization Provide
- Profile Information: Name, email address, phone number, and profile image.
- Organization & Role Info: Your association with a company (
company_id), your assigned role (Director, Admin, Member), and your reporting relationships. - Business Registration Details (web portal only, at Organization sign-up): business name, business type, state, and city.
- User-Uploaded Content: Documents and images you attach to leads, projects, builders, and other CRM records through the app or web portal. You are responsible for ensuring you have the right to upload any content containing another person's information.
- Billing & Subscription Information (web portal only, Admin/Director only): billing contact name, billing email, billing address, GSTIN where provided, and a record of your Organization's plan, trial status, and invoices. Card and bank details are entered directly into our payment processor's interface — we never receive or store full card numbers. The mobile application collects no billing information and contains no purchase functionality.
B. Information Collected Automatically
- Device & Auth Session Data: When you log in, we collect details about the device you are using, including:
- Unique Device ID (UUID-v4, generated once per install, or the platform vendor identifier on iOS)
- Device Name (for example, “iPhone 15 Pro”)
- Device Type (for example, “mobile”, “desktop”)
- Operating System and OS Version (for example, “iOS 17.4.1”)
- App Version and client metadata
- Notification Tokens: Firebase Cloud Messaging (FCM) tokens, used to deliver push notifications and alerts according to your notification preferences.
- Crash and Diagnostic Data: We use Firebase Crashlytics to collect crash reports, stack traces, exception messages, device model, operating system version, and app version when the application encounters an error. This data is used solely to diagnose and fix stability problems. It is not used for advertising or profiling.
C. Information We Do Not Collect
- We do not collect biometric data.The mobile application can use your device's Face ID, Touch ID, or fingerprint unlock as a convenience for unlocking the app. This check is performed entirely by your device's operating system. Your biometric data never leaves your device, is never transmitted to us, and is never stored on our servers.
- We do not collect precise or background location data.
- We do not use advertising identifiers, advertising SDKs, or cross-app tracking. The mobile application contains no analytics or advertising SDKs other than the crash reporting described above.
- We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
4. Third-Party Integrations
A. Google Sign-In
- Scopes requested:
profile(name, picture, identity metadata) andemail(primary account email). - Purpose: To verify your identity and enable secure sign-in to an existing OVERTON CRM SOLUTIONS LLP account, and to display your name and avatar in the CRM interface.
- Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
B. Apple Sign-In
- Scopes requested:
name(first and last name) andemail(primary Apple account email). - Purpose: To verify your identity and enable secure sign-in to an existing OVERTON CRM SOLUTIONS LLP account.
- If you choose Apple's Hide My Email option, we receive and store only the private relay address Apple generates. We accept relay addresses, we do not attempt to resolve them to your real address, and we do not require you to disclose it.
C. Facebook (Meta) Lead Ads Integration — Web Portal Only
This integration is configured and used through the OVERTON CRM SOLUTIONS LLP web portal. It is not available in the mobile application.
- Permissions requested:
pages_show_list,pages_manage_metadata,pages_read_engagement,leads_retrieval,ads_read. - What we store: The Facebook (Meta) Page ID and the Page Access Token, held encrypted at rest in our database. These credentials are required to maintain a subscription to Meta lead generation webhooks.
- Purpose: To receive webhook notifications when a customer submits a lead form on Facebook (Meta), parse the submitted lead data (name, email, phone, form answers) and save it into your Organization's lead list.
- Disconnection: An Organization can disconnect any linked Page at any time from the CRM settings panel. Disconnecting sends an API request to Meta unsubscribing our servers from that Page's webhooks and permanently erases the Page ID and Page Access Token from our databases.
5. How We Use Your Information
- Service Delivery: To manage lead workflows, inventories, follow-ups, site visits, and calendar schedules.
- Authentication and Session Security: To sign you in, and to use device UUIDs and OS/app versions to monitor active sessions and detect unauthorized access.
- System Communication: To send push notifications such as site visit reminders and follow-up reminders, in accordance with the Notification Preferences you configure in the app.
- Stability and Support: To diagnose crashes and respond to support requests.
- Lead Synchronization: To parse and import leads submitted through an Organization's connected Facebook (Meta) forms into its CRM.
We do not use your personal information for automated decision-making that produces legal or similarly significant effects.
6. How We Share Your Information
We do not sell personal data. We share it only with the following categories of recipient, and only to the extent needed to run the Services.
| Recipient | Data Shared | Purpose |
|---|---|---|
| Google LLC — Firebase Cloud Messaging | Device push token, device metadata | Delivering push notifications |
| Google LLC — Firebase Crashlytics | Crash reports, device model, OS and app version | Diagnosing application crashes |
| Google LLC — Google Sign-In | Authentication request, email | Verifying identity at sign-in |
| Apple Inc. — Sign in with Apple | Authentication request, email | Verifying identity at sign-in |
| Meta Platforms, Inc. | Page ID, Page Access Token, webhook subscription | Retrieving Lead Ads submissions (web portal only) |
| Your Organization | Your profile, activity, and assigned records | Workspace administration by your Admin or Director |
| Payment processor | Billing contact details, transaction amount, card data entered directly by you | Processing subscription payments (web portal only) |
| Hostinger (Hosting and infrastructure provider) | Data at rest and in transit | Operating the Services |
We may also disclose information where required by law, court order, or a valid request from a public authority, or where necessary to establish, exercise, or defend legal claims.
