Privacy Policy
Last updated: July 27, 2026 · Effective date: [[EFFECTIVE DATE]]
1. Controller identity and address
[[LEGAL ENTITY NAME]], Mexican federal taxpayer ID (RFC) [[RFC]], doing business as Black Tiger Partners ("Black Tiger", "we", "us"), with registered address at [[FULL REGISTERED ADDRESS]], is the controller responsible for processing your personal data under Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), its Regulations, and the Privacy Notice Guidelines.
This policy covers blacktiger.partners, the CRM at crm.blacktiger.partners, the WhatsApp and Instagram chatbots we operate, and any integration the account holder chooses to connect, including QuickBooks Online.
Privacy contact: [[PRIVACY EMAIL]].
2. Personal data we process
2.1 CRM users (our clients and their staff)
- Name, email address, phone number, role, and the organization they belong to.
- Access credentials managed by Supabase Auth (passwords are stored hashed by the authentication provider; Black Tiger cannot read them).
- In-product activity: actions on prospects, cards, internal messages, and audit logs.
- Integration tokens connected by the user or by Black Tiger on the organization's behalf.
2.2 Prospects and end customers recorded by our clients in the CRM
- Name or company name, email, phone, website, commercial notes, pipeline stage, quotes, and invoices.
- Interaction history and files the CRM user attaches.
2.3 People who interact with our chatbots
- WhatsApp phone number or Instagram identifier, and profile name where the channel exposes it.
- Message content, timestamps, and any data the person volunteers (name, email, appointment details).
2.4 Website visitors
- Contact and audit form submissions: name, email, company, website, phone.
- Technical and browsing data collected via Google Tag Manager and Google Analytics (see section 11).
2.5 Financial data
- Client organization billing records: amounts, invoice numbers, currencies, issue and due dates, payment status.
- Data retrieved from QuickBooks Online while the integration is active (see section 4).
- Bank or card statements a CRM user chooses to upload for automated analysis (see section 7, subprocessor Anthropic).
We do not deliberately process sensitive personal data (health, ethnic origin, beliefs, sexual orientation, biometrics). If a person includes such data in a chatbot message or a CRM note, it is retained only as part of that record and used for no additional purpose.
We do not request or store payment card numbers. Subscription charges are processed by Stripe, which receives payment details directly.
3. Purposes of processing
3.1 Primary purposes (necessary for the contractual relationship)
- Create and administer CRM accounts and enforce per-organization permissions.
- Deliver the contracted services: prospect and pipeline management, WhatsApp and Instagram automation, marketing reporting, internal invoicing, and financial visibility.
- Handle chatbot requests: reply to messages, book, confirm, or cancel appointments on behalf of the relevant business.
- Sync information with integrations the account holder has explicitly connected.
- Invoice, collect payment, and administer the commercial relationship.
- Technical support, security, abuse prevention, and access auditing.
- Comply with legal and tax obligations and with lawful requests from competent authorities.
3.2 Secondary purposes (not necessary; you may object without losing the service)
- Sending commercial communications, product updates, and educational content.
- Measuring website and product usage for improvement and aggregate analytics.
- Producing case studies or reference material, always with prior written authorization from the client organization.
To object to processing for secondary purposes, write to [[PRIVACY EMAIL]] from or citing the relevant email address. Under Mexican law you have five business days from becoming aware of this notice to object, and you may also object at any time afterwards.
4. QuickBooks Online (Intuit) integration
The QuickBooks Online integration is optional and is established through Intuit's official OAuth 2.0 flow, in which the QuickBooks account holder grants explicit consent on Intuit's own authorization screen. Authorized Black Tiger personnel perform the connection at the client organization's request; it is never established without that authorization on Intuit's screen.
We request a single scope: com.intuit.quickbooks.accounting. We do not request payroll access, QuickBooks Payments access, or Intuit user identity/profile data.
4.1 What we read from QuickBooks
When importing invoices (pull), we read the following from each invoice in the connected account:
| QuickBooks field | Where it lands in our systems |
|---|---|
| Invoice Id and document number | biz_invoices.qbo_invoice_id and folio |
| Total amount, currency, outstanding balance | biz_invoices.amount, currency, and payment status derived from the balance |
| Transaction date and due date | biz_invoices.issued_date, due_date |
| Customer name and customer Id on the invoice | biz_invoices.notes and prospects.qbo_customer_id, to link the invoice to the matching CRM record |
We do not read or store the chart of accounts, journal entries, balance sheets, tax filings, payroll, employees, or payment methods. We do not access consolidated QuickBooks financial reports.
