Privacy Policy
Last updated: July 12, 2026
1. Who we are
Power CRM ("Power CRM", "we", "us") is an application distributed through the GoHighLevel marketplace and installed by agencies into their own GoHighLevel accounts. This policy explains what data the application accesses, why, where it is stored, who else processes it, how long we keep it, and how it is deleted.
Contact for any privacy matter, including access, correction and deletion requests: support@power-crm.com.
Roles. For the CRM data inside your GoHighLevel account, you are the data controller and Power CRM acts as a data processor on your instructions. For the information you give us directly — a demo request, a support ticket, an account login — we are the controller.
2. The OAuth scopes we request
When you install Power CRM you complete GoHighLevel's OAuth flow and choose which locations (sub-accounts) the application may access. Power CRM currently requests the full GoHighLevel marketplace scope set — 140 scopes, requested unconditionally at install regardless of which modules you enable, listed by category below. We are disclosing the complete surface rather than a summary, because the token you grant is capable of everything in this list, whether or not a given module uses it today. The scopes we actively exercise are the contact, custom field, custom value, location, user, calendar, appointment, conversation/message and media scopes; the remainder are requested but unused at present. We are working to narrow the request to only the scopes the product exercises.
- Contacts —
contacts.readonly,contacts.write. - Custom data —
locations/customFields.*,locations/customValues.*,objects/record.*,objects/schema.*,associations.*,associations/relation.*(read and write). - Locations, companies, users —
locations.readonly,locations.write,locations/templates.readonly,locations/tags.*,businesses.readonly,businesses.write,companies.readonly,users.readonly,users.write,marketplace-installer-details.readonly. - Calendars and tasks —
calendars.*,calendars/events.*,calendars/groups.*,calendars/resources.*,locations/tasks.*,recurring-tasks.*(read and write). - Conversations and messaging —
conversations.*,conversations/message.write,conversations/message.readonly,conversations/livechat.write,conversations/reports.readonly,campaigns.readonly. The message-write scope is what lets the app send the onboarding reminders described in section 6. - Telephony —
phonenumbers.read,numberpools.read,twilioaccount.read(read access to the location's connected Twilio/LeadConnector telephony account). - Payments and commerce —
payments/orders.collectPayment,payments/orders.*,payments/transactions.readonly,payments/subscriptions.readonly,payments/coupons.*,payments/integration.*,payments/custom-provider.*,charges.write,charges.readonly,invoices.*,invoices/estimate.*,invoices/schedule.*,invoices/template.*,products.*,products/prices.*,products/collection.*,store/setting.*,store/shipping.*. These include the ability to write charges and collect payment on an order. Power CRM does not use them today and takes no payment through your GoHighLevel account, but the granted token permits it. - Content and marketing —
blogs/post.write,blogs/post-update.write,blogs/list.readonly,blogs/posts.readonly,blogs/author.readonly,blogs/category.readonly,blogs/check-slug.readonly,socialplanner/post.*,socialplanner/account.*,socialplanner/oauth.write,socialplanner/oauth.readonly,socialplanner/csv.*,socialplanner/tag.*,socialplanner/category.*,socialplanner/statistics.readonly,emails/builder.*,emails/schedule.readonly,funnels/*,forms.*,surveys.readonly,workflows.readonly,links.*,courses.*,wordpress.site.readonly,custom-menu-link.*,brand-boards/design-kit.*. This includes writing blog posts and connecting social accounts. Unused today. - AI and voice —
conversation-ai.*,agent-studio.*,voice-ai-agents.*,voice-ai-agent-goals.*,voice-ai-dashboard.readonly,knowledge-bases.*. Unused today. - Documents, opportunities, media —
documents_contracts/*,documents_contracts_template/*,opportunities.*,medias.readonly,medias.write. - OAuth —
oauth.readonly,oauth.write.
What we actually read and store is much narrower than what we are permitted to: contacts and their custom field values, location custom fields/folders/values, locations and companies, users, calendars and appointments (with notes), conversation/message events, and media such as a client logo. If you want the exact request payloads for your install, email support@power-crm.com.
