LTCRM Legal

Privacy Policy

Effective date: September 1, 2026 · Last updated: September 1, 2026

This Privacy Policy explains how LTCRM collects, accesses, uses, stores, shares, retains, and deletes information. It applies to the LTCRM website, customer relationship management service, and Google Sheets integration available at ltoccrm.uz.

1. Introduction

LTCRM is a business customer relationship management application operated by YATT Sobitxonov Nurilloxon Imommuhammadxon o'gli, based in Tashkent, Uzbekistan (“LTCRM”, “we”, “us”, or “our”). LTCRM helps organizations manage contacts, leads, pipelines, follow-up tasks, team access, reports, and lead imports from Google Sheets.

We determine how account, service-operation, security, and support information is used. Each customer organization determines why and how its CRM records are used and which team members may access them. When we host or process those CRM records, we do so to provide LTCRM to that organization and follow its authorized instructions.

2. Information We Collect

Depending on how LTCRM is used, we collect or process:

  • Account information: a user's name, email address, password hash, organization membership, role, account status, and whether a password change is required.
  • Authentication and security information: secure session records, password-reset records when email delivery is available, login rate-limit records, request identifiers, audit events, and limited operational error logs.
  • Support communications: information a person sends when requesting assistance, reporting a security problem, or making a privacy request.
  • Google integration information: the Google account and spreadsheet information described in the “Google Account and Google Sheets Data” section below.

We do not intentionally record passwords, Google OAuth tokens, contact details, note bodies, or free-form CRM descriptions in ordinary application logs.

3. Information Customers Enter Into LTCRM

Customer organizations and their authorized users may enter or import business records, including contact names, phone numbers, email addresses, Telegram usernames, lead titles, descriptions, sources, campaigns, notes, estimated values, pipelines, stages, assignees, tasks, due dates, activity history, and lead outcomes.

The customer organization controls this information and is responsible for having a lawful basis and any notices or permissions needed to collect, import, use, and contact the people represented in its CRM. If an LTCRM customer entered your information, that organization is normally the best first contact for questions or requests about the CRM record. We will assist the organization with verified requests when required.

LTCRM uses tenant-scoped access controls so that a user can access only organizations and records allowed by their membership and role. Sales agents have additional restrictions on which leads and tasks they may view.

4. Google Account and Google Sheets Data

LTCRM accesses a spreadsheet only after an authorized administrator of an LTCRM organization supplies and connects the specific Google Sheets URL. LTCRM does not search a person's Google Drive or automatically choose spreadsheets. Publicly readable Sheets may be inspected through the Google Sheets API without connecting a Google Account. If the selected Sheet is private, the administrator must explicitly continue through Google OAuth and grant access.

For a private Sheet, LTCRM requests only:

  • OpenID and email: to identify the Google account used for the connection; and
  • Google Sheets read-only access: to read the specific spreadsheet and tab selected by the administrator.

LTCRM does not request a Google Drive scope, list files in Google Drive, or request permission to edit a spreadsheet. The integration may access the connected Google account email address; OAuth access and refresh tokens; the selected spreadsheet's identifier, title, tabs, headers, and cell values; and synchronization status, row identity, counts, and sanitized error information.

LTCRM uses selected Sheet headers and cell values to preview and map columns and to create and manage CRM contacts and leads according to the administrator's configured pipeline, stage, assignee, source, and field mapping. LTCRM performs manual or scheduled read-only synchronization, prevents the same imported row from creating duplicate leads, and shows connection and synchronization history.

Imported Sheet information becomes CRM data in the organization's LTCRM workspace. LTCRM does not overwrite an existing CRM lead when the source row later changes, and deleting a row from Google Sheets does not automatically delete the lead already created in LTCRM.

5. How We Use Information

We use information only as reasonably necessary to:

  • provide and maintain LTCRM and its customer workspaces;
  • authenticate users and enforce organization, role, lead, and task permissions;
  • store, organize, search, filter, and report on customer-authorized CRM records;
  • connect the specific Google Sheet selected by an administrator, preview its structure, import configured rows, and report synchronization results;
  • prevent duplicate imports and preserve useful CRM and audit history;
  • secure, monitor, troubleshoot, back up, and improve service reliability;
  • respond to support, security, legal, and privacy requests; and
  • comply with applicable law and enforce our Terms of Service.

LTCRM does not use Google user data for advertising, retargeting, personalized marketing, determining creditworthiness, lending decisions, or training generalized artificial intelligence or machine-learning models. LTCRM does not sell Google user data.

6. Google API Limited Use Disclosure

LTCRM's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

Access, use, and transfer of Google user data are limited to providing the visible Google Sheets import and synchronization features described in this Policy. We do not transfer Google user data to advertising platforms, data brokers, or information resellers. Human access is prohibited except when the user gives affirmative permission for specific support, when access is necessary to investigate security or abuse, when required by law, or when data is aggregated for permitted internal operations.

