Privacy Policy
Effective 14 August 2026
There are two kinds of personal information here, and they are treated differently. Your account information is ours to look after, and this policy explains what we do with it. The records you put in your workspace - your own customers and their details - are yours. We only hold them for you, and we act on your instructions. If you are a business subject to the UK or EU GDPR, the Data Processing Addendum covers that second category in the language the law expects.
1. Who we are
CRM Niche provides the CRM service at www.crmniche.com. For your account information we are the data controller. For your workspace records we are a data processor acting for you.
Privacy questions: privacy@crmniche.com
2. What we collect
Information you give us
- Account: your name, email address, and a hashed password. We never store your password in a readable form.
- Workspace: your business name, industry, and the settings you choose.
- Billing: your billing email and subscription status. Card details are entered on Stripe's own pages and never reach our servers.
- Support: what you write in a support request, plus your email, workspace name, and current plan, so we can answer.
Information collected automatically
- Server logs: IP address, browser type, page requested, and timestamp. Our hosting provider keeps these to run and secure the service.
- Audit log: significant actions inside a workspace - invitations, role changes, exports, plan changes - recorded with who did them and when, so a workspace admin can see what happened.
We do not use analytics trackers, advertising pixels, or session recording, and we do not build behavioural profiles of you.
Information you put in about other people
Your workspace holds records about your customers. We do not decide what goes in there, we do not analyse it, and we do not use it for any purpose of our own. See section 8.
3. Cookies
We use cookies for one thing: keeping you signed in. They are strictly necessary for the service to function, which is why you do not see a cookie banner - under UK and EU rules, consent is not required for strictly necessary cookies, and asking for consent we do not need would be theatre.
| Cookie | Purpose | Life |
|---|---|---|
| sb-…-auth-token | Keeps you signed in between pages | Until you sign out or it expires |
| sb-…-code-verifier | Completes a sign-in or password reset securely | Minutes |
| gcal_state | Protects the Google Calendar connection against request forgery | 10 minutes |
There are no advertising or analytics cookies. Blocking the cookies above will stop you being able to sign in.
4. Why we are allowed to use it
| What we do | Lawful basis (UK/EU GDPR) |
|---|---|
| Run your account and provide the service | Performance of a contract |
| Take payment and prevent billing fraud | Contract, and legal obligation for tax records |
| Keep the service secure and available | Legitimate interests |
| Send service notices you need to receive | Contract |
| Answer your support requests | Contract, and legitimate interests |
We do not send marketing email to customers without asking first, and any marketing email we do send has an unsubscribe link that works.
5. Who else sees it
We share data with a short list of service providers who help us run CRM Niche. Each one is named, along with exactly what reaches it, on the Sub-processors page. They may use it only to provide their service to us.
Beyond that, we share data only when the law requires it, and we will tell you unless we are legally prevented from doing so. If the business is ever sold or merged, your data may transfer with it, and you will be told before that happens.
We never sell personal information, and we do not share it for cross-context behavioural advertising. Under California law that means there is nothing for you to opt out of, because it does not happen.
Places you send data yourself
If you connect an integration, we send data where you tell us to. Today that can include Slack, Discord, Telegram, Zapier, Make, n8n or any other endpoint reached through the Webhooks card. Those are your choices and your accounts, and their own privacy terms apply once the data arrives.
6. Where the data lives
CRM Niche runs in the United States. If you are outside the United States, using the service means your data is transferred there. For transfers out of the UK, EU, or Switzerland we rely on the European Commission's Standard Contractual Clauses, together with the UK Addendum where the UK GDPR applies. Those clauses are built into our Data Processing Addendum.
7. How long we keep it
- Workspace records: for as long as the workspace exists. Deleting a workspace removes them from the live database immediately; encrypted backups roll off within 30 days.
- Account: until you delete it, plus the same 30-day backup window.
- Billing records: up to 7 years, because tax law requires it.
- Support requests: 24 months.
- Server logs: retained by our hosting provider on their standard schedule, typically 30 days.
8. Your rights
Depending on where you live you have some or all of the following rights over the personal information we hold about you:
- ask for a copy of it;
- have it corrected if it is wrong;
- have it deleted;
- ask us to restrict or stop a particular use;
- receive it in a portable format;
- object to processing based on legitimate interests;
- withdraw consent where we relied on consent;
- not be discriminated against for exercising any of these rights.
Write to privacy@crmniche.com. We answer within 30 days and it costs nothing. We will ask you to confirm your identity from the email address on the account. You may use an authorised agent where your local law allows it.
If you are one of our customers' customers and want your details removed from a business's CRM, contact that business directly. They control those records, not us. If you contact us we will pass your request to them and tell you we have done so.
Regional additions
- UK and EU: you may complain to your national supervisory authority. In the UK that is the Information Commissioner's Office.
- California: the categories we collect are identifiers, commercial information, and internet activity, as described in section 2. We collect them for the business purposes in section 4. We do not sell or share personal information, and we do not use sensitive personal information for inferring characteristics.
- Canada: you may complain to the Office of the Privacy Commissioner of Canada.
- Australia: you may complain to the Office of the Australian Information Commissioner.
9. Security
- All traffic is encrypted in transit, and data is encrypted at rest.
- Every workspace is isolated at the database level, so one customer's queries cannot reach another customer's records.
- Session cookies cannot be read by scripts in the page, which stops a stolen session being used to impersonate you.
- Integration credentials, such as webhook URLs and calendar tokens, are stored encrypted and are never returned to the browser.
- Passwords are hashed, and checked against known breached-password lists.
No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator within the time limits the law sets, which is 72 hours under the GDPR.
10. Children
CRM Niche is for businesses and requires you to be 18 or older. We do not knowingly collect information from children. If you believe a child has given us information, write to privacy@crmniche.com and we will delete it.
11. Artificial intelligence
There is one optional AI feature: during setup you can describe your business in a sentence and get a suggested CRM configuration. Only that sentence is sent to our AI provider. No contacts, jobs, notes, or customer records are ever sent, and the provider does not use it to train models. The feature is optional, and the setup works without it.
12. Changes
If we change this policy materially we will email account holders at least 14 days beforehand. The effective date at the top always tells you which version you are reading.