Privacy Notice
This notice explains what personal data we handle, why, who else sees it, and how you can control it. It is written to satisfy Mexico's Federal Law on the Protection of Personal Data Held by Private Parties and, for California residents, the CCPA/CPRA.
Contents
- Who is responsible for your data
- Two different roles: your account and your contacts
- What we handle
- What we use it for
- Refusing the secondary purposes
- Who else receives it
- Transfers outside Mexico
- Your rights and how to exercise them
- Withdrawing consent
- Security, and our staff's access
- How long we keep things
- Cookies and tracking
- California residents (CCPA/CPRA)
- Minors
- Changes to this notice
1. Who is responsible for your data
inSpace Agency LLC ("inSpace", "we") is the controller of your personal data.
| Legal name | inSpace Agency LLC |
|---|---|
| State of formation | [US STATE — e.g. Delaware] |
| Address | [FULL REGISTERED ADDRESS: street, city, state, ZIP] |
| Privacy contact | privacidad@inspacecrm.com |
| Service covered | inSpace CRM, at inspacecrm.com and its subdomains |
2. Two different roles: your account and your contacts
inSpace CRM is a tool other companies use to manage their customers. That means we handle two kinds of data under two different legal responsibilities.
When you are our customer
If you registered an account, we are the controller of your account data: your name, email, phone and activity inside the system. This notice governs that.
When your data sits in someone else's CRM
If your name appears as a contact inside a workspace belonging to a company that uses inSpace CRM, that company is the controller and we are only its processor: we handle the data on their instructions and never for our own purposes.
In that case, exercise your rights with that company rather than with us. If you write to us anyway we will tell you who to approach where we can identify them, and pass your request along.
3. What we handle
3.1 Your account data (we are the controller)
| Category | Specifics | Source |
|---|---|---|
| Identity | First and last name, company name, chosen subdomain | You, at signup |
| Contact | Email address, phone number | You |
| Authentication | Password (stored only as a bcrypt hash, never in the clear) and password reset tokens | Generated by the system |
| Usage and security | IP address, last sign-in, signup and login attempts, audit log of administrative actions | Recorded automatically |
| Settings | Language, timezone, currency, credentials for services you connect (such as your email sending account) | You |
We do not handle sensitive personal data as Mexican law defines it: no racial or ethnic origin, health, genetic or biometric data, religious or philosophical belief, union membership, political opinion or sexual preference. We also ask for no financial data, because the service does not currently charge.
3.2 Data our customers load (we are the processor)
Workspaces may contain each customer's contacts — name, email, phone, company, job title, address, notes, tags and custom fields — along with the history of emails, messages, logged calls, appointments and form submissions.
What goes in those fields is the customer's decision. Our contract forbids loading sensitive data without the express consent the law requires, but we cannot inspect or guarantee what a customer enters.
4. What we use it for
Primary purposes — necessary to provide the service
- Creating and running your account and workspace.
- Verifying that the email you registered is yours, before granting access.
- Authenticating you and keeping your session.
- Sending service messages you cannot opt out of: email confirmation, password resets, security notices and changes to this notice.
- Enforcing your plan's limits and preventing abuse, automated signup and fraud.
- Providing support when you ask for it.
- Meeting legal obligations and responding to lawful requests from authorities.
Secondary purposes — you can refuse these and keep the service
- Product news and informational content.
- Invitations to surveys or product research interviews.
- Aggregate, non-identifying usage statistics that inform what we build.
5. Refusing the secondary purposes
Email privacidad@inspacecrm.com with the subject "Secondary purposes", from the address you registered with. You have five business days from when this notice is made available to you, and you may also do it at any time afterwards.
Today we only send you email your account cannot work without — verification, password recovery and service notices — which carries no unsubscribe link because there is nothing to unsubscribe from short of closing the account. If we ever send you informational or promotional email, each one will carry its own link to stop receiving them.
6. Who else receives it
We do not sell your personal data, or exchange it for anything of value. We do not share it with advertisers or social networks. The service carries no analytics, no tracking pixels and no third-party advertising.
| Provider | What it receives | Why | Where |
|---|---|---|---|
| [HOSTING PROVIDER] | All service data, by virtue of hosting it | Hosting the application and database | [COUNTRY] |
| Mailgun Technologies, Inc. | Recipient address and message content | Delivering service email | United States or European Union, depending on the configured region |
| Google LLC (Google Fonts) | Visitor IP address and browser details | Serving the interface typefaces | United States |
| jsDelivr and cdnjs | Visitor IP address and browser details | Serving interface libraries and icons | Global delivery network |
These transfers do not require your consent, being necessary to perform the agreement between us. Any transfer that would require consent will be disclosed and requested separately, before it happens.
We may also disclose data where an authority lawfully requires it, or to protect people's rights, safety or property.
7. Transfers outside Mexico
You should know this plainly: inSpace Agency LLC is a US company, and the infrastructure serving the product sits outside Mexican territory. If you are in Mexico, your data is transferred and stored abroad from the moment you create an account.