4.2 What we write to QuickBooks
Only on the express instruction of an authorized CRM user, and one invoice at a time, we may:
- Create or update an invoice in the connected account using the amount, document number, due date, and description captured in the CRM. Only invoices denominated in US dollars (USD) are synced.
- Create or look up the matching Customer record, sending its name and, where present in the CRM, its email address.
We do not provide accounting services. We do not reconcile, close periods, file returns, or modify the client's books on our own initiative, automatically, or on a schedule. Every write to QuickBooks originates from an explicit user action inside the CRM.
4.3 How we use this data
- Financial visibility inside the CRM: showing real invoicing, outstanding receivables, and overdue invoices in the same place the commercial relationship lives.
- Comparing real invoicing against marketing spend to measure return per client and per campaign.
- Avoiding double entry between the CRM and the client's accounting.
We do not use QuickBooks data for advertising, do not sell it, do not share it with third parties for commercial purposes, do not combine it across client organizations, and do not use it to train artificial-intelligence models.
4.4 Disconnecting, and what happens to the data
- The client organization may request disconnection at any time by writing to [[PRIVACY EMAIL]], or by revoking access directly from its Intuit account.
- On disconnection we revoke the token with Intuit, mark the integration as revoked, and delete the refresh token, the access token, and the connection metadata (company realm id and company name) from our database.
- From that moment on, nothing further is read from or written to QuickBooks.
- Invoices already imported remain in the CRM as part of the organization's own financial history, because they form part of its commercial record. If you also want them deleted, request it expressly in the same email and we will do so.
5. Other optional integrations
- Google Calendar: read, create, update, and delete events on the connected calendar, plus the account email address to identify it. Used only to sync the calendar with the CRM. Use of Google API data is additionally governed by the Google API Services User Data Policy, including its Limited Use requirements.
- WhatsApp Business API and Instagram (Meta): receiving and sending messages on the channels the organization connects.
- Meta Ads, Google Ads, Google Analytics 4, Google Search Console, Google Business Profile: campaign and site metrics for marketing reports.
- Google Drive: linking files the user chooses to associate with a client or project.
- QuickBooks Online: see section 4.
Each integration is enabled at the client organization's discretion and can be disconnected at any time.
6. Where data is stored and for how long
Data is stored on Supabase infrastructure (PostgreSQL database and file storage) and processed in Vercel serverless functions. Both providers operate servers outside Mexico, primarily in the United States, which constitutes an international transfer (see section 7).
| Data type | Retention |
|---|---|
| CRM user accounts | For the term of the contract, plus applicable statutory tax and liability periods |
| Prospects, clients, CRM records | Controlled by the client organization; retained while its account is active |
| Chatbot conversations | Up to 12 months, unless the client organization requests less or the law requires more |
| Invoices and financial records, including those imported from QuickBooks | While the account is active and for the period required by applicable tax rules |
| Integration tokens | Until disconnection or revocation; deleted at that point |
| Audit and security logs | Up to 24 months |
On termination, the client organization may request export and deletion of its data as described in section 9.
7. Transfers and subprocessors
We do not sell personal data. Transfers are limited to providers that supply infrastructure and processing services on our instruction and under confidentiality obligations, and to the cases the LFPDPPP permits without consent (competent authority, compliance with legal obligations, exercise of rights in legal proceedings).
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Vercel Inc. (USA) | Hosting of the website, CRM, and serverless functions | All data transiting the application; technical logs |
| Supabase Inc. (USA) | Database, authentication, file storage | All CRM data, integration tokens, files |
| Intuit Inc. (USA) | QuickBooks Online accounting integration | Invoices, customer names and emails, per section 4 |
| Meta Platforms, Inc. (USA) | WhatsApp and Instagram messaging; Meta Ads metrics | Phone numbers, profile identifiers, message content, campaign metrics |
| Google LLC (USA) | Calendar, Drive, Analytics, Ads, Search Console, Business Profile, Tag Manager | Calendar events, linked files, browsing data, metrics |
| Anthropic PBC (USA) | Large-language-model processing: automated chatbot replies, ad-account analysis, analysis of documents and account statements the user uploads | Content of the messages or documents submitted for analysis, including financial data when a user uploads a statement |
| Resend, Inc. (USA) | Transactional email and notifications | Name, email address, message content |
| Stripe, Inc. (USA) | Subscription payment processing | Billing and payment data, received directly by Stripe |
| Slack Technologies (USA) | Internal operational alerts, where the organization configures them | Alert metadata; may include a prospect name |
Data sent to Anthropic for processing is not used to train its models, per its commercial API terms. We will update this list when it changes, as described in section 13.
8. Security measures and token handling
- Encryption in transit: all traffic runs over HTTPS/TLS.
