Skip to content
Nametech Canada

NameCRM security

NameCRM holds what a service business cannot afford to leak: client records, emails, call recordings, contracts and invoices. This page explains how that information is protected, in plain words first, with the technical detail underneath for whoever checks it for you.

Every statement here describes how NameCRM works today. Where some information leaves Canada, we say so.

Where your database and files are stored
Canada
Where your database and files are stored
Automated test suites every change must pass
230+
Automated test suites every change must pass
Scripts loaded from outside servers
0
Scripts loaded from outside servers
In Trash before a deleted record is gone for good
30 days
In Trash before a deleted record is gone for good

How it is protected

What keeps your data safe

Many small business tools load code from other companies' servers on every page, so a problem on one of those servers can reach every page that loads from it. NameCRM is built the other way, and every change to it is checked before it ships.

  • No code from outside servers

    Every piece of code NameCRM runs in your browser comes from our own servers, at a version we chose and checked. Your browser refuses code from anywhere else.

    Technical detailScripts are self hosted at exact, pinned versions, downloaded from the official npm registry with integrity checked, each with a Subresource Integrity hash so a changed copy is refused. A Content Security Policy blocks scripts from any other origin; in a real browser test, an injected outside script was blocked on every page.

  • Every change is checked before it ships

    No change to NameCRM goes live until it passes automated checks. A change that tries to add code from an outside source is refused, and every code change carries a written security review.

    Technical detailOver 230 automated test suites must pass before release. A supply chain check refuses any new third party script. A written security review is required on every code change.

  • Each account sees only its own data

    The rules that decide who can read what are enforced by the database itself, so one account cannot read another account's data.

    Technical detailRow level security (RLS) policies in the Postgres database.

  • Two-step sign-in for staff

    Staff accounts can turn on two-step sign-in. With it on, a password alone is not enough to get in: a code from their authenticator app is needed too.

    Technical detailTime based one-time passcodes (TOTP) from an authenticator app.

  • Encrypted while it travels

    Information is encrypted while it travels between your browser and NameCRM.

    Technical detailEncryption in transit over HTTPS (TLS).

  • AI that does not train on your data

    NameCRM's AI features, including drafting, assistants, the AI phone receptionist and transcription, use Anthropic, Deepgram and ElevenLabs. We have set each of these providers so that the content we send them is not used to train their models.

    Technical detailThe setting on each provider, and where each one runs, is listed on our AI trust page. See the AI trust page

Data residency

Where your data lives

Your records are stored in Canada. The servers that run the application are in the United States, and information passes through them on the way to the database. Our privacy policy says the same.

  • Database and file storage

    Canada (Montreal)

    Supabase

    Region ca-central-1

  • Application servers

    United States

    Vercel

    Runs the application and its server functions

Retention

How long we keep things

Deleting something in NameCRM has a clear, written outcome.

  1. You delete a record

    It moves to Trash and is permanently deleted after 30 days.

  2. An account closes

    Its data is kept for 90 days so the account can be reopened with everything in place. After 90 days it is deleted.

  3. Invoices and payment records

    Kept for 6 years, as Canada Revenue Agency rules require.

The rules we follow

  • BC's Personal Information Protection Act (PIPA) governs how we handle personal information in British Columbia
  • Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) applies when information crosses a provincial or national border
  • Commercial email and text messages sent through NameCRM follow Canada's Anti-Spam Legislation (CASL)
  • Our privacy policy names a Privacy Officer, Seemab Akbar, who takes any question or request about your information

Written by the Nametech Canada team. Every statement on this page was checked on September 28, 2026.