Privacy Policy
Last updated: August 26, 2026
1. Introduction
Kasar places the utmost importance on privacy, data security, and compliance with the General Data Protection Regulation (GDPR). This policy details how your personal data is managed, collected, and used when you use our services.
2. What data do we collect?
We only collect the information necessary for Kasar services to operate properly, including:
- Account information: name, email, password (encrypted)
- Usage data and technical logs (IP addresses, device, browser, interactions, etc.)
- Data from integrations (see next section)
- No sensitive data within the meaning of the GDPR (origin, health, opinions, etc.) is processed
2.1 Traffic source measurement
When you reach kasar.app from another site, a search engine, an AI assistant or a link we sent you, we record where you came from in a cookie set on the kasar.app domain. It holds only the originating channel: the source, the channel type, the campaign name, the referring site and the landing page.
This cookie holds no name, no email address and no third-party advertising identifier. It is not shared with ad networks and is not used to track you across other websites. If you contact us or book a demo, this origin is attached to your request so that we know which channels make us known. It is kept for 180 days.
No cookie is set if your visit carries no source information. You can delete it at any time from your browser settings.
2.2 Website analytics
To understand how our public website is used and improve it, we measure page audience with a single tool: PostHog, hosted in the European Union. It records the pages viewed, the country inferred from your IP address, your device and browser, time spent, scroll depth and the elements you click.
This measurement is COOKIE-FREE: we store nothing on your device, neither cookies nor local storage. To tell visits apart, PostHog derives a hashed technical identifier from your IP address and browser; it rotates daily and cannot recognise you from one day to the next. That is why no consent banner is imposed on you: there is nothing to consent to.
We do not record your browsing: no session video or replay is captured. The measurement is aggregated — it exists to understand a page, not to watch a person.
This data is not tied to your identity, is never sold, is not used for advertising targeting and enables no tracking across other websites. You may object at any time by writing to our contact address, or by enabling your browser’s “Do Not Track” signal, which we honour.
3. Integrations and extensions
Kasar lets you connect various third-party services to enrich your CRM experience (Gmail, WhatsApp, LinkedIn, Chrome extension, browser, etc.). When you enable these integrations, we may collect the following depending on your action:
- Information from emails (addresses, metadata, content based on permissions)
- Contacts and profiles from LinkedIn
- Information from WhatsApp conversations (content, contacts, subject to your explicit authorization)
- Items captured via our Chrome extension (page data when the user performs an action such as "Add to CRM")
- Events and metadata from Google Calendar (see dedicated section below)
All such data is collected only at your express initiative and is used solely to provide the requested functionality.
4. Kasar CRM Chrome extension
The Kasar CRM Chrome extension complements the platform by letting you import contacts and sync your conversations directly from your browser. Here are the specifics of the extension:
4.1 Data collected by the extension
All data is sent exclusively to your personal Kasar CRM workspace via the kasar.app API. No data is shared with third parties.
- Contact information: names, email addresses, job titles, company names, profile URLs, phone numbers — extracted from LinkedIn, Gmail, and WhatsApp
- Conversations: LinkedIn and WhatsApp messages synced to your CRM, only at your initiative
- Transcripts: content of Google Meet meetings, recorded to your CRM at your request
4.2 Permissions used
- storage: local storage of your preferences (language, side panel position)
- tabs: broadcasting authentication state changes across your tabs
- cookies: reading the kasar.app session cookie to authenticate your API requests
- scripting: injecting content scripts on supported platforms
- Host access: LinkedIn, Gmail, Google Meet, WhatsApp Web, and kasar.app only
4.3 Local storage
The extension stores only your interface preferences (language, panel position) locally via chrome.storage.local. No password, session token, or sensitive personal data is kept locally. Uninstalling the extension removes these preferences but does not delete data already synced to your CRM.
4.4 Remote code
The extension does not execute any remote code. All code is included in the extension package.
