Skip to content

Privacy Policy

Last updated:

This Privacy Policy explains how SA SIMPLE CODE LTD ("Simple CRM", "we", "us") collects, uses and shares personal data, and the rights you have. It covers personal data about:

  • Visitors to our website at https://simplecrms.com (the "Site");
  • Users of Simple CRM at https://app.simplecrms.com (the "Service"): the people who have an account in a customer's workspace;
  • Prospects and contacts: people who write to us, or whose business we work with.

What this policy does not cover. The boards, items, docs, files and form responses that a customer stores in the Service ("Customer Data") belong to that customer. We process Customer Data as the customer's processor, only on its instructions, under our Data Processing Agreement. If your personal data is in a customer's workspace, for example because you filled in its form or you are one of its clients, that customer's privacy policy applies, and you should contact it first. See section 10.

1. The data we collect

Data you give us.

Data Examples When
Account data Name, email address, password (stored only as a hash), job title, phone, profile picture When you sign up, or an admin invites you and you accept
Workspace data Your role, teams, and settings such as theme and notification preferences As you use the Service
Communications Support requests, emails and feedback you send us When you contact us
Billing data Billing contact, company name, address, tax ID, invoices When you buy a paid plan

Card numbers are entered directly with our payment provider and never reach our servers.

Data we receive from others.

  • Google. If you choose "Continue with Google", Google sends us basic profile information about your Google account. Section 3 explains exactly what we receive and what we do with it.
  • Your workspace admin. An admin who invites you gives us your email address, and may set your name, role and teams.

Data we collect automatically.

  • Usage and device data: IP address, browser and operating system, pages and features used, dates and times, and the referring page.
  • Logs: server and error logs, sign-in events and security events, such as failed sign-in attempts.
  • Activity in the Service: the activity log records who changed what and when, so customers can see the history of their boards.
  • Cookies: a small number of cookies that the Site and Service need to work. See our Cookie Policy.

We do not use advertising, analytics or tracking cookies, and we do not buy personal data.

2. How we use data, and our legal bases

2.1 Purposes.

Purpose Legal basis (GDPR / UK GDPR)
Create and run your account, sign you in, and provide the Service Contract
Send service emails: invitations, password resets, and the notifications you have turned on Contract
Answer support requests Contract; legitimate interest
Keep the Service secure: detect abuse, rate-limit sign-in attempts, investigate incidents Legitimate interest; legal obligation
Understand how the Service is used and improve it, using aggregated or de-identified data Legitimate interest
Billing, accounting and tax Contract; legal obligation
Send product news to customer contacts (you can opt out at any time) Legitimate interest, or consent where required
Comply with the law, and establish or defend legal claims Legal obligation; legitimate interest

2.2 What we do not do. We do not sell personal data. We do not use it for targeted advertising. We do not use Customer Data to train AI models.

3. Google user data

You can sign in to Simple CRM with your Google account. When you do, Google shares a small amount of information with us, and this section explains what that is and what we do with it. Simple CRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3.1 What we access. We ask Google only for basic sign-in information (the openid, email and profile scopes). Google then sends us:

  • your Google account ID (a number that identifies your Google account);
  • your email address, and whether Google has verified it;
  • your name;
  • the address of your Google profile picture.

We do not request access to your Gmail, Google Drive, Google Calendar, contacts or any other Google service, and we cannot see your Google password.

3.2 How we use it. We use this data only to sign you in to Simple CRM:

  • We use your verified email address to find the Simple CRM account that a workspace admin has already invited you to. Google sign-in cannot create a new account.
  • We save your Google account ID in that account, so you can sign in with Google next time, and so that a different Google account with the same email address can never take it over.
  • The first time you sign in, we use your name as your display name in Simple CRM. You can change it in your profile at any time.
  • We do not use or save your profile picture.

We do not use Google user data for any other purpose. In particular, we do not use it for advertising, we do not sell it, we do not use it to build user profiles, and we do not use it to develop, improve or train AI or machine learning models.

3.3 How we store it. We store only your Google account ID, in your user record in our database, which is encrypted at rest. We do not store the access token or refresh token Google issues: we use the sign-in response once, at the moment you sign in, and then discard it. Your email address and name are stored as part of your Simple CRM account in the same way as for users who sign in with a password.

3.4 How we share it. We do not sell, rent or transfer Google user data to third parties. It is processed only by our hosting and database providers listed on our Subprocessors page, only to run the Service. We may disclose it only if the law requires it, or as part of a merger or acquisition, in which case this policy continues to apply to it. Within Simple CRM, other users in your workspace can see your name and email address, as they can for every user.

3.5 Human access. Our staff do not read Google user data, except with your explicit consent (for example, to answer your support request), when it is needed for security purposes, such as investigating abuse, or to comply with the law.

3.6 How we protect it. Sign-in with Google uses OAuth 2.0 with PKCE over encrypted connections (TLS). Data is encrypted at rest, and access to production systems is limited to the people who need it. See our Security page.

3.7 Retention and deletion.

  • Your Google account ID is kept for as long as your Simple CRM account exists, and is deleted together with it.
  • To unlink Google from your account, or to have your Google account ID deleted, write to simplecodesa+privacy@gmail.com. We will do so within 30 days.
  • You can also revoke Simple CRM's access at any time in your Google Account at myaccount.google.com/permissions. After that, you can still sign in with your email address and a password; if you have never set one, use "Forgot password" on the sign-in page.
  • To delete your whole account and its data, ask your workspace admin, or write to us.

