The short version
- We collect what we need to run your account, take payment and support you. We do not sell personal data and we do not use it for advertising.
- The contacts, notes and emails you put into GoggleCRM belong to you. We process them only on your instructions.
- Email sync is read-only and only keeps emails with people already in your CRM. Stored email content is encrypted.
- AI features are optional. When they are on, our AI provider is not allowed to train on your data.
- We only use the cookie needed to keep you logged in. No tracking or advertising cookies.
1. Who we are
GoggleCRM Limited ("we", "us", "our") provides the GoggleCRM service. We are registered in England and Wales under company number 15731633, our registered office is at 85 Great Portland Street, London, England, W1W 7LT, and we are registered with the Information Commissioner's Office under number ZB842168.
This policy applies to our website, the GoggleCRM app and our related emails and support. It is written to meet the UK GDPR and the Data Protection Act 2018.
2. Controller or processor
We are the controller of personal data about our customers and their users that we need to run our business: account details, billing records, support conversations, security logs and website visits. This policy explains how we handle that data.
We are a processor for the data our customers put into GoggleCRM, such as their contacts, companies, notes, projects, files and synced emails ("Customer Data"). Our customer is the controller of that data and decides how it is used. We process it only on their instructions, under the data processing terms in Schedule 1 of our Terms of Service.
3. What we collect
| Type | Examples | Where it comes from |
|---|---|---|
| Account details | Name, business email, company name, hashed password, role, time zone, digest settings | You, or the admin who invited you |
| Billing details | Billing name and address, VAT number, subscription status, invoices. Card details are held by Stripe, not us | You, through Stripe Checkout |
| Legal records | Which version of our terms you accepted, when, and from which IP address | Automatically when you accept |
| Support records | Emails and messages you send us | You |
| Security and technical data | IP address, login attempts, browser type, error logs | Automatically when you use the Service |
| Usage data | Counts of AI requests and features used, for limits and billing | Automatically |
| Mailbox connection | Mailbox address, display name and encrypted access tokens | Microsoft, when you connect your mailbox |
| Customer Data (as processor) | Contacts, companies, projects, notes, files, custom fields, and emails exchanged with your contacts | You and your users, and your connected mailbox |
4. How we use it and why
| Purpose | Lawful basis |
|---|---|
| Creating and running your account, providing the Service and its features, sending invitations, password resets and the morning digest | Performance of our contract with your business, and our legitimate interest in providing the Service to its users |
| Taking payments, issuing invoices and keeping accounting records | Contract and legal obligation |
| Keeping the Service secure, preventing fraud and abuse, and recording acceptance of our terms | Legitimate interests and legal obligation |
| Answering support requests and telling you about important changes to the Service or these policies | Contract and legitimate interests |
| Improving the Service using anonymised, aggregated statistics | Legitimate interests |
| Sending product news and offers to business customers | Legitimate interests (you can opt out at any time) or consent where required |
| Processing Customer Data | On our customer's instructions. The customer is responsible for the lawful basis |
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. Relationship scores and nudges in the app help our customers prioritise their own work and are not decisions about anyone.
5. Email data
If a user connects a Microsoft 365 or Outlook.com mailbox:
- We request read-only access (Microsoft Graph Mail.Read, User.Read and offline access). We cannot send, move or delete email.
- We check the Inbox and Sent Items and only store messages to or from addresses that already belong to contacts in the customer's CRM. Everything else is discarded without being stored.
- For stored messages we keep the subject, a short preview, the new part of the message body (quoted history is removed), sender, date and direction. These are encrypted at rest.
- If the customer switches on contact suggestions, we keep only the email address, display name and a count for people the user emails who are not yet contacts. No content is kept for them.
- Email data is used only to provide features to that customer: timelines, last-contact dates, reminders, nudges and, if switched on, AI features. It is never sold, used for advertising or used to train AI models.
- A user can disconnect their mailbox at any time, and can choose to delete all emails stored from it. You can also remove our access in your Microsoft account settings.
6. AI features
AI features are optional and are switched on or off by each customer's admin. When they are off, no data is sent to an AI provider.
When they are on, the minimum data needed for the task, such as a contact's recent emails, notes and reminders, is sent to Anthropic, PBC to generate a summary, a draft or a list of promises. Anthropic acts as our sub-processor, does not use data received through its commercial API to train its models under our agreement, and keeps it only for a limited period for safety and abuse monitoring. AI results are stored only in the customer's account.
8. International transfers
Some providers process data outside the UK. When they do, we make sure the transfer is protected by UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework where the provider is certified), the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, or another safeguard allowed by UK law. You can ask us for details.
9. How long we keep it
| Data | How long |
|---|---|
| Account and Customer Data | While the account is open. After it ends, kept for 30 days for export or reactivation, then deleted within 90 days. Backups are overwritten within a further 30 days |
| Billing and invoice records | 6 years after the end of the financial year they relate to, as required for tax |
| Terms acceptance records | For as long as the account exists, plus 6 years |
| Login attempt logs | 7 days |
| Password reset and invitation links | Expire after 1 hour and 7 days respectively, then deleted |
| AI usage counts | 13 months |
| Completed or dismissed reminders | 180 days |
| Support emails | 3 years after the last contact |
10. How we protect it
We use encryption in transit and at rest for sensitive data such as mailbox tokens and email content, strong password hashing, login rate limiting, strict separation between customer accounts, firewalled servers, regular encrypted backups and limited staff access. Full details are in Schedule 2 of our Terms of Service. No system is completely secure, and if a breach affects your data we will tell you as the law requires.
11. Your rights
Where we are the controller, you have the right to:
- be told how we use your data (this policy);
- get a copy of your data;
- have inaccurate data corrected;
- have your data deleted, where there is no good reason for us to keep it;
- restrict or object to how we use your data, including for direct marketing, which we will always stop;
- receive your data in a portable format; and
- withdraw consent where we rely on it, without affecting earlier processing.
Email [email protected] to use any of these rights. We may need to confirm your identity. We will reply within one month, and tell you if we need longer for a complex request. There is normally no fee.
12. If you are in a customer's CRM
If a business uses GoggleCRM and has added your details, or emailed you from a connected mailbox, that business is the controller of your data and is responsible for telling you how it uses it. Please contact them first. If you contact us, we will pass your request to them and help them respond.
14. Marketing
We may send occasional emails about GoggleCRM to business customers and users. Every marketing email has an unsubscribe link, and you can also opt out by emailing us. Service emails, such as security notices, billing emails and your morning digest, are part of the Service. You can switch the digest off in your account settings.
15. Children
GoggleCRM is a business service for people aged 18 and over. We do not knowingly collect data from children.
16. Changes to this policy
We will update this policy when our practices change. We will tell customers about material changes by email or in the app before they take effect, and the date at the top will always show the latest version.
17. Contact and complaints
Questions or concerns: email [email protected] or write to GoggleCRM Limited, 85 Great Portland Street, London, England, W1W 7LT.
If you are unhappy with how we have handled your data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.