5. Google Calendar integration
Kasar lets you connect your Google Calendar account to centralize your events within the CRM. This section precisely details which Google data we access, how it is used, stored, and shared.
5.1 Data accessed
When you authorize the Google Calendar connection, Kasar accesses the following data:
- List of your calendars (names, identifiers)
- Events from your calendars (title, description, dates/times, location, attendees, confirmation status, recurrence)
- Associated metadata (event identifiers, creation/modification dates, time zones)
5.2 Use of the data
Google Calendar data is used solely to:
- Display your events in the Kasar CRM calendar interface
- Allow creating and updating events from Kasar to Google Calendar
- Associate events with your CRM contacts and opportunities
Data use is strictly limited to the visible and essential features of the application. No secondary processing is performed.
5.3 Storage and retention
Data from Google Calendar is stored in your dedicated workspace within the Kasar infrastructure (encrypted database hosted by Supabase). It is retained as long as your Google Calendar integration is active. Disconnecting the integration triggers deletion of the synced data.
5.4 Data sharing
Google Calendar data is not shared with any third party. It is only accessible to members of your Kasar organization, according to the permissions defined in your workspace.
5.5 What Kasar does NOT do with your Google data
- Kasar does not sell or transfer your Google data to advertising platforms, data brokers, or any other information reseller
- Kasar does not use your Google data to serve ads, targeting, or ad retargeting
- Kasar does not use your Google data to determine creditworthiness or for lending purposes
- Kasar does not use your Google data to train general artificial intelligence or machine learning models (outside of personalization specific to your account)
- Kasar does not allow humans to read your Google data, except (a) with your explicit consent, (b) for security purposes (investigating abuse), (c) to comply with a legal obligation, or (d) when data is aggregated and anonymized for internal operations
5.6 Compliance with the Google API Services User Data Policy
Kasar’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google API Services User Data Policy.
6. Meta Lead Ads integration (Facebook and Instagram)
Kasar lets advertisers connect their Facebook Page in order to automatically retrieve leads submitted through their instant forms (Lead Ads), on both Facebook and Instagram. This section details exactly which Meta data we access, and how it is used, stored, and shared.
6.1 Data accessed
When you connect a Page, Kasar accesses the following data:
- The answers submitted by the person in the advertiser’s form: typically name, email address, phone number, company, plus any custom question the advertiser defined
- Lead metadata: lead ID, submission date, originating form, and the ad, ad set, and campaign identifiers
- The list of Pages you administer (name, ID), so you can choose which one to connect
6.2 Use of the data
Meta data is used exclusively to:
- Create or enrich a record in the advertiser’s workspace, so they can follow up with the people who asked to be contacted
- Attribute the lead to the campaign that generated it, so the advertiser can measure its performance
Use of the data is strictly limited to the visible, essential features of the application. No secondary processing is performed.
6.3 Storage and retention
Each lead is written to the isolated database schema of the relevant organisation (encrypted database, hosted by Supabase in the European Union). Data is never pooled across advertisers. It is retained for as long as the workspace is active, and deleted on request or upon account deletion.
6.4 Data sharing
Leads received from Meta are not shared with any third party. They are only accessible to members of the organisation that owns the connected Page, according to the permissions defined in their workspace.
6.5 What Kasar does NOT do with your Meta data
- Kasar does not sell or transfer leads to advertising platforms, data brokers, or any other information reseller
- Kasar never pools leads across advertisers
- Kasar does not use leads to serve advertising, targeting, or retargeting
- Kasar does not use leads to determine creditworthiness or for lending purposes
- Kasar does not use leads to train general artificial intelligence or machine learning models
- Kasar does not allow humans to read this data, except (a) with your explicit consent, (b) for security purposes, (c) to comply with a legal obligation, or (d) when the data is aggregated and anonymised
6.6 Revocation and deletion
You can disconnect a Page at any time from Kasar’s integration settings: the subscription to Meta notifications is then removed and no new leads are received. You can also revoke access from your Facebook account settings. Any request to delete data already received can be sent to the contact address at the end of this policy, and Kasar acts on it within the timeframes set out by the GDPR.
