Privacy Policy
Bolt CRM ("we") is committed to protecting the privacy of our users and of their own customers. This policy explains what data we collect, how we use it, and what your rights are.
1. Data we collect
- Account: name, email and phone number of the user who creates the account.
- Operational: data of imported contacts (name, phone, email, messages exchanged through WhatsApp/Instagram), deals, activities and reports generated by normal use of the CRM.
- Technical: IP address, user agent and access logs, for security and auditing.
- Integrations: OAuth tokens (Google Calendar, Meta) stored encrypted.
2. How we use it
- To operate the service (deliver messages, generate reports, sync calendars).
- Technical support and product improvement.
- Account communication (billing, updates).
- Marketing only with your explicit consent.
3. How we protect it
- In transit: HTTPS/TLS 1.3 on every endpoint.
- At rest: Supabase Postgres with encryption at rest (AES-256).
- Multi-tenant: Row-Level Security (RLS) isolates data per workspace.
- Passwords: never stored in plain text — we use one-way bcrypt hashing.
4. Sharing
We do not sell data. We share with sub-processors only what is strictly necessary to operate the service:
- Supabase (database and authentication) — United States
- Amazon Web Services (Supabase infrastructure) — United States
- Vultr / The Constant Company (application servers) — Brazil
- Cloudflare (CDN and protection) — Brazil and United States
- Anthropic (AI-suggested replies, when you trigger them) — United States
- Resend (system email delivery) — United States
- Meta/Google (integrations you explicitly authorize)
- Evolution API (WhatsApp)
4.1. Requests from public authorities
If we receive a request for data from a public authority, law enforcement or a court, we always apply these four steps:
- We review legitimacy. Every request is reviewed before anything is handed over. We verify that it comes from a competent authority, that it is properly grounded, and that a legal basis exists.
- We challenge unlawful requests. If a request is overbroad, lacks legal basis, or exceeds the requester's authority, we refuse it and challenge it through the appropriate channels.
- We disclose the minimum. When disclosure is mandatory, we provide only the data specifically required, never an entire database and never other customers' data.
- We keep a record. We log every request: who asked, what was asked, what we answered, the legal reasoning, and who took part in the decision.
Whenever the law allows, we notify the affected customer before disclosing any data, so they can defend themselves.
5. Your rights (LGPD)
6. Retention
Active data is kept for as long as your account is active. After cancellation we keep backups for 30 days and then delete the data permanently.
7. Cookies
We use essential cookies for the login session. Analytics cookies (Google Analytics, Meta Pixel) are optional and can be disabled in your browser settings.
8. Contact
Privacy questions: contato@usebolt.app
← Back to Bolt CRM