Ayris CRM Privacy Policy

Effective October 7, 2026. Version: 2026-10-05-r4.

Ayris Home Service LLC ("Ayris," "we," "us") operates Ayris CRM. This Policy explains personal information handling for our CRM, account and support services, and related website interactions. It does not replace the privacy notices a customer must provide to its own contacts.

1. Information we process

  • Account and workspace information: names, email addresses, company and workspace names, memberships, permissions, account verification, and subscription details. Passwords are stored as password hashes; optional authentication and recovery information is processed to protect access.
  • Customer-provided CRM content: seller and buyer contact details, property information, notes, communications and consent records, appointment and transaction information, uploaded files, documents, and signature text or images that you or your users choose to store.
  • Billing information: plan, subscription and payment status, provider identifiers, invoice records, and billing contact details. Stripe collects payment details through its checkout and portal. We do not store full payment-card numbers or card security codes in the CRM.
  • Support and operational information: support requests, attachments you choose to provide, account activity and acceptance records, and technical records such as timestamps, errors, device/browser details and network information received by our hosting and delivery providers.

Provide only information reasonably needed for your work. Do not upload unnecessary sensitive identifiers or credentials. Document and signature images are used as customer content; their presence does not establish an identity-verification or biometric-identification service.

2. Why we use information

We process information to create and verify accounts; provide separate workspaces and permissions; store, display, export, and manage customer content; process subscriptions; send transactional verification, password-reset and service messages; respond to support; prevent misuse; troubleshoot and maintain the Service; and meet legal obligations.

Customers decide the purposes of their CRM records and are responsible for lawful collection, notices, consent and use. For that content, we generally process it on the customer's behalf to deliver the requested software. This description alone does not establish the contractual status of a service provider or processor under a particular privacy law; any required data-processing terms must also be in place. For our own accounts, billing, security, and business records, we determine the purposes of processing. Where a particular privacy law applies, our roles and obligations follow that law rather than labels in this Policy.

3. Sharing and providers

We share information as reasonably necessary with:

  • Your authorized workspace users: permissions and sharing choices determine who can access content. People with access may download or share it independently.
  • Service providers: Render hosts the CRM and its storage; Resend delivers configured transactional email; Stripe processes payments and subscription management; Squarespace hosts the public marketing website. Each receives information needed for its function and may process technical or account information under its own applicable privacy terms. For example, email delivery requires the recipient address and message content; subscription processing requires billing and subscription information. Squarespace may also act independently for certain automatically collected visitor information, including security-related network information. Provider notices describe those providers' own practices; they do not replace this Policy or remove our obligations for processing we arrange.
  • Integrations you select: if you configure a communication, AI, document, or other integration, relevant content may be sent to that provider to carry out your request. Review the provider's privacy terms and settings before enabling it. This Policy does not promise that an external AI provider avoids retaining or training on submissions.
  • Authorized support and professional advisers: limited access may be needed for support, security, legal, accounting, or operational purposes. Workspace separation is not a promise that administrators can never access stored information.
  • Legal and safety recipients: when reasonably necessary to comply with law or valid legal process, protect rights and security, or investigate unlawful activity.
  • A business successor: in a merger, acquisition, financing, or sale, subject to appropriate protections and applicable notice requirements.

We do not sell customer CRM content or use it for third-party targeted advertising. We do not use customer CRM content to train our own general-purpose AI models. Those statements do not purport to describe processing independently controlled by an integration you select. They do not exempt our hosting, email, or payment arrangements from applicable contractual and legal restrictions. We remain responsible for obligations applicable to processing we arrange.

4. Cookies, browser storage, and the marketing website

The Service and its providers use necessary session and security technologies to operate accounts and remember relevant preferences. Our Squarespace marketing website has nonessential cookies restricted and visitor activity logging disabled. Necessary cookies and technical processing needed for security and delivery may still occur. This restriction does not promise that every provider's technical processing stops. Third-party sites reached through links have their own policies. Browser controls can restrict cookies or storage, which may affect functionality.

