Privacy Policy
Last updated: April 18, 2026
Kepler CRM (“Kepler,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use the Kepler CRM platform and related services.
Summary: We collect only the information necessary to provide our services. We do not sell your personal data to third parties.
1. Information We Collect
Account Information
When you sign up for Kepler CRM, we collect information through Google OAuth, including:
- Your name and email address
- Google profile picture
- Google account identifier
Business Information
To provide our services, we collect business details you provide, including:
- Business name, address, phone number, and email
- Business logo and branding preferences
- Team member information (names, roles, contact details)
- Service offerings and pricing information
Customer Data
When you use Kepler CRM to manage your business, you may store customer information such as:
- Customer names, email addresses, and phone numbers
- Vehicle or property details related to service requests
- Appointment and scheduling information
- Invoice and payment records
- Communication history (SMS, email)
Usage Data
We automatically collect certain information when you use our platform, including browser type, device information, pages visited, and interaction patterns to improve our services.
2. How We Use Your Information
We use the information described above to operate and support the Services. Typical uses include:
- Provide, maintain, and improve the Kepler CRM platform
- Authenticate your identity and manage your account
- Process payments and manage subscriptions
- Send service-related notifications and updates
- Provide customer support
- Comply with legal obligations
Service Improvement and Analytics
We use aggregated and de-identified Service usage data — such as feature-interaction metrics, performance telemetry, and anonymized patterns — to monitor reliability, diagnose issues, and improve Service functionality, including intelligent features within the platform. Aggregated and de-identified data does not identify you or your customers and is not used to build profiles of individual users.
We also collect diagnostic information such as crash reports, error traces, and uptime telemetry to keep the platform stable and to triage incidents reported by our customers.
3. Third-Party Services
We integrate with third-party services and infrastructure providers to deliver the Kepler CRM platform. Current providers include:
- Amazon Web Services — cloud hosting and storage
- Anthropic and OpenAI — language-model infrastructure supporting in-product assistance and content features
- Google — authentication and calendar integration
- Meta (Facebook/Instagram) — social media integrations
- QuickBooks — accounting integration
- Sentry — error monitoring and performance tracking
- Stripe — payment processing for subscriptions and customer payments
- Telnyx — SMS and voice communications infrastructure
These providers act as sub-processors under written agreements that require confidentiality, security controls, and processing limited to the purposes described in this Policy. Each third-party service also operates under its own privacy policy. We share only the minimum information necessary for each integration to function, and a current list of sub-processors is available on request.
4. Payment Information
Payment processing is handled by Stripe. We do not store credit card numbers or bank account details on our servers. Stripe’s handling of your payment information is governed by their privacy policy and PCI-DSS compliance standards.
5. SMS/Text Message Communications
Kepler CRM enables businesses to send service-related text messages to their customers through our platform. Message content, phone numbers, and consent records are stored securely. Text messaging opt-in data and consent will not be sold, shared, or rented to third parties for their marketing or promotional purposes.
6. Children's Privacy
The Kepler CRM platform is designed for business users and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to remove it.
7. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure cloud infrastructure hosted on AWS
- Regular security reviews and updates
- Access controls and authentication requirements
Access to production systems is restricted to authorized Kepler personnel who have completed security training and background verification. Such access is role-based, logged, and limited to what is necessary to operate the Service, provide technical support, investigate security events, and fulfill your support requests. Access is audited on a recurring basis as part of our internal security program.
Service Availability
We operate the Service on redundant cloud infrastructure with automated backups and monitoring. We target industry-standard availability for the Service and publish planned maintenance windows in advance when scheduled work may affect access.
8. Data Retention
We retain your data for as long as your account is active or as needed to provide our services. If you close your account, we will delete or anonymize your data within 90 days, except where retention is required by law. Routine backup copies may be retained for a short additional period under our backup-rotation policy before being overwritten.
9. Roles and Responsibilities for Customer Data
When you use the Service to manage your own customers, you act as the controller of that customer information and Kepler acts as the processor, handling such information on your behalf and under your instructions as set out in these terms and any applicable data processing addendum. For information you provide directly to us about your account and business, Kepler acts as the controller. We process personal information consistent with applicable laws, including the GDPR and CCPA where they apply.
Regional Compliance Programs
We maintain internal programs to support compliance with laws applicable to the Service, including the CCPA, GDPR where relevant, and U.S. state consumer-privacy statutes. We will cooperate in good faith with reasonable requests necessary for you to meet your own compliance obligations.
10. Your Rights
Depending on your location, you may have the following rights:
- Access to your personal data
- Correction of inaccurate data
- Deletion of your data
- Data portability
- Opt-out of certain data processing activities
To exercise these rights, contact us at the email address below.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. Continued use of our services after changes constitutes acceptance.
12. Contact Us
You can reach our support team by email or through the in-product help center. We aim to respond to support requests within one business day.
Questions about this Privacy Policy?
Email: support@kepler-crm.com