This policy explains how CrowdStack (“we”, “us”) collects, uses, and shares personal data when you visit our website or use our Support, CRM, and Revenue products (the “Service”).
We aim to handle personal data lawfully, fairly, and transparently, in line with the UK GDPR and the Data Protection Act 2018 (and, where applicable, the EU GDPR).
1. Who is responsible
For account, billing, and website data, CrowdStack is the data controller. For Customer Data that you store about your own customers or contacts inside a workspace, you are typically the controller and we process that data on your instructions as a processor.
Contact: support@crowdstack.org.
2. Data we collect
Account and workspace data
- name, email address, and password (stored hashed);
- company or organisation name and workspace settings;
- role and membership details for invited users;
- billing and subscription status where you have a paid plan.
Customer Data you submit
- tickets, messages, contacts, companies, deals, notes, tags, and related CRM or support records;
- files and attachments you upload;
- configuration for portals, knowledge articles, workflows, and integrations.
Usage and technical data
- log data such as IP address, browser type, device information, and approximate location derived from IP;
- product usage events that help us operate and improve the Service;
- cookies and similar technologies, as described in our cookie policy.
Communications
- messages you send to us (for example support emails or feature requests);
- transactional emails related to your account.
3. How we use personal data
We use personal data to:
- provide, secure, and maintain the Service;
- create and administer accounts and workspaces;
- process payments and prevent fraud;
- communicate about the Service, including security and product notices;
- improve reliability, performance, and features;
- comply with legal obligations; and
- enforce our terms and protect our rights and users.
4. Lawful bases
Where we act as controller, we typically rely on:
- Contract: to provide the Service you request;
- Legitimate interests: to secure, improve, and market the Service in ways that do not override your rights;
- Consent: where required (for example certain cookies or optional marketing);
- Legal obligation: where the law requires us to retain or disclose information.
When we act as processor, we process Customer Data under your instructions and the applicable data-processing terms.
5. Sharing
We do not sell personal data. We share it only with:
- infrastructure and service providers who help us host email, SMS, storage, analytics, authentication, or payments, under appropriate contracts;
- professional advisers where needed;
- authorities when required by law or to protect rights and safety;
- a successor organisation if we transfer or reorganise the business, subject to appropriate safeguards.
If you connect third-party products (for example Stripe), those providers process data under their own policies.
6. International transfers
We may process data in the United Kingdom, the European Economic Area, and other countries where our providers operate. Where data leaves the UK/EEA, we use appropriate safeguards such as the UK International Data Transfer Agreement / Addendum or standard contractual clauses, unless an adequacy decision applies.
7. Retention
We keep account data for as long as your account is active and for a reasonable period afterwards for backups, disputes, and legal compliance. Customer Data is retained while your workspace exists; you may delete records in-product. After account closure we delete or anonymise personal data within a reasonable period unless the law requires longer retention.
8. Security
We use technical and organisational measures appropriate to the risk, including access controls, encryption in transit where supported, and hashed passwords. No online service is completely secure; please choose a strong password and limit who you invite to your workspace.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your personal data; to object to certain processing; to data portability; and to withdraw consent where processing is based on consent. You may also complain to the UK Information Commissioner’s Office (ICO) or your local supervisory authority.
To exercise rights relating to your CrowdStack account, email support@crowdstack.org. If your data sits in a customer workspace, contact that organisation first; they control that Customer Data.
10. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children for account registration.
11. Changes
We may update this policy from time to time. We will revise the date above and, for material changes, provide additional notice where appropriate.
12. Contact
Privacy enquiries: support@crowdstack.org.