Legal
Privacy Policy
Bridge CRM — a product of Talent Bridge Services · Last updated 19 July 2026
This Privacy Policy explains how Talent Bridge Services ("Talent Bridge Services," "we," "us," or "our") collects, uses, stores, and shares information through Bridge CRM — our multi-tenant customer relationship management platform for ad-fed enrollment sales teams (academies, coaching institutes, and study-abroad/placement agencies) — across our web admin console, desktop apps (Mac and Windows), and Android agent app.
This policy covers the whole Bridge CRM service. It supersedes and broadens our earlier, narrower privacy notice that was scoped only to the Android agent app's device permissions. That earlier notice is folded into this document as the "Android Agent App Permissions" section below — nothing in that original notice is contradicted or withdrawn, it is simply now one part of a larger policy.
1. Scope
This policy applies to two categories of people:
- Tenant users — the businesses (and their admins/agents) who sign up for and operate a Bridge CRM account.
- End customers / leads — the individuals whose contact details a tenant business collects and manages inside their Bridge CRM account (for example, someone who filled out a Meta Lead Ad form for an academy that uses Bridge CRM).
For end-customer data, the tenant business is generally the data controller and Talent Bridge Services acts as a data processor / service provider on their behalf. Questions about a specific lead's data should first be directed to the business that collected it; see our Data Deletion Instructions for how to reach us directly as well.
2. Information We Collect
| Category | Examples | Source |
| Tenant admin & agent accounts | Name, work email, phone number, password (stored hashed), role, workspace settings | Provided at signup / added by a tenant admin |
| End-customer / lead data | Name, phone number, email, lead-form answers, source/campaign, notes, status, follow-up history | Meta (Facebook/Instagram) Lead Ads webhook, manual entry by an agent, CSV/Zoho/HubSpot/Pipedrive import |
| Call & message data | Call recordings, AI-generated transcripts and summaries, WhatsApp/voice messages sent by Bridgy | Generated when Bridgy or an agent contacts a lead |
| Usage & device data | Login timestamps, IP address, app/OS version, crash and error logs | Automatically collected by the app |
| Website analytics | Pages visited, referrer, approximate location (if analytics cookies are enabled on our marketing site) | Cookies / standard web logs, see Section 9 |
3. Why We Use This Information
- Service delivery — operating the CRM: storing and organizing lead and account data, letting agents work leads, generating reports.
- AI-assisted contact — our built-in assistant, Bridgy, can reach out to a fresh lead automatically (within roughly 60 seconds) by WhatsApp or voice message in Hindi or English, and summarize calls, so the tenant's team can respond faster.
- Analytics & product improvement — understanding feature usage and reliability so we can fix bugs and improve the product, including improving Bridgy's own models over time using a limited, de-identified subset of data as described in Section 6a.
- Security & fraud prevention — detecting unauthorized access, abuse, or account compromise.
- Legal compliance — responding to lawful requests and enforcing our Terms of Service.
We do not use lead or customer data to build advertising profiles, and we do not use it for any purpose beyond delivering the CRM service to the tenant business that owns that data, and the model-improvement use described in Section 6a.
4. How We Store & Protect Data
- Database-per-tenant isolation — every tenant account gets its own isolated database. This is physical separation, not row-level access control within a shared database — one tenant's data cannot leak into another's through an application bug.
- Encryption at rest for personally identifiable fields (names, phone numbers, emails, call transcripts).
- Encryption in transit via HTTPS/TLS for all client-server communication.
- Audit logs of sensitive actions (exports, deletions, permission changes, admin logins).
- TOTP-based two-factor authentication available for admin accounts.
- Call audio and transcripts processed by Bridgy are handled on Talent Bridge Services' own infrastructure (an on-prem GPU server), not sent to third-party LLM APIs.
We do not currently hold a SOC 2 or ISO 27001 certification. The practices above describe how we actually protect data today; we are not claiming a formal certification we do not have.
5. Who We Share Data With
We do not sell customer or lead data, and we do not share it with third parties for advertising purposes. Ever.
- Meta / Facebook — data flows from Meta to us, not the other way around: when a tenant connects a Meta Lead Ads form, we ingest the resulting lead submissions via webhook. We do not send tenant or lead data back to Meta for advertising or any purpose other than the lead-management service described in Section 6 below.
- Infrastructure providers — our hosting provider (a GPU VPS located in India) processes data solely to keep the service running, under our instruction, and does not use it for its own purposes.
- Legal disclosure — we may disclose information if required by law, court order, or a valid government request, or to protect the rights, safety, or property of Talent Bridge Services, our customers, or others.
We do not have any other third-party data-sharing arrangements. If that ever changes, we will update this policy first.
