Privacy Policy

Obermatt CRM · Last updated 1 July 2026

Obermatt CRM is an internal customer-relationship tool operated by Obermatt AG (Schaffhauserstrasse, Zürich, Switzerland) for its own team. This policy explains how the application handles data, with particular emphasis on the optional Google integrations (Contacts sync and Gmail correspondence import).

Google Contacts integration

When a team member chooses to connect their Google account, Obermatt CRM requests the Google Contacts permission (https://www.googleapis.com/auth/contacts). It is used for a single purpose: to copy contacts that already exist in Obermatt CRM, one-way, into that user’s own Google Contacts, filed under a label named “Obermatt CRM”, so the user has those business contacts on their own devices.

The application only creates, updates, and removes the contacts it placed there itself (identified by an internal marker). It does not read, use, or modify the user’s other Google contacts for any other purpose. The integration is one-way (Obermatt CRM → Google), entirely optional, and runs only when the user connects their account and triggers a sync (manually or via a scheduled refresh of the same data).

Gmail integration

When a team member chooses to connect their Google account for sending, Obermatt CRM requests permission to send email on their behalf (https://www.googleapis.com/auth/gmail.send) and to read that account’s own email address (https://www.googleapis.com/auth/userinfo.email). It is used for a single purpose: when the user composes a message to a business contact from within Obermatt CRM (individually or as a batch to several contacts), the message is sent through the user’s own Gmail account and filed onto the contact’s timeline, so the team has a record of the correspondence.

The access is limited to sending: Obermatt CRM never reads, alters, labels, or deletes any existing Gmail message. Messages are sent only when the user explicitly composes and sends them from the CRM. The feature is entirely optional and runs only when the user connects Gmail and chooses to send via Gmail.

Limited Use disclosure

Obermatt CRM’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide and improve the user-facing contact-sync and correspondence-import features described above; it is never sold or transferred to third parties, never used for advertising, and never used to train generalized artificial-intelligence or machine-learning models.

What we store

For each Google service a user connects (Contacts and/or Gmail), Obermatt CRM stores an encrypted Google OAuth refresh token (AES-256-GCM, encrypted at rest), the connected account’s email address, and basic status (last run time and counts). No content from a user’s existing Google contacts is read into or retained by Obermatt CRM. Email messages that a user explicitly imports for a given contact are stored in Obermatt CRM as email activity entries on that contact’s timeline — the same kind of record the team already keeps for correspondence — visible only to authorized Obermatt staff.

Your choices

A user can disconnect the Google Contacts sync at any time under Settings → Google Kontakte, which deletes the stored token and stops syncing. A user can revoke Obermatt CRM’s Gmail access at any time from their Google Account permissions, which stops all further access. Contacts already copied into the user’s Google account remain there and can be deleted by the user (for example, by deleting the “Obermatt CRM” label and its contacts). Email correspondence already imported into Obermatt CRM can be removed by deleting the corresponding timeline entries.

Security

All access is over HTTPS. OAuth tokens are encrypted at rest and are only ever used server-side. Application access is restricted to authenticated, authorized Obermatt staff; each user can only reach their own Google connection.

The CRM itself

Independently of the Google integration, Obermatt CRM stores Obermatt’s own business contact data (names, organisations, email addresses, postal addresses, and activity history) for internal sales and relationship management. Access is limited to authorized Obermatt staff and the data is not shared externally.

Contact

Questions about this policy can be directed to info@obermatt.com.