Legal

LimoSphere CRM Privacy Policy

LimoSphere CRM is a shared inbox for chauffeur and limousine operators. This policy explains what it collects from the mailboxes and messaging accounts you connect, how that information is used and protected, and the specific commitments we make about Google user data.

Effective 1 September 2026

1. Scope of This Policy

This policy describes how LimoSphere handles data in LimoSphere CRM, the shared inbox product that connects an operator's mailbox, phone numbers and messaging accounts so their team can work customer conversations from one place. It sits alongside the LimoSphere platform privacy policy; where the two differ on the handling of connected mailbox data, this policy governs.

1.1 Who the parties are

Transportation operators who subscribe to LimoSphere CRM are our customers, and they are the controllers of the conversation data in their workspace. LimoSphere acts as a processor on their behalf. Passengers and other people who contact an operator are data subjects whose messages pass through the product.

1.2 What this policy does not cover

This policy does not cover your mail provider's own handling of your data. Mail stored in Gmail or Microsoft 365 remains governed by your agreement with that provider, and disconnecting LimoSphere CRM has no effect on the mailbox itself.

2. Information We Collect

2.1 Account and workspace information

To provision and secure a workspace we hold the operator's company name, the email addresses and display names of the team members granted access, their assigned roles and permissions, and the configuration of each connected inbox.

2.2 Conversation content from connected accounts

Once you connect an account, LimoSphere CRM stores the content it needs to display that conversation to your team:

  • Email: message bodies, subject lines, sender and recipient addresses, message identifiers and threading headers, timestamps, and attachments.
  • SMS and messaging: message text, the phone numbers or handles either side of the conversation, and delivery status.
  • Calls: call metadata such as the numbers, direction, duration and outcome, and — where the operator has enabled it — call recordings.
  • Contact records: names, email addresses and phone numbers of the people your team corresponds with, matched against your existing customer records.

2.3 Credentials and access tokens

For mailboxes connected by signing in with Google or Microsoft, we store the access and refresh tokens that provider issues. We never receive or store your provider password. For mailboxes connected with direct IMAP and SMTP details, we store the credentials you supply. All of these are encrypted at rest.

2.4 Technical and diagnostic information

Our servers record IP addresses, browser and device information, timestamps, and error and delivery logs. This data is used to operate the service, investigate faults and detect abuse.

3. Google User Data

This section applies specifically to data LimoSphere CRM receives from Google APIs when you connect a Gmail or Google Workspace mailbox. It is written to be read on its own.

3.1 Permissions we request and why

When you connect a Google mailbox, LimoSphere CRM asks for two things. The Gmail scope https://mail.google.com/ is required to read incoming mail into your shared inbox and to send your team's replies from your own address; Google's IMAP and SMTP interfaces accept no narrower permission, and no read-only or send-only alternative exists for IMAP access. The basic profile email scope is used for a single purpose: to confirm which mailbox granted consent, so the connection binds to the address you intended and cannot be attached to a different one.

3.2 How we use Google user data

Message content, headers and attachments retrieved from your Google mailbox are used only to provide the shared-inbox features you signed up for:

  • Displaying incoming mail as conversations inside your own LimoSphere workspace.
  • Threading replies so an ongoing exchange stays in one conversation rather than fragmenting.
  • Matching a message to the customer record it belongs to.
  • Sending the replies your agents compose, from your own business address.
  • Where your workspace has enabled assisted replies, generating a suggested draft for your agent to review before anything is sent.

3.3 Human access to Google user data

LimoSphere personnel do not read the contents of your mailbox. Access by a named engineer is permitted only in narrow circumstances: when you ask us to investigate a specific problem and grant access for that purpose, when it is necessary to address a security incident or abuse, or where we are legally compelled. Such access is logged.

3.4 What we never do with Google user data

  • We do not sell, rent or trade Google user data to anyone.
  • We do not use Google user data for advertising, ad targeting, profiling or resale.
  • We do not use Google user data to develop, improve or train generalized or generative artificial intelligence or machine-learning models.
  • We do not transfer Google user data to third parties except as strictly necessary to provide the service, comply with law, or as part of a merger or acquisition where the receiving party is bound by this policy.
Limited Use disclosure. LimoSphere's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. You may revoke LimoSphere CRM's access to your Google account at any time from your Google Account permissions page.

