Account and Data Security
Convertly uses organization and role boundaries to protect CRM data. Security also depends on how each customer manages users, integrations, exports, and provider accounts.
Organization isolation
Section titled “Organization isolation”CRM records are scoped to one organization. Purpose-built application routes validate the signed-in user, organization, role, request fields, and target record before returning or changing data.
A platform support role may have controlled cross-organization capabilities required to operate the service. Tenant users do not receive cross-organization access.
Role-based access
Section titled “Role-based access”Admin, Manager, Sales, and Staff have different scopes. Sensitive actions such as tenant API-key management, Stripe account management, and permanent lead deletion require elevated tenant access.
See Roles and access.
Secrets
Section titled “Secrets”API keys, provider tokens, SMTP passwords, and other integration secrets are resolved on the server. Stored secret values are not returned to normal settings screens. Newly generated credentials may be shown once and should be copied to an approved secret store.
Never put tenant credentials in browser JavaScript, public forms, URLs, screenshots, support messages, or documentation.
Account recovery
Section titled “Account recovery”Password and protected account changes use time-limited, one-time verification challenges. Public reset requests do not reveal whether an address belongs to an account.
Public intake
Section titled “Public intake”Native forms, API intake, Meta webhooks, Stripe webhooks, and Universal Webhooks use different authentication and validation appropriate to their source. Public form embeds use a form token and must never expose a tenant API key.
Transport and provider processing
Section titled “Transport and provider processing”Use Convertly only over https://app.convertlycrm.com. Data may be sent to customer-configured or service providers when features are enabled, including Stripe, Google, Meta, email delivery, AI providers, and abuse-protection services.
Review the Privacy Policy and the relevant provider terms before enabling integrations.
Customer responsibilities
Section titled “Customer responsibilities”- Give users the least access they need.
- Remove access promptly when someone leaves.
- Review intake recipients and provider connections.
- Obtain appropriate consent for lead data and advertising events.
- Protect exported files and copied credentials.
- Define retention and recovery requirements in the applicable agreement.
Do not assume an unpublished backup, recovery, retention, or response-time guarantee. Contact support for current contractual commitments.