Privacy policy

This policy explains what we collect, why we process it, and the choices available to you and your organization.

Last updated: September 17, 2026

Introduction

This Privacy Policy describes how CRAIM ("we", "us") collects, uses, and shares information when you use our websites, applications, and related services (the "Services").

By using the Services, you agree to this policy. If you do not agree, do not use the Services.

Information we collect

Account and profile data: name, work email, company name, role, and authentication identifiers you provide when you register or are invited to a workspace.

Service data: deals, contacts, messages, files, and configuration you upload or generate while using CRAIM, including content processed to provide CRM and AI features.

Technical data: device and browser type, IP address, approximate location derived from IP, timestamps, and diagnostic logs needed to operate and secure the Services.

Communications: messages you send to support, sales, or security teams, including metadata needed to respond.

Payment data: when you purchase paid plans, our payment processor handles card details; we receive limited billing status and receipt information.

Cookies and analytics

Our own cookies: craim_consent remembers your answer to the cookie banner for 180 days; craim_attr records which campaign, search, or link brought you to our marketing site, keeping the first and the last visit for 90 days so that we can tell which advertising actually works.

Measurement providers: Google Analytics 4 and Yandex Metrica measure traffic and behaviour on our public marketing site. They are not loaded inside the signed-in application, where your workspace data lives. What you type into the knowledge base search box is sent to them as a search term, so that we can see which documentation is missing; the contents of other fields are not.

Session recording: Yandex Metrica records interactions with marketing pages, such as mouse movement, clicks, and scrolling, so that we can see where a page confuses people. What you type into the sign-up, sign-in, and password reset fields is replaced with asterisks in your browser before anything is sent, and password fields are never recorded at all.

Consent: nothing beyond strictly necessary cookies runs until you accept it. Google's tags start with advertising and analytics storage denied; Yandex Metrica and any advertising pixel are not loaded until you accept.

You can withdraw consent at any time by deleting the craim_consent cookie, and you can block or delete cookies in your browser settings.

How we use information

Provide and improve the Services, including AI features that summarize threads, suggest next steps, and draft messages according to your workspace settings.

Operate security monitoring, abuse prevention, and fraud detection.

Send transactional notices, product updates (where permitted), and respond to requests.

Meet legal obligations and enforce our Terms.

Analyze aggregated or de-identified usage to understand feature adoption; we do not sell personal data as traditionally defined in U.S. state privacy laws.

AI processing

Certain features send prompts and relevant context to third-party AI model providers that process them on our behalf. We configure retention and logging consistent with your plan and agreements.

You control what data is indexed for retrieval-style features and which actions require human approval before customer-facing delivery.

CRAIM app for Shopify

This section applies when a merchant installs the CRAIM app from the Shopify App Store and connects a store to a CRAIM workspace. The merchant decides how their customers' data is used; CRAIM processes it on the merchant's behalf to provide the app.

What we access: the app has read-only access to orders and reads them only when a customer asks about an order in a channel the merchant connected, such as Gmail, WhatsApp or Telegram. For the matching orders it reads the order number and dates, the email address and phone number on the order, payment and fulfillment status, cancellation and refunds, the order total, item names, quantities and SKUs, shipment status with carrier and tracking number, the order status page link, and the shipping address lines without the recipient's name. We also store the store's domain and an encrypted access token. The app cannot change orders, issue refunds or charge customers.

How we use it: only to answer that customer's question. We confirm that the person asking owns the order, by matching the email address or WhatsApp number they write from with the one on the order or by sending a one-time code to the email address on the order; prepare a reply with the order's status; and show the merchant the question and the reply in the Shopify admin. We do not sell this data or use it for advertising.

AI processing: to prepare a reply, the customer's question and the relevant order details are sent to third-party AI model providers that process them on our behalf. They may process data outside the customer's country, including outside the European Economic Area.

Retention: order details the app reads are kept in the record of the AI run that answered the question, and the text and order details in those records are removed after a limited retention period. Verification codes expire after 10 minutes. Messages customers send in the merchant's channels remain part of the merchant's conversation history in CRAIM until the merchant deletes them or closes the workspace.

Privacy requests: we act on Shopify's privacy webhooks. When Shopify asks us to erase a customer's data, we remove the order details about that customer from AI run records. When a store uninstalls the app, Shopify asks us 48 hours later to erase the store's data, and we remove its order details from AI run records and delete the store connection. Requests for a copy of a customer's data are recorded so we can provide it to the merchant.

Merchants and their customers can reach us at support@craim.ltd.

Sharing

Service providers who host infrastructure, deliver email, process payments, or support analytics, bound by confidentiality and processing terms.

Professional advisers when required for audits, legal compliance, or corporate transactions.

Authorities when required by law or to protect the rights, safety, and security of users and the public.

With your direction, such as integrations you enable between CRAIM and third-party systems you control.

Retention

We retain account and service data for as long as your workspace is active and for a reasonable period afterward to recover from accidental deletion, resolve disputes, and meet legal duties.

Backup copies may persist for a limited period consistent with our disaster recovery program.

You may request deletion subject to exceptions (for example, legal holds or unresolved bills) described in your agreement.

Security

We implement administrative, technical, and organizational measures designed to protect data, including encryption in transit, access controls, and least-privilege engineering practices.

No method of transmission or storage is completely secure; we encourage strong passwords, SSO where available, and prompt reporting of suspected incidents.

Your rights and choices

Depending on your location, you may have rights to access, correct, delete, or export personal data, and to object to or restrict certain processing.

Workspace administrators may exercise many controls on behalf of their organization. Individuals can contact us to exercise rights that apply to their personal data.

Marketing emails include an unsubscribe mechanism where required; transactional and security notices may continue.

International transfers

If we transfer personal data across borders, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms required by applicable law.

Children

The Services are not directed to children under 16. We do not knowingly collect personal data from children. Contact us if you believe we have collected such data.

Changes

We may update this policy from time to time. We will post the new version with an updated date and, where changes are material, provide additional notice as required by law.

Contact

Questions about this Privacy Policy or our privacy practices: contact CRAIM support.

You can also email support@craim.ltd.

Enterprise customers may require a data processing addendum, subprocessors list, or regional terms. Contact CRAIM support through Telegram so we route your request correctly.

Contact support

support@craim.ltd