Privacy Notice
TUSK is a sales CRM for web-design studios, provided as a hosted subscription service at tuskcrm.com.
What we collect
Account data. Authentication is provided by Clerk (our identity subprocessor). We store the Clerk account identifier, your workspace membership and role, and subscription state. Your sign-in email and password are held by Clerk; TUSK's own database stores only an opaque account reference for Clerk-authenticated users, not your password and not your sign-in email address.
Workspace content you enter. Leads, clients, call outcomes, notes, invoices, email templates, and uploaded documents. This content belongs to your workspace, is stored scoped to your workspace ID, and is never shared across workspaces. We process it only to operate the service for you.
Billing data. Payments are processed by Stripe. Card details are entered on Stripe-hosted surfaces and never touch TUSK's servers. We store your subscription plan, status, billing period, and Stripe event and customer references needed to reconcile your subscription.
Security and operational records. We keep short-retention security audit events (for example: request denied, rate limit exceeded, row written) containing the route, HTTP method, status, a request identifier, and where applicable your workspace and account identifiers — never the content of your records. IP addresses are processed transiently for rate limiting and abuse prevention.
Your connected Google account (outreach mailbox)
If you connect a Gmail or Google Workspace mailbox to send outreach, TUSK requests only two Google permissions: your email address (to show which mailbox is connected) and the ability to send email on your behalf (gmail.send). TUSK cannot read, browse, delete, or modify your inbox — the send-only permission does not allow it.
- What we store: your mailbox address and the OAuth refresh token Google issues, encrypted at rest (AES-256-GCM). We never see or store your Google password.
- How it is used: solely to send the outreach messages you compose and approve inside TUSK, from your own address. Every send is initiated by you or by automation rules you have explicitly enabled in your workspace.
- What we never do with it: no reading of mail, no contact harvesting, no advertising use, no sale or transfer of Google user data, and no use of this data to train machine-learning or AI models.
- Disconnecting: you can disconnect the mailbox at any time in TUSK (which deletes the stored token) and additionally revoke TUSK's access at myaccount.google.com/permissions.
TUSK's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Business listing data. Lead discovery and website reports use Google Maps Platform (Places) and Google PageSpeed Insights to retrieve public business listing details and public website performance measurements. These lookups concern businesses you search for; they do not involve your mailbox or its contents.
What we do not do
- No advertising, no sale of personal data, no cross-context behavioral tracking.
- No analytics or tracking scripts in the application.
- No reading of your workspace content except as required to operate the service, investigate abuse, or comply with law.
Subprocessors
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare (Workers, D1, R2, Queues) | Application hosting, database, file storage | All service data, encrypted in transit |
| Clerk | Authentication | Sign-in credentials, email, sessions |
| Stripe | Payments and subscription billing | Billing identity, payment method, invoices |
| Google (Gmail API) | Sending outreach from your own connected mailbox | Mailbox address, encrypted OAuth token, outgoing messages you compose |
| Google (Maps Platform, PageSpeed Insights) | Business listing lookup, website reports | Public business listing data and public website measurements |
The application loads no third-party fonts, analytics, or tracking scripts; visitor IP addresses are not disclosed to font or analytics providers because none are used.
Data retention and deletion
- Workspace content is retained while your subscription is active.
- Account deletion removes workspaces you solely own (rows and stored files), removes your memberships, redacts your local account record, and revokes active sessions. A minimal inactive marker of the external account reference is retained to prevent accidental re-provisioning. Shared workspaces with other owners are not deleted.
- Deleted data may persist in encrypted backups for up to 35 days before rotation; backups are restored only for disaster recovery.
- Billing records are retained as required for tax and accounting law.
- You may export your workspace data at any time from within the product.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, restrict, or delete your personal data. Contact jord9211@gmail.com and we will respond to verified requests.
Security
Tenant isolation is enforced at the application layer on every read and write. Documents are stored in private object storage with per-workspace keys and authenticated access only. Traffic is encrypted in transit. Mailbox tokens are encrypted at rest. Rate limiting and security audit logging protect against abuse.
Changes
We will post changes here with a revised effective date and notify account owners of material changes by email.
This notice is maintained by a small operator and is pending formal legal review; material updates will be posted here.