Security & data handling

A plain-language explanation of how DesertCRM scopes access during an engagement, handles customer CRM data, and which third parties this website itself relies on. Written for the person on the other side of a vendor security review.

Scoped access

Every engagement runs on named accounts the customer provisions inside its own Microsoft tenant. Access is least-privilege by default — we request the minimum role needed for the scoped work, and we document exactly what was requested and why before it's granted.

Revocable access

The customer controls that access and can revoke it at any time, for any reason. We ask for removal proactively at the end of an engagement rather than waiting to be asked.

Customer credentials

We do not ask for shared passwords or generic logins. Access is granted through identities the customer provisions and administers, and no customer credentials are stored in our systems.

Confidential information

A mutual non-disclosure agreement is available on request before any access is granted. Findings and deliverables produced during an engagement belong to the customer. We do not publish engagement details — including that an engagement happened — without written permission.

Handling of customer CRM information

Delivery work happens inside the customer's own Dynamics 365 / Power Platform tenant. There is no bulk export of CRM data to our systems without a separate written agreement. When a specific deliverable requires an export, that data is deleted after delivery on request.

Third parties / subprocessors used by this website

These are scoped to the desertcrm.com website — not to engagement delivery, which happens inside the customer's own tenant as described above.

  • Cloudflare — sits in front of the site for network delivery
  • Railway — hosts the website's Node server
  • Netlify Blobs — stores form submissions and chat transcripts
  • Zoho Mail — relays outbound notification email
  • xAI — powers the chat widget's responses
  • Google Analytics 4 — only if a measurement ID is configured for this site; not active otherwise

Data retention

Website inquiries are retained for as long as they're relevant to a potential or active engagement. Use our contact form to request deletion at any time.

What we don't claim

DesertCRM does not claim SOC 2 or ISO certification, and this page makes no representations about insurance coverage — that information is available on request during procurement if applicable.

Questions for a vendor security review?

Send them through the contact form and we'll respond directly.

This page is issued by Golden Consulting Partners LLC, doing business as Desert CRM & AI, Phoenix, Arizona. Last updated: September 2026.