Bonalta CRM — the vertically-native CRM built to convert

Legal

Privacy Policy

Effective June 1, 2026

Bonalta (“Bonalta,” “we,” “us,” or “our”) provides managed lead acquisition (Bonalta Campaigns) and business software including CRM, phone, AI, and payments. This Privacy Policy explains how we handle personal information when you visit bonalta.com, submit a form, use our products, or otherwise interact with us.

Information we collect

We collect information you provide directly, such as your name, work email, phone number, company, vertical, team size, and messages submitted through contact forms or sales conversations.

If you use Bonalta software or Bonalta Campaigns, we also process account, billing, usage, call/SMS metadata, CRM records, and content you or your team upload or generate in the platform.

We automatically collect technical data such as IP address, browser type, device identifiers, pages viewed, referral URLs, and similar analytics when you use our websites and services.

How we use information

We use personal information to:

  • Respond to inquiries, demos, pilots, and sales requests
  • Provide, operate, secure, and improve Bonalta Campaigns and the Bonalta software suite
  • Send service-related communications, onboarding, support, billing, and product updates
  • Send marketing messages where permitted by law and your consent
  • Run advertising campaigns on your behalf when you are a Campaigns customer
  • Detect fraud, enforce our terms, and comply with legal obligations

SMS, calls, and email

If you provide a phone number or email address and consent to receive communications from us, we may contact you by SMS/text message, phone call (including autodialed or prerecorded calls where permitted), and email about Bonalta products, services, and offers.

Message frequency varies. Message and data rates may apply. You can reply STOP to opt out of SMS messages or HELP for assistance. Email opt-out links are included in marketing emails where required.

Consent to receive marketing messages is not a condition of purchasing our services. We maintain records of consent where required.

How we share information

We do not sell your personal information. We share information only as described below:

  • Service providers that help us host infrastructure, process payments, deliver email/SMS/voice, analytics, customer support, and advertising operations
  • Advertising platforms such as Meta, Google, and TikTok when operating campaigns for customers or measuring performance, subject to platform policies and customer authorizations
  • Professional advisors, auditors, or authorities when required by law, subpoena, or to protect rights, safety, and security
  • A successor entity in connection with a merger, acquisition, or asset sale, with notice where required

Google user data and Google API Services

Bonalta CRM lets a user connect their own Google account so their email works inside the CRM. Connecting is always optional, is started by the user from Settings → Email accounts, and requires the user to grant access on Google's own consent screen. Bonalta never accesses a Google account that has not been explicitly connected in this way.

When a user connects a Google account, Bonalta requests only the two Gmail scopes below, and uses each one for a single, specific feature:

  • https://www.googleapis.com/auth/gmail.readonly — used to read the user's Gmail labels, message lists and message contents so the CRM can display that email history next to the matching contact, lead or deal record. Bonalta only reads with this scope. It never modifies, labels, archives or deletes anything in the mailbox, which is why we do not request gmail.modify or full mail access.
  • https://www.googleapis.com/auth/gmail.send — used only to deliver an email that the user has composed inside Bonalta and explicitly sent by clicking Send, so the message is delivered from the user's own address and stays in their own Gmail Sent folder. Bonalta never sends bulk or marketing email through this scope, and never sends without a direct user action.

How we store, use, and share Google user data

OAuth access and refresh tokens are encrypted at rest. Synced Gmail data is stored in our database scoped to the individual user and to their organization's tenant, and is visible only to people authorized within that organization. We use Google user data solely to provide the email features described above. We do not sell Google user data, use it for advertising, or use it to build profiles for purposes unrelated to the CRM features the user connected the account for.

If a user chooses to use Bonalta's optional AI writing assistant, the subject and plain-text body of recent messages exchanged with the contact being written to, which may include messages synced from Gmail, are sent to our AI subprocessors (currently OpenAI and Anthropic) so the assistant can draft or improve that specific message. This happens only when the user actively invokes the assistant, and the data is used only to produce that response. Google user data is never used to develop, improve, or train generalized artificial intelligence or machine learning models, whether ours or a third party's, and our AI subprocessors are contractually bound not to train on it.

Bonalta's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

A user can disconnect their Google account at any time from Settings → Email accounts in Bonalta, or revoke Bonalta's access directly from their Google Account at https://myaccount.google.com/connections. On disconnection we stop all Gmail API access and delete the stored tokens; synced message data is deleted on request to privacy@bonalta.com and on account deletion.

Healthcare and regulated data

Some customers operate in healthcare or other regulated industries. Bonalta may process protected health information only under a Business Associate Agreement or other appropriate contract when applicable. Customers remain responsible for obtaining patient or consumer consents required for their use of Bonalta products.

Retention and security

We retain personal information for as long as needed to provide services, meet legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type and customer configuration.

We use administrative, technical, and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure.

Your choices and rights

Depending on your location, you may have rights to access, correct, delete, or obtain a copy of personal information we hold about you, or to opt out of certain processing including targeted advertising or sales of personal information where applicable.

To exercise privacy rights, contact us at hello@bonalta.com. We may verify your request before responding. Authorized agents may submit requests where permitted by law.

Cookies and analytics

Our websites may use cookies and similar technologies for essential functionality, preferences, and analytics. You can control cookies through your browser settings. Blocking cookies may affect site functionality.

International users

Bonalta is based in the United States. If you access our services from outside the U.S., you understand that information may be processed in the U.S. and other countries that may have different data protection laws.

Children

Our services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the effective date. Material changes may be communicated by email or a notice on our website where required.

Contact us

Questions about this Privacy Policy or our data practices:

Bonalta · hello@bonalta.com · +1 (305) 859-4659 · Miami, Florida, USA