1. Scope and privacy roles
This Privacy Policy describes how TEN LLC ("Ten CRM," "we," "us," or "our") handles personal information in connection with tencrm.app, the Ten CRM product preview, the pre-launch waitlist, launch and support communications, and, when available, the Ten CRM service.
Pre-launch notice. Ten CRM is still in development and is currently targeting a Q1 2027 launch window. The current public site and waitlist are live; the production CRM is not yet generally available. The Q1 2027 window is a target, not a guaranteed release date. Where this policy describes planned production practices, we identify them as intended or launch requirements. We will update this policy before accepting production customer CRM data if the final implementation materially differs.
When Ten CRM decides why information is used
For website visitors, waitlist members, business contacts, support correspondents, and Ten CRM account administration, Ten CRM generally acts as the business or controller that determines why and how the information is processed.
When a customer controls CRM content
For customer-controlled CRM records placed into the production service - such as a customer's own contacts, companies, deals, notes, tasks, and activity history - Ten CRM expects to act primarily as a service provider or processor on behalf of the customer. The customer remains responsible for deciding what data it puts into Ten CRM and for having an appropriate legal basis to use that data.
2. Categories of information we collect
Information you provide directly
- Waitlist and early-access information: first and last name, work email, company name, team size, current CRM, product complaints, requested features, referral source, and other information you choose to submit.
- Communications: information contained in messages sent to hello@tencrm.app, support@tencrm.app, or other Ten CRM communication channels.
- Account and workspace information, when launched: account identifiers, workspace membership, role, authentication and security settings, preferences, and administrative configuration.
- Customer CRM content, when launched: contacts, companies, deal records, notes, tasks, activity history, email-template content, imports, integration configuration, and other information a customer chooses to store in Ten CRM.
- Billing information, when launched: billing contact, subscription status, transaction metadata, and related records. We intend to use a payment provider so raw payment-card data is handled by that provider rather than stored directly by Ten CRM.
Technical, device, and security information
Our infrastructure may process IP address, browser and device information, request headers, timestamps, approximate geographic region inferred from network information, error and diagnostic data, anti-abuse signals, security events, and similar technical information needed to deliver and protect the service.
Information the current site does not request
The pre-launch site does not request payment-card information, government identification numbers, precise geolocation, health information, biometric identifiers, or consumer advertising profiles.
3. Sources of information
We obtain information from:
- you, when you submit the waitlist form, contact us, use a preview, or later use Ten CRM;
- your employer or workspace administrator, if they create or manage a business account for you;
- customers that upload or connect business records to Ten CRM;
- service providers that help us operate, secure, and support the service; and
- integrations that a customer intentionally connects to Ten CRM.
4. Why we use information
We may process information to:
- operate the website, waitlist, product preview, and future CRM service;
- reserve launch spots and send early-access, launch, transactional, security, and service communications;
- authenticate users, manage workspaces, and enforce permissions;
- provide customer support and investigate reported problems;
- protect the service against fraud, spam, abuse, unauthorized access, and security incidents;
- maintain, debug, measure, and improve product performance and reliability;
- understand feature demand and prioritize product development;
- process subscriptions and maintain business records when paid service begins;
- comply with legal obligations, preserve rights, respond to lawful requests, and enforce agreements; and
- carry out a merger, financing, acquisition, reorganization, or sale of assets subject to applicable law.
Legal bases where applicable
Where laws such as the GDPR require a legal basis, Ten CRM may rely on performance of a contract, steps requested before entering a contract, legitimate interests in operating and securing a business service, consent where required, and compliance with legal obligations. If we rely on consent, you may withdraw it subject to applicable law.
5. Customer CRM data
Customer CRM content belongs to the customer or its licensors; Ten CRM does not claim ownership of customer business records merely because they are stored in the service. Our production design is intended to use customer data only to provide, secure, maintain, and support the service; follow customer instructions; comply with law; and improve the product using information that does not identify a customer or individual where feasible.
Before paid launch, Ten CRM intends to publish product-specific terms covering customer data, account deletion, export, retention, subprocessors, and any data-processing terms applicable to the service.
8. AI and customer data
Ten CRM is not being built around mandatory AI. The planned approach is customer-controlled, bring-your-own-provider integrations for specific functions that are useful - for example, drafting an email, summarizing a thread, or cleaning up notes.
