Privacy Policy
This Privacy Policy explains how Systems Mastery Pty Ltd ATF Mann Family Trust trading as Systems Mastery (ACN 138 024 441, ABN 62 698 393 859), of Albert Road, Lilydale, Victoria 3140, Australia, collects, uses, stores, and shares information when you use Customer Relationship OS (CROS). We take privacy seriously — the whole point of CROS is that you own your data.
1. Information we collect
Account information
When you create an account we collect your email address, a hashed password, your display name if you provide one, and metadata about your session (IP address, user agent, sign-in times) for security and rate-limiting.
Workspace content
Content you create inside CROS — contacts, deals, purchases, bookings, forms, funnels, emails, templates — is stored in your workspace’s database. Because CROS is self-hostable, this database can be one you control directly; in managed deployments, we operate the database on your behalf.
Data your customers submit
If your public forms, funnels, or storefront collect information from your customers (name, email, phone, payment details), that data is stored in your workspace and treated as Customer Data under our Terms. You are the data controller for that information; we are the processor.
Analytics and diagnostics
We may collect anonymous usage metrics (page loads, feature usage counts, error reports) to improve the product. Where product analytics tools (e.g. PostHog) are enabled in your workspace, they run under your account and configuration.
2. How we use information
- Provide the service — sign-in, session persistence, workspace scoping.
- Send transactional email — password resets, purchase confirmations, booking reminders.
- Bill for the service via Stripe.
- Improve and secure the product — error tracking, rate limiting, abuse detection.
- Comply with legal obligations.
We do not sell your personal information. We do not use your Customer Data to train machine-learning models.
3. Sub-processors
Customer Relationship OS uses the following third-party service providers (“sub-processors”) to deliver the service. Each is bound by their own privacy commitments; links to their policies are provided on request.
| Provider | Purpose | Region |
|---|---|---|
| Cloudflare | CDN + file storage (R2) | Global |
| Railway | Application hosting + database | EU West / US |
| Stripe | Payment processing | US |
| Resend | Transactional email delivery | US |
4. Cookies and tracking
We use a small number of cookies necessary to operate the service (session authentication, theme preference). See our Cookie Policy for the full list.
5. Data retention
Account and workspace data are retained for the duration of your relationship with us plus a reasonable window (typically 30 days after cancellation) to allow for reactivation and export. Backup media may retain content longer under standard retention cycles.
Email delivery logs are retained for up to 12 months for debugging, deliverability analysis, and compliance with anti-spam laws.
6. Security
We follow industry-standard security practices including HTTPS in transit, encryption at rest for our managed database and file storage, hashed password storage, rate limiting on public endpoints, and least-privilege access controls for our operators. No system is perfectly secure; we notify affected users of confirmed data breaches without undue delay, and in any case within 72 hours where required by law.
7. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your account and associated data.
- Receive your data in a portable format.
- Object to certain processing or withdraw consent.
- Lodge a complaint with your local data-protection authority.
To exercise these rights, email contact@systemsmastery.com. We respond within 30 days. If we deny your request, we’ll explain why and how to appeal.
8. International transfers
Some of our sub-processors are located outside your country of residence. We rely on standard contractual clauses and equivalent safeguards to protect personal data when it moves across borders.
9. Children
CROS is not directed at children under 16. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.
10. Changes
We will update this Privacy Policy from time to time. Material changes will be notified by email or an in-product notice at least 30 days before they take effect.
11. Contact
Privacy questions can be sent to contact@systemsmastery.com. For requests under GDPR, the Australian Privacy Act, or similar laws, please include enough information to verify your identity.