Privacy Policy
How TruxCRM collects, uses, stores, and protects information when you use our website and platform.
Last updated: 27 June 2026
This Privacy Policy explains how TruxCRM, a software product owned and operated by GrowAx Enterprises, based in Lahore, Pakistan ("TruxCRM", "we", "us", or "our"), handles information in connection with our marketing website at truxcrm.com and our application at app.truxcrm.com (together, the "Service"). By using the Service, you agree to this Policy.
Contents
- Our role
- Information we collect
- What we do not collect
- Cookies
- How we use information
- Email sending
- AI assistant
- Service providers
- Where data is processed
- Security
- Retention
- Your choices
- Broker responsibilities
- Children
- Changes
- Contact
1. Our role
We provide a multi-company CRM. Each broker company ("Customer") manages its own records inside its own company-scoped workspace. With respect to information a Customer enters about its end customers, carriers, and operations ("Customer Data"), the Customer is the controller and TruxCRM is the processor acting on the Customer's instructions. With respect to a Customer's own account and the operation of the Service, we act as a controller.
2. Information we collect
Account and business information
When a company account is created, we collect business details (such as company name, address, contact details, and any MC/DOT or license numbers entered), and user details for admins and agents (name, email address, phone number, and a password, which is stored only in hashed form).
Customer and operational data you enter
The Service stores the records you create, including leads, quotes, orders, customer contact details, vehicle information, pickup and delivery locations, carrier and dispatch information, payment-history notes, tasks, and documents you generate or upload (such as signed order PDFs, invoices, and insurance files).
Email configuration and logs
If you connect an email account to send messages, we store the configuration you provide (such as SMTP host, username, and From address). Sensitive credentials, such as email passwords or API keys, are stored in encrypted form. We also keep limited logs of messages sent through the Service (such as recipient, subject, type, and status) for delivery tracking and support.
Technical and usage data
When you use the Service we automatically receive standard technical data, such as IP address, browser type and user agent, timestamps, and activity logs of actions taken in the account. This is used to operate, secure, and troubleshoot the Service.
3. What we do not collect
- We do not process or store full payment-card numbers. The Service records payment notes and methods entered by the Customer; it is not a card-processing system, and customers should not transmit full card details through it.
- We do not sell personal information.
- We do not use third-party advertising networks or cross-site advertising trackers.
4. Cookies
The application uses a single essential session cookie to keep you signed in. It is required for the Service to function and is not used for advertising or cross-site tracking. If you disable it, you will not be able to log in.
This marketing website uses Google Analytics to count visits and understand which pages people find useful. It sets cookies in your browser and sends Google your IP address, the pages you view, and general details such as your browser and country. It does not receive your name or any information you type into a form. We keep Google Signals switched off, so this data is not used for advertising or combined with your activity on other websites. You can prevent it with any browser setting or extension that blocks analytics cookies, and the site works normally without it. Analytics is not used inside the application itself.
5. How we use information
- To provide, operate, and maintain the Service.
- To authenticate users and enforce company-scoped, role-based access.
- To generate documents (such as order PDFs and invoices) and send transactional and system messages.
- To provide support, investigate issues, and secure the Service against abuse.
- To maintain and improve reliability and performance.
6. Email sending
Messages you send through the Service are delivered using the email account or provider that you configure. We send on your behalf using your configuration; we do not read your mailbox. You are responsible for the content of messages you send and for complying with applicable email and anti-spam laws.
7. AI assistant
The Service includes a read-only AI assistant. To answer a question, your query together with relevant CRM data may be sent to a third-party AI provider (Google) to generate a response. The assistant is read-only: it cannot create, modify, dispatch, invoice, delete, or otherwise change your records. AI responses may be inaccurate and should be verified before being relied upon.
8. Service providers
We rely on a limited set of service providers to run the Service, and share information with them only as needed for that purpose. These currently include our database and file storage provider (Supabase), our application hosting provider (Hostinger), our DNS and content-delivery provider (Cloudflare), our AI provider (Google), and our website analytics provider (Google Analytics, on the marketing website only). Email is delivered through the provider you configure. These providers process data under their own terms and security practices.
9. Where data is processed
The Service is operated from Pakistan, and data is currently stored and processed using infrastructure located in Singapore (database and file storage) and the European Union (application hosting). By using the Service, you consent to the processing of information in these locations. We may change infrastructure or regions over time as the Service evolves.
10. Security
We take reasonable measures to protect information, including hashed passwords, encryption of sensitive stored credentials, company-scoped data access enforced on the server, private handling of operational documents, and role-based permissions. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Retention
We retain account and Customer Data for as long as the account is active and as needed to provide the Service, and afterwards as required for legitimate operational, legal, or security purposes. Certain logs and notifications are pruned automatically over time. A Customer may request deletion of its account data as described below.
12. Your choices
Admins and agents can view and update much of their information directly within the application. To request export or deletion of company account data, contact us at the address below. If you are an end customer of a broker that uses TruxCRM, your information is controlled by that broker; please direct access or deletion requests to the broker, and we will support them as the broker's processor.
13. Broker responsibilities
If you use the Service to store or send information about your customers or other third parties, you are responsible for having a lawful basis to do so, for obtaining any required consents, and for complying with all laws applicable to that data and to the messages you send.
14. Children
The Service is a business tool intended for use by adults (18 and over) acting on behalf of a business. It is not directed to children, and we do not knowingly collect information from children.
15. Changes
We may update this Policy from time to time. Material changes will be reflected by updating the date above. Your continued use of the Service after an update constitutes acceptance of the revised Policy.
16. Contact
Questions about this Policy or your information can be sent to support@truxcrm.com or by mail to GrowAx Enterprises, No. 1, Near UBL Bank, Manzoor Colony, Harbanspura Road, Lahore Cantt, Lahore, Pakistan. GrowAx Enterprises is the owner and operator of TruxCRM.