- No core AI requirement: the CRM is intended to work without connecting an AI provider.
- No Ten CRM-owned general-purpose model training: Ten CRM does not plan to train a Ten CRM-owned general-purpose AI model on customer CRM content.
- Customer choice: AI-assisted features should require a workspace to intentionally enable a supported provider or feature.
- Provider terms apply: information sent to an external AI provider is also handled under that provider's agreement and privacy terms.
- Minimize what leaves Ten CRM: our design goal is to send only the information necessary for the customer-requested AI action and to document the data flow before enabling production integrations.
9. Sale, sharing, targeted advertising, and data brokerage
Ten CRM does not currently sell personal information. Ten CRM does not currently share personal information from the pre-launch site for cross-context behavioral advertising or targeted advertising. Ten CRM does not operate a data-broker business and does not intend to use customer CRM content to build third-party advertising audiences.
If those practices ever materially change, we will update this policy and provide legally required choice mechanisms before the new practice begins.
10. Retention and deletion
We retain information for only as long as reasonably necessary for the purposes described in this policy, subject to legal, tax, accounting, security, backup, dispute-resolution, and recordkeeping needs.
- Waitlist records: generally through the launch period and for up to 24 months after our last meaningful interaction, unless you ask us to delete the record sooner or law requires longer retention.
- Support and business communications: retained as reasonably necessary to answer the request, maintain business records, resolve disputes, and protect the service.
- Security logs: retained for periods appropriate to incident detection, abuse prevention, and investigation.
- Production CRM data: specific active-account, expired-trial, backup, export, and deletion periods will be published before paid launch.
Deletion from active systems may not immediately remove information from encrypted backups or legally required records. Backup copies will be handled according to the retention schedule applicable to those systems.
11. Security
We use administrative, technical, and organizational measures appropriate to the service and its stage of development. The current waitlist uses HTTPS, Cloudflare edge protection and Turnstile, server-side request validation, hidden server-side secrets, a non-public database path, and restricted database permissions. The production CRM is being designed around tenant isolation, least privilege, managed authentication, role-based access, private tenant-scoped document access, protected integration credentials, backups, audit-relevant logging, secure deployment access, and documented incident procedures.
No service can guarantee absolute security. If you believe you found a vulnerability, contact support@tencrm.app and see our Security Overview.
12. Your privacy choices and rights
Email choices
You may unsubscribe from non-essential launch or marketing messages using the unsubscribe link provided in the message or by contacting us. We may still send transactional, account, security, or legally required communications when applicable.
Access, correction, deletion, and portability
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a portable copy of certain personal information. You may also have rights to restrict or object to processing, opt out of certain uses, or appeal a decision.
U.S. state privacy rights
Residents of Colorado, California, Connecticut, Virginia, and other jurisdictions may have specific rights under applicable state privacy laws. Where those laws apply to Ten CRM, we will honor applicable rights and non-discrimination requirements. Because Ten CRM does not currently sell personal data or use the pre-launch site for targeted advertising, there is no current sale/targeted-advertising opt-out to exercise.
EEA, UK, and Switzerland
Where applicable, individuals may have rights to access, rectify, erase, restrict, port, or object to processing, withdraw consent, and lodge a complaint with a competent supervisory authority.
Submitting a request
Email hello@tencrm.app with enough information for us to understand the request. We may need to verify identity or authority before completing it. Authorized agents may submit requests where permitted by law.
13. International data transfers
Ten CRM is based in the United States, and our providers may process information in the United States and other countries. Those locations may have privacy laws that differ from your home jurisdiction. Where required, Ten CRM intends to use legally recognized transfer mechanisms or contractual safeguards for restricted international transfers.
14. Children
Ten CRM is a business product and is not directed to children. We do not knowingly collect personal information from children under 13 through the pre-launch site. If you believe a child has submitted information to us, contact hello@tencrm.app so we can investigate and delete it where appropriate.
15. Changes to this policy
We may update this policy as Ten CRM develops, laws change, or our vendors and product architecture change. We will update the "Last updated" date and provide additional notice when required by law or when a change materially affects how customer or user information is handled.
16. Contact Ten CRM
TEN LLC operates tencrm.app and Ten CRM.