Nossa
Privacy Policy
Status: DRAFT — not yet in effect. Must be reviewed by counsel before Nossa CRM accepts a customer.
Last updated: 13 September 2026
1. Who we are
Nossa CRM is operated by OhSnap AR LLC ("OhSnap", "we", "us"), a limited liability company registered in the United States.
- Registered address: OhSnap AR LLC, 2222 Peachtree Rd NW, Atlanta, GA 30309, United States
- Contact: privacy@nossacrm.com
This policy covers nossacrm.com and the Nossa CRM application. nossa.app and nossacrm.app redirect here and are covered by the same policy.
2. The two roles we play, and why it matters to you
Read this section even if you skip the rest. Nossa CRM handles two different kinds of personal data under two different responsibilities.
We are the controller of your account data. When you sign up, we decide why and how we hold your name, email address and workspace settings. Questions about that data come to us.
We are a processor of the data you put into your workspace. Your contacts, their phone numbers, your conversations with them, your deal records — that is your data about your people. You decide why it exists and what happens to it. We only act on your instructions. If you are one of those contacts and want to know why a business holds your details, that business is who you ask, not us. We will help them answer you, and we will tell you who they are if you ask us.
Where OhSnap runs a workspace on a client's behalf as their agency, OhSnap is the processor for that workspace and the client remains the controller.
3. What we collect
Account data (we are the controller)
| Data | Where it comes from |
|---|---|
| Email address | You, at sign-up |
| Name | You, optionally, at sign-up |
| Password | You. We never see it — authentication is handled by Supabase Auth, which stores a hash |
| Language preference | Your choice of English or Portuguese |
| Organization and workspace names, roles and membership | You |
| Invitations you send (recipient email address) | You |
| Sign-in events and session records | Automatically, when you use the product |
Workspace content (we are the processor)
What we hold depends on what you put in. The application is capable of storing:
- Contacts — name, email address, phone number, company, preferred language, consent records, and platform identifiers such as an advertising lead ID or a social account ID
- Companies associated with those contacts
- Deals — title, value, source, stage, activity history and AI-generated suggestions
- Conversations and messages — content, direction, timestamps and the identifier the originating platform gave them
- Forms and submissions — the answers people give you, and advertising click identifiers where present
- Bookings — who, when, and against which booking page
- Automations and their run history
- Approvals — what was proposed, who decided, and what they decided
Records we keep about activity
- An append-only event ledger. Business events are recorded permanently and cannot be edited or deleted, including by us. This is deliberate: it is how advertising conversions are reconciled without being double-counted, and how an action taken by AI can be audited afterwards. See section 8 on deletion.
- AI action logs — every write made through our Claude integration, what it did, and which approval authorised it.
- API and OAuth records — which applications you have authorised, what access you granted, and when a credential was last used.
What we do not collect
We do not run advertising trackers or third-party analytics on the application. We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under California law.
4. Why we process it, and our legal basis
| Purpose | Basis (UK/EU GDPR) | Basis (LGPD) |
|---|---|---|
| Providing the product to you | Performance of a contract | Execução de contrato |
| Keeping accounts secure, preventing abuse | Legitimate interests | Legítimo interesse |
| Sending service messages about your account | Performance of a contract | Execução de contrato |
| Processing workspace content | On your documented instructions, as processor | Como operador |
| Meeting legal and tax obligations | Legal obligation | Cumprimento de obrigação legal |
| Marketing email to you about Nossa CRM | Consent, withdrawable at any time | Consentimento |
5. Artificial intelligence
Nossa CRM uses Anthropic's Claude API to draft messages, summarise threads and suggest next steps.
Three commitments:
- Nothing customer-facing is sent without a human approving it. Drafts are proposals. A person in your account approves, edits or declines each one.
- Every AI-originated write is attributed and reversible. The action log records what was done and which approval authorised it.
- Your data is not used to train models. We use Anthropic's commercial API, under terms that do not permit training on customer inputs or outputs.
You can restrict how much autonomy AI has in each workspace, and switch it off entirely with the workspace kill switch.
6. Who we share it with
We use these subprocessors. Each is bound by a contract that limits them to processing on our instructions.
| Subprocessor | What for | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | United States (us-east-1) |
| Vercel | Application hosting | United States, global edge |
| Cloudflare | DNS | Global |
| Resend (using Amazon SES) | Transactional email | United States |
| Inngest | Background job processing | United States |
| Anthropic | AI drafting and summarisation | United States |
Planned, and not yet in use — this table will be updated before each goes live: Stripe (billing), Twilio (SMS and voice), Meta, Google and LinkedIn (advertising conversion measurement, only for accounts you connect yourself).
