Legal

Privacy policy

Last updated 16 September 2026

This policy explains what Services CRM does with personal data. There are two different groups of people involved — the businesses who run their work on the CRM, and the customers those businesses keep records about — so the two are set out separately below.

1. Who we are

Services CRM is operated by services-crm, a company registered in England and Wales (company number 17462016), whose registered office is 42 Buxton Avenue, Gorleston, Norfolk, NR31 6HF, United Kingdom. You can reach us at [email protected].

We are the data controller for the information described in sections 3 and 5. For the information described in section 4, the business using the CRM is the controller and we act as their processor.

2. Two roles, kept apart

The distinction matters, because it decides who you ask about what.

Whose dataOur roleWho to contact
People who sign up and use the CRM — owners, admins and staff of a business. Controller. We decide what to collect and why. Us, at the address above.
The customers, quotes, jobs, invoices, payments, expenses and photos a business enters, and the mail it sends its customers through us. Processor. We only store it, serve it back and send it on, on that business's instructions. The business you dealt with. See section 11.

3. What we hold about account holders

Everything here exists because the service cannot work without it.

WhatWhyLawful basis
Your name, email address, role, and a scrypt hash of your password. Never the password itself. To create your account, sign you in, and decide what you can see. Performance of a contract
The date you joined and the last time you were seen. So an account owner can see who is still using the account. Legitimate interests — running the account
Business details you enter: trading name, tagline, phone, email, website, logo, VAT number, the bank details printed on your invoices — and, if you turn on card payments, the key to your own Stripe account, stored encrypted and never shown again. To draw your quotes and invoices with your own branding and payment details, and to take card payments into your account. Performance of a contract
Billing references from Stripe: a customer ID, a subscription ID, status and renewal date. Card numbers never reach our servers — Stripe handles the payment. To take the subscription payment and know whether the account is in good standing. Performance of a contract; legal obligation for tax records
A SHA-256 hash of your session token and its expiry. The token itself is only in your browser. To keep you signed in without storing anything that could be replayed if the database leaked. Performance of a contract
The email address of anyone you invite to your account, and a hash of the invite link we email them. To let them join your account. Invites expire after 14 days. Legitimate interests — team access
The email address you sign up with, and a hash of the link we send to confirm it, before your account exists. The same for a password reset. To make the account against an address that really is yours, and to let you back in if you forget your password. Sign-up links expire after 24 hours, reset links after 2. Performance of a contract, and the steps before one
An activity trail: what each person on an account did and when — a quote sent, a price changed, an invoice reopened — and each time they signed in or out, with the kind of device and browser ("Safari on iPhone"). Never the IP address, and never failed attempts. So the owner and admins of an account can see what happened and who did it, and spot a sign-in that was not theirs. Legitimate interests — accountability and account security
For each question asked of the assistant: who asked, when, and how much computing it took. Not the question, and not the answer. To count questions against your plan's monthly allowance. Performance of a contract
The IP address of anyone using a form or page open to the public — the enquiry form, sign-up, password reset, sign-in, and the pages a customer answers a quote or pays an invoice on. At sign-in, the email address that was tried as well. Held in memory for one hour and never written to disk. To stop one source flooding a business with junk enquiries, or guessing at passwords. Legitimate interests — preventing abuse

What we do not do

No advertising, no profiling, no selling or sharing data with anyone for their own purposes, and no using your business records to market anything to you or to your customers. No analytics inside the CRM at all — only on the public pages, and only if you agree to it (section 5).

4. What businesses store about their own customers

A business using the CRM enters records about the people it works for: name, phone number, email address, site address, free-text notes, photographs of the site taken for a quote, and the quotes, bookings, jobs, invoices and payments attached to them. Some of that arrives through an enquiry form on the business's own website, and some from the customer directly — their answer to a quote, with a reason if they turned it down, and a card payment made on an invoice. A business can also record what it spends and any other money it receives, with receipts, and the names of the suppliers and people involved.