By registering and accepting this notice you consent to that international transfer. The United States has no adequacy finding equivalent to the Mexican framework, so the protection you receive is the one this notice describes and the one our contracts with providers require.
8. Your rights and how to exercise them
For data we control, you may request:
- Access — what we hold about you and how we use it.
- Rectification — correction of data that is wrong or incomplete.
- Cancellation — deletion, where no legal duty requires us to keep it.
- Objection — objection to a specific use, for a legitimate reason.
Send your request to privacidad@inspacecrm.com with:
- Your name and an address where we can reply.
- Proof of identity, or of authority if you act on someone's behalf.
- A clear description of which data and which right.
- For rectification, the exact correction and supporting documentation.
We answer within twenty business days and, where the request succeeds, act on it within fifteen business days after that. There is no charge, except reproduction or delivery costs if you ask for copies on physical media.
If you believe your request was mishandled you may complain to the competent Mexican data protection authority. [CONFIRM WITH COUNSEL: following the 2025 reform, INAI's functions moved to the Secretaría Anticorrupción y Buen Gobierno; verify the current name and procedure before publishing.]
9. Withdrawing consent
You may withdraw consent at any time by writing to the same address. Withdrawing it for the primary purposes means we can no longer provide the service, and your account will be closed.
10. Security, and our staff's access
The technical detail — what is protected, how, and how we check it — is at inspacecrm.com/security. The essentials:
- Passwords are stored as bcrypt hashes. Nobody, including us, can read them.
- Traffic is encrypted with TLS.
- Every workspace is isolated: queries filter by workspace, and session cookies are host-only per subdomain, so a session cannot cross from one customer to another.
- API keys are stored only as hashes and shown once.
Our staff's access to your account. Authorised inSpace staff can enter a customer's account to provide support or fix a fault. When that happens, both entering and leaving are written to the audit log with who did it and when. It is real access to personal data, which is why we state it here rather than omit it.
No system is infallible. If a breach materially affects your rights, we will tell you without delay so you can act.
11. How long we keep things
| Data | Retention |
|---|---|
| Active account and workspace | For as long as the account exists |
| Unverified signup's subdomain | Released automatically after 7 days |
| API rate-limit counters | Purged after 5 minutes |
| Audit log, access records and IP addresses | Not deleted automatically. Kept while the account exists and for as long as they may be needed to evidence compliance |
| Contacts and their history inside a workspace | Controlled by the customer responsible for that workspace; deleted when they delete them |
When you close your account we delete or block your data, except what we must keep to meet a legal obligation or to defend a claim.
12. Cookies and tracking
We use no advertising, analytics or cross-site tracking cookies. There is no Google Analytics, no Meta pixel, no session recording.
| Cookie | Purpose | Lifetime |
|---|---|---|
PHPSESSID | Keeping you signed in and protecting forms against cross-site request forgery | Up to 2 hours of inactivity |
| Language preference | Remembering whether you read the site in Spanish or English | For the session |
Note that loading typefaces and icons from the providers in section 6 sends your IP address to those services, even though we set no cookie that way.
13. California residents (CCPA/CPRA)
If you live in California, the CCPA gives you additional rights. We offer them regardless of whether we currently meet the thresholds that make that law mandatory.
| CCPA category | Collected | Source |
|---|---|---|
| Identifiers (name, email, phone, IP, account id) | Yes | You and automatic logs |
| Commercial information (plan, service usage) | Yes | System records |
| Internet or network activity (which parts of the service you use) | Yes | System records |
| Professional or employment information (company, job title) | Yes | You |
| Precise geolocation | No | — |
| Sensitive categories (origin, health, biometrics, sexual orientation) | No | — |
| Biometric information | No | — |
Your rights
- Know what personal information we collect, use and disclose.
- Delete the personal information we hold, subject to the exceptions the law allows.
- Correct inaccurate information.
- Non-discrimination for exercising any of these. You will not get a different service or price for asking.
- Limit the use of sensitive information — not applicable, because we collect none.
We do not sell or share personal information in the sense the CCPA/CPRA gives those terms, including cross-context behavioural advertising. We have not done so in the preceding twelve months and do not intend to. That is why there is no "Do Not Sell or Share My Personal Information" link: there would be nothing to switch off.
To exercise these rights, email privacidad@inspacecrm.com. We will verify your identity before responding. You may use an authorised agent, who must prove their authorisation.
14. Minors
The service is aimed at businesses, not minors. We do not knowingly collect data from anyone under 18 in Mexico or under 13 under US law. If you learn that a minor has given us data, write to us and we will delete it.
15. Changes to this notice
We may update this notice when the law, the service or our practices change. The current version always lives at inspacecrm.com/privacy, with its version number and date. If a change materially affects how we handle your data, we will email you at least thirty calendar days before it takes effect, so you can object or close your account.