SSTM CRM Privacy Policy
Effective 24 July 2026
1. Who this policy covers
This policy explains how SSTM CRM handles personal information when people visit the public website, create or use a CRM workspace, contact support, or purchase a subscription.
2. Information we process
- Account and workspace details, including names, email addresses, business names, roles, authentication records, and preferences.
- CRM content supplied by customers, including contacts, companies, leads, deals, tasks, cases, notes, imports, and attachments.
- Support messages and operational records needed to investigate a request or keep the service secure.
- Subscription status and Paddle customer, transaction, and subscription identifiers. SSTM CRM does not store complete payment card details.
- Basic technical information such as request timestamps, browser or device information, and security logs.
3. How information is used
We process information to:
- provide and administer CRM workspaces;
- authenticate users and enforce workspace permissions;
- process subscriptions, invoices, cancellations, and refunds;
- answer support requests and send service communications;
- protect the service, prevent abuse, and diagnose problems; and
- meet legal, accounting, and regulatory obligations.
4. Service providers and disclosure
SSTM CRM uses service providers only where needed to run the product. Railway hosts the application, Supabase stores production workspace data, Paddle processes online billing as Merchant of Record, and email providers deliver support and account messages. These providers process information under their own terms and privacy commitments.
Information may also be disclosed when required by law, to protect users or the service, or as part of a business reorganization with appropriate safeguards. Customer data is not sold.
5. Data retention
Account and workspace information is kept while the workspace is active and as reasonably needed to provide support, resolve disputes, prevent fraud, and meet legal or accounting obligations. When deletion is requested, information is deleted or de-identified unless retention is required by law or needed for a legitimate security or dispute record.
6. Security
SSTM CRM uses access controls, encrypted HTTPS connections, role-based permissions, and service-provider safeguards designed to protect workspace information. No online system can guarantee absolute security, so workspace administrators should also use strong passwords, protect account access, and assign roles carefully.
7. Local storage and cookies
The CRM uses browser storage and essential session technologies to keep users signed in and remember interface preferences. Paddle may use its own essential technologies when checkout, billing, or the customer portal is opened. SSTM CRM does not use this information to sell personal data.
8. Your choices and rights
Depending on location, people may have rights to access, correct, export, delete, restrict, or object to processing of personal information. Workspace administrators can manage many records directly. Other requests can be sent to the contact address below. Identity or authority may need to be verified before a request is completed.
9. Policy changes
This policy may be updated when the service, providers, or legal requirements change. The effective date above identifies the current version. Material changes will be communicated when required.
Contact SSTM CRM at info.sstmcrm@gmail.com.