SheetsmithCRM

Sheetsmith CRM — Privacy Policy

Last updated: 19 September 2026

Sheetsmith CRM is provided by M Woodison, trading as Miso Developments, 11 Cherry Rise, Flackwell Heath, Bucks, HP10 9PS, United Kingdom. Questions or requests: support@sheetsmith.co.uk.

This policy covers two different kinds of personal data.

1. Data about you, our customer — we are the controller

WhatWhy we have itLawful basisHow long
Your email address and password (the password is stored only as a hash by our login provider)To create and secure your account and let you log inContractUntil you delete your account
Your plan, and a Stripe customer reference if you payTo give you what you have paid forContractUntil you delete your account
Emails you send to support@sheetsmith.co.ukTo answer youLegitimate interests (running a support desk)90 days
Technical logs: time, type of request, result, your account's internal id and the IP address the request came from. Never any CRM content; not used for tracking or profilingTo keep the service secure, investigate incidents and fix faultsLegitimate interests (security)30 days

Payments are taken by Stripe, which is the seller of record and an independent controller of your billing details. We never receive your card number. See Stripe's privacy policy at https://stripe.com/gb/privacy.

We do not sell your data, use it for advertising, or send marketing email. Service emails (verification, password reset, notice of changes to terms or price) are sent because they are needed to run your account.

2. Data you put into the CRM about other people — you are the controller

Names, contact details, notes and the rest of what you record belong to you. We only store and display them for you, as your processor, under the Data Processing Agreement in our Terms of Service. We do not read, analyse, share or use that data for any purpose of our own. If one of your contacts asks us about their data, we will pass the request to you.

3. Where data is kept and who else handles it

Everything is stored in Amazon Web Services' London (UK) region, encrypted in transit and at rest. AWS is our only sub-processor for CRM data. We do not transfer CRM data outside the UK.

4. Cookies and tracking

None. There are no analytics, no advertising scripts and no third-party code in the app. The app keeps your login session in your browser's own storage, which is strictly necessary for it to work, and clears it when you log out.

5. Your rights

You can see and export everything from Settings, correct it in the app, and delete your account — which erases your data and your login immediately, and from encrypted backups within 35 days. You also have the rights to object and to restrict processing; email us and we will respond within one month. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/.

6. If something goes wrong

If a security incident affects your data we will tell you without undue delay and within 48 hours of becoming aware of it, and we will report to the ICO where the law requires.

7. Changes

We will email you at least 30 days before any change to this policy that matters.