Who we are
Tigra Sales is a visual sales CRM for teams. You sign in, join or create a workspace, and manage pipelines, deals, people, organizations, activities, and notes. This policy applies to the Tigra Sales website, application, and related APIs.
What we collect
Account & authentication
- Identity details from Sign in with Google (typically name, email address, and profile picture as provided by Google).
- Session data needed to keep you logged in securely.
- Display preferences you set (timezone, currency, date and number formats).
Workspace CRM content
Workspace admins and members enter business CRM data that may include personal data about customers and prospects, for example:
- People & organizations — names, emails, phone numbers, company details, and custom field values.
- Deals — titles, values, currencies, stages, owners, participants, probability, expected close dates, win/loss timestamps and reasons, and custom fields.
- Activities & notes — tasks, calls, emails, meetings, free-text notes, and due dates.
- Audit history — automatic deal changelogs (who changed stage, value, owner, fields, and when).
- Membership — workspace invitations, roles (admin/member), team-leader relationships, and participation status.
API & integrations
- Workspace API tokens (stored hashed) and metadata about token use for creating deals, notes, and custom fields.
- If a workspace connects Google Ads, we store the Google Ads customer ID you supply and an OAuth refresh token, encrypted at rest. This grant is write-only: we do not read campaigns, keywords, spend, audiences, or any other data from your Google Ads account.
Technical data
- Standard server logs (IP address, user agent, timestamps, request paths) for security, reliability, and debugging.
- Cookies or similar technologies required for authentication, CSRF protection, and session continuity.
How we use data
We use personal and workspace data to:
- Provide, operate, and improve the CRM (boards, lists, reports, forecasting, reminders, audit trails).
- Authenticate users, enforce workspace access rules, and process invitations.
- Honour your display preferences when showing dates, money, and numbers.
- Enable API integrations and optional Google Ads conversion sync when configured by a workspace.
- Maintain security, prevent abuse, troubleshoot issues, and meet legal obligations.
- Communicate about the service (for example account, security, or material product notices).
We do not sell your personal data. We do not use your workspace CRM content to train public AI models.
Workspaces, multi-tenancy & access
Tigra Sales is multi-tenant. CRM records are scoped to a workspace. Within a workspace, access follows the product’s hierarchy: workspace admins can see broader data; team leaders see their team’s deals; members see deals they own (or participate in, as configured). Super admins may access the platform admin tools needed to operate the service.
Workspace customers decide what CRM content to store and who to invite. If you enter personal data about third parties (leads, clients, colleagues), you are responsible for having a lawful basis to do so and for how your organization uses that data inside the product.
Third-party services
- Google — OAuth sign-in; optionally Google Ads for conversion upload when a workspace connects it. Google’s own privacy terms apply to their services.
- Hosting & infrastructure — cloud providers and email/log services that process data on our behalf under contractual safeguards.
When a workspace connects Google Ads, deal information configured for conversion sync — deal value, currency, close timestamp, and the ad click identifier captured when the lead arrived — is transmitted to that workspace’s own Google Ads account and to no other party. Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use it for advertising targeting by us, for lending decisions, or to develop, improve, or train AI/ML models.
When you push data into Tigra Sales via the workspace API (for example from a website form), that data is treated as workspace CRM content under this policy and your organization’s instructions.
Retention & security
We retain account and workspace data for as long as the account/workspace remains active and as needed to provide the service. Soft-deleted records (for example deals, people, organizations) may remain recoverable for a period consistent with product design and backups. Audit changelogs are designed to be append-only so teams can reconstruct deal history.
We apply technical and organizational measures appropriate to a multi-tenant SaaS CRM, including authentication controls, workspace scoping, hashed API tokens, and encrypted transport (HTTPS). Google Ads OAuth refresh tokens are encrypted at rest. No method of transmission or storage is perfectly secure; you should use strong Google account security and limit workspace membership and API tokens to people who need them.
A stored Google Ads refresh token is retained only while the connection is in place, and is deleted along with the workspace when the workspace is deleted. You can revoke our access to your Google Ads account at any time from your Google Account permissions page.
Your rights
Depending on where you live (including under the EU/EEA GDPR and similar laws), you may have rights to access, correct, delete, restrict, or export personal data, and to object to certain processing. You may also withdraw consent where processing is based on consent, and lodge a complaint with a supervisory authority.
Workspace users can often update profile-related details and CRM records directly in the app. For account deletion or privacy requests that cannot be completed in-product, contact us as described below. We may need to verify your identity and, for workspace CRM content, may direct requests to the relevant workspace admin where they act as the controller of that data.
Children
Tigra Sales is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided data, contact us so we can delete it.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may also be communicated through the product or by email where appropriate.
Contact
For privacy questions or requests, contact us through your workspace administrator or via the support channel provided in the Tigra Sales application. Include enough detail for us to identify your account and request.
See also our Terms of Use.