Privacy Policy

How Telegram CRM collects, uses, and protects your data.

Last updated: August 9, 2026

1. Introduction

Telegram CRM (“we”, “us”, “our”) provides a multi-tenant platform for managing Telegram bots, contacts, campaigns, and automations. This Privacy Policy explains what information we process when you use our website, dashboard, and API.

By creating an account or using the service, you agree to the practices described here. If you do not agree, please do not use the service.

2. Information we collect

Account & workspace data

When you register we collect your name, email address, organization name, and authentication credentials (stored as a secure password hash).

Telegram & contact data

When you connect a bot we store bot metadata, encrypted bot tokens, webhook configuration, and messages exchanged between your bot and its users. Contact profiles may include Telegram ID, username, names, tags, custom fields, notes, and assignment metadata.

Usage & technical data

We collect logs needed to operate the service: IP addresses, browser type, API requests, error reports, billing events, and product analytics. If you configure outbound webhooks or API keys, related delivery metadata is stored.

Payment data

Paid subscriptions are processed by Stripe. We store Stripe customer and subscription identifiers; we do not store full card numbers on our servers.

3. How we use information

We use collected data to:

- Provide and maintain the Telegram CRM platform - Deliver inbox, campaigns, automations, and bot flows - Authenticate users and enforce role-based access - Send transactional emails (invitations, password reset, notifications) - Monitor abuse, enforce limits, and improve reliability - Comply with legal obligations

We do not sell your personal data or contact lists to third parties.

4. Telegram & third-party services

Telegram CRM integrates with the Telegram Bot API. Message content and user identifiers are processed to provide inbox and automation features. Telegram’s own terms and privacy policy apply to end users interacting with your bots.

We may use subprocessors such as hosting providers, email delivery (e.g. Resend or SMTP), payment processing (Stripe), and optional error monitoring (e.g. Sentry). Each is used only to deliver the service.

5. Data retention

We retain account and workspace data while your subscription is active. Message history, contacts, and audit logs are kept according to your plan and operational needs.

When you delete data or close an account, we remove or anonymize information within a reasonable period, except where retention is required for security, billing, or legal compliance.

6. Security

We protect data using industry-standard measures including encrypted bot tokens (AES-256), HTTPS in transit, role-based access control, signed webhooks, and rate limiting.

No method of transmission or storage is 100% secure. You are responsible for safeguarding your account credentials and API keys.

7. Your rights

Depending on your jurisdiction you may have the right to access, correct, export, or delete personal data we hold about you.

Workspace owners can export contacts and manage team access from the dashboard. To request account deletion or a copy of your data, contact us using the details below.

8. Cookies & local storage

We use essential cookies and browser storage to keep you signed in, remember locale/theme preferences, and protect against abuse. We do not use third-party advertising cookies on the core product.

9. International transfers

Your data may be processed in countries other than your own, wherever our infrastructure or subprocessors operate. We take steps to ensure appropriate safeguards when data crosses borders.

10. Contact us

Questions about this policy or your data?

Email: hello@telegramcrm.app

Or use the contact form at /contact.