Privacy Policy
Effective date: June 17, 2026
Who we are
Foxadex (the "Service," "we," or "us") is a product of Monster Motorsports Corp (the "Company").
We provide a multi-tenant business platform — CRM, contact management, email and calendar sync, marketing broadcasts, landing pages, and related tools — used by organizations ("customers") and their employees ("users").
The roles we play
For data about you as a user of the Service (your name, email, login credentials, billing details), we act as a data controller.
For data about your contacts and customers that you upload or sync into the platform, we act as a data processor on your behalf — you remain the controller of that data and are responsible for obtaining the legal basis to collect and use it.
What data we collect
Account information
- Name, email address, and password (stored as a salted hash — we never see the original).
- Organization name, role, and team membership.
- Profile photo, timezone, and display preferences (if provided).
CRM and contact data
- Contacts you create or import (names, email addresses, phone numbers, companies, tags, notes, custom fields).
- Deals, tasks, calls, meetings, attachments, and other CRM records you create.
- Activity history (who changed what, when).
Email and calendar sync
- If you connect a Google or Microsoft account, we access your email and calendar with read/write permissions only to log messages and events linked to your CRM contacts and to send replies from within the app. You can disconnect at any time from Settings.
- We do not sell, advertise against, or train any AI model on your mailbox or calendar contents.
Broadcast / marketing email
- Subject lines, message bodies, recipient lists, and send timestamps for broadcasts you create.
- Per-recipient send, delivery, bounce, open, click, and unsubscribe events.
- Suppression list (email addresses that have unsubscribed, bounced, or filed a complaint).
Applicant tracking (ATS / hiring)
- Job applicant data your organization creates or imports: name, contact details, résumé/CV file, links (LinkedIn, portfolio), work history, education, skills, and any interviewer notes or ratings.
- Interview questions your organization configures and the answers your team logs against each candidate, including any star ratings.
- Résumés you upload are sent to Anthropic once for structured parsing (extracting name, email, work history, etc.) and are not otherwise shared. Parsing is deterministic and does not decide whether to hire; a human reviews every candidate.
Billing
- Plan, seat count, subscription status, and invoice history.
- Payment card details are collected and processed by Stripe; we never see full card numbers. We store only Stripe customer/subscription IDs.
Technical / usage data
- Browser, device type, IP address, and timestamps for security and abuse-prevention purposes.
- Session cookies (used only to keep you logged in) and a handful of preference cookies (theme, sidebar state). All cookies we set are strictly necessary for the Service to function, so we do not display a cookie consent banner (ePrivacy / GDPR exempt essential cookies from prior-consent requirements). We do not use third-party advertising trackers.
How we use your data
- To provide, secure, and maintain the Service.
- To authenticate you and protect your account.
- To process payments and manage your subscription.
- To send transactional emails (password resets, invoices, security alerts) — you can't opt out of these without closing your account.
- To answer support requests and improve the product.
- To comply with our legal obligations (tax, accounting, fraud prevention, law-enforcement requests where legally required).
We do not sell your personal data. We do not use your data to train AI models. We do not share your CRM contacts with other customers.
Legal bases for processing (GDPR Article 6)
Where GDPR applies, we rely on the following lawful bases:
- Contract (Art. 6(1)(b)) — creating and running your account, providing the Service, processing payments.
- Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing abuse, product analytics on aggregate usage, and (where you are our customer's employee) letting your employer manage its workforce records.
- Legal obligation (Art. 6(1)(c)) — tax, accounting, anti-money-laundering, and responding to lawful government requests.
- Consent (Art. 6(1)(a)) — connecting third-party accounts (Google, Microsoft), enabling optional AI features, and any other processing we explicitly ask you to opt into. You can withdraw consent at any time; withdrawal does not affect processing that already happened.
For personal data of your contacts, customers, or job applicants that you upload into the Service, your organization is the controller and is responsible for choosing and documenting the lawful basis under Article 6 (and, for applicants, any Article 9 conditions if special-category data is involved). We process that data on your instructions as a processor.
