Sayl CRM Sign in

Privacy Policy

Last updated 23 September 2026

This policy explains how Sayl CRM collects, uses and stores information. It is published at https://crm.sayl.in/privacy/ and covers the CRM application at crm.sayl.in and the integrations it connects to on your behalf.

Who we are

Sayl CRM is a customer relationship and marketing platform operated by Sayl Technology (sayl.in). We act as a processor for the customer data our business customers load into their workspace, and as a controller for the account data of the people who use the product.

Information we collect

Account information. Name, email address, phone number, password (stored only as a hash), workspace and role.

Customer records you enter or import. Contacts, leads, phone numbers, email addresses, notes, quotes, invoices and the activities your team records against them.

Messages. WhatsApp conversations sent and received through numbers you connect, email you send through the platform, and the delivery status of each.

Usage and security logs. Sign-in times, IP addresses, and a record of actions taken in the workspace, kept so account owners can audit their own workspace.

Google Calendar and YouTube data

Google API Services User Data Policy. Sayl CRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

If you connect your own Google account, we request only the access needed for the specific feature you connected it for — never your Gmail, Drive, or Contacts. The scopes we request are:

Specifically we store:

Google Calendar is connected per person — a meeting one user books always uses that user's own calendar and Google Meet link, never a colleague's. YouTube is connected once per workspace, since a business's channel is shared.

We do not read any calendar event or video we did not create ourselves through the CRM. We use Google user data only to provide and improve the user-facing features described above. We do not use it for advertising, we do not sell it, we do not transfer it to third parties except as necessary to provide those features or as required by law, and we do not use it to develop, improve or train generalised AI or machine-learning models. No human reads Google user data except with your explicit consent, for security purposes, or where required by law.

You can disconnect either integration at any time from Settings → Integrations in the CRM, which deletes the stored token immediately. You can also revoke access at any time at myaccount.google.com/permissions.

Facebook and Instagram data

If you connect a Facebook Page or an Instagram professional account, we request only the access needed to publish on your behalf and to attribute the enquiries a post produces. We store the encrypted Page access token for each Page you choose, the Page and Instagram account id, name and profile picture, the id and link of posts published through the CRM, and, for click-to-WhatsApp enquiries, the referral details Meta sends with the customer's first message. We do not collect your Facebook friends list or personal profile content, we do not use Meta data for advertising, and we do not sell it or share it with third parties. Disconnecting an account deletes its stored token immediately.

WhatsApp data

Where you connect a WhatsApp Business number, we store the messages sent and received on it so your team has the conversation history, along with the sender's WhatsApp profile name and number. Message content is used to operate the CRM — routing, replies, and the automated assistant you configure — and for no other purpose.

How we use information

To provide the product: storing your records, sending the messages you send, publishing the posts you publish, and showing you the results. To keep the service secure and diagnose faults. To contact you about your account. We do not sell personal information, and we do not use your customers' data to train models.

Sharing

We share information only with the providers needed to deliver the service — Meta (WhatsApp, Facebook, Instagram) for the messages and posts you send, Google for the Calendar and YouTube features you connect, your email provider for email you send, and our hosting and database infrastructure — and where the law requires it.

Retention and deletion

Workspace data is retained for as long as the workspace is active. You can delete individual records at any time. To delete an entire workspace and everything in it, or to request a copy of your data, write to support@sayl.in. Disconnecting a Google, Facebook or Instagram account deletes its stored token immediately.

Security

Traffic is encrypted in transit with TLS. Access tokens and third-party credentials are encrypted at rest and are never displayed back after they are saved. Access within a workspace is governed by roles its owner controls, and data belonging to one workspace is not readable from another.

Your rights

You may request access to, correction of, or deletion of your personal information by writing to support@sayl.in. If you are an end customer of one of our business customers, please contact that business directly — they control their own records, and we act on their instructions.

Changes

We will update this page when this policy changes and revise the date at the top. Material changes will be notified to workspace owners.

Contact

Sayl Technology
support@sayl.in