Privacy Policy
Last updated: July 9, 2026
Your relationships are personal, and so is your data. This Privacy Policy explains what A.R.O collects, why, the legal bases we rely on, and the rights you have — including under the EU/UK General Data Protection Regulation (GDPR). It applies to aro-pcrm.com.
Who we are (data controller)
A.R.O is operated by ARO PCRM, the data controller for your account data. For privacy questions or to exercise your rights, contact us at admin@aro-pcrm.com.
ARO PCRM · 45 S Arroyo Pkwy, Suite 1108, Pasadena, CA 91105, USA.
Information we collect
Account information — your name, email, and a securely hashed password (or, if you use Google/Microsoft sign-in, your verified email and name from that provider).
Content you add or import — contacts, notes, interactions, reminders, events, and groups.
Connected-account data — when you connect Google, Microsoft, or Apple, we access the contacts, calendar, and (where you enable it) email metadata needed to provide the features you turned on.
Technical data — a strictly necessary session cookie to keep you signed in (and a short-lived cookie during sign-in), plus minimal logs needed to run and secure the Service. If you accept analytics in our cookie banner, we also set Google Analytics cookies to measure aggregate, anonymized usage — never for advertising.
Legal bases for processing (GDPR Art. 6)
Performance of a contract — to provide the CRM you signed up for: storing your contacts, syncing, reminders, and the dashboard.
Consent — for optional integrations you choose to connect (Google/Microsoft/Apple) and optional AI features. You can withdraw consent at any time by disconnecting them or turning the feature off.
Legitimate interests — to keep the Service secure, prevent abuse, and maintain minimal operational logs.
How we use it
We use your data only to provide and improve the Service for you: organizing your contacts, syncing your calendar, generating reminders and briefings, and powering features you choose to use. We do not sell your data, and we do not use it for advertising.
Google user data and Limited Use
When you connect a Google account, A.R.O requests only the scopes needed for the features you turn on, and uses them only to provide those features to you:
Contacts (read & write) — import your Google Contacts into your private CRM and sync back contacts you add or edit in A.R.O.
Other contacts (read-only) — surface Google's auto-saved “other contacts” so you can choose to add them.
Calendar events (read & write) — show your upcoming events and create ones you add in A.R.O.
Tasks (read & write) — mirror the reminders you create in A.R.O into your Google Tasks.
Gmail send-only — send an email that you have written and approved, from your own account. A.R.O has no read, list, or modify access to your Gmail mailbox.
We do not use Google user data for advertising, we do not sell it, and no human reads it except where you explicitly ask us to (for support) or where required for security or by law.
Limited Use. A.R.O's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies
We set strictly necessary cookies (aro_session to keep you logged in, and a short-lived sign-in cookie) that are exempt from consent because the Service can't function without them. With your consent, we also use Google Analytics to understand aggregate, anonymized usage — those analytics cookies load only after you accept in our cookie banner, you can decline, and we never use them for advertising. See our Cookie Policy.
AI processing
If you use AI features (e.g. drafting a message or summarizing your network), the relevant content is sent to an AI model provider (such as Anthropic) to generate that output. We don't use your data to train models, and providers process it under their terms as our sub-processor.
Sub-processors & international transfers
We rely on a small set of processors to run the Service, each receiving only what's needed for its function: hosting and managed database (DigitalOcean); the integration providers you connect (Google, Microsoft, Apple); AI model providers for AI features you use (Anthropic, OpenAI, or xAI); payment processing (Stripe); and transactional email (Resend); plus product analytics (Google Analytics) if you accept it.
Some of these providers are located outside the EEA/UK (e.g. in the United States). Where personal data is transferred internationally, it is protected by appropriate safeguards such as the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
Contacts you add (your responsibilities)
When you import or add other people's details, you act as the controller of that data and A.R.O acts as your processor. You are responsible for having a lawful basis to store it and for honoring those people's requests. We process it only to provide the Service to you and on your instructions.
Your rights
Subject to GDPR (and similar laws), you can: access your data, correct it, erase it, restrict or object to processing, port it to another service, and withdraw consent at any time.
You can act on most of these yourself: in Settings → Your data you can export everything (JSON) and permanently delete your account and data, and in Settings → Accounts & sync you can disconnect any integration. For anything else, email admin@aro-pcrm.com and we'll respond within 30 days.
If you're in the EEA/UK and believe we've mishandled your data, you have the right to lodge a complaint with your local data protection authority.
California privacy rights (CCPA/CPRA)
If you're a California resident, you have the right to know what personal information we collect and how we use it, to access and delete it, to correct inaccuracies, to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information — and not to be treated differently for exercising any of these rights.
The categories we collect are described in “Information we collect” above: identifiers (name, email), the account content you add (contacts, notes, reminders, events), data from accounts you choose to connect, and limited technical/usage data. We collect it from you and from the services you connect, and use it solely to provide the Service.
We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes that require an opt-out — so there is nothing to opt out of. You can still exercise your access, deletion, and correction rights yourself in Settings → Your data, or by emailing admin@aro-pcrm.com (you may use an authorized agent). We respond within the timelines the law requires.
Security and protection of sensitive data
We protect your data — including sensitive data from connected accounts, such as your Google, Microsoft, and Apple contacts, calendar events, tasks, and the OAuth tokens used to send email on your behalf — with layered safeguards:
In transit — all traffic is encrypted with TLS (HTTPS) between your browser, our servers, and the provider APIs.
At rest — passwords are hashed (never stored in plain text), and API keys and OAuth access/refresh tokens are encrypted at rest using AES-256-GCM. Data is held in a managed, access-restricted database.
Access controls — every record is scoped to your own account, all access requires authentication, and each integration requests the least access needed and only reads what you approve (every import is reviewed before it is applied).
Minimization & deletion — we keep connected-account data only as long as needed to provide the feature you enabled; you can disconnect any integration, or permanently delete your account and all associated data, at any time in Settings.
No system is perfectly secure, so we also encourage strong, unique passwords and keeping your own exports.
Data retention
We keep your data while your account is active. When you delete your account, we delete or anonymize your data within a reasonable period (typically within 30 days), except where we must retain limited records to comply with the law.
Children
A.R.O is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
We'll post any changes here with an updated date. Material changes will be highlighted.
Contact
Questions or requests about your privacy? Email admin@aro-pcrm.com or use our contact page.