Applicants and hiring data (ATS)
If your organization uses the ATS (Applicant Tracking) module, you are the controllerfor the applicant data you enter (résumés, contact information, interview notes, ratings, and answers to interview questions). You are responsible for having a lawful basis to collect and retain that data — typically the applicant's consent, your legitimate interests in recruitment, or steps taken prior to entering a contract at the applicant's request (GDPR Art. 6(1)(a), (b), (f)).
- Please do not upload special-category data (health, religion, race, biometric identifiers, sexual orientation, trade-union membership) unless you have an Article 9 lawful ground.
- Interview answers and ratings are visible to every user in your organization who has ATS access; only the answer's original author or an org admin can edit an existing answer.
- Applicant records are retained for the life of your account or until you delete them. We recommend a documented retention schedule aligned with local recruitment law (commonly 6–24 months).
- Applicants may exercise their GDPR rights directly against your organization; if an applicant contacts us we will forward the request to you.
Automated decision-making (GDPR Article 22)
We do not make decisions producing legal or similarly significant effects about you or your applicants using solely automated processing. AI-assisted features (résumé parsing, text summarization, contact suggestions) surface information for a human to review — they do not approve, reject, or rank people or transactions on their own.
Staff and support access (impersonation)
To resolve support requests and diagnose bugs, a small number of our engineers with the super-adminrole can "view as" a specific user in a customer organization. When active, this mode is limited to that one user's permissions and cannot exceed them. We keep access to this mode tightly restricted and audit its use.
AI features
Some optional features (text summarization, OCR on business cards, contact suggestions) send the specific content you choose to process — and only that content — to third-party AI providers including OpenRouter, Anthropic, and Google. These providers process the content under contracts that prohibit training on the data and require deletion within their stated retention windows.
AI features are off by default where applicable. You can avoid them entirely by not using them; we will not silently route your data to an AI provider.
Third-party processors we use
- Render — application hosting and database.
- Resend — broadcast email delivery.
- Stripe — payment processing.
- Google — OAuth, Gmail and Calendar sync (only if you connect a Google account).
- Microsoft — OAuth, Outlook and Calendar sync (only if you connect a Microsoft account).
- OpenRouter / Anthropic / Google AI — for the AI-powered features described above.
- Pexels — public stock photography (no personal data is sent).
Each processor is bound by a data-processing agreement that limits how they can use the data we share with them.
Data retention
- Account data is retained for the life of your account plus 30 days after closure, then deleted.
- CRM data is controlled by your organization — when an admin deletes a record, it is removed from active storage and purged from backups within 30 days.
- Unsubscribe and suppression records are retained indefinitely for CAN-SPAM and GDPR compliance even after a broadcast itself is deleted.
- Email/calendar sync data is deleted when you disconnect the source account.
- Applicant records (résumés, notes, interview answers) are retained for the life of your account or until an org admin deletes them. Applicants can request deletion via your organization; we will assist you in fulfilling verified requests.
- Billing records are retained as long as required by applicable tax and accounting law (typically 7 years).
Your rights
Depending on where you live, you may have the following rights. Under GDPR (residents of the EU / EEA / UK / Switzerland) these are:
- Access the personal data we hold about you (Art. 15).
- Rectify inaccurate or incomplete information (Art. 16).
- Erase your account and the personal data we control (Art. 17 — "right to be forgotten").
- Restrict processing while a dispute is being resolved (Art. 18).
- Data portability — receive your data in a structured, machine-readable format (Art. 20).
- Object to processing based on our legitimate interests (Art. 21).
- Not be subject to solely automated decisions with legal or similarly significant effects (Art. 22) — we do not perform any such decisions.
- Withdraw consent at any time for processing that relies on it (e.g. disconnecting an OAuth integration). Withdrawal does not affect processing carried out before withdrawal.
- Lodge a complaint with your local data-protection supervisory authority.
