Last updated: September 1, 2026
Privacy Policy
Welcome to GTG CRM! Effective date: September 1, 2026. This Privacy Policy explains what data GTG CRM collects, how we use it, and your rights over it.
1. Who we are
GTG CRM ("we," "us") is provided by one of two affiliated companies, depending on how you pay:
- If you pay via VNPay, your agreement is with GTG CRM CO., LTD., a company registered in Ho Chi Minh City, Vietnam (Tax Code / MST 0319186711).
- If you pay via Chargebee, your agreement is with GTG CRM, INC., a Delaware corporation (United States).
Both companies operate the same platform under a written agreement between them — GTG CRM CO., LTD. develops, hosts, and supports the platform (including for customers billed by GTG CRM, INC.), and GTG CRM, INC. holds the underlying platform intellectual property. We refer to whichever of the two is your contracting party as "GTG CRM," "we," "us," or "your business" ("you," "your workspace").
2. What GTG CRM is
GTG CRM is a business-operations suite, not only a CRM — it can include, depending on which modules your workspace enables: customer relationship management (contacts, companies, deals); marketing and messaging (email, SMS, live chat, social media management); e-commerce and point-of-sale; warehouse and inventory management; support ticketing; human resources and payroll; recruitment; manufacturing planning and shop-floor execution; food-and-beverage operations; accounting, invoicing, and bank reconciliation; contract generation; an AI assistant that can act on your workspace's own data; and a website/landing-page builder.
3. Two roles we hold — controller and processor
- As controller, for data about you as our customer: your account details, billing information, and how you use GTG CRM.
- As processor, for the data your business puts into GTG CRM about your own customers, employees, suppliers, and contacts — you are the controller of that data; we process it on your instructions, under a data processing agreement.
4. What we collect
- Account & billing: Name, work email, phone, password, billing address, payment method.
- Your workspace's business data: Contacts, companies, deals, employee records, payroll data, invoices, orders, inventory, manufacturing records, contracts, support tickets, campaign data — whichever modules you use.
- Communications you send through us: Email, SMS, voice call recordings and transcripts (where enabled), live chat messages, social media messages. We do not share or sell a recipient's mobile number, SMS opt-in status, or consent data with any third party for marketing purposes.
- Automatically collected: IP address, device/browser type, pages viewed, referring source, session data — cookies only with your consent (§8).
- Financial data: If you connect a bank feed: account and routing identifiers, account owner name, balances, and transaction history, read via our bank-data connectivity providers — SePay for Vietnamese bank accounts (live today); Plaid (US) and Enable Banking (EEA/UK) are being onboarded and are not yet live. For some banks, we store your bank connection credentials, encrypted. Payment card data is processed by our payment providers, not stored by us directly (§12).
- Identity/regulatory documents: If you purchase a regulated phone number, identity or business-registration documents required by that country's telecom regulator.
- Content processed by AI features: The relevant contact/deal/document/message content needed to generate the output you asked for.
- Messages from your own website visitors: If your published website uses our AI chatbot or live chat, a visitor's typed messages are processed the same way, even though that visitor may never become your customer.
5. Who we share it with — our service providers
- Platform development, hosting & support: If your contracting party is GTG CRM, INC., GTG CRM CO., LTD. (our affiliated Vietnam operations company) develops, hosts, and supports the platform on GTG CRM, INC.'s behalf, under a written agreement between the two companies.
- Cloud infrastructure: Amazon Web Services.
- AI: OpenAI, Google (Gemini), and Anthropic (Claude).
- Analytics & session replay: Product-analytics and session-replay providers, to understand and improve site/product usage.
- Payments & banking: Chargebee (billing platform; Stripe processes the underlying card payment) for subscriptions outside Vietnam, VNPay for subscriptions inside Vietnam; SePay reads bank feed data for connected Vietnamese bank accounts today — Plaid (US) and Enable Banking (EEA/UK) are being onboarded for bank feeds outside Vietnam and are not yet live.
- Tax & e-invoicing: Region-specific e-invoicing/tax transport providers. For Peppol-network e-invoicing specifically, you connect and issue through your own account with your own provider (for example, B2BRouter) — we never hold a shared credential that issues on your behalf.
- Communications: SMS/voice/email delivery providers, and — only if you connect them — your own Gmail, Outlook, Slack, or Zalo account.
- Social & advertising platforms: We operate our own developer accounts with Facebook/Meta, LinkedIn, TikTok, YouTube (Google), and Zalo to power the social and advertising features you use; connecting your own account authorizes GTG CRM to act on it through our app, under each platform's own rules. Advertising spend is billed and controlled directly by you on the ad platform, not by us.
- Delivery & logistics: If you use in-platform shipping, we connect to courier partners on your behalf using our own account with the courier (for example, Grab Express); for couriers where you connect your own shop account instead (for example, GHN, ViettelPost), the connection uses your own credentials.
- Domain registration: Only if you register a domain through us.
A full, named list is available on our sub-processor page, kept current as providers change.
