Mato/CRM
TermsPrivacyAcceptable Use
← Back to home

Legal

Privacy Policy

Last updated: July 3, 2026

Plain-language summary (not part of the policy): Mato CRM is a tool that takes contact-form submissions from your website and puts them in your inbox. This policy explains the personal information we handle, why we handle it, who we share it with, and the choices you have. We do not sell or share personal information for advertising. If you have questions, write to privacy@matocrm.com.

1. Who we are

Mato CRM is operated under the registered US trade name Mato CRM. In this policy “we,” “us,” and “our” mean the operator of Mato CRM. We handle all contact by email — you can reach us at privacy@matocrm.com for any privacy question.

This policy covers our website, the Mato customer portal, the Mato operator portal, and the public contact-form intake endpoint we host on behalf of our customers.

2. Two groups of people this policy is about

Mato CRM handles personal information about two very different groups of people. Your rights and our role differ depending on which group you are in.

Tenants — our paying customers. Tenants are the small businesses (and the owners or staff who sign up on their behalf) that use Mato to receive contact-form leads. When we collect information from a tenant, we are the controller of that information. We decide what to collect and why.

Form submitters — visitors to a tenant’s website. Form submitters are people who fill out a contact form on a website that uses Mato. When a form submitter sends a message, that information goes to the tenant’s inbox. The tenant decides what fields to collect and why. We are a service provider (a processor) acting on the tenant’s instructions. The tenant is the controller; we are the processor.

This distinction matters for your rights (Section 9) and for how we handle requests (Section 10).

3. Information we collect

3.1 From tenants (when you sign up and use Mato)

  • Name and business name
  • Email address
  • Hashed password (we store a one-way hash using argon2id; we never see your plaintext password)
  • Stripe customer ID and subscription ID (Stripe processes your payment; we do not store card numbers, CVV, or full billing addresses)
  • Plan and billing status (active, past due, canceled)
  • Login timestamps, session metadata, and IP address from your portal sessions
  • Audit records of admin actions you take in the portal

3.2 From form submitters (when someone fills out a tenant’s contact form)

  • Name, email, phone number, and free-text message that the submitter types into the form
  • IP address and browser user agent at the time of submission
  • The page URL the form was submitted from
  • A timestamp

We do not place tracking pixels, advertising tags, or third-party analytics on the contact form.

3.3 Information we do not collect

We do not collect:

  • Social Security numbers, tax IDs, or government-issued ID numbers
  • Payment card numbers, CVV codes, or bank account numbers (Stripe handles these — we never see them)
  • Biometric data
  • Precise geolocation (we see IP address only, which gives a rough region)
  • Information about children under 13 (the service is not directed at children)
  • Protected Health Information (PHI) under HIPAA — our Terms of Service prohibit this use, and we do not sign Business Associate Agreements

4. How we use information

We use tenant information to:

  • Provide the service: authenticate logins, show your inbox, run the contact-form endpoint
  • Process billing through Stripe and send billing-related email
  • Send transactional email (new-lead alerts, password resets, account notices)
  • Detect and block abuse, spam, and unauthorized access
  • Keep audit logs of admin actions for security and dispute resolution
  • Comply with our legal obligations (tax reporting, lawful requests)

We use form-submitter information only to:

  • Deliver the submission to the tenant’s inbox
  • Send the tenant an alert email containing the submission
  • Score the submission for spam so the tenant’s inbox stays clean
  • Keep a short audit record so we can investigate abuse if asked

We do not use form-submitter information for any purpose other than running the service for the tenant.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use customer data or form-submission data to train artificial intelligence or machine-learning models.

5. Legal bases for processing

Mato CRM serves US small businesses and is operated from the United States. The European General Data Protection Regulation (GDPR) is not the primary framework for this service. We process EU subjects only incidentally, when a person located in the EU happens to fill out a US tenant’s contact form. For those cases we apply equivalent safeguards (described in Section 11). We have not appointed a GDPR Article 27 representative.

For US tenants, our legal bases are:

  • Contract. We process tenant information to provide the service the tenant signed up for.
  • Legitimate interest. We process limited information to keep the service secure, prevent fraud and spam, and operate our business (for example, billing, tax records, audit logs).
  • Legal obligation. We retain certain records (such as billing data) for as long as tax law requires.
  • Consent. Where we ask for it (for example, optional product-update emails).

For form submitters, the legal basis sits with the tenant (the controller). The tenant chose to put a contact form on their site and decides why they collect the data. Our role is limited to running the pipeline.

6. Sub-processors

We use the following third-party companies (sub-processors) to operate Mato CRM. Each is bound by a written agreement that limits how they can use the information we share with them.

