← Back to ERPnBox

Privacy Policy

Last updated: July 31, 2026

1. Introduction

ERPnBox ("we," "our," or "us") operates the ERPnBox platform, a cloud-based Customer Relationship Management (CRM) and Enterprise Resource Planning (ERP) solution. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, including our website, applications, and integrations with third-party services such as Meta (Facebook/Instagram).

2. Information We Collect

2.1 Account Information

When you register for an ERPnBox account, we collect your name, email address, company name, and other information you provide during registration.

2.2 CRM Data

Data you enter into ERPnBox modules (contacts, leads, deals, activities, etc.) is stored securely within your tenant-isolated environment. This data belongs to you and is processed solely to provide our services.

2.3 Social Media Integration Data (SocialSync)

When you connect your Facebook Pages through our SocialSync feature, we collect:

  • Facebook Page IDs and names you choose to connect
  • Page access tokens (securely stored and encrypted) to retrieve lead data
  • Lead form submissions from Facebook/Instagram Lead Ads, including names, email addresses, phone numbers, and other fields submitted by leads
  • Form metadata (form IDs, form names)

We access this data only through permissions you explicitly grant via the Facebook OAuth authorization flow. We do not access any data beyond what is required for the lead synchronization functionality.

2.4 Financial Account Data (Bank Connections & Payments)

If you choose to connect a bank account to the ERPnBox Finance module, the connection is made through Stripe Financial Connections. You authenticate directly with your financial institution inside Stripe's secure interface — your online banking credentials are never seen, transmitted, or stored by ERPnBox. With your explicit authorization, we may receive:

  • Account details (institution name, account type, last four digits, and tokenized account/routing numbers used to verify accounts and process bank payments)
  • Account balances
  • Transaction data (date, amount, description, and merchant information) used to power bank feeds, bookkeeping, and reconciliation

We use this data solely to provide accounting functionality within your tenant-isolated environment: importing bank transactions, matching them to your ledger, reconciling accounts, and verifying accounts for payments you initiate. We do not sell this data, share it with third parties for their own purposes, or use it for advertising, credit decisioning, or any purpose unrelated to the services you request. Financial account data is stored encrypted in the United States. You can disconnect a bank account at any time from the Finance Banking settings or by contacting support@erpnbox.com, which revokes our access to further data; imported transactions already in your books remain under your control and follow the retention rules in Section 7.

2.5 Usage and Log Data

We automatically collect certain information when you use our platform, including IP addresses, browser type, pages visited, and actions taken within the application. This data is used for security, analytics, and service improvement.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the ERPnBox platform
  • Synchronize leads from Facebook/Instagram Lead Ads into your CRM
  • Import bank transactions and balances you authorize (via Stripe Financial Connections) to power bank feeds, reconciliation, and bank payments in the Finance module
  • Process and assign leads based on your configured rules
  • Send system notifications, account updates, and security alerts
  • Provide customer support
  • Ensure the security and integrity of our platform
  • Comply with legal obligations

4. Data Sharing and Disclosure

We do not sell, rent, or share your personal data or CRM data with third parties for their marketing purposes. We may share data only in the following circumstances:

  • Service Providers: With trusted third-party providers who help us operate our platform (hosting, email delivery, analytics), under strict data processing agreements.
  • Payments & Banking Infrastructure: With Stripe, our payments and bank-connection processor, solely to provide billing, bank account verification, and bank feed functionality you enable. Stripe processes this data under its own privacy program.
  • Legal Requirements: When required by law, court order, or governmental authority.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users.
  • With Your Consent: When you explicitly authorize sharing.

5. Meta (Facebook) Platform Data

Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies. Specifically:

  • We only request permissions necessary for lead synchronization functionality
  • Data obtained from Meta is used solely to sync leads into your CRM and is not used for any other purpose
  • We do not transfer Meta data to third parties, including data brokers or advertising networks
  • We do not use Meta data for purposes unrelated to the core functionality of our app
  • You can disconnect your Facebook Pages at any time from Settings > SocialSync, which revokes our access

6. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption of data in transit (TLS/SSL) and sensitive data at rest
  • Tenant-level data isolation — each organization's data is logically separated
  • Role-based access controls and authentication via JWT tokens
  • Regular security audits and monitoring
  • Secure storage of access tokens and API credentials

7. Data Retention

We retain your data for as long as your account is active or as needed to provide our services. CRM data is retained within your tenant environment until you delete it or close your account. Sync logs from SocialSync are retained for audit purposes and can be viewed in the SocialSync Dashboard. Upon account termination, all tenant data is permanently deleted within 30 days.

8. User Data Deletion

You have the right to request deletion of your data at any time. To request data deletion:

  • Disconnect Facebook: Go to Settings > SocialSync and click "Disconnect" to remove your Facebook connection and associated sync data.
  • Delete Account: Contact us at support@erpnbox.com to request full account and data deletion.
  • Delete Specific Records: Use the CRM interface to delete individual records at any time.

We will process deletion requests within 30 days and confirm completion via email.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Data portability — receive your data in a structured, machine-readable format
  • Withdraw consent at any time for consent-based processing

To exercise any of these rights, contact us at support@erpnbox.com.

10. Cookies

We use essential cookies and local storage for authentication (JWT tokens) and user preferences (theme, navigation order). We do not use third-party tracking cookies or advertising cookies.

11. Children's Privacy

ERPnBox is a business application not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of ERPnBox after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

© 2026 Zocube. All rights reserved.

ERPnBox is a product by Zocube