- Encryption at rest: the database and file storage are encrypted at rest by Supabase infrastructure.
- Per-organization isolation: PostgreSQL Row Level Security policies prevent one organization from reaching another's data.
- OAuth tokens: QuickBooks and other integration tokens are stored in database columns with no read grant to application user roles; only the privileged server-side process can read them. They are covered by database encryption at rest, but we do not apply an additional application-level encryption layer to the token value itself.
- Never in code: neither tokens nor app credentials are committed to source control; they live in hosting-provider environment variables.
- Rotation: Intuit rotates the QuickBooks refresh token on every renewal, and our system persists the new value and discards the previous one in the same operation. Access tokens are short-lived and renewed automatically.
- Never in URLs: we do not transmit tokens or personal data in query strings.
- Access control and auditing: role-based permissions, logging of sensitive actions, and least privilege for Black Tiger staff.
- Restricted QuickBooks connection: only authorized Black Tiger personnel can establish or revoke the OAuth connection, and only with the QuickBooks account holder's authorization.
No system is infallible. In the event of a breach that materially affects your property or moral rights, we will notify you without delay so you can take action.
9. Your rights and how to exercise them
You have the right to access your data, rectify it when inaccurate or incomplete, request its cancellation (deletion) when you believe it is not needed for the stated purposes, and object to its processing for specific purposes — the "ARCO" rights under Mexican law. You may also limit its use or disclosure.
Procedure:
- Email [[PRIVACY EMAIL]] with the subject "ARCO request".
- Include: full name and a means of reply; a copy of valid government-issued ID (or of the power of attorney if acting as legal representative); a clear description of the data and the right you wish to exercise; and any document that helps locate the data.
- We respond within 20 business days of receiving a complete request. Where the request is granted, we give it effect within 15 business days of that response. Both periods may be extended once for an equal term where circumstances justify it, with prior notice to you.
- Exercising these rights is free of charge; only justified shipping or reproduction costs may be charged.
- If you believe your request was not properly handled, you may file a complaint with Mexico's data protection authority.
Where we act as processor on behalf of a client organization — for example, regarding prospects it enters in the CRM, or its accounting data in QuickBooks — we will route your request to that organization, which is the controller for that data, and inform you accordingly.
10. Withdrawing consent
You may withdraw consent at any time by writing to [[PRIVACY EMAIL]] following the procedure in section 9. We action withdrawals within 20 business days.
Additional channels depending on the case:
- Integrations: disconnect from the CRM, revoke access at the provider (Intuit, Google, Meta), or request it by email.
- Chatbots: reply "BAJA" or "STOP" on the relevant WhatsApp channel, or request conversation deletion by email.
- Marketing email: use the unsubscribe link in any message, or reply asking to be removed.
Note that withdrawal may prevent us from continuing to provide the contracted service where the processing is necessary to deliver it, and that it does not apply retroactively to processing already carried out or to data we must retain by law.
11. Cookies and tracking technologies
Yes, we use cookies and tracking technologies on the public website. Specifically:
- Google Tag Manager and Google Analytics 4 on blacktiger.partners content pages. These legal pages load no analytics tags. They collect browsing data (pages viewed, traffic source, device type, cookie identifier) and record clicks on WhatsApp contact buttons.
- Browser local storage to remember the site language preference and, in the CRM, to keep the session signed in and store interface preferences. This storage is functional and necessary.
You can block or delete cookies from your browser settings, or install the Google Analytics opt-out add-on. Blocking analytics cookies does not affect the website; blocking CRM local storage prevents signing in.
As of this date we do not operate a cookie consent manager on the website. We state this explicitly rather than omit it.
12. Minors
Our services are intended for businesses and adults. We do not knowingly collect data from minors. If we learn that a minor's data was received without the consent of a parent or guardian, we delete it.
13. Changes to this policy
We may amend this policy to reflect changes in law, in our services, in our privacy practices, or in the subprocessor list. Changes are communicated as follows:
- The current version is always published at blacktiger.partners/legal/privacy, with the last-updated date visible at the top.
- Material changes — new purposes, new transfers, or a change of controller — are notified at least 15 calendar days in advance to CRM users' registered email addresses and by a visible in-product notice.
- Minor changes, such as wording corrections or updated contact details, are reflected directly on this page.
14. Contact
- Privacy matters and ARCO requests: [[PRIVACY EMAIL]]
- General contact: info@blacktiger.partners
- Address: [[FULL REGISTERED ADDRESS]]
- Website: blacktiger.partners
Spanish version: Aviso de Privacidad. Related document: Terms of Service. Each client organization may additionally maintain its own privacy notice toward its end customers.