Your company's data is 100% private
Your quotations, clients, payments and messages belong to your company alone. No one outside your company can see them, and they are never shared, sold or used for advertising. Every record is locked to your company, and inside your company each person sees only what their role allows.
End-to-end protection, step by step
- On the wayHTTPS encryption
- At the doorSecure login
- Inside your teamRoles & permissions
- At restEncrypted secrets & private files
- On the serverHardening & monitoring
Data in transit
HTTPS encryption everywhere
Every page, form, file and API call travels over an encrypted HTTPS (TLS) connection. Plain http:// is redirected to https:// automatically, and browsers are told to always use the secure connection (HSTS).
Protection against fake requests
Every form and action carries a secret security token (CSRF protection), so another website cannot make your browser change anything in your CRM.
Login & accounts
Passwords never stored
Passwords are saved only as one-way hashes (bcrypt). Nobody — not even us — can read your password.
2-step login code
A 6-digit code is emailed when someone logs in from a new device. Codes expire in 10 minutes and stop working after wrong tries.
Automatic lockout
After 5 wrong passwords the login is locked for 15 minutes. Repeated attempts from one network are blocked too, which stops password-guessing attacks.
One device per login
A login can be active on one device at a time. If the same ID logs in elsewhere, the other device is logged out at once. Idle sessions end automatically.
Office IP restriction
Company admins can allow logins only from their office internet connection.
Verified email addresses
Every user confirms their email address with a code before the account is fully active.
Access inside your company
Complete separation between companies
Every record belongs to exactly one company, and every database query is filtered by that company. No one outside your company can see your data.
Role-based access
Admin, manager, employee and field roles. Employees see only their own leads and clients, managers see their team, and the admin sees everything.
Downloads and deletion by admins only
Only company admins can download data or delete records, so data cannot quietly leave the company or disappear.
Instant access removal
Disabling or deleting a user logs them out immediately — on every device.
Data storage
Encrypted secrets
WhatsApp access tokens, payment gateway keys and "keep me logged in" tokens are stored with AES-256-GCM encryption.
Private files stay private
Payment proofs, field photos and other private files are never public. They open only after the system checks who is logged in and whether they are allowed to see that file.
Automatic clean-up
Old chat messages, login history and location points are deleted automatically after their retention period, so data is not kept longer than needed.
Website & server protection
Hardened server
Configuration files, database files, backups and hidden files can never be opened from the web. Folder listing is switched off, and uploaded files can never run as programs.
Security headers
Browser security headers block click-jacking, content sniffing and unwanted access to camera or location. The public website runs with a strict Content Security Policy.
Hidden from search engines
CRM pages are blocked from Google and other search engines and are never indexed.
Safe exports and content
Spreadsheet exports are protected against formula injection, and website content is cleaned so no harmful code can be added.
Monitoring & control
Login history
Every login is recorded with time, IP address and device, so admins can spot unusual access quickly.
Super Admin controls
Every feature can be switched on or off per company, and a company's access can be suspended instantly if needed.
How you can help keep your account safe
- Use a strong password that you do not use on any other website, and never share your login.
- Give each team member their own login with the lowest role they need.
- Disable a user's login as soon as they leave your company.
- Check Login History from time to time, and tell us at once if you see anything unusual.
Frequently asked questions
Can anyone else see my company's data?
No. No one outside your company can see it. Every record belongs to one company and every query is filtered by that company, so your data is 100% private to your business. It is never shared, sold or used for advertising.
What does end-to-end data protection mean here?
It means your data is protected at every step: while it travels (HTTPS encryption), when someone logs in (hashed passwords, 2-step codes, lockouts), inside your company (roles and permissions), while it is stored (encrypted secrets, private files) and on the server (hardening and monitoring).
Can your staff see my data?
Our team accesses a company's data only when needed to give support, fix a problem or meet a legal requirement, and only for that purpose.
What happens if an employee leaves?
The admin disables or deletes their login and they are logged out on every device immediately. Their leads become unassigned so the admin can hand them to someone else, and no records are lost.
Can I get my data back or have it deleted?
Yes. Admins can download quotations and reports, and you can ask us for a full copy or for deletion of your company's data at any time. See our Data Policy.
Report a security concern
If you think you have found a security problem, please contact us right away at 91infoindia@gmail.com. We look into every report and reply as quickly as possible.
Related: Data Policy · Privacy Policy · Terms & Conditions
See how securely your team can work with PoolCo CRM.