Legal & Privacy

Privacy Policy

This policy explains how Ocean Technolab collects, uses, protects, and manages information shared through our website, contact forms, WhatsApp, phone, email, client service conversations, or the Ocean CRM mobile application.

Effective: July 3, 2026Last updated: July 20, 2026

1. Overview

Ocean Technolab operates the website at www.oceantechnolab.com and provides website design and development, ecommerce solutions, full stack development, software development, mobile app development, graphic design, and digital marketing services, including our own product, Ocean CRM, available as a web application and as an Android app on the Google Play Store.

This Privacy Policy applies to visitors, prospects, clients, partners, Ocean CRM account holders and their users, and any person who shares information with us through our website, contact form, email, phone, WhatsApp, social channels, project communication channels, or the Ocean CRM app.

By using our website, contacting Ocean Technolab, or installing/using the Ocean CRM app, you agree to the practices described in this Privacy Policy.

2. Information We Collect

We collect different categories of information depending on how you interact with us — as a website visitor, an agency/project client, or an Ocean CRM account holder or user. These fall into two roles:

  • As a Data Controller — for information we collect to run our own business relationship with you (Section 2.1).
  • As a Data Processor — for information our clients enter into Ocean CRM about their own leads, which we host and process only on their instructions (Section 2.2).

2.1 Account & Contact Information (Data Controller Role)

Collected to manage the business relationship, billing, and system access:

  • User profiles: Names, business email addresses, phone numbers, and profile photos of your team members.
  • Organization details: Company name, billing address, business registration numbers (e.g., GSTIN/tax IDs), and website URLs.
  • Billing records: Transaction IDs, invoices, and billing history. Actual card/payment details are collected directly by our secure payment processor (e.g., Razorpay/Stripe) — we do not store full card numbers on our own servers.

2.2 Service & CRM Data (Data Processor Role)

This is the data you (or your organization) enter, upload, or sync into Ocean CRM. You own this data; we host and process it only to provide the service to you:

  • Lead database: Names, email addresses, phone numbers, job titles, and company details of your leads.
  • Sales pipeline details: Deal stages, contract values, transaction histories, and sales forecasts.
  • Activity logs & notes: Text notes, task reminders, call logs, meeting schedules, and interaction history with leads.
  • Uploaded media & files: PDF contracts, image attachments (e.g., photos of business cards or receipts), and text documents attached to lead records.

2.3 Technical & App Diagnostics (Automatically Collected)

Collected automatically when you browse our website or use Ocean CRM (web or app):

  • Device & system info: Device type, operating system version, app version, screen resolution, and IP address.
  • App usage data: Crash/error logs, load times, and feature-usage data (which screens/buttons are used), collected via standard Android system diagnostics (Google Play's built-in app vitals) to help us monitor app stability. We do not use third-party analytics or crash-reporting SDKs inside the app.
  • Website analytics: Pages visited, approximate location, referral source, and browsing activity via cookies/server logs (see Section 6).

3. How We Use Information

We use personal and business information to respond to inquiries, schedule calls, prepare proposals, understand project requirements, deliver services, provide support, and maintain client relationships.

We may use contact information to share project updates, invoices, support responses, service notices, or follow-up communication related to website, ecommerce, software, app, design, marketing, or Ocean CRM work.

We may use website and app usage information to improve our content, navigation, service pages, performance, security, and overall user experience.

4. Services and Project Data

For service delivery, clients may share brand assets, business data, website access, hosting access, product information, customer workflows, marketing assets, analytics access, or integration details.

Technical credentials. For custom website/software development projects, clients may share:

  • Server & hosting access: Login credentials for AWS, DigitalOcean, cPanel, Netlify, or similar.
  • Database access: Connection details for MongoDB, PostgreSQL, MySQL, or similar databases.
  • Domain registrar access: Details for GoDaddy, Namecheap, Cloudflare, or similar.
  • Third-party API keys: For services such as WhatsApp Business API, Stripe, Firebase, or Mailchimp, provided by the client to enable integrations we build for them.

We use project data and technical credentials only for the purpose of planning, designing, developing, testing, launching, maintaining, or marketing the agreed work, unless the client gives separate permission for another use.

Client access credentials, confidential files, and business information are handled with care and shared internally only with people who need them for the project or support request.

