Skip to content
GoggleCRM
  • Features
  • Email sync
  • Security
  • Pricing
  • FAQ
Log in Start free trial

Privacy Policy

Last updated 3 October 2026. How GoggleCRM Limited collects, uses and protects personal data.

Contents
  1. Who we are
  2. Controller or processor
  3. What we collect
  4. How we use it and why
  5. Email data
  6. AI features
  7. Who we share it with
  8. International transfers
  9. How long we keep it
  10. How we protect it
  11. Your rights
  12. If you are in a customer's CRM
  13. Cookies
  14. Marketing
  15. Children
  16. Changes to this policy
  17. Contact and complaints
Read the Terms of Service

The short version

  • We collect what we need to run your account, take payment and support you. We do not sell personal data and we do not use it for advertising.
  • The contacts, notes and emails you put into GoggleCRM belong to you. We process them only on your instructions.
  • Email sync is read-only and only keeps emails with people already in your CRM. Stored email content is encrypted.
  • AI features are optional. When they are on, our AI provider is not allowed to train on your data.
  • We only use the cookie needed to keep you logged in. No tracking or advertising cookies.

1. Who we are

GoggleCRM Limited ("we", "us", "our") provides the GoggleCRM service. We are registered in England and Wales under company number 15731633, our registered office is at 85 Great Portland Street, London, England, W1W 7LT, and we are registered with the Information Commissioner's Office under number ZB842168.

This policy applies to our website, the GoggleCRM app and our related emails and support. It is written to meet the UK GDPR and the Data Protection Act 2018.

2. Controller or processor

We are the controller of personal data about our customers and their users that we need to run our business: account details, billing records, support conversations, security logs and website visits. This policy explains how we handle that data.

We are a processor for the data our customers put into GoggleCRM, such as their contacts, companies, notes, projects, files and synced emails ("Customer Data"). Our customer is the controller of that data and decides how it is used. We process it only on their instructions, under the data processing terms in Schedule 1 of our Terms of Service.

3. What we collect

TypeExamplesWhere it comes from
Account detailsName, business email, company name, hashed password, role, time zone, digest settingsYou, or the admin who invited you
Billing detailsBilling name and address, VAT number, subscription status, invoices. Card details are held by Stripe, not usYou, through Stripe Checkout
Legal recordsWhich version of our terms you accepted, when, and from which IP addressAutomatically when you accept
Support recordsEmails and messages you send usYou
Security and technical dataIP address, login attempts, browser type, error logsAutomatically when you use the Service
Usage dataCounts of AI requests and features used, for limits and billingAutomatically
Mailbox connectionMailbox address, display name and encrypted access tokensMicrosoft, when you connect your mailbox
Customer Data (as processor)Contacts, companies, projects, notes, files, custom fields, and emails exchanged with your contactsYou and your users, and your connected mailbox

4. How we use it and why

PurposeLawful basis
Creating and running your account, providing the Service and its features, sending invitations, password resets and the morning digestPerformance of our contract with your business, and our legitimate interest in providing the Service to its users
Taking payments, issuing invoices and keeping accounting recordsContract and legal obligation
Keeping the Service secure, preventing fraud and abuse, and recording acceptance of our termsLegitimate interests and legal obligation
Answering support requests and telling you about important changes to the Service or these policiesContract and legitimate interests
Improving the Service using anonymised, aggregated statisticsLegitimate interests
Sending product news and offers to business customersLegitimate interests (you can opt out at any time) or consent where required
Processing Customer DataOn our customer's instructions. The customer is responsible for the lawful basis

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. Relationship scores and nudges in the app help our customers prioritise their own work and are not decisions about anyone.

5. Email data

If a user connects a Microsoft 365 or Outlook.com mailbox:

  • We request read-only access (Microsoft Graph Mail.Read, User.Read and offline access). We cannot send, move or delete email.
  • We check the Inbox and Sent Items and only store messages to or from addresses that already belong to contacts in the customer's CRM. Everything else is discarded without being stored.
  • For stored messages we keep the subject, a short preview, the new part of the message body (quoted history is removed), sender, date and direction. These are encrypted at rest.
  • If the customer switches on contact suggestions, we keep only the email address, display name and a count for people the user emails who are not yet contacts. No content is kept for them.
  • Email data is used only to provide features to that customer: timelines, last-contact dates, reminders, nudges and, if switched on, AI features. It is never sold, used for advertising or used to train AI models.
  • A user can disconnect their mailbox at any time, and can choose to delete all emails stored from it. You can also remove our access in your Microsoft account settings.

6. AI features

AI features are optional and are switched on or off by each customer's admin. When they are off, no data is sent to an AI provider.