We use that data only to do what the business asks of the CRM, and nothing else: store it, draw its quotes and invoices, and — when the business asks —

  • email its customers: quotes, booking confirmations and changes, invoices, reminders about unpaid ones, and receipts. They come from our sending address under the business's name, and replies go to the business, not to us;
  • take card payments into the business's own Stripe account, for a business that turns them on (see section 6);
  • answer the assistant's questions, for a business that turns the assistant on (see section 6).

We do not read it, analyse it for ourselves, or use it to train anything. Each account's records are scoped to that account: one business cannot see another's, and every query is filtered by the account of the person signed in.

Businesses using the CRM are responsible for having their own lawful basis for the records they keep, and for telling their customers about it in their own privacy notice. If you need a data processing agreement covering our role as your processor, contact us at [email protected].

5. Cookies

Services CRM uses cookies to run the service and, only if you agree, to count visits to the public pages — the home page, the blog, the help guide and this policy — with Google Analytics. There are no advertising cookies, and no analytics inside the CRM or on the pages a customer opens to answer a quote or pay an invoice.

Every cookie this site can set.
NameWhat it doesHow long
crm_session Keeps you signed in. Holds a random token and nothing else — no name, no email, no account details. Marked HttpOnly and SameSite=Lax, and Secure whenever the site is served over HTTPS, so scripts cannot read it and other sites cannot use it. 30 days, or until you sign out
crm_admin_session The same thing for our own support login. It is never set on a customer's browser. A few hours
crm_cookie_consent Remembers what you chose on the cookie notice, so you are not asked again on every visit. Holds one word and nothing identifying. 1 year
_ga, _ga_BQ985B1MK3 Set by Google Analytics, and only once you choose Accept. A random ID that lets it tell one visitor's pages from another's, and your visits apart from each other. Never set inside the CRM. Up to 2 years

Choosing not to use them

The sign-in cookie is what UK law calls strictly necessary: without it there is no way to stay signed in, so the CRM cannot work. That kind of cookie does not legally require consent, but we ask anyway, because you should know what a site puts on your machine.

Google Analytics is different: it is not needed to run anything, so it waits for your consent. Until you choose Accept, the public pages do not load it at all, and nothing is sent to Google. Once you accept, it records which of those pages you visit, how you arrived, and the kind of device and browser you use, with your IP address, and reports it to us as totals. We use it only to see which pages people read. The lawful basis is your consent.

Choose Use without cookies on the notice and we will set neither. You can read every page here, but you will not be able to sign in until you allow the sign-in cookie — we will say so plainly rather than quietly setting it anyway, and allowing it then does not turn on analytics. To change your mind either way, use the Cookies link in the footer of the home page; declining there stops Google Analytics and removes its cookies straight away. Signing out of the CRM removes the session cookie immediately, and clearing cookies in your browser removes all of them.

The pages a business's customer reaches from an email — to answer a quote or pay an invoice — set no cookies of ours at all. Paying by card moves on to Stripe's own checkout page, which works under Stripe's cookie policy rather than this one.

6. Who else is involved

These are the only third parties that touch any of it.

WhoWhat they getWhy
Stripe Payments Europe, Ltd. Your name, email and card details, entered on Stripe's own checkout page. To take subscription payments. We never see or store the card.
Stripe, on a business's own account Only for a business that turns card payments on: the customer's email address, the invoice reference, what the work was and the amount, from us; and the card details, which the customer enters on Stripe's own page. We read back the payment and Stripe's fee. To let a customer pay an invoice by card. The money goes to the business's Stripe account and never passes through ours; we never see or store the card.
Postmark (ActiveCampaign, LLC) The mail we send, and who it goes to. For account holders: sign-up confirmations, password resets, invitations, and word that a customer answered a quote or paid. For a business's customers: their name and email address, and the quotes, bookings, invoices, reminders and receipts that business sends them, attachments included. To deliver email.
Anthropic, PBC Only for a business that turns the assistant on, and only when somebody asks it something: the records that question needs, which can include customers' names, addresses and what they were billed. To answer the question. The question and the answer are not kept by us.
Railway (railway.com) Everything, as the operator of the servers the database and uploaded files sit on. To host the service.
Google Fonts Your IP address and browser details, when a page here loads its typefaces — including the pages a customer opens to answer a quote or pay an invoice. Page styling. No cookie is set by this, and no account data is sent.
Google Analytics (Google Ireland Limited) Only if you accept analytics cookies: the public pages you visit, how you arrived, your device and browser, and your IP address. Never anything from inside the CRM, and never a business's customer records. To count visits to the public pages. See section 5.

