Skip to content

Legal

Privacy Policy

Effective August 18, 2026. This policy explains what SerapisERP collects, why, and the choices you have.

Who we are

SerapisERP (“Serapis”, “we”, “us”) is a business management platform — CRM, calling, messaging, marketing, and back-office modules — operated from Hollywood, Florida, United States, and served at serapiserp.com and app.serapiserp.com. This policy covers both the marketing site and the application.

Information we collect

Account information. Name, email address, password hash (never the password itself), organization details, and role assignments.

Customer content. The business data you and your team store in the product: contacts, leads, deals, invoices, documents, notes, campaign content, website and storefront content, and similar records. This data belongs to you; we process it only to provide the service.

Communications data. When you use the calling, SMS, and email modules: call metadata (numbers, times, durations), call recordings and transcripts where you enable them, message content you send or receive through the platform, and delivery events. Calls answered by our AI receptionist (Serapis Talk) are transcribed and summarized; the system attempts to redact payment card and Social Security numbers from stored transcripts.

Usage and log data. IP address, browser type, pages viewed, and security-relevant events (sign-ins, failed logins, permission changes), used for operating and protecting the service.

How we use information

To provide and improve the service; to authenticate you and enforce roles and permissions; to send messages you initiate (calls, SMS, email) through our carriers; to notify you about activity in your account; to secure the platform against abuse; and to comply with law. We do not sell personal information, and we do not use your customer content for advertising.

Google user data

Signing in with Google shares only your basic profile (name, email, profile photo) with us. Separately, you may choose to connect Google Mail & Calendar from the Integrations page, which grants the app access to Gmail (read/modify/send) and Google Calendar scopes for your account.

We use that access only to provide user-facing features you invoke:

  • sending email you compose, or sequences and campaigns you schedule, from your own address;
  • showing and organizing your inbox inside the CRM;
  • reading and creating calendar events for scheduling features.

SerapisERP’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising; we do not sell it; we do not transfer it except to provide the features above, to comply with law, or as part of a merger or acquisition with equivalent protections; and humans do not read it except with your permission, for security, or to comply with law. You can revoke access at any time at myaccount.google.com/permissions, and disconnecting removes our stored tokens.

Microsoft account data

Signing in with Microsoft shares your basic profile (name, email) with us. We request no mailbox or file access through Microsoft sign-in.

Calls, texts, and AI features

The platform includes AI features — an AI phone receptionist, AI dialing assistance, and AI-drafted content. The AI receptionist identifies itself as an AI assistant when asked, and calls it handles are transcribed and summarized for the account owner. You are responsible for complying with call-recording consent and telemarketing laws in your jurisdiction when you enable these features. AI outputs can be imperfect; review them before relying on them.

Sharing and service providers

We share data only with the processors needed to run the service, under their own privacy and security terms:

  • Cloudflare — hosting, storage, and network security
  • OpenAI — AI conversation and summarization processing
  • Vonage — voice calls and SMS delivery
  • Twilio and other carriers — where you connect your own trunk
  • Stripe — payment processing (we never store card numbers)
  • Google and Microsoft — sign-in and, if connected, mail/calendar
  • Resend — transactional email delivery

We may disclose information when required by law, or to protect the rights, safety, and security of Serapis, our users, or the public.

Retention and deletion

We keep your data while your account is active. You can delete records inside the product at any time; deleting your organization or account removes your customer content from the live systems, with residual copies in encrypted backups expiring on a rolling basis. Disconnecting an integration deletes its stored tokens.

Security

Data is encrypted in transit (TLS) and at rest on our infrastructure providers. Passwords are stored as bcrypt hashes. Access inside an organization is governed by per-module roles, and our public API surface is contract-tested. No system is perfectly secure; report suspected issues via the contact page and we will respond promptly.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Account holders can exercise most of these directly in the product; for anything else, contact us and we will respond within 30 days. If you are a customer of one of our customers, contact that business first — we process their data on their instructions.

Children

The service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.

Changes and contact

We will post any changes to this policy here and update the effective date; material changes will be announced in the product. Questions and requests: serapiserp.com/contact.