When they are on, the minimum data needed for the task, such as a contact's recent emails, notes and reminders, is sent to Anthropic, PBC to generate a summary, a draft or a list of promises. Anthropic acts as our sub-processor, does not use data received through its commercial API to train its models under our agreement, and keeps it only for a limited period for safety and abuse monitoring. AI results are stored only in the customer's account.

7. Who we share it with

We share personal data only with the service providers below, who process it on our instructions under written contracts, or where the law requires us to.

ProviderWhat they doLocation
DigitalOcean, LLCHosting, databases, file storage and backupsUK (primary), EU (backup)
Cloudflare, Inc.Website security, DNS and traffic routingGlobal network
Postmark (ActiveCampaign, LLC)Sending system emails such as invitations, password resets and digestsUSA
Stripe Payments UK, LtdPayment processing, invoices and billing portalUK, EU and USA
Anthropic, PBCAI features, only when switched on by the customerUSA
Microsoft CorporationMailbox access through Microsoft Graph, only when a user connects their mailbox. Microsoft is the user's own email providerAs set by the user's Microsoft account

We may also share data with professional advisers, insurers, law enforcement or regulators where required, and with a buyer or successor if our business or assets are sold or reorganised, in which case this policy will continue to apply to your data.

8. International transfers

Some providers process data outside the UK. When they do, we make sure the transfer is protected by UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework where the provider is certified), the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, or another safeguard allowed by UK law. You can ask us for details.

9. How long we keep it

DataHow long
Account and Customer DataWhile the account is open. After it ends, kept for 30 days for export or reactivation, then deleted within 90 days. Backups are overwritten within a further 30 days
Billing and invoice records6 years after the end of the financial year they relate to, as required for tax
Terms acceptance recordsFor as long as the account exists, plus 6 years
Login attempt logs7 days
Password reset and invitation linksExpire after 1 hour and 7 days respectively, then deleted
AI usage counts13 months
Completed or dismissed reminders180 days
Support emails3 years after the last contact

10. How we protect it

We use encryption in transit and at rest for sensitive data such as mailbox tokens and email content, strong password hashing, login rate limiting, strict separation between customer accounts, firewalled servers, regular encrypted backups and limited staff access. Full details are in Schedule 2 of our Terms of Service. No system is completely secure, and if a breach affects your data we will tell you as the law requires.

11. Your rights

Where we are the controller, you have the right to:

  • be told how we use your data (this policy);
  • get a copy of your data;
  • have inaccurate data corrected;
  • have your data deleted, where there is no good reason for us to keep it;
  • restrict or object to how we use your data, including for direct marketing, which we will always stop;
  • receive your data in a portable format; and
  • withdraw consent where we rely on it, without affecting earlier processing.

Email [email protected] to use any of these rights. We may need to confirm your identity. We will reply within one month, and tell you if we need longer for a complex request. There is normally no fee.

12. If you are in a customer's CRM

If a business uses GoggleCRM and has added your details, or emailed you from a connected mailbox, that business is the controller of your data and is responsible for telling you how it uses it. Please contact them first. If you contact us, we will pass your request to them and help them respond.

13. Cookies

We use one strictly necessary cookie, gcrm_sid, which keeps you logged in and protects forms against forgery. It is deleted when you close your browser or log out, and expires after 8 hours of inactivity. Because it is essential to the Service, it does not need your consent.

We do not use analytics, advertising or tracking cookies, and our pages do not load third-party scripts or fonts. If we ever add optional cookies, we will ask for your consent first and update this section.

14. Marketing

We may send occasional emails about GoggleCRM to business customers and users. Every marketing email has an unsubscribe link, and you can also opt out by emailing us. Service emails, such as security notices, billing emails and your morning digest, are part of the Service. You can switch the digest off in your account settings.

15. Children

GoggleCRM is a business service for people aged 18 and over. We do not knowingly collect data from children.

16. Changes to this policy

We will update this policy when our practices change. We will tell customers about material changes by email or in the app before they take effect, and the date at the top will always show the latest version.

17. Contact and complaints

Questions or concerns: email [email protected] or write to GoggleCRM Limited, 85 Great Portland Street, London, England, W1W 7LT.

If you are unhappy with how we have handled your data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.

GoggleCRM

The relationship CRM that keeps in touch for you. Made in Yorkshire for small teams who live in their inbox.

Product
  • Features
  • Pricing
  • Log in
  • Start free trial
Legal
  • Terms of Service
  • Privacy Policy
  • Cookies
  • Data processing terms
Company

GoggleCRM Limited, registered in England and Wales, company number 15731633.

Registered office: 85 Great Portland Street, London, England, W1W 7LT.

ICO registration ZB842168.

[email protected]

Copyright 2026 GoggleCRM Limited. All rights reserved.