7. WhatsApp integration
Kasar lets you link a WhatsApp account so that your business conversations appear in the CRM. Linking is done by scanning a QR code: Kasar becomes a companion device of your phone, in the same way WhatsApp Web does. This section sets out what we access, what we retain, and for how long.
7.1 Data accessed
Once the account is linked, Kasar accesses the following:
- The list of your conversations, one-to-one and group, with the date of their latest message
- The content of the messages exchanged, including attachments, images and voice messages
- Your correspondents’ identifiers: phone number, WhatsApp-internal technical identifier, the profile name they chose themselves, and the name you gave them in your address book where WhatsApp provides it
- Their profile picture, and the membership of the groups you belong to
7.2 What we retain, and what that entails
To display a complete, up-to-date conversation list, Kasar keeps a technical index of your account’s conversations: for each one, the correspondent’s identifier, the date of the latest message and a truncated excerpt of it. That excerpt is encrypted at rest, with the same keys as recorded message content.
This index records EVERY conversation seen, including those of people who are not records in your CRM. For the duration of the link, it therefore constitutes a trace of who talks to whom. We state this explicitly because it is a direct consequence of how an inbox works: without it, the list could not be complete.
Appearing in this index is NOT the same as being recorded in the CRM. Only conversations you explicitly add, or that your sync rules admit, result in interactions being recorded against a record.
7.3 Retention and deletion
Data is written to your organisation’s isolated database schema, hosted in the European Union, and is never pooled across organisations. The conversation index and the WhatsApp session are deleted as soon as you disconnect the account from Kasar — no trace of your correspondent list remains. Interactions already recorded against records follow the fate of your CRM data and are deleted on request.
Profile pictures are not stored: they are relayed on demand from WhatsApp’s servers.
7.4 What Kasar does NOT do with your WhatsApp data
- Kasar never sends a message on your behalf without an explicit action from you
- Kasar does not sell or transfer your conversations or contacts to third parties
- Kasar never pools this data across organisations
- Kasar does not use your conversation content to train general artificial-intelligence models
- Kasar does not allow humans to read your messages, except (a) with your explicit consent, (b) for security purposes, or (c) to comply with a legal obligation
7.5 A note on third parties
WhatsApp is a Meta service, and your use of it remains governed by its own terms. Your correspondents are not aware that your account is linked to Kasar: as the controller for your workspace, it is for you to inform them where your context requires it.
8. Use of artificial intelligence providers
For certain advanced operations (classification, summarization, text generation, etc.), Kasar offers the use of third-party AI services (e.g. US-based providers). Any data processed by these services goes through a zero-retention layer: these providers do not store or reuse your information for any other purpose. Transfer to these services is encrypted and limited to what is strictly necessary.
9. Security, storage, and international transfers
Kasar implements advanced security measures:
- End-to-end encryption during transfer and storage of data
- Strong authentication and strict access control
- No retention beyond the time needed to provide the service
- Some data may transit outside the EU (notably for AI), exclusively under adequate safeguards (standard contractual clauses, zero-retention layers, providers certified under the EU-US Privacy Framework, etc.)
10. Your rights over your data
In accordance with applicable regulations, you have rights that are accessible directly within the Kasar interface:
- Access, export, and portability of all your data
- Modification or rectification of your information
- Permanent deletion of your account and your data ("right to be forgotten")
- Fine-grained management of consents and integrations (opt-in / opt-out at any time)
For any specific request, you may also contact us directly.
11. Contact and policy updates
For any question about privacy or the exercise of your rights:
Kasar reserves the right to update this policy from time to time to reflect regulatory, technical, or service changes. Any material update will be notified on the platform and the revision date will be adjusted accordingly.
By using our services, you accept this privacy policy. We invite you to review it regularly to stay informed about our commitments and practices.