Privacy policy
What Falconzo collects, why we collect it, how connected mailboxes and messaging channels are handled, and the controls you have over your information.
Last updated: [Effective date]
About this policy
This policy explains how FalconPlans, trading as Falconzo, handles personal information in the Falconzo customer relationship management service, on this website, and in the email and messaging integrations you can connect to it.
It is written to be read by the people who run a business on Falconzo, so it uses ordinary language rather than legal shorthand. Where a detail depends on your contract with us, or on information we cannot state accurately in a public page, you will see a bracketed placeholder.
Two different roles
Falconzo holds two kinds of information, and it matters which one is in question.
The first is information about you as our customer: the account you created, the person who signed up, billing arrangements, and the support conversations we have with you. We decide how that information is used, so we are responsible for it.
The second is the CRM data you put into Falconzo: your contacts, your companies, your leads, your deals, your mail and your conversations. That data is yours. You decide what to collect, why you collect it, how long to keep it and who in your team can see it. We store and process it on your instructions so that the product works for you, and we do not use it for our own purposes.
In data protection language, you are the controller of your CRM data and we are the processor acting for you. If one of your contacts asks what is held about them, the answer comes from you, not from us. We will help you answer it.
Information we collect
Account details
When you create an account we collect your name, your email address, a password and the organisation the account belongs to. Passwords are stored as a bcrypt hash and never in readable form, so nobody at Falconzo can see or recover your password. We also store your interface preferences, such as your theme and notification settings, and the role that determines what you may see and do.
The CRM records you choose to store
Falconzo stores whatever you decide to keep in it. That usually includes:
- Contacts: name, job title, department, email addresses, phone numbers, address, website, owner, tags, the company they work for, who they report to, and whether they have opted out of email.
- Companies: name, domain, address, phone, parent company, owner, tags and the people who work there.
- Leads: name, company name, email, phone, status, source and owner.
- Deals: title, value, currency, pipeline, stage, status, expected close date, owner and the contact and company they relate to.
- Tasks, notes and file attachments on any of those records.
- Custom fields and custom objects: field names and values you define yourself, which may hold any information you choose to put in them.
- Records you bring in through CSV import.
Because custom fields are yours to define, we cannot list everything a Falconzo account might hold. That is one of the reasons the decision about what to collect stays with you.
Connected mailbox content
If a user connects a mailbox, Falconzo synchronises mail from it so that conversations can be shown next to the related CRM records. For each synchronised message we store the subject, the message body in text and HTML form, the sender and the other participants, timestamps and threading information, and a description of each attachment such as its file name, type and size.
Attachment contents stay with your mail provider. Falconzo lists what is attached and fetches the file from the provider when someone asks to download it.
The first synchronisation reaches back over a window chosen when the mailbox is connected: 30, 90 or 180 days, with 90 days as the default. After that, new mail synchronises as it arrives.
Connected messaging conversations and lead forms
If you connect WhatsApp, Facebook Messenger or Instagram, Falconzo stores the conversations that arrive on those channels: message text, the direction of each message, timestamps, the attachment descriptors the provider supplies, and the identifier the provider uses for the person you are talking to, such as a WhatsApp number or a Messenger or Instagram account id, along with their display name and profile picture where the provider supplies one.
If you connect Facebook or Instagram lead forms, the answers a person submits on those forms arrive in Falconzo as a lead.
Activity records
Falconzo keeps an audit log of actions that change a record, and a per-field history showing what a value was before and after it changed, who changed it and when. These exist so that your team can answer questions about its own data. They necessarily record which user did what.
Technical information
Our systems record the ordinary technical information a web service needs in order to run, such as the requests made to the service and the errors that occur, so that we can keep it working and investigate faults.
Why we use each category
- Account details: to create and secure your account, to sign you in, to apply your permissions, to send service messages and to bill you.
- CRM records: to provide the product you asked for. We store, display, search, link and export this data on your instructions.
- Mailbox content: to show conversations alongside the right CRM record, to power the inbox views, and to let you reply and forward from Falconzo.
- Messaging conversations and lead form submissions: to deliver them to your shared inbox, to let you reply, and to create leads from form answers.
- Audit log and field history: to give your team an accurate record of who changed what.
- Technical information: to operate the service, diagnose faults and protect the service from abuse.
We do not sell personal information, and we do not use the contents of your CRM records, your mail or your messages to advertise to you or to anyone else.
How connected email and messaging work
Connections are made by the user who owns them, and they are always approved at the provider. When you connect Gmail or Google Workspace, Microsoft 365 or Outlook, Zoho Mail, Yahoo Mail, WhatsApp, Messenger or Instagram, you are sent to that provider's own authorisation screen and you grant the access there. Mailboxes connected over IMAP and SMTP use the mailbox credentials you supply.