4. Where data is stored, and for how long

4.1 Location. The Service is hosted by the providers listed on our Subprocessors page, in Israel (the AWS Tel Aviv region) and the European Union, as listed on that page.

4.2 International transfers. Some of our providers process data in other countries, including the United States. The European Commission recognizes Israel as providing an adequate level of protection, so data can flow between the EU and Israel. When personal data leaves the EEA, the UK, Switzerland or Israel for a country without an adequacy decision, we protect it with the European Commission's Standard Contractual Clauses (and the UK Addendum), or with the EU-U.S. Data Privacy Framework where the provider is certified.

4.3 Retention. We keep personal data only for as long as we need it for the purposes above. To decide how long that is, we consider the kind of data and how sensitive it is, the risk to you, why we hold it, and how long the law, accounting rules or a possible legal claim require us to keep it. The usual periods are:

Data How long
Account data While the account is active, then deleted within 90 days of the workspace being closed
Deleted items, boards and docs 30 days in the trash, then permanently deleted
Activity log 365 days
Notifications 180 days
Sessions Up to 30 days of inactivity, and never more than 90 days
Server and security logs Up to 90 days
Support emails 3 years after the conversation ends
Billing records As long as tax law requires, usually 7 years
Backups Overwritten within 30 days

5. Who we share data with

We share personal data only in these cases:

  • Service providers who host and run the Service for us, such as hosting, the database, file storage and email delivery. They are listed on our Subprocessors page and may use the data only to provide their service to us.
  • Your workspace. Other Users in your workspace, and its admins, can see your name, profile picture, email address and activity, depending on their permissions. Admins can manage your account in that workspace.
  • Integrations you or your admin connect, such as webhooks or API clients. Data sent to them is governed by their own terms.
  • Legal reasons. When the law, a court order or a valid government request requires it, or to protect the rights, safety and property of our customers, the public or us. Where the law allows, we will tell the customer about a request for its data first.
  • Business transfers. If we are involved in a merger, acquisition or sale of assets, personal data may transfer to the new owner, and this policy will continue to apply to it.

6. Cookies

We use only the cookies that the Site and Service need to work, plus two that remember your display preferences. Each one is listed in our Cookie Policy. We do not use cookies for advertising or cross-site tracking. We honor Global Privacy Control signals, although we do not sell or share personal data in the first place.

7. Communications

Service emails (invitations, password resets, security alerts, billing notices, and changes to our terms) are part of the Service, and you cannot opt out of them while you have an account.

Notification emails about your boards can be turned on or off in your notification settings.

Product news is sent only to customer contacts, and every message has an unsubscribe link.

8. Security

We protect personal data with encryption in transit and at rest, access controls, Argon2id password hashing, sign-in rate limiting and the other measures described on our Security page. No system is perfectly secure. If a personal data breach affects you, we will notify you and the competent authorities as the law requires.

9. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and get a copy of it;
  • correct data that is inaccurate or incomplete;
  • delete your data;
  • restrict or object to our processing, including processing based on legitimate interest and direct marketing;
  • port your data to another service in a common, machine-readable format;
  • withdraw consent where we rely on it, without affecting what we did before;
  • not be discriminated against for using these rights.

How to use them. Many of these rights you can exercise yourself in your profile settings. For anything else, write to simplecodesa+privacy@gmail.com. We may need to verify your identity first. We answer within 30 days. If the request is complex, we may extend that period as the law allows, and will tell you why. An authorized agent may make a request for you if they can show that they are allowed to act for you.

Data in a customer's workspace. If your request is about Customer Data, we will pass it to the customer that controls it (see section 10).

Complaints. If you are not satisfied with our answer, you may complain to your data protection authority. In the EU, that is the authority in your country. In the UK, it is the ICO. In Israel, it is the Privacy Protection Authority.

Israel residents. We process personal data under the Israeli Protection of Privacy Law and its Data Security Regulations. You may ask to review the data we hold about you, and to have it corrected or deleted if it is inaccurate, incomplete, unclear or outdated. You are not required by law to give us personal data, but without the data in section 1 we cannot provide the Service. For Customer Data, the customer is the database controller and we hold the data for it.

United States residents. We do not sell or share personal data as those terms are defined in US state privacy laws, such as the California Consumer Privacy Act, and we do not use sensitive personal information for purposes that require an opt-out. In the past 12 months we collected the categories of data described in section 1, for the purposes in section 2, and disclosed them only to the recipients in section 5.

10. Controller and processor

  • We are the controller of personal data about visitors, Users (account and usage data), prospects and contacts. This policy covers that data.
  • We are a processor for Customer Data. The customer is the controller. It decides what to store and who can see it, and we follow its instructions under the Data Processing Agreement. If you are an individual whose data is in a customer's workspace, please contact that customer. If you contact us, we will pass your request on to it.

11. Other notices

Changes to this policy. We will post changes here and update the date at the top. If a change is significant, we will also tell workspace admins by email or in the Service before it takes effect.

Children. The Service is meant for businesses and is not directed to anyone under 16. We do not knowingly collect their personal data. If you believe a child has given us personal data, write to us and we will delete it.

Links to other sites. The Site and Service may link to websites we do not operate. Their privacy practices are their own.

Accessibility. If you need this policy in another format, write to simplecodesa+support@gmail.com.

Contact. SA SIMPLE CODE LTD, company number 516820560, [REGISTERED ADDRESS], Israel. Privacy questions and requests: simplecodesa+privacy@gmail.com.