Google-sourced data (Gmail, Google Ads, YouTube) is subject to Google's own Limited Use restrictions: we do not sell or transfer it to advertising platforms, data brokers, or resellers; we do not use it to serve ads or determine credit-worthiness; and any AI processing of it is limited to that user's own use case. The use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. AI-assisted features
Some GTG CRM features use third-party AI services (our AI providers) to generate a response: an AI assistant that can answer questions using your workspace's own data; automatic drafting of articles, images, or contract drafts; matching a description of your business to website templates when you build a site; and an optional AI chat feature on your published website. The relevant content — which may include contact information, business records, your own description of your business, or a chatbot visitor's message — is sent to our AI providers to generate the response. We do not permit our AI providers to use your data to train or improve any model beyond generating your own response — this reflects the terms we operate under with each provider we use. We do not use AI to make decisions about a person with legal or similarly significant effects without a human able to review that decision.
7. Data subject rights
- If you're a GTG CRM customer: you can access, correct, or delete your account data directly within the product, and can request an export of your data by contacting us. Deleting your workspace deletes your workspace's data (§10); some connected third-party links are disconnected as part of that process.
- If you're a contact, employee, or other individual whose data a GTG CRM customer holds about you: GTG CRM is a processor for that business, not the controller of your data — contact that business directly to exercise your rights. You can also contact us directly at any time; you do not need to identify or reach the business first, though including any detail you can — the business's name, the email or phone number the business would have on file for you, or roughly when you interacted with them — helps us locate your data faster, since we don't have a way to search across all businesses' data by your identity alone. This is currently a manual process, not an automated one.
8. Cookies and tracking
We use cookies for three purposes: essential (always on), analytics (only with your consent), and advertising (only with your separate consent). On first visit, you can choose "Essential only," "Accept analytics," or "Accept all," or manage each category individually, and change your choice at any time via the "Cookie preferences" button on any page. We honor the Global Privacy Control signal automatically.
9. How long we keep data
We keep your account and workspace data for as long as your account is active, plus a period after closure for data recovery and legal obligations.
Statutory retention for accounting and invoicing records, by country: today, this only has a confirmed answer for Vietnam — electronic invoices issued through GTG CRM in Vietnam must be retained for a minimum of 10 years under Vietnamese law (Điều 41(5)(b), Luật Kế toán 88/2015/QH13). This obligation applies to your own business as the issuing "đơn vị kế toán," and separately to the licensed e-invoicing provider used for transmission (for example, MISA or Viettel S-Invoice). GTG CRM also keeps a copy of this data in our own systems as a matter of product practice, to support your recordkeeping — this is not itself an independent statutory duty on GTG CRM, and this practice continues even if your workspace is later deleted (§10). For other countries where GTG CRM's Peppol-network e-invoicing is available, your business connects and issues through your own account with your own e-invoicing service provider (we never hold a shared credential that issues on your behalf), so the statutory retention duty for those documents sits with your business and your provider in the same way described above for Vietnam. We have not yet sourced and confirmed each of those countries' specific retention periods, so we do not state a number here for them yet; we will add each country's confirmed retention period here as it is sourced. If you operate in a country not yet listed here and need to know your applicable retention period sooner, contact us.
Retention periods for other record types not covered above vary; we will state a specific period here as each one is confirmed, and you can always ask us for the current retention period that applies to a specific category of your data.
10. What happens when a workspace is deleted
If a workspace is deleted — by you, or automatically after its credit balance has been negative for 3 consecutive months, following a notice to the workspace owner — we delete the workspace's data and take reasonable steps to disconnect any third-party accounts you connected to it. This applies to every workspace on this basis, whether or not it has ever made a paid purchase. Records we're independently required to keep by law (for example, Vietnamese electronic invoices, per §9), and our own billing and accounting records of your account, survive workspace deletion for their required retention period — deleting your workspace doesn't delete those specific records early. We do not control what a connected third-party service does with data it already received before disconnection.
11. International data transfers
Your data may be transferred to and processed in Singapore (where our infrastructure runs), Vietnam (where our operating entity is based and administers the platform), and other countries where our service providers operate, including the United States (where our AI-assisted features send relevant content for processing) — and, if you connect your own e-invoicing provider for Peppol-network statutory invoicing, the country where that provider processes your data. Where required by the law of your country, we use one of the following to make that transfer lawful: standard contractual clauses, an appointed local representative, or an equivalent mechanism specific to that country's law. We are putting these mechanisms in place market by market as we expand to new countries; contact us if you'd like to confirm the specific mechanism that applies to your country today.
12. Security measures
We use technical and organizational measures appropriate to the sensitivity of the data we hold, including access controls scoped to your workspace and role and enforced on our servers, and an encrypted connection between your browser and GTG CRM. Internal traffic between our own services runs within a private network we control, rather than being individually encrypted hop-by-hop. Payment card data is processed by our payment providers directly — we receive only a masked card number. We are strengthening how infrastructure credentials are managed platform-wide and do not claim this work is complete; no method of transmission or storage is completely secure.
13. Breach notification
If we become aware of a data breach affecting your data, we will notify you and the relevant authority as required by applicable law.
14. Your rights, by region
Depending on where you're located, you may have additional rights over your data beyond what's already described in §7 — for example, the right to receive a copy of your data in a portable format, or to object to certain uses. These rights vary by country and we're in the process of documenting them region by region as we confirm the specifics with counsel. Contact us and we'll confirm what applies to you and help you exercise it, whether or not it's explicitly listed here yet.
15. Changes to this policy
We will post any changes here with a new effective date, and keep the prior version available so you can see what you agreed to on the day you agreed to it. For a material change, we will provide notice before it takes effect.
16. Contact us
support@gtgcrm.com