Your company's data is 100% private

Your quotations, clients, payments and messages belong to your company alone. No one outside your company can see them, and they are never shared, sold or used for advertising. Every record is locked to your company, and inside your company each person sees only what their role allows.

End-to-end protection, step by step

  1. On the wayHTTPS encryption
  2. At the doorSecure login
  3. Inside your teamRoles & permissions
  4. At restEncrypted secrets & private files
  5. On the serverHardening & monitoring

Data in transit

HTTPS encryption everywhere

Every page, form, file and API call travels over an encrypted HTTPS (TLS) connection. Plain http:// is redirected to https:// automatically, and browsers are told to always use the secure connection (HSTS).

Protection against fake requests

Every form and action carries a secret security token (CSRF protection), so another website cannot make your browser change anything in your CRM.

Login & accounts

Passwords never stored

Passwords are saved only as one-way hashes (bcrypt). Nobody — not even us — can read your password.

2-step login code

A 6-digit code is emailed when someone logs in from a new device. Codes expire in 10 minutes and stop working after wrong tries.

Automatic lockout

After 5 wrong passwords the login is locked for 15 minutes. Repeated attempts from one network are blocked too, which stops password-guessing attacks.

One device per login

A login can be active on one device at a time. If the same ID logs in elsewhere, the other device is logged out at once. Idle sessions end automatically.

Office IP restriction

Company admins can allow logins only from their office internet connection.

Verified email addresses

Every user confirms their email address with a code before the account is fully active.

Access inside your company

Complete separation between companies

Every record belongs to exactly one company, and every database query is filtered by that company. No one outside your company can see your data.

Role-based access

Admin, manager, employee and field roles. Employees see only their own leads and clients, managers see their team, and the admin sees everything.

Downloads and deletion by admins only

Only company admins can download data or delete records, so data cannot quietly leave the company or disappear.

Instant access removal

Disabling or deleting a user logs them out immediately — on every device.

Data storage

Encrypted secrets

WhatsApp access tokens, payment gateway keys and "keep me logged in" tokens are stored with AES-256-GCM encryption.

Private files stay private

Payment proofs, field photos and other private files are never public. They open only after the system checks who is logged in and whether they are allowed to see that file.

Automatic clean-up

Old chat messages, login history and location points are deleted automatically after their retention period, so data is not kept longer than needed.

Website & server protection

Hardened server

Configuration files, database files, backups and hidden files can never be opened from the web. Folder listing is switched off, and uploaded files can never run as programs.

Security headers

Browser security headers block click-jacking, content sniffing and unwanted access to camera or location. The public website runs with a strict Content Security Policy.

Hidden from search engines

CRM pages are blocked from Google and other search engines and are never indexed.

Safe exports and content

Spreadsheet exports are protected against formula injection, and website content is cleaned so no harmful code can be added.

Monitoring & control

Login history

Every login is recorded with time, IP address and device, so admins can spot unusual access quickly.

Super Admin controls

Every feature can be switched on or off per company, and a company's access can be suspended instantly if needed.

How you can help keep your account safe

Frequently asked questions

Can anyone else see my company's data?

No. No one outside your company can see it. Every record belongs to one company and every query is filtered by that company, so your data is 100% private to your business. It is never shared, sold or used for advertising.

What does end-to-end data protection mean here?

It means your data is protected at every step: while it travels (HTTPS encryption), when someone logs in (hashed passwords, 2-step codes, lockouts), inside your company (roles and permissions), while it is stored (encrypted secrets, private files) and on the server (hardening and monitoring).

Can your staff see my data?

Our team accesses a company's data only when needed to give support, fix a problem or meet a legal requirement, and only for that purpose.

What happens if an employee leaves?

The admin disables or deletes their login and they are logged out on every device immediately. Their leads become unassigned so the admin can hand them to someone else, and no records are lost.

Can I get my data back or have it deleted?

Yes. Admins can download quotations and reports, and you can ask us for a full copy or for deletion of your company's data at any time. See our Data Policy.

Report a security concern

If you think you have found a security problem, please contact us right away at 91infoindia@gmail.com. We look into every report and reply as quickly as possible.

Related: Data Policy · Privacy Policy · Terms & Conditions

See how securely your team can work with PoolCo CRM.

Email WhatsApp