Pay2All legal

Privacy Policy

How Pay2All handles account, CRM, integration, and Google user data.

Effective and last updated: July 19, 2026

On this page

1. Overview

This Privacy Policy explains how Pay2All collects, uses, stores, and shares information when you visit our website, create an account, use the CRM, or connect an external service. It also explains the choices and rights available to you.

Organizations using Pay2All decide what customer and business information their users enter into the CRM. For that information, the organization is responsible for providing appropriate notices and having a lawful basis to process it. Pay2All processes that information to provide the service to the organization.

2. Information we collect

Depending on the features you use, we may collect:

  • Account information such as name, work email, phone number, company, role, and login credentials.
  • CRM records such as leads, contacts, accounts, deals, tasks, follow-ups, notes, and activity history.
  • Files and business records such as proposals, quotations, identity or KYC documents, and uploaded documents.
  • Billing and operational records such as subscription selection, wallet entries, and transaction references. We do not treat CRM wallet balances as bank deposits.
  • Integration data such as connected-account email addresses, encrypted OAuth tokens, configuration details, and user-initiated actions.
  • Technical data such as IP address, browser and device information, authentication cookies, page URLs, timestamps, and security logs.
  • Support messages and other information you choose to send us.

3. How we use information

  • Provide, operate, maintain, and secure the CRM and its public pages.
  • Authenticate users, enforce roles and permissions, prevent abuse, and troubleshoot incidents.
  • Store and organize business records, generate documents, and carry out actions requested by users.
  • Connect user-selected services such as Gmail and Google Drive.
  • Respond to support requests and send essential service communications.
  • Improve reliability and functionality using aggregated operational information.
  • Comply with applicable law and enforce our agreements.

4. Google user data and Gmail

Gmail is optional. When you choose Connect Gmail, Pay2All requests permission to identify the connected Google account and send email through that account. The requested Gmail permission is gmail.send. We do not request permission to read, search, download, or delete your Gmail inbox.

We store the connected email address and encrypted OAuth access and refresh tokens so the connection can work. When you direct the CRM to send an email, the recipient, subject, message, and any selected attachment or secure proposal link are transmitted to Google for delivery. The CRM may record the recipient, subject, delivery event, and linked CRM record in its activity timeline.

Google user data is used only to provide the user-facing Gmail sending feature. We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or allow people to read it except when necessary for security, support with your consent, legal compliance, or service operation. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Gmail from CRM settings at any time, which deletes the stored connection tokens from the CRM. You can also revoke access from your Google Account security settings. Revocation does not remove emails already sent or ordinary CRM activity records retained by your organization.

5. AI-assisted features

If your organization enables an AI provider, the CRM may send the instructions and relevant deal, customer, company, product, or pricing context needed to generate a requested draft. AI-generated proposals remain editable and should be reviewed before use. Your organization selects and configures the provider, and that provider processes the data under its own terms and privacy policy.

6. When information is shared

We may share information only as needed with:

  • Your organization, its administrators, and users according to configured permissions.
  • Hosting, database, email, file storage, authentication, monitoring, and support providers working for us.
  • Integrations you or your organization deliberately enable, including Google and configured AI or payment providers.
  • Authorities or other parties when reasonably necessary to comply with law, protect rights and safety, or investigate fraud and abuse.
  • A successor in connection with a merger, financing, reorganization, or sale, subject to appropriate confidentiality protections.

We do not sell personal information or Google user data.

7. Retention and deletion

We retain information while an account or organization is active and as needed to provide the service, satisfy legal and accounting requirements, resolve disputes, prevent abuse, and enforce agreements. Retention can vary by record type and organization settings. Authorized users may delete many CRM records and disconnect integrations in the product. For an account or privacy request, contact us at admin@pay2allservices.com.

8. Security

We use safeguards designed to protect information, including encrypted transport, protected authentication cookies, role-based access controls, secret encryption, and access restrictions. No service can guarantee absolute security. Keep your credentials confidential, use available multi-factor authentication, and notify us promptly of suspected unauthorized access.

9. Your choices and rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection regarding your personal information, and may withdraw consent where processing relies on consent. If an organization controls the CRM record, contact that organization first; we will assist it where appropriate.

You can manage integration permissions in CRM settings, revoke Google access through your Google Account, and control browser cookies through browser settings. Blocking essential authentication cookies may prevent the service from working.

10. Children

The service is intended for businesses and authorized adult users. It is not directed to children, and we do not knowingly collect personal information directly from children through account registration.

11. Changes and contact

We may update this policy to reflect changes to the service, law, or our practices. We will update the date at the top and provide additional notice when appropriate. Questions, complaints, and privacy requests can be sent to admin@pay2allservices.com.

Questions about this policy?

Contact our support team for assistance.

admin@pay2allservices.com