We also receive GoHighLevel webhooks (contact create/update/delete, contact custom field and tag changes,
message inbound/outbound, appointment create/update/delete, location create/update, and
app.uninstall). In production, every inbound webhook is signature-verified (RSA-SHA256 against
GoHighLevel's published public key) and an unsigned or invalid request is rejected with a 401.
We do not sell your data or your clients' data. We do not use it to train AI models. We do not use it for advertising.
3. Data you give us directly
- Demo, pricing and support forms — your name, work email, agency name, sub-account count, and whatever you write in the message. Used to reply to you and to quote you.
- Account credentials — if you use the standalone (non-SSO) login, an email address and a password stored only as a bcrypt hash. We never store your password in a recoverable form.
- Data you enter into the application — onboarding field values, documents, meeting notes and agendas, custom values, and any credentials you choose to store in a secret field.
- Error reports — when the application encounters a client-side error, technical details of that error are recorded server-side so we can fix it.
4. Where the data is stored
Power CRM stores data in a MongoDB database that we operate. Cached CRM data, the pending write queue, onboarding configuration and status, documents, meeting records, appointment mirrors, custom values, crawled website content and OAuth tokens are all held there. Data is encrypted in transit (TLS) and access to the production database is restricted to the personnel who operate the service.
The cache exists for two reasons: to serve reads without calling the GoHighLevel API on every page load, and to hold writes durably in a queue so an edit is not lost when the CRM API is rate-limited or unavailable. GoHighLevel remains the source of truth.
5. Sub-processors
The following third parties may process data on our behalf, strictly to deliver a feature you have enabled:
- GoHighLevel (HighLevel Inc.) — the CRM the application is installed into and the source of the CRM data. Always in scope.
- AI providers — depending on the provider you configure in AI settings: Anthropic (directly or via the Claude connection), OpenRouter, or OpenAI. When you use AI field generation, the AI assistant, the field-description generator or meeting action items, the relevant client context (field values and crawled website content) is sent to the configured provider to produce the response. If you do not enable the AI modules, no data is sent to an AI provider.
- Telnyx — carriage for the Fax module: sending and receiving faxes and provisioning fax numbers. Only in scope if you enable Fax.
- Google (Places / Business Profile) — the Google Business lookup used by AI field generation, to verify a client's public business details. Only in scope if a Places key is configured.
- Google Drive — when you use AI image selection against a client's Drive folder, to list and retrieve those images. Only in scope if you use that feature.
- agentsrecon — the website crawl / scrape service that retrieves the public pages of a client's website to build the knowledge base that grounds the AI features, and that powers Brand Fetch. Public web content only.
- Apollo.io — third-party business and contact enrichment, used by the lead module to look up company and person data. Only in scope if you use lead enrichment.
- Explorium — the alternate third-party enrichment provider for the same lead module. Only in scope if you use lead enrichment.
- emails4agents — the transactional email transport for mail Power CRM sends from its own systems (for example, inbound-fax notifications). Note: onboarding reminders to your clients are not sent through this transport — they go out through GoHighLevel itself (see section 6).
- Cloud hosting — the infrastructure provider that runs the application and its MongoDB database.
Email support@power-crm.com for the current sub-processor list at any time.
6. Automated email and SMS we send to your clients on your behalf
If you enable onboarding reminders, Power CRM contacts your clients to ask them to supply the onboarding information you have flagged as missing. It sends both email and SMS text messages:
- Email — up to twice a day, at 6:00 AM and 4:00 PM in the client's local timezone.
- SMS — in the 4:00 PM window, every 3 days, starting on day 0.
Both are sent through your own GoHighLevel account — from your location's connected email and phone number, on your instruction, with Power CRM acting as your processor. Reminders stop automatically when onboarding reaches 100%, when the client's status leaves onboarding, and are skipped when the client has touched a field in the last 4 hours. A 20-hour de-duplication guard prevents double sends.
Messaging consent (A2P 10DLC / TCPA). Because these messages go out from your number, under your brand, you are the sender and you are responsible for compliance. Before you enable SMS reminders you must have obtained the recipient's prior express written consent to receive automated text messages at that number, and that consent must be documented. Consent to receive marketing or automated messages is not a condition of purchase of any product or service. Message frequency is as described above and may vary. Message and data rates may apply. Recipients can reply STOP to opt out at any time and HELP for help; opt-outs are honoured by GoHighLevel's messaging platform, which is the carrier-facing sender. You are also responsible for maintaining a registered A2P 10DLC brand and campaign for the number you send from, and for having a lawful basis (and, where required, consent) to contact your own clients by email. If you cannot meet those conditions, leave onboarding reminders disabled.
