Privacy Policy
Last updated: August 2, 2026
EnvelopeZilla ("the Service") is operated by Virtual Office CRM ("we", "us"). The Service processes lead-notification emails sent to your dedicated EnvelopeZilla address in order to create and update contacts in your own HighLevel sub-account. This policy describes what we collect, why, and what we do (and never do) with it.
Information we process
- Inbound lead emails. The contents of emails sent to your dedicated address (sender, subject, body), processed to extract lead details.
- Parsed lead data. Names, email addresses, phone numbers, and any fields you map, written into your sub-account and retained in a per-account processing log that powers your activity feed (pruned automatically; most recent entries only).
- Configuration. Your parser rules, sample emails you paste while building rules, and settings such as your automation tag.
- Credentials. OAuth tokens for your sub-account, granted by you at install, encrypted at rest (AES-GCM). We never see or store your HighLevel password.
- Operational logs. Technical events (installs, processing outcomes, errors) used to operate and support the Service.
How your data is used
For one purpose: delivering leads into your sub-account and showing you what happened. We do not sell or rent data. We do not share lead data with third parties except the infrastructure providers below. We do not use your data to train machine-learning models or to market to your contacts.
Infrastructure providers
The Service runs on Cloudflare (email receiving, compute, storage) and writes to HighLevel (your CRM) via its official API. Data is processed in the United States.
Retention and deletion
Processing logs are pruned automatically to the most recent entries per account. Uninstalling the app stops all processing immediately: emails to your address are rejected and your OAuth tokens are deleted. To request deletion of remaining stored rules and logs, or a copy of what we hold for your account, contact info@virtualofficecrm.com — we respond within 30 days.
Lead-subject rights
Leads whose details flow through the Service belong to your business relationship, and you (the sub-account owner) are the data controller for them. If a person asks us directly to remove their information, we will refer the request to you and cooperate with its fulfilment.
Security
Credentials are encrypted at rest; access to production systems is limited to the operator; every account's data is scoped to its own sub-account and never readable by another account.
Changes
We may update this policy; material changes will be reflected on this page with a new "last updated" date.