Sheetsmith CRM — Privacy Policy
Last updated: 19 September 2026
Sheetsmith CRM is provided by M Woodison, trading as Miso Developments, 11 Cherry Rise, Flackwell Heath, Bucks, HP10 9PS, United Kingdom. Questions or requests: support@sheetsmith.co.uk.
This policy covers two different kinds of personal data.
1. Data about you, our customer — we are the controller
| What | Why we have it | Lawful basis | How long |
|---|---|---|---|
| Your email address and password (the password is stored only as a hash by our login provider) | To create and secure your account and let you log in | Contract | Until you delete your account |
| Your plan, and a Stripe customer reference if you pay | To give you what you have paid for | Contract | Until you delete your account |
| Emails you send to support@sheetsmith.co.uk | To answer you | Legitimate interests (running a support desk) | 90 days |
| Technical logs: time, type of request, result, your account's internal id and the IP address the request came from. Never any CRM content; not used for tracking or profiling | To keep the service secure, investigate incidents and fix faults | Legitimate interests (security) | 30 days |
Payments are taken by Stripe, which is the seller of record and an independent controller of your billing details. We never receive your card number. See Stripe's privacy policy at https://stripe.com/gb/privacy.
We do not sell your data, use it for advertising, or send marketing email. Service emails (verification, password reset, notice of changes to terms or price) are sent because they are needed to run your account.
2. Data you put into the CRM about other people — you are the controller
Names, contact details, notes and the rest of what you record belong to you. We only store and display them for you, as your processor, under the Data Processing Agreement in our Terms of Service. We do not read, analyse, share or use that data for any purpose of our own. If one of your contacts asks us about their data, we will pass the request to you.
3. Where data is kept and who else handles it
Everything is stored in Amazon Web Services' London (UK) region, encrypted in transit and at rest. AWS is our only sub-processor for CRM data. We do not transfer CRM data outside the UK.
4. Cookies and tracking
None. There are no analytics, no advertising scripts and no third-party code in the app. The app keeps your login session in your browser's own storage, which is strictly necessary for it to work, and clears it when you log out.
5. Your rights
You can see and export everything from Settings, correct it in the app, and delete your account — which erases your data and your login immediately, and from encrypted backups within 35 days. You also have the rights to object and to restrict processing; email us and we will respond within one month. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/.
6. If something goes wrong
If a security incident affects your data we will tell you without undue delay and within 48 hours of becoming aware of it, and we will report to the ICO where the law requires.
7. Changes
We will email you at least 30 days before any change to this policy that matters.