7. Retention and deletion
- On uninstall. When you remove Power CRM from GoHighLevel, the
app.uninstallwebhook fires and we delete, for the affected location: your installation record, the stored OAuth tokens, webhook events and webhook logs, audit logs, the contact field cache, the cached GoHighLevel custom fields and field folders, the pending field-sync queue, and the location record itself.
We must be straight with you about what that does not cover. The automatic uninstall cleanup does not currently delete the following, which remain in our database until you ask us to remove them: your client records, appointments, sync cache, conflict records, contact mappings, custom field values, custom field history and field history, onboarding field status and flagged fields, crawled website content, cached brand data, client documents, meeting agendas and transcripts, leads, and fax settings. We also delete the stored tokens locally rather than calling GoHighLevel's revocation endpoint — deleting the record means we can no longer use them, but you should also remove the app's authorisation in GoHighLevel if you want the grant itself withdrawn. Sync workers are not selectively stopped on uninstall; they simply find no installation or token to act on for that location.
To have everything deleted, email support@power-crm.com and ask for full deletion. We will purge all remaining records for your account and confirm, within 30 days. Data inside your GoHighLevel account is never touched. - On request. Email support@power-crm.com and we will delete your account data. We action deletion requests within 30 days.
- While you are a customer. Cached CRM data is retained for as long as the app is installed, because that is what makes it work. Documents, onboarding history, field history and meeting records are retained until you delete them or terminate.
- Backups. Deleted data may persist in encrypted operational backups for a limited period before being overwritten on the ordinary backup rotation.
- Logs. Operational and error logs are retained for a limited period for security and debugging.
8. Your rights (GDPR / UK GDPR)
If you are in the EEA or the UK, you have the right to access, rectify, erase, restrict processing of, and port your personal data, and to object to processing. Where we act as a processor for CRM data belonging to your clients, direct those requests to your agency as the controller — we will assist you in fulfilling them.
Our lawful bases are: contract (providing the service you installed), legitimate interests (securing and improving the service, replying to your enquiries), and consent where you have given it. Exercise any right by emailing support@power-crm.com. You also have the right to lodge a complaint with your supervisory authority.
International transfers. Our infrastructure and sub-processors may process data outside your country. Where personal data is transferred out of the EEA or the UK, we rely on appropriate safeguards, including Standard Contractual Clauses with the relevant sub-processor.
9. Your rights (CCPA / CPRA — California)
California residents have the right to know what personal information is collected, to access and delete it, to correct it, to opt out of its sale or sharing, and not to be discriminated against for exercising those rights.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. With respect to CRM data belonging to your clients, Power CRM is a service provider and processes it only to perform the service. Exercise your rights by emailing support@power-crm.com; we will verify your request and respond within the statutory timeframe.
10. Security
Data is encrypted in transit. Passwords for the standalone login are bcrypt-hashed and authentication endpoints are rate-limited. Inbound webhooks are signature-verified. Secret custom values are held behind an explicit reveal step so access to a stored credential is a deliberate, recorded action. Access to production systems is limited to the personnel who need it.
No system is perfectly secure. If you believe you have found a vulnerability, email support@power-crm.com with "SECURITY" in the subject line, and please give us a chance to fix it before disclosing it publicly.
11. Cookies and analytics
This marketing website uses only what is necessary to serve the pages, plus — where enabled — a privacy-respecting analytics tag loaded after the page has finished rendering, to count visits. The application itself uses cookies and local storage strictly to keep you signed in and to hold your interface preferences. We do not run advertising trackers on this site.
12. Children
Power CRM is a business tool. It is not directed at children and we do not knowingly collect personal information from anyone under 16.
13. Changes to this policy
If we make a material change to this policy we will update the date at the top and, for material changes affecting how we process your data, notify installed customers by email.
14. Contact
Privacy questions, data requests and complaints: support@power-crm.com. See also our Terms of Service.