We also disclose personal data where we are legally required to, and to professional advisers under a duty of confidentiality. If OhSnap is acquired, data may transfer to the buyer, who remains bound by this policy until you are told otherwise.
7. International transfers
Our infrastructure is in the United States. If you are in the UK, the EEA or Brazil, using Nossa CRM means your data is transferred there.
For UK and EEA transfers we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where applicable.
For transfers from Brazil we rely on the ANPD's standard contractual clauses under LGPD Article 33. [PENDING: clauses to be executed with each subprocessor before Brazilian customers are onboarded — Phase 4.]
8. How long we keep it
- Account data: while your account is open, and for up to 90 days after you close it.
- Workspace content: for as long as the controller keeps it, and deleted on their instruction.
- Ledger events: retained permanently. They are immutable by design and cannot be altered or removed, including by us.
That last point needs to be said plainly. If you ask us to erase your personal data, we will erase it everywhere we can, and we will redact the personal data inside ledger entries so that no identifying content remains — but the entry itself, its timestamp and its type, stay. We consider this necessary for the integrity of financial and advertising records. If you believe that balance is wrong in your case, tell us and we will look at it individually.
Backups persist for up to 30 days after deletion, after which they cycle out.
9. Your rights
Wherever you are, you can ask us to:
- tell you what we hold about you, and give you a copy
- correct anything inaccurate
- delete it, subject to section 8
- restrict or object to how we use it
- export it in a portable format
- withdraw consent, where consent is the basis
Write to privacy@nossacrm.com. We respond within 15 days — the LGPD deadline, which we apply to everyone rather than operating two standards.
If we are only the processor, we will forward your request to the controller and tell you who they are.
UK and EEA: you may complain to your supervisory authority — the ICO in the UK, or your national authority in the EEA. Brazil: you may complain to the ANPD. Our Encarregado (DPO) is [TO BE APPOINTED — required before Brazilian launch]. California: you have the rights described above, and we will not discriminate against you for exercising them.
10. Text messages and calls
If a business sends you a text message through Nossa CRM, that business is responsible for having your consent.
Where forms are used to collect consent, Nossa CRM requires an explicit, unticked consent checkbox — it cannot be removed by the business using it. SMS traffic is registered under A2P 10DLC, and the messages sent must match the samples registered with the carriers.
Reply STOP to any message to opt out. Opt-outs are honoured automatically and immediately, and cannot be overridden by the business that messaged you.
11. Cookies
We use strictly necessary cookies only:
| Cookie | Purpose |
|---|---|
| Supabase authentication cookies | Keeping you signed in |
nossa_locale | Remembering whether you chose English or Portuguese |
No advertising or analytics cookies are set, which is why you are not being shown a consent banner.
12. Security
Data is encrypted in transit (TLS) and at rest. Access between customers is enforced at the database level by row-level security, and that isolation is covered by an automated test suite that runs on every change. Secrets and credentials are stored only as cryptographic digests, never in readable form. Access to production is limited to people who need it.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulator as required — within 72 hours for UK/EEA regulators.
13. Children
Nossa CRM is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, write to us and we will delete it.
14. Changes
We will post any change here and update the date at the top. If a change materially affects your rights, we will email you at least 30 days beforehand.
15. Google user data
Nossa CRM asks for the Google Ads scope https://www.googleapis.com/auth/adwords so that it can read the advertising accounts you choose to connect and send conversion measurements back to them.
What we access. Only the Google Ads accounts your Google user is already permitted to see, and only after you grant access on Google's own consent screen. We do not read Gmail, Drive, Calendar, Contacts or any other Google service, and we do not request scopes for them.
What we do with it. We display your connected accounts so you can choose which workspace maps to which advertising account, and we send conversion events you have generated in Nossa CRM back to that account so your reporting reflects what actually closed. Nothing else.
Limited Use. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- we use Google user data only to provide and improve the features you connected it for
- we do not transfer it to others except as necessary to provide those features, for security purposes, or to comply with the law
- we do not use it for advertising of our own
- we do not allow humans to read it, except with your explicit consent for specific messages, where required for security or to comply with the law, or where the data has been aggregated and de-identified
Revoking access. Disconnect the account in Nossa CRM, or revoke it directly at myaccount.google.com/permissions. Revoking stops all further access immediately. Conversion records already sent to Google remain in your Google Ads account and are governed by Google's terms.
Retention. We store the OAuth refresh token and the account identifiers you connected. Both are deleted when you disconnect the account or close your workspace.
16. Contact
OhSnap AR LLC privacy@nossacrm.com
OhSnap AR LLC, 2222 Peachtree Rd NW, Atlanta, GA 30309, United States