We will hand data to anyone else only where the law requires it — a court order, or a properly made request from a public authority.

7. Where it is kept

The database and the uploaded files — enquiry photos, expense receipts and logos — are stored on servers in the Netherlands, in the European Economic Area. Stripe processes payments in the EEA and may transfer data to the United States under the safeguards set out in its own privacy policy.

Postmark and Anthropic are based in the United States, so the mail we send and any question put to the assistant are processed there. Google may process analytics data in the United States too, for anyone who has accepted it.

8. How long we keep it

  • Account and business records — for as long as the account is open.
  • After an account is closed — we delete the account and everything belonging to it immediately, including its uploaded photos, receipts and logo. Cancelling a subscription does not close an account: its records stay, read-only, until it is closed.
  • Session records — 30 days, then swept automatically. Invites expire after 14 days.
  • Sign-up and password reset links — 24 hours and 2 hours respectively, then deleted automatically. Each works once.
  • The activity trail and assistant usage counts — for as long as the account is open, and deleted with it. What was asked of the assistant, and its answers, are never kept.
  • Photographs sent with an enquiry — kept with the quote they belong to. Deleting the quote, the customer or the account deletes the image files as well, not only the records of them.
  • Expense receipts — kept with the expense they belong to. Deleting the expense, replacing or removing the receipt, or closing the account deletes the file too.
  • IP addresses on public forms and pages, and at sign-in — one hour, in memory only.

9. How it is protected

  • Passwords are hashed with scrypt, each with its own salt. We cannot read yours.
  • Session tokens are stored only as SHA-256 hashes, so a copy of the database is not a way in.
  • The key to a business's own Stripe account, and the links printed on its quotes and invoices, are encrypted (AES-256-GCM) with a key kept outside the database. A Stripe key is never shown again once it has been saved.
  • Repeated failed sign-ins from one address are refused for an hour, and sign-up and reset links are short-lived and single-use.
  • The assistant can only read, and only the records of the account that asked.
  • Every record belongs to exactly one account, and every query is scoped to the person signed in.
  • Cookies are HttpOnly and SameSite=Lax, which keeps scripts and other sites away from your session.
  • The service is served over HTTPS, and cookies are marked Secure when it is.
  • Staff, admin and owner roles limit what each person on an account can see and change — staff cannot open business settings, bank details, the activity trail or the subscription.

10. Your rights

Under UK GDPR you can ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct anything that is wrong;
  • delete it, where we do not have to keep it for tax or legal reasons;
  • hand it over in a portable format, or send it to someone else;
  • stop or restrict a particular use, including anything we do on the basis of legitimate interests.

Write to [email protected] and we will answer within one month. There is no charge. If you are unhappy with how we handle it you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.

11. If a business you dealt with uses Services CRM

If you got a quote or an invoice from a business running on Services CRM, your details are in that business's account. They decide what to keep and for how long, so requests to see, correct or delete your record go to them, not to us — they are the ones who can act on it.

Mail from them is sent through us, from our address with their name on it; replying reaches them, not us. If you pay one of their invoices by card, you are paying into their own Stripe account — the payment is between you, them and Stripe.

If you cannot reach them, contact us at [email protected] and we will pass it on and tell you who they are.

12. Changes to this policy

If we change how any of this works we will update this page and change the date at the top. Anything that materially affects account holders will also be sent to them by email.

13. Contact

services-crm
Registered in England and Wales, company number 17462016
42 Buxton Avenue, Gorleston, Norfolk, NR31 6HF
[email protected]