We do not implement a separate browser Do Not Track response in the CRM. Our marketing website's nonessential-cookie restriction applies to visitors without requiring a Do Not Track or Global Privacy Control signal; this is not a representation that every provider recognizes or responds to those signals. Necessary account, security and delivery processing continues. We do not configure advertising pixels or third-party targeted-advertising integrations on the marketing website. Linked sites and service providers may independently process information under their own notices; we do not control tracking after you leave our site.

5. Security and backups

We use access controls and technical safeguards intended to protect information. No system or transmission is completely secure, and we cannot guarantee that information will never be lost, corrupted, or accessed without authorization. You should protect your account, manage workspace permissions, and keep independent copies of important records and signed documents.

Operational backups and recovery copies may retain personal information. We do not promise a specific backup schedule, restoration outcome, recovery time, or permanent document archive. These limitations do not excuse safeguards, breach notifications, or other duties required by applicable law.

6. Retention and deletion

We retain information for the purposes described above, considering the account relationship, customer instructions, the type of record, legal and tax requirements, dispute resolution, security, and recovery needs. Cancellation of payment does not automatically delete an account or workspace. Workspace deletion requests use a staged review, rather than immediate erasure.

You can request deletion through the workspace controls where available or by contacting us. We verify the requester and authority, assess the requested scope and applicable legal obligations, and explain any retention exception. Restricted backup copies may remain after removal from active systems; retained copies are not intended for ordinary product use. A recovery operation does not revoke an outstanding deletion request or authorize renewed ordinary use of content that was removed in response to it. The recovery and deletion process must account for restored copies and applicable retention exceptions. Our current launch configuration does not automatically erase a workspace when a subscription is canceled or automatically expire every backup. Retention is governed by the following criteria:

  • Active workspace content is kept to provide the storage and workflows requested by its owner, subject to verified deletion requests and applicable law.
  • Canceled or inactive workspace content is retained only while needed for an authorized export, an account or ownership issue, recovery, a dispute, or a legal requirement. Cancellation alone is not a request to destroy business records.
  • Recovery copies are retained while needed for recovery or an applicable hold. We review obsolete copies for removal and include them in verified deletion-request handling. A copy is not treated as erased merely because the active workspace was removed.
  • Security, support, and acceptance records are retained while needed to protect accounts, resolve the relevant issue, document consent, or address claims. Financial records may be retained to meet applicable accounting, tax, and legal obligations.
  • A valid legal hold can require continued restricted retention. We assess its scope and review whether it remains necessary.

We review retention needs and verified requests manually. We record the relevant retention reason and communicate any exception, outstanding backup handling, and expected next step to the requester. We will not retain personal information longer than permitted by applicable law. This Policy does not promise immediate or fully automatic erasure.

7. Your choices and rights

Account users can review relevant account information, manage permissions, and use available export and data controls. Contact us to request access, correction, deletion, a copy of information, or to exercise another applicable privacy right. We may need to verify identity and authority without collecting unnecessary information. Applicable law determines available rights, exceptions, timing, appeal rights, and authorized-agent procedures. We do not discriminate for exercising a protected privacy right.

If your information was added by a CRM customer and you do not have an account with us, contact that business first. We can help route a request, but cannot give an unrelated person access to a customer's workspace. The customer is responsible for its own communications and marketing opt-outs; account security and necessary service notices may still be sent.

8. Location and children

Our current CRM hosting is in the United States. Providers may process information in other locations according to their arrangements. International use may involve cross-border transfers; where required, applicable transfer protections must be established before processing. This Policy alone is not a data-processing agreement or an international transfer mechanism.

The Service is for adult business users and is not directed to children under 18. If you believe a child has provided personal information, contact us so we can assess and address it.

9. Updates and contact

We will publish a dated version of this Policy and provide notice of material changes as required. A change does not retroactively authorize a materially different use of previously collected information where consent or other legal requirements apply.

Ayris Home Service LLC — Ayris CRM

Privacy and support requests: support@ayriscrm.com.