To keep synchronising after that first authorisation, Falconzo has to store the credential the provider issued. Those credentials, whether OAuth tokens or IMAP passwords, are encrypted with AES-256-GCM before they are stored, and they are never sent to your browser. They are used only to talk to the provider on your behalf.
Who can see what follows a simple rule:
- A personal mailbox is visible only to the user who connected it. Other people in your organisation, including administrators, do not see its contents in Falconzo.
- A shared mailbox, such as a sales or support address, belongs to the organisation and is governed by your roles and permissions. Every connection starts as personal, and someone with the right permission can convert it into a shared one afterwards.
- Messaging channels arrive in a shared inbox and follow the same permissions.
Mail is sanitised before it is displayed. Scripts, embedded styles and event handlers are removed, and remote images are blocked until the reader chooses to load them, because a remote image can tell the sender that a message was opened.
You can disconnect any integration from settings at any time. Disconnecting removes the stored credentials, ends the synchronisation, and removes the synchronised threads and messages Falconzo held for that connection. It does not delete anything in the mailbox or the messaging account itself, and it does not remove CRM records such as contacts, notes or deals that were created while it was connected.
Sharing with others
We share information only in the situations below.
- Within your organisation, according to the roles and permissions you configure.
- With the providers you choose to connect, because synchronising a mailbox or sending a reply means talking to that provider. Their handling of your data is governed by their own terms and privacy policies.
- With service providers who help us run Falconzo, in categories such as hosting and infrastructure, delivery of service email, payment processing, and error monitoring and support tooling. They act on our instructions and may use the data only to provide their service to us. We give the current list on request rather than publishing it here, so that this page cannot quietly go out of date.
- Where the law requires it, or to establish or defend legal claims.
- In connection with a merger, acquisition or sale of assets, in which case we will tell account owners before their data becomes subject to a different policy.
How long we keep information
Your CRM data stays in your account until you or your organisation delete it, or until the account is closed. After an account is closed we keep the data for [Data retention period] and then delete it, except where we have to keep certain records for longer, such as billing records.
Deleting a record in the product moves it to the trash, where it stops appearing in your lists and can be restored if it was deleted by mistake. Erasing it for good is a request you can make at any time. The data deletion page explains how, along with how to disconnect an integration or close an account entirely.
Security
Passwords are hashed with bcrypt. Credentials for connected mailboxes are encrypted with AES-256-GCM and are never sent to the browser. Access within an organisation is controlled by roles and permissions, personal mailboxes stay private to the person who connected them, changes to records are recorded in an audit log, and mail is sanitised before display with remote images blocked by default.
The security page describes this in more detail, including what we do not claim.
Your choices and controls
- Update your name, email address, password and preferences in your account settings.
- Edit or delete any CRM record you have permission to change, including contacts, companies, leads, deals, tasks, notes and files. Deleted records go to the trash first, so a mistake can be undone.
- Export your records to CSV, to keep a copy or to move to another system.
- Mark a contact or lead as opted out of email. Falconzo will then refuse to send to them.
- Mark a mail thread as not related to the CRM, and stop that address being suggested again.
- Disconnect a mailbox or a messaging channel at any time.
- Choose which notifications you receive.
Access, correction, export and deletion
Depending on where you live, you may have rights over your personal information, such as the right to ask for a copy of it, to have it corrected, to have it deleted, or to object to how it is used. Which rights apply to you depends on the law of [Jurisdiction] and on the law of the place where you live.
If you are a Falconzo customer, most of these actions are things you can do yourself inside the product. If you are one of our customer's contacts and you want to know what a business holds about you, the request belongs with that business, because they decided what to store. Ask them directly. If you contact us instead, we will pass the request on to them where we can identify the account.
The data deletion and data request page sets out how to make a request, what to include and what to expect. You can also write to us at [Privacy contact email].
Cookies and browser storage
Falconzo uses a small number of strictly necessary items in your browser to keep you signed in, and stores some interface preferences on your device. It does not use advertising or cross-site tracking cookies. The cookie policy lists what is stored and why.
Children
Falconzo is a business tool and is not intended for children. We do not knowingly collect personal information from children. If you believe a child has given us personal information, write to [Privacy contact email] and we will remove it.
Changes to this policy
We update this policy when the product changes or when the way we handle information changes. The date at the top of this page shows when it was last updated. If a change materially affects how we handle your information, we will tell account owners by email or by a notice in the product before it takes effect, and the previous version stays available on request.
Contact us
Questions about this policy, or about how your information is handled, can go to [Privacy contact email], or by post to FalconPlans, [Business address].
Your use of Falconzo is also governed by our terms of service.