6. Meta Platform Data
Data obtained through Meta's APIs (including Lead Ads data) is used
solely to provide our lead-management services to the business that connected its Meta account to Bridge CRM — receiving that business's own leads into their own CRM workspace. Consistent with Meta's Lead Ads Terms of Service, we do not use Meta-sourced lead data for any other purpose, including AI model training (see Section 6a, which explicitly excludes Meta-sourced data). It is not shared with any third party outside of delivering that service, and is deleted in accordance with our
Data Deletion policy.
6a. Use of Data to Improve Bridgy (AI Model Training)
Bridgy — our built-in AI assistant — improves over time by learning from patterns in how leads are worked across the platform. We are deliberate about the scope of this:
- Leads sourced from Meta (Facebook/Instagram) Lead Ads are excluded from this process entirely — never swept, stored, or used for model training, in any form, identified or de-identified. This is a deliberate restriction, not an oversight: Meta's Lead Ads Terms of Service limit use of that data to fulfilling the lead form's original purpose, and we honor that.
- Only leads added by other methods — manual entry by an agent, or CSV/Zoho/HubSpot/Pipedrive import — are eligible to be used for model improvement.
- Before any eligible lead-outcome data is used to improve our models, it is passed through a sweeper that strips personally identifiable information — names, phone numbers, email addresses, and free-text notes are removed or irreversibly de-identified. What remains is structural/behavioral data: things like which lead sources convert fastest, which call outcomes correlate with success, and similar aggregate patterns — not "who said what."
- We do not train models on raw, identifiable lead records, and we do not need the original PII to improve Bridgy — only the de-identified patterns.
- You can request more detail on this process at any time via the contact in Section 14, and tenant admins can ask us to exclude their workspace's data from this process entirely.
7. Data Retention
- Lead and account data is retained for as long as the tenant's account is active, or until the tenant deletes it.
- When a lead is deleted inside Bridge CRM, it moves to a recoverable Bin/Trash for 7 days (to protect against accidental deletion), then is permanently purged.
- If a tenant closes their account, or an individual submits an explicit deletion request under Section 8, we honor that request as described in our Data Deletion Instructions — including purging immediately without waiting for the recovery window, if the requester asks for that.
8. Your Rights
Depending on whether you are a tenant admin, an agent, or an end-customer/lead, you can:
- Access & export — tenants can use the built-in one-click "Export everything" feature at any time to download a ZIP of all their leads, calls, activity, and audit history. No lock-in.
- Correct — tenant admins/agents can correct lead records directly inside the CRM.
- Delete — see our dedicated Data Deletion Instructions page for exactly how to request deletion, whether you are a lead, an agent, or a tenant closing their whole account.
9. Cookies & Tracking on Our Website
Our marketing website may use essential cookies to keep the site functioning (e.g., remembering a cookie-consent choice) and, if enabled, basic analytics cookies to understand traffic. We do not use cookies for third-party advertising or cross-site tracking. The web admin console uses session cookies/tokens strictly to keep you signed in.
10. Children's Data
Bridge CRM is a B2B product for enrollment sales teams and is not directed at, or intended for use by, children under 18. Lead data collected by our tenant customers may in some cases relate to prospective students who are minors, submitted by a parent, guardian, or the institution itself as part of an admissions inquiry — this is handled as ordinary lead data under the controls in this policy.
11. International Data Transfers
All Bridge CRM data is hosted on servers located in India. We do not currently offer data residency in any other region, and we do not routinely transfer tenant or lead data outside India.
12. Android Agent App Permissions
The Bridge CRM Android agent app requests a small set of device permissions so field agents can work leads efficiently. This section condenses what was previously our stand-alone mobile-app privacy notice:
- Call log access — to automatically log calls made to leads against the correct CRM record.
- Incoming caller ID — to identify an incoming call as a known lead and surface their record.
- Microphone / voice notes — to let agents attach voice notes to a lead record.
- Camera (optional) — for the optional on-device face check-in/out feature, used for attendance; face data is processed on-device for this feature.
These permissions are used only for the stated CRM purposes and are never sold or repurposed for advertising.
13. Changes to This Policy
We may update this policy as Bridge CRM evolves. We will update the "Last updated" date above when we do. Material changes affecting how we handle Meta Platform Data, model-training use, or end-customer data will be communicated to tenant admins.
14. Grievance Officer & Contact
Questions about this policy, or requests relating to your data, can be sent to hello@talentbridgeservices.tech.
Grievance Officer — for complaints or grievances about how your personal data is handled, contact our Grievance Officer at
hello@talentbridgeservices.tech (subject line: "Grievance"). We acknowledge grievances within 7 business days and aim to resolve them within 30 days.