Practical guidance
Ferrum CRM Mobile Privacy Policy
Privacy policy for the Ferrum CRM Android app (xyz.ironops.crm) by Iron Automations LLC: data collected, use, processors, and rights.
- Updated
- Content owner
- Ferrum
- Review owner
- Operator review
This policy covers the Ferrum CRM Android app (package xyz.ironops.crm), developed by Iron Automations LLC (“Ferrum” is our product name).
Last updated: September 2026.
Who we are
Ferrum CRM is the mobile app for the Ferrum CRM platform, operated by Iron Automations LLC. For any privacy question, contact us at [email protected].
Data the app collects
- Account credentials — your account email and password (or Google sign-in, where enabled) used to log in. A secure session token is stored encrypted on your device to keep you signed in.
- Business contact records you enter — contacts, conversations, bookings, pipeline and job records you create or manage in the CRM. These are your organization’s business data, scoped to your account.
- Device push token — registered only if you enable notifications, solely to deliver CRM alerts (new messages, bookings, assignments). Never used for marketing.
- Saved payment card via Stripe — if you save a card, the card details are processed directly by Stripe. We never see or store your full card number on our servers.
- Product analytics (PostHog) — the app ships
posthog-react-nativeand sendsapp_open,login(method: password, google, or apple),lead_opened(contact_id),call_tapped(contact_id),text_sent(conversation_id),push_permission_granted,push_permission_denied,$screen(pathname), and SDK app-lifecycle events. Identify uses the account user id plusemail_domainandrole(never the full email). Abefore_sendscrub drops email/phone/name/address/ssn/dob/birth keys, redacts email-address values to[redacted], allowlistsemail_domain, and strips URL query/hash. Session replay is not enabled.
The app does not collect location data, advertising identifiers, or device contacts, and it never scans your photo library — images are uploaded only when you choose to attach one.
How we use your data
Your data is used solely to provide the CRM service: signing you in, showing your organization’s records, sending the notifications you enabled, processing payments you authorize, and emailing you about your account. We do not sell your data and do not share it for advertising.
Service providers (processors)
- Supabase — hosting, database and authentication
- Expo push — delivering push notifications
- Stripe — payment processing
- Resend — sending account emails
- PostHog — product analytics events described above
Security
All communication between the app and our servers is encrypted in transit over HTTPS (TLS). Account access is scoped to your organization, so your account can only see the business data it is authorized to see.
Retention
CRM records are retained for as long as your organization needs them to run its business, or as required by law. When your account is deleted, your account and its associated personal data are removed — see how to delete your account.
Your rights and deletion
You may request access to, correction of, or deletion of your personal data at any time. To delete your Ferrum CRM account and associated data, follow the steps on our account deletion page. For any other request, email [email protected].
Children
Ferrum CRM is a business tool and is not directed to children under 13.
Changes
Material changes to this policy will be reflected on this page with an updated date.
Ferrum CRM for Android (xyz.ironops.crm) by Iron Automations LLC — [email protected]