5. Ocean CRM Mobile Application

This section applies specifically to the Ocean CRM app available on the Google Play Store.

What Ocean CRM stores on your behalf

Ocean CRM stores the Service & CRM Data described in Section 2.2 (lead databases, sales pipeline details, activity logs, and uploaded files) that you or your organization enter into the app. You own this data. Ocean Technolab processes it only to provide the CRM service and support to you, and does not use it for any other purpose, such as selling it or using it to advertise to your leads. The app also generates the Technical & App Diagnostics described in Section 2.3 automatically, used only to keep the app stable and working correctly.

App permissions

The Ocean CRM Android app requests the following permissions. Each is used only when you actively use the related feature, and you can allow or revoke any of them at any time from your device Settings:

  • Contacts: To let you import phone contacts as leads into your CRM.
  • Storage / Photos: To let you attach images, documents, or business cards to a lead or deal, and to save/export files from the app.
  • Microphone: To let you record voice notes attached to a lead or deal.
  • Notifications: To send task reminders and lead-activity alerts.

We do not use any third-party analytics, advertising, or crash-reporting SDKs (such as Google Analytics or Firebase) inside the Ocean CRM app. If this changes in the future, we will update this Policy and the app's Google Play Data Safety disclosure beforehand.

Push notifications

If you enable notifications, we send task reminders and lead alerts to your device through Google's push notification service. You can turn these off anytime in the app or device settings.

6. Ocean CRM Google Calendar Integration

Ocean CRM's Google Calendar connection is optional and requires your explicit Google OAuth consent. You can connect Google Calendar, view connection status, select a target calendar, and disconnect the integration from your Ocean CRM account settings.

When you connect Google Calendar, Ocean CRM may access your Google account email address, available calendar list and calendar names, your selected target calendar ID, and calendar event data required to create, update, or manage CRM appointment and task events. The exact Google OAuth scopes are controlled by our backend authorization flow and should match the permissions shown during Google's consent process.

Ocean CRM uses Google Calendar data only to provide and improve the user-facing calendar sync feature. This may include creating or updating calendar events for CRM tasks, appointments, meetings, reminders, and client follow-ups selected or generated inside Ocean CRM.

Ocean CRM does not use Google Calendar data for advertising, retargeting, credit scoring, selling data, or unrelated analytics. Ocean CRM does not sell Google user data.

Ocean CRM does not transfer Google Calendar data to third parties except when necessary to provide the integration, comply with law, protect security, or with your consent.

Human access to Google Calendar data is restricted and only occurs when necessary for support requested by you, security investigation, legal compliance, or internal operations under privacy controls.

OAuth tokens or credentials, if stored, are protected using reasonable security controls and used only to maintain the Google Calendar sync connection.

You can disconnect Google Calendar from Ocean CRM account settings at any time. After disconnection, Ocean CRM will stop syncing new events with Google Calendar. You may also revoke Ocean CRM's Google access from your Google Account permissions page.

Ocean CRM’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Ocean CRM LinkedIn Lead Gen Forms Integration

If an Ocean CRM customer connects LinkedIn Lead Gen Forms, or if you submit information through a LinkedIn Lead Gen Form connected to Ocean CRM, Ocean CRM may collect lead information received from LinkedIn.

The LinkedIn lead information we receive may include name, email address, phone number, company name, job title, form responses, LinkedIn lead form ID, submitted time, campaign or source information, and related metadata made available through the authorized LinkedIn integration.

Ocean CRM uses LinkedIn lead data to import leads into Ocean CRM, assign and manage leads, support follow-ups, provide CRM reporting, track lead sources, and enable customer communication.

Ocean CRM uses LinkedIn APIs only to fetch and sync authorized lead data. Ocean CRM does not sell LinkedIn lead data.

LinkedIn access tokens or integration credentials may be stored using encryption or other reasonable security controls to keep the integration working.

LinkedIn lead data may be shared only with authorized users inside the customer's organization, service providers needed to operate Ocean CRM, or where legally required.

Customers are responsible for ensuring they have the required permissions, notices, consents, and lawful basis to collect and process leads from LinkedIn through Ocean CRM.

