Practical guidance

Ferrum CRM Mobile Privacy Policy

Privacy policy for the Ferrum CRM Android app (xyz.ironops.crm) by Iron Automations LLC: data collected, use, processors, and rights.

Updated
Content owner
Ferrum
Review owner
Operator review

This policy covers the Ferrum CRM Android app (package xyz.ironops.crm), developed by Iron Automations LLC (“Ferrum” is our product name).

Last updated: September 2026.

Who we are

Ferrum CRM is the mobile app for the Ferrum CRM platform, operated by Iron Automations LLC. For any privacy question, contact us at [email protected].

Data the app collects

  • Account credentials — your account email and password (or Google sign-in, where enabled) used to log in. A secure session token is stored encrypted on your device to keep you signed in.
  • Business contact records you enter — contacts, conversations, bookings, pipeline and job records you create or manage in the CRM. These are your organization’s business data, scoped to your account.
  • Device push token — registered only if you enable notifications, solely to deliver CRM alerts (new messages, bookings, assignments). Never used for marketing.
  • Saved payment card via Stripe — if you save a card, the card details are processed directly by Stripe. We never see or store your full card number on our servers.
  • Product analytics (PostHog) — the app ships posthog-react-native and sends app_open, login (method: password, google, or apple), lead_opened (contact_id), call_tapped (contact_id), text_sent (conversation_id), push_permission_granted, push_permission_denied, $screen (pathname), and SDK app-lifecycle events. Identify uses the account user id plus email_domain and role (never the full email). A before_send scrub drops email/phone/name/address/ssn/dob/birth keys, redacts email-address values to [redacted], allowlists email_domain, and strips URL query/hash. Session replay is not enabled.

The app does not collect location data, advertising identifiers, or device contacts, and it never scans your photo library — images are uploaded only when you choose to attach one.

How we use your data

Your data is used solely to provide the CRM service: signing you in, showing your organization’s records, sending the notifications you enabled, processing payments you authorize, and emailing you about your account. We do not sell your data and do not share it for advertising.

Service providers (processors)

  • Supabase — hosting, database and authentication
  • Expo push — delivering push notifications
  • Stripe — payment processing
  • Resend — sending account emails
  • PostHog — product analytics events described above

Security

All communication between the app and our servers is encrypted in transit over HTTPS (TLS). Account access is scoped to your organization, so your account can only see the business data it is authorized to see.

Retention

CRM records are retained for as long as your organization needs them to run its business, or as required by law. When your account is deleted, your account and its associated personal data are removed — see how to delete your account.

Your rights and deletion

You may request access to, correction of, or deletion of your personal data at any time. To delete your Ferrum CRM account and associated data, follow the steps on our account deletion page. For any other request, email [email protected].

Children

Ferrum CRM is a business tool and is not directed to children under 13.

Changes

Material changes to this policy will be reflected on this page with an updated date.


Ferrum CRM for Android (xyz.ironops.crm) by Iron Automations LLC — [email protected]