4. How We Use Information

Beyond the channel-specific uses described above, we process information in LimoSphere CRM for the following purposes and no others:

  • Providing, hosting and maintaining the shared inbox and its features.
  • Routing conversations to the right agent and tracking their status.
  • Authenticating users and enforcing the permissions your administrators configure.
  • Sending operational notifications to your agents about conversations they are responsible for.
  • Investigating faults, preventing abuse, and protecting the security of the service.
  • Meeting our legal, tax and regulatory obligations.

5. Sharing and Subprocessors

We do not sell personal information. We share data only with infrastructure and communications providers who process it on our behalf under contract, and only to the extent needed to deliver the service:

  • Cloud hosting and managed database providers, which store your workspace data.
  • Object storage, which holds attachments and call recordings.
  • Your own connected communications providers — Google, Microsoft, RingCentral, Twilio, WhatsApp and Telegram — which carry the messages you send and receive.
  • Push notification services, used to alert your agents to activity in conversations assigned to them.

5.1 Legal disclosure

We may disclose information where we are required to by law, court order or other valid legal process, or where disclosure is necessary to protect the rights, property or safety of LimoSphere, our customers, or the public. Where we are permitted to notify the affected customer, we will.

6. Retention and Deletion

6.1 While your account is active

Conversation data is retained for as long as your workspace is active, because the product's purpose is to keep a durable customer history. Operators can delete individual messages, conversations and contacts at any time.

6.2 Disconnecting an inbox

Disconnecting an inbox deletes the stored credentials and tokens for that account and stops all further synchronisation immediately. Conversations already imported remain in your workspace as your business record unless you delete them.

6.3 Closing your account

When a workspace is closed, we delete or irreversibly anonymise its data within 90 days, except where a longer period is required by law. Backups are purged on their own rolling schedule, after which the data is unrecoverable.

6.4 Requesting deletion

Operators may request deletion of their workspace data by contacting us at the address at the foot of this page. Passengers and other individuals who wish to have their data removed should contact the operator they corresponded with, who controls that record; we will assist that operator in fulfilling the request.

7. Security

We apply technical and organisational measures appropriate to the sensitivity of the data LimoSphere CRM handles:

  • Provider credentials and OAuth tokens are encrypted at rest using AES-256-GCM with keys held separately from the database.
  • All traffic between your browser, LimoSphere and your communications providers is encrypted in transit using TLS.
  • Every record is scoped to the operator that owns it, so one workspace cannot query another's conversations.
  • Access to production systems is restricted to named personnel, requires multi-factor authentication, and is logged.
  • Agent permissions are enforced per request, so a team member only reaches the inboxes their administrator granted.

7.1 No system is perfect

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your data, we will notify the affected operator without undue delay and in accordance with applicable law.

8. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, export, restrict or delete your personal information, and to object to certain processing. To exercise them, contact us at the address below or, if your data sits in an operator's workspace, contact that operator directly.

  • Revoke a Google connection at any time at myaccount.google.com/permissions.
  • Revoke a Microsoft connection at any time from your Microsoft account's app permissions.
  • Disconnect any inbox from within LimoSphere CRM, which deletes its stored credentials.
  • Ask us for a copy of the personal data we hold about you.
  • Ask us to correct information that is inaccurate or incomplete.

9. International Transfers

LimoSphere operates internationally, and your information may be processed in countries other than the one you live in, including the United States. Where we transfer personal data out of a jurisdiction that restricts such transfers, we rely on an appropriate safeguard recognised under that jurisdiction's law, such as standard contractual clauses.

10. Children

LimoSphere CRM is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

11. Changes to This Policy

We may update this policy as the product develops or the law changes. The effective date at the top of this page always reflects the current version. If a change materially affects how we handle connected mailbox data, we will notify workspace administrators before it takes effect.