Sub-processorPurposeCountry of processing
Stripe, Inc.Payment processing and subscription billingUnited States (Ireland for EU subjects)
Resend, Inc.Transactional email delivery (new-lead alerts, billing notices, password resets)United States
Railway Corp.API application hosting, Postgres database, log storageUnited States (runs on top of Google Cloud and AWS infrastructure)
Vercel, Inc.Web application hosting (marketing site and customer dashboard)United States

The table above is the current sub-processor list; a standalone copy is available any time from privacy@matocrm.com. We give 30 days’ notice before adding a new sub-processor.

7. How information is protected

  • In transit. All connections use TLS (HTTPS).
  • At rest. Tenant and lead data is stored in a managed Postgres database hosted by Railway. Railway encrypts the underlying storage at rest.
  • Passwords. We store passwords as argon2id hashes. We never see the plaintext.
  • Card data. We do not store card numbers. Stripe handles payments end-to-end.
  • Access control. Only operator staff with a business need can access production. Access is logged.
  • Audit logging. Admin actions, logins, and billing events are recorded in an audit log.

We do not claim end-to-end encryption. Lead content is stored in plaintext in the database so we can deliver it to the tenant’s inbox and so the tenant can search it. We do not hold a SOC 2 or ISO 27001 certification, and we do not sign HIPAA Business Associate Agreements.

If we discover a security incident that affects your personal information, we will notify you as required by applicable law. For tenant breaches, we aim to notify within 72 hours of confirmation.

8. How long we keep information

CategoryRetention
Active leads (form submissions)24 months from creation, then deleted by an automated job
Spam-quarantined leads30 days, then deleted
Lead IP address90 days, then nulled out
Audit events7 years (then anonymized)
Tenant account informationFor as long as the account is active, plus 30 days after cancellation
Login sessions30 days, or until you log out
Billing records (Stripe-linked)7 years (US tax requirement)
Outbound email bodies30 days, then truncated to status and timestamp
Password reset and email verification tokensUntil used or expired (max 24 hours)

When a tenant cancels, we keep the data for a 30-day grace period so the tenant can export it or reactivate. After that we delete tenant and lead data, except records we are required by law to keep (mainly Stripe-linked billing records).

9. Your rights

The rights below apply under the California Consumer Privacy Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), and the Utah Consumer Privacy Act (UCPA). Other US states have similar laws; we apply the same process to all of them.

You can ask us to:

  • Know and access. Tell you what personal information we have about you and give you a copy.
  • Delete. Delete personal information we have collected from you.
  • Correct. Fix inaccurate personal information.
  • Port. Send you a copy in a machine-readable format (we provide JSON).
  • Opt out of sale, sharing, and targeted advertising. We do not sell, share, or target ads, so this is automatic. We also honor the Global Privacy Control browser signal by not engaging in any sale or share.
  • Limit use of sensitive personal information. We do not knowingly collect sensitive personal information.
  • Be free from retaliation. We will not deny service or charge you a different price because you used these rights.

You can use an authorized agent to make a request. We will ask the agent to prove they have your permission and we will verify your identity before we act.

We respond within 45 days. If a request is complex we may extend by another 45 days and tell you why.

To exercise a right, write to privacy@matocrm.com with the subject “Privacy request” and tell us what you want us to do.

10. If you submitted a contact form on a tenant’s website

We are the processor for that submission, not the controller. The tenant (the business whose website you used) is the controller and decides what to do with your message.

If you ask us to delete the submission, here is what we do:

  1. We confirm you are the person who sent the submission (we ask you to send the request from the same email address).
  2. We forward your request to the tenant. The tenant has 15 days to act or object.
  3. If the tenant authorizes deletion, or does not respond in 15 days, we delete the personal fields (name, email, phone, message, IP) and keep only a non-identifying audit record of the deletion.
  4. We log the chain in our audit system.

You can also reach out to the tenant directly — they will usually be the fastest path. The tenant is required by our Terms of Service to publish their own privacy notice on the page that hosts the form.

11. International users

The service is operated from the United States and built for US small businesses. If you are outside the US and you submit a contact form on a US tenant’s website, your information is transferred to and processed in the US. We treat incidental EU and UK submissions with safeguards equivalent to those required by GDPR (transparency, deletion on request, breach notice). We will execute Standard Contractual Clauses on request from a controller who needs them.

We do not market the service outside the US.

12. Children’s privacy

Mato CRM is not directed at children under 13. We do not knowingly collect information from children under 13. If you are a parent or guardian and you believe your child has submitted information to us, write to privacy@matocrm.com and we will delete it.

13. Changes to this policy

We may update this policy. If we make material changes, we will email tenants and update the “Last updated” date at the top. If you keep using the service after the effective date of an update, you accept the change.

14. Contact

  • Privacy questions and rights requests: privacy@matocrm.com
  • General support: support@matocrm.com
  • Operator: Mato CRM (all contact by email)
© 2026 Mato CRMTerms · Privacy · Acceptable Usematocrm.com