Customers can disconnect the LinkedIn integration from Ocean CRM. After disconnection, future LinkedIn lead syncing will stop, and deletion or retention of previously imported CRM records will follow Ocean CRM's data retention and account deletion policies.

LinkedIn is a third-party platform, and LinkedIn's own collection and processing of data is governed by LinkedIn's Privacy Policy.

8. Cookies and Analytics

Our website may use cookies, analytics tools, pixels, or similar technologies to understand visitor behavior, measure performance, and improve services.

Cookies may help remember preferences, measure traffic sources, identify popular pages, and understand how visitors interact with our content.

You can control cookies through your browser settings. Blocking cookies may affect some website features or measurement accuracy.

9. Sharing Information

We do not sell personal information. We may share information only when required to deliver services, operate the website or app, process communication, comply with law, protect our rights, or work with trusted service providers.

Service providers may include hosting companies, email platforms, analytics tools, payment or accounting tools, CRM infrastructure providers, development tools, and communication platforms.

Where third-party tools are used, their own privacy policies and security practices may also apply.

10. Data Security

We use reasonable technical, administrative, and organizational measures to protect information from unauthorized access, misuse, loss, alteration, or disclosure. Data transmitted between the Ocean CRM app and our servers is encrypted in transit.

No website, app, internet transmission, email, or online storage system is completely secure. For sensitive project access or credentials, clients should use secure sharing methods whenever possible.

If we become aware of a security issue affecting personal or client data, we will take appropriate steps to investigate, respond, and notify affected parties where required by applicable law.

11. Data Retention

We retain inquiry, project, support, billing, and communication records for as long as needed to respond to requests, deliver services, meet legal or accounting obligations, resolve disputes, and maintain business records.

For Ocean CRM, we retain your account and CRM data for as long as your account remains active. Project files and access details may be retained during active work and for a reasonable period after completion to provide support, maintenance, or reference for future requests.

You may request deletion or correction of your personal information, subject to legal, contractual, operational, or legitimate business requirements.

12. Your Rights, Account & Data Deletion

Depending on applicable law, you may request access to personal information we hold about you, ask us to correct inaccurate information, request deletion, withdraw consent, or object to certain processing.

Deleting your Ocean CRM Account

  • In-App Deletion Redirect: You can request account deletion directly within the Ocean CRM mobile app settings, which will redirect you to our secure web portal to complete the account and data deletion process.
  • Web Deletion Request: If you have already uninstalled the app and wish to request deletion of your personal account, you can submit a request by sending an email to support@oceantechnolab.com from your registered business email address. We will process your request within 30 days.
  • Scope of Deletion:
    • Personal Data: Deleting your account permanently deletes your personal profile, credentials, and contact details from our active directories.
    • Organization Data: Deleting your individual user account does not delete lead databases, transactions, files, or logs owned by your organization. This data remains intact for organization continuity.
    • Organization Termination: All organization-owned data will be permanently deleted only when the organization's account subscription is canceled and terminated.
  • Deleting Only Part of Your Data: If you'd like to delete specific data (e.g., a set of leads or uploaded files) without deleting your entire account, email us at support@oceantechnolab.com with details of what you'd like removed, and we'll process it separately from a full account deletion.

14. Children's Privacy

Our website and services, including Ocean CRM, are intended for business users, clients, and general website visitors. They are not directed to children.

We do not knowingly collect personal information from children. If you believe a child has shared personal information with us, please contact us so we can review and remove it where appropriate.

15. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our services, website, app, technology, legal requirements, or business practices.

The latest version will be posted on this page with the updated date. Continued use of our website, app, or services after changes are posted means you accept the updated policy.

16. Contact Us

For privacy questions, requests, or concerns, email us at support@oceantechnolab.com.

You can also contact Ocean Technolab by phone at +91 78599 93590, by WhatsApp at +91 785 999 3590, or by visiting/contacting us at Shreeji Skyline, 615-616, Sun Pharma Road, near Nayra Petrol Pump, Mathura Nagri Society, Atladara, Vadodara, Gujarat.

Need to request data deletion?

If you have uninstalled Ocean CRM and wish to remove your account data, send us an email request from your registered address.

Email Deletion Request

Have questions about privacy?

Contact Ocean Technolab for privacy requests, contact-form data questions, or project data handling concerns.