California residents have equivalent rights under the CCPA / CPRA (access, deletion, correction, opt-out of "sale" or "sharing" — we do neither — and non-discrimination for exercising rights).
For data we process on behalf of an organization (e.g. you are a contact in someone else's CRM), please contact that organization directly to exercise these rights — we will forward your request if you contact us.
To make a request, email support@monstermotorsports.com. We will respond within 30 days.
Security
We encrypt data in transit (TLS) between your browser and the Service, and between the Service and its managed database. Data at rest is encrypted at the storage layer by our hosting provider. Passwords are stored as bcrypt hashes (cost factor 12) — we never see the original. OAuth access/refresh tokens and mailbox (IMAP/SMTP) passwords receive an additional application-layer envelope encryption (AES-256-GCM) using a key that lives outside the database, so a database dump alone is not enough to use them. We apply the principle of least privilege internally and log access for audit purposes.
No system is perfectly secure. If we ever discover a breach affecting your personal data, we will notify you and the relevant authorities within the timeframes required by law (72 hours under GDPR).
International transfers
We host primarily in the United States and may transfer data to other jurisdictions where our processors operate. For personal data transferred out of the EU / EEA / UK / Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs)— and, for UK data, the ICO's International Data Transfer Addendum — signed with each sub-processor, along with any supplementary measures (encryption in transit and at rest, access controls, audit logging) required to keep protection to an essentially equivalent level.
Children
The Service is not directed to anyone under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided personal data through the Service, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will email you and post a notice in the app at least 30 days before they take effect. The "Effective date" at the top of this page reflects the most recent revision.
Data protection contact
For all privacy questions, GDPR / CCPA requests, or to reach our data protection point of contact, email support@monstermotorsports.com. We respond within 30 days (or the shorter window your local law requires).
We have not appointed a formal Data Protection Officer because our core activities do not require one under GDPR Art. 37. If that changes, this section will be updated with their name and contact.
EU / UK data subjects who cannot resolve a matter with us may also contact their national supervisory authority (in the UK: the Information Commissioner's Office).
GDPR as a company standard
We treat GDPR as our internal baseline, not a feature we flip on for European customers. Every customer, wherever they operate, gets the same technical controls.
Because you are the controller of the personal data you upload into Foxadex — your contacts, customers, and job applicants — you are the party a data subject asks first when they exercise their GDPR rights. Foxadex gives you the mechanics to answer those requests directly:
- Access & portability (Art. 15, 20).Org admins can export a portable JSON archive of the entire tenant (contacts, deals, emails, tasks, applicants) from Settings. For a single data-subject request, search the CRM or ATS by the person's identifier and export the matching records.
- Erasure — "right to be forgotten" (Art. 17). Any admin can delete individual contacts, deals, applicants, or messages in-place; cascade-delete removes their linked records. To remove an entire user account and everything they authored, email support@monstermotorsports.com — we process verified requests within 30 days.
- Rectification (Art. 16). Every field on every record is editable in-place; no data is write-once.
- Object / withdraw consent (Art. 21, 7).Every broadcast email carries an unsubscribe link that adds the recipient to your org's suppression list. Suppressed addresses are honored across every subsequent broadcast the org sends, indefinitely.
- Data Processing Agreement (Art. 28).Available on request — incorporates the current EU Standard Contractual Clauses and the UK ICO's International Data Transfer Addendum where applicable.
- Breach notification (Art. 33, 34). If we discover a breach affecting your personal data we notify you and the relevant authorities within the 72-hour window GDPR requires.
If youare a data subject (a contact in someone's CRM, a candidate in someone's ATS) and want a copy or deletion of your data, please contact the organization that holds it — they own the record and can act on it directly. If they don't respond within the time your local law requires, contact us and we'll escalate.
Contact us
General questions? Email support@monstermotorsports.com.
This document is provided for informational purposes and is not legal advice. Please have counsel in your jurisdiction review it before relying on it for compliance.