7. Data Storage, Security & Location
- Company Partitioning: All records (leads, settings, custom options) are isolated at the Organization level. Your data is not visible or accessible to users of another Organization.
- Encryption in transit: All communication between the applications and our servers uses TLS/HTTPS.
- Encryption at rest: OAuth tokens and integration credentials (Meta Page Access Tokens, SMTP credentials, SMS configuration) are encrypted at rest. Passwords are stored as salted hashes and are never recoverable in plain text.
- On-device storage: On mobile, authentication tokens are stored in the platform secure store — the iOS Keychain or the Android Keystore — and not in plain application storage.
- Data location: Our servers and databases are hosted in India.
8. Data Retention
- Active accounts: We retain your profile and activity data for as long as your account remains active within an Organization's workspace.
- After account anonymization: Personal identifiers (name, email, phone, profile image) are permanently anonymized. Business records that must remain with the Organization — such as leads, follow-ups, and site visits reassigned to other team members — are retained by the Organization as its own records.
- Crash and diagnostic data: Retained by Firebase Crashlytics for up to 90 days.
- Session and device records: Retained for up to 12 months from last activity, for security auditing.
- Billing records: Invoices and transaction records are retained for 8 years as required by Indian tax and companies law, and are not deleted on account or workspace deletion.
- Backups: Deleted data may persist in encrypted backups for up to 30 days after deletion, after which it is overwritten.
- After Organization deletion: All Organization records and associated databases are erased within 90 days of a verified request.
9. Your Rights
Subject to applicable law, including the Digital Personal Data Protection Act, 2023 (India) and, where applicable, the GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data. You can edit your profile name and image directly in the app at any time.
- Erasure of your personal data, as described in Section 10.
- Withdraw consent, including disabling specific alerts from the Notification Preferences panel, or revoking notification permission in your device settings.
- Portability— request a machine-readable copy of your personal data.
- Grievance redressal— raise a complaint with our Grievance Officer (Section 12).
Because your Organization is the controller of its workspace, requests concerning workspace or lead data are routed to that Organization. Requests concerning your own personal identifiers are honoured as set out below.
10. Data Deletion
A. Employee / Member Accounts (mobile and web)
- Open the OVERTON CRM SOLUTIONS LLP app and go to Profile.
- Tap Delete Account.
- Select a reason for deletion and tap Submit.
- Your request is sent to your Organization's Admin or Director, who actions it from the web portal.
- On approval, all active login sessions and authentication tokens are immediately revoked, your account is deactivated and flagged as deleted, and your personal identifiers (name, email, phone, profile image) are permanently anonymized.
Reassignment.If you currently own active leads or have employees reporting to you, those records and reporting relationships are reassigned to your Organization's Admin before anonymization completes. This reassignment does not prevent the deletion of your personal data.
B. Organization Owner / Admin Accounts (web portal)
- Sign in to the OVERTON CRM SOLUTIONS LLP web portal.
- Open the profile menu at the top right.
- Select Delete Account, choose a reason, and submit.
Before an Admin account is deleted, the system verifies that at least one other active Admin remains in the Organization, so the workspace does not become unadministrable.
C. Full Organization / Workspace Deletion
Deletion of an entire Organization workspace, including all corporate records, settings, and databases, cannot be self-served. The Organization's authorized representative must email support@overton.in. Following identity verification, we will erase all Organization account records and associated databases within 90 days.
D. Facebook (Meta) Data — Removal and Deletion
Self-service, from OVERTON CRM SOLUTIONS LLP: disconnect the linked Page from the CRM settings panel in the web portal. This unsubscribes our webhook via the Meta API and permanently erases the stored Page ID and Page Access Token.
Self-service, from Facebook (Meta):
- Go to Settings & Privacy → Settings in your Facebook (Meta) account.
- Select Apps and Websites in the left menu.
- Locate OVERTON CRM SOLUTIONS LLP and click Remove.
- Confirm removal, then click Remove again.
Deleting specific synced leads: email support@overton.in with your company name, the connected Page, and the leads or date range to erase. We will process and confirm within 3 business days.
The dedicated data deletion instructions page for the Meta App Dashboard is available at https://overton.in/data-deletion.
11. Children's Privacy
OVERTON CRM SOLUTIONS LLP is a business-to-business product intended solely for use by employees and representatives of registered organizations. It is not directed to, and we do not knowingly collect personal data from, anyone under the age of 18. If you believe a minor has provided us with personal data, contact us and we will delete it.
12. Contact & Grievance Officer
For any question about this Privacy Policy, or to exercise any right described above:
Statutory Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) Rules:
Name: Bhargav K
Designation: Grievance Officer
Email: info@overton.in
Address: BLOCK NO F-25/FLAT NO 346, UTSAV APPTS., B/H VYASWADI, Vadaj, vadaj, Ahmadabad City, Ahmedabad- 380013, Gujarat, India
We acknowledge grievances within 24 hours and aim to resolve them within 15 days of receipt.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top of this page. If the changes are material — for example, a new category of data collected or a new third party receiving your data — we will notify you in the app, by email, or both, before the change takes effect. Continued use of the Services after the effective date constitutes acceptance of the revised policy.