Privacy Policy
Effective date: August 6, 2026
What data we collect
Zyloq CRM collects information necessary to provide our customer relationship management services to digital marketing agencies and their clients.
- Account information: name, email address, phone number, job role, and company affiliation when you register or are invited to use Zyloq CRM.
- Customer and lead data: names, mobile numbers, email addresses, locations, service interests, lead sources, follow-up notes, and call outcomes entered by you or your team.
- Meta Lead Ads data: when connected, we receive lead data from Meta (Facebook/Instagram) forms, including full name, email, phone number, and any custom questions and answers submitted by the lead.
- Usage data: IP address, browser type, device information, and pages visited, collected automatically to improve service reliability and security.
How Meta Lead Ads data is processed
When you connect a Meta page to Zyloq CRM, we receive webhook events from Meta each time a lead submits a form. Our system:
- Maps the incoming lead to the correct company based on the connected Meta page ID.
- Stores standard fields such as name, email, and phone number.
- Captures all custom form questions and answers in a structured format for your review.
- Records campaign and form metadata (campaign ID, form ID, adset ID, etc.) when available.
- Checks for duplicate leads by mobile number and appends new information to the existing lead record instead of creating duplicates.
Meta Lead Ads data is processed only to help you manage leads and is never sold or shared with unrelated third parties.
How customer information is stored
All data is stored in a secure, enterprise-grade cloud database with the following safeguards:
- Data is isolated by company/tenant using Row Level Security (RLS) policies.
- Employees can only access data scoped to their role and assigned leads.
- All database connections are encrypted in transit using TLS.
- Backups are performed regularly to protect against data loss.
- We do not store passwords; authentication is handled via secure email-based one-time passcodes (OTP).
How to request deletion
You can request deletion of your personal data or your organization's data at any time by contacting us at the email below. We will process verified requests within 30 days and confirm once completed.
Please include the email address associated with your account and a description of the data you would like removed.
Contact us
For privacy-related questions, data access requests, or deletion requests, please email:
Effective date
This Privacy Policy is effective as of August 6, 2026. We may update it from time to time, and the latest version will always be available at this page.
