Legal
Privacy Policy
1. Who we are
This Privacy Policy applies to Rendimiento Engineering LLC, a Washington limited liability company doing business as Brun CRM (“Brun,” “we,” “us,” or “our”). You can contact us at [email protected].
This Policy describes how we collect, use, and share personal information when you visit our website (bruncrm.com), create an account, or use the Brun CRM service (collectively, the “Service”).
2. The short version
Because Brun encrypts your customer data in your browser before it reaches us, we cannot read most of what you store in the Service. This means:
- We do not see the names, contact details, or notes about the leads and contacts you store in Brun.
- We do see information about you as an account holder: your email, billing status, login times, and similar operational data.
- We do collect some technical information about how you use the Service (IP addresses, browser type, error logs).
3. Personal information we collect
3.1 Information you give us
When you request access or create an account:
- Name
- Email address
- Company name
- Password (stored in salted, hashed form — we cannot see the plaintext)
When you subscribe:
- Billing contact information
- Payment method information (collected and processed by Stripe — we do not store full card numbers)
- Billing address
When you communicate with us:
- The contents of your messages and any information you voluntarily include
3.2 Information we collect automatically
Operational and usage data:
- IP address
- Browser type and version
- Operating system
- Pages visited and features used
- Login times and session data
- Referring URL
- Error logs and crash reports
Cookies and similar technologies:
- Session cookies (required for login)
- Functional cookies (to remember preferences)
We do not use advertising cookies, cross-site tracking, or third-party analytics that share data with advertisers.
3.3 Information encrypted and unreadable to us
The following categories of information are encrypted in your browser before reaching our servers and are not readable by us:
- Lead names, contact information, and metadata
- Notes and history attached to leads
- Custom content your team enters in the Service
Our servers store this content as ciphertext. We do not have, and cannot produce, plaintext versions of this data.
3.4 Information we do not collect
We do not collect:
- Social Security numbers
- Government-issued ID numbers
- Biometric data
- Precise geolocation data
- Data from children under 13 (the Service is not directed at children)
- Protected Health Information (PHI) subject to HIPAA — our Terms of Service prohibit this use
4. How we use personal information
- Provide the Service. Authenticate users, serve the application, sync data between sessions, and deliver features.
- Process payments. Through Stripe, our payment processor.
- Communicate with you. Send transactional emails (billing confirmations, password resets, security notices), respond to support requests, and occasionally notify you of significant product changes.
- Maintain and improve the Service. Diagnose technical problems, analyze aggregate usage patterns, and develop new features.
- Security and fraud prevention. Detect and prevent unauthorized access, abuse of the Service, and fraudulent activity.
- Legal compliance. Comply with applicable laws, respond to lawful requests from authorities, and enforce our Terms of Service.
We do not sell your personal information. We do not use your personal information for cross-context behavioral advertising. We do not use AI or machine learning to train models on your encrypted Customer Data — and because we cannot read it, this would not be possible even if we wanted to.
5. Legal bases for processing
- Contract. Processing necessary to provide you the Service you subscribed to.
- Legitimate interest. Security, fraud prevention, and reasonable product analytics.
- Consent. Where required (for example, non-essential cookies, if any).
- Legal obligation. Tax reporting, responding to lawful requests, and similar.
6. How we share personal information
6.1 Service providers (subprocessors)
We use carefully selected third-party service providers to help us operate the Service. As of the effective date of this Policy, our subprocessors are listed at bruncrm.com/subprocessors and will be updated when we add, change, or remove subprocessors. These subprocessors are bound by written agreements that restrict their use of personal information to providing services to us.
6.2 Legal requirements
We may disclose personal information if required to do so by law, subpoena, court order, or similar legal process — but note that because of our encryption model, the information we can disclose is limited to the unencrypted operational data described in Sections 3.1 and 3.2. We cannot decrypt Customer Data in response to legal process.
Where legally permitted, we will notify affected customers of legal requests before responding.
6.3 Business transfers
If we are involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your personal information is transferred and becomes subject to a different privacy policy.
6.4 With your consent
We may share personal information for other purposes with your explicit consent.
6.5 What we do not do
We do not sell your personal information. We do not share personal information with advertisers, data brokers, or for cross-context behavioral advertising.
7. How long we keep personal information
| Data category | Retention period |
|---|---|
| Account information (name, email) | Duration of account, plus 30 days |
| Encrypted Customer Data | Duration of account, plus 30 days in production; residual ciphertext in encrypted backups is deleted on a rolling basis through normal backup rotation |
| Billing records | 7 years (as required for tax purposes) |
| Security logs | 12 months |
| Support communications | 3 years |
| Marketing emails list (if any) | Until you unsubscribe |
After applicable retention periods, we delete or anonymize personal information.
8. Security
We use reasonable administrative, technical, and physical safeguards to protect personal information, including:
- End-to-end encryption of Customer Data (AES-256-GCM)
- Encryption in transit (HTTPS/TLS)
- Hashed and salted passwords (PBKDF2 or equivalent)
- Access controls and the principle of least privilege for our staff
- Regular software updates and security patching
- Third-party payment processing through Stripe (PCI-DSS compliant)
However, no system is perfectly secure. In the event of a security incident affecting your personal information, we will notify you as required by applicable law.
9. Your rights
9.1 Rights available to all users
Regardless of where you live, you can:
- Access your account information through your user settings.
- Update or correct your information through your user settings.
- Export your Customer Data using the built-in export feature.
- Delete your account and associated data.
- Contact us with any privacy-related questions at [email protected].
9.2 Rights under California law (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know what personal information we collect, use, and share about you.
- Right to access the specific pieces of personal information we have collected.
- Right to delete personal information we have collected from you, subject to certain exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising, so this right is not currently applicable — but you retain it if that ever changes.
- Right to limit use of sensitive personal information. We do not collect sensitive personal information as defined by CPRA.
- Right to non-discrimination for exercising your rights.
To exercise these rights, contact us at [email protected]. We will respond within 45 days as required by law.
Authorized agents. You can designate an authorized agent to make a request on your behalf. We will require verification of your identity and the agent's authority.
Categories of personal information collected in the past 12 months: Identifiers (name, email, IP address), commercial information (subscription and billing records), internet activity (usage data, logs), and geolocation data (city-level, derived from IP).
Categories disclosed for business purposes in the past 12 months: Identifiers and commercial information, disclosed to our subprocessors as listed at bruncrm.com/subprocessors.
Categories sold or shared: None.
9.3 Rights under other state privacy laws
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights similar to those described above, including rights to access, delete, correct, and (where applicable) opt out of sales or targeted advertising. Contact us at [email protected] to exercise these rights and we will handle your request in accordance with applicable law.
9.4 Washington My Health My Data Act
Washington's My Health My Data Act provides heightened protections for “consumer health data.” Brun is a general-purpose CRM and does not intentionally collect consumer health data. If you place health-related information into the Service, it is subject to the same end-to-end encryption as other Customer Data and is not readable by us. If you are a healthcare provider or otherwise need to store PHI, Brun is not an appropriate tool — our Terms of Service prohibit this use.
10. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly. Parents or guardians who believe their child has provided us with information should contact us at [email protected].
11. International users
The Service is operated from the United States and is intended for customers in the United States. If you access the Service from outside the United States, you understand that your personal information will be transferred to, stored, and processed in the United States.
12. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and update the “Last updated” date at the top of this page. Continued use of the Service after the effective date of the updated Policy constitutes acceptance.
13. Contact us
Questions, requests, or complaints about this Privacy Policy can be sent to [email protected].