7. Data Sharing

We disclose information only as needed to:

  • authorized users within the relevant LTCRM customer organization;
  • infrastructure, hosting, database, security, monitoring, backup, email, and integration providers that help operate LTCRM under appropriate restrictions;
  • Google, when an administrator directs LTCRM to access the connected Google service;
  • professional advisers subject to confidentiality obligations; or
  • authorities or other parties when reasonably necessary to comply with law, protect rights and safety, or investigate fraud, abuse, or a security incident.

We do not sell personal information or Google user data. Service providers may process information only to perform services for LTCRM and not for their independent advertising purposes.

8. Data Storage and Security

LTCRM stores application data in its production PostgreSQL database and maintains operational backups. The production database is not published directly to the internet. Browser traffic is protected with HTTPS. LTCRM uses organization-scoped authorization, role-based access controls, protected server-managed sessions, one-way password hashing, request-origin checks, security headers, restricted container permissions, audit logging, and encryption for Google OAuth credentials.

Access to production systems is limited to authorized operational personnel. No method of transmission or storage is completely secure, so users must protect their passwords and notify us promptly if they suspect unauthorized access.

9. OAuth Credentials and Tokens

Google OAuth access and refresh tokens are encrypted at rest using authenticated encryption. They remain on the server side, are not included in ordinary page data, are not exposed to normal LTCRM users, and are not written to ordinary application logs. LTCRM decrypts a token only inside the server integration service when it is needed to perform an operation the organization authorized, such as reading the connected private Sheet or refreshing expired access.

Google OAuth client credentials and LTCRM's encryption key are server-side deployment secrets. They are not supplied to customer organizations or their users.

10. Data Retention

Account, CRM, task, activity, import, synchronization, and audit records are retained while needed to provide the workspace, preserve operational history, meet legal obligations, resolve disputes, and protect the service. LTCRM does not currently offer a customer-configurable retention period. Expired sessions, password-reset tokens, rate-limit records, and short-lived OAuth state records are removed through operational cleanup.

OAuth access and refresh tokens are retained while the Google connection is active and are removed from LTCRM when an administrator disconnects Google. Operational import history and leads already created from imported rows are retained after disconnection.

11. Data Deletion

LTCRM does not currently provide self-service workspace deletion or bulk export. A user or customer organization may request access, correction, export, restriction, or deletion by emailing snurillo05@gmail.com. The request should identify the relevant LTCRM account or organization but must not include a password or OAuth token.

We verify the requester's identity and authority and, where CRM data is controlled by a customer organization, coordinate with that organization. A request may be limited where retention is required for security, audit integrity, legal obligations, disputes, or the rights of others. Deletion from the live database may not immediately remove information from protected backups. Backup copies are isolated from ordinary processing and age out under the applicable backup schedule unless longer retention is legally required.

12. Disconnecting Google

An authorized organization owner or administrator can disconnect Google from LTCRM under Settings → Integrations. LTCRM then attempts to revoke the Google credential, removes the locally stored access and refresh tokens, marks the connection as disconnected, and stops future private-Sheet access. The Google Account owner can also revoke LTCRM from the third-party connections section of their Google Account.

Disconnecting Google does not automatically delete CRM contacts or leads already imported from the Sheet. Once imported, LTCRM becomes the organization's CRM system of record for those leads, and automatically deleting them could destroy follow-up, assignment, task, note, and activity history. An authorized organization representative may request deletion separately using the process in “Data Deletion”.

13. Cookies and Sessions

LTCRM uses a secure, server-managed session cookie that is necessary to keep users signed in and protect their workspace. The session cookie is not used for third-party advertising. LTCRM does not currently use third-party advertising cookies. Blocking the required session cookie may prevent sign-in.

14. International Processing

LTCRM is operated from Uzbekistan. Infrastructure and integration providers, including Google, may process information in other countries where they or their service providers operate. Those countries may have privacy laws different from the laws where a user lives. Where applicable, we use contractual, technical, and organizational safeguards appropriate to the processing and transfer.

15. Children's Privacy

LTCRM is a business service intended for use by adults and is not directed to children under 18. We do not knowingly ask children to create LTCRM accounts. Contact us if you believe a child's information was provided improperly so that we can investigate and take appropriate action.

16. Changes to This Policy

We may update this Policy when LTCRM's practices, providers, features, or legal requirements change. The current version will be published at this URL and will show its effective and last-updated dates. If a change materially affects how LTCRM accesses or uses Google user data, we will update the disclosure before using the data for the new purpose and request additional consent when required.

17. Contact Us

Questions, privacy requests, data-deletion requests, and security concerns may be sent to the LTCRM operator at the contact below. This is the current public support and privacy contact for LTCRM.

YATT Sobitxonov Nurilloxon Imommuhammadxon o'gli
LTCRM
Tashkent, Uzbekistan
Email: snurillo05@gmail.com

18. Effective Date

This Privacy Policy is effective as of September 1, 2026 and was last updated on September 1, 2026.