Privacy Policy

Last updated: 16 June 2026

Action required: review with legal counsel and replace the legal entity name, registered address, sub-processor list, and ICO/EU complaint route to match your registered business.

1. Who we are

CleanDupTool ("we", "us") provides a CRM data-cleansing service. We act as a data controller for account and analytics data and as a data processor for CRM records you upload. The legal entity and registered address will be confirmed on this page once finalised. For all privacy enquiries contact privacy@cleanduptool.com.

2. Data we collect

  • Account data — name, email, organisation name, password hash, role.
  • CRM data you upload — Contacts, Companies, Leads or Accounts you choose to deduplicate. Held only as long as needed for processing or as you choose to retain it.
  • Billing data — payment metadata via Stripe (we never store full card numbers).
  • Audit log — security-relevant actions taken in your account.
  • Anonymous product analytics — page path, event name, anonymous session id, and explicit UTM campaign tags only. No IP, no user-agent, no referrer, no user id is stored. Because these records cannot identify you, no consent banner is required.

3. Lawful bases (UK GDPR / EU GDPR Art. 6)

  • Contract — providing the deduplication service you signed up for.
  • Legitimate interest — security audit logs, anonymous product analytics, fraud prevention.
  • Legal obligation — billing records, responding to lawful requests.
  • Consent — marketing emails (opt-in only; revoke any time via unsubscribe).

4. Retention

  • Analytics events: 90 days, then auto-deleted.
  • Audit log: 13 months.
  • Email send log: 6 months.
  • Suppressed-email list: kept indefinitely so we continue to honour unsubscribes.
  • Account and CRM data: kept while your account is active; deleted within 30 days of account closure.
  • Billing records: 6 years where required by UK tax law.

5. Your rights

You have the right to access, correct, port, restrict processing of, or erase your personal data. You can:

  • Download all your data from Settings → Privacy & your data.
  • Delete your account from the same screen — this erases your profile and, if you are the sole member, your organisation's data.
  • Email privacy@cleanduptool.com for any other request. We respond within 30 days.
  • Lodge a complaint with the UK ICO (ico.org.uk) or your local EU supervisory authority.

6. Sub-processors & transfers

We use a small set of GDPR-compliant sub-processors:

  • Supabase (hosted database & auth) — EU region.
  • Cloudflare (edge runtime) — global, with EU data localisation where available.
  • Stripe (payments).
  • Resend / email provider (transactional email).

Where data leaves the UK/EEA, transfers rely on the UK IDTA or EU Standard Contractual Clauses.

7. Security

All traffic is TLS-encrypted. Row-Level Security isolates every workspace at the database layer. Passwords are checked against the Have I Been Pwned database on signup and change. Privileged operations are gated by role checks and logged.

8. Cookies & tracking

We use only strictly-necessary cookies and storage (session, auth token, your theme preference). No third-party advertising cookies. The session id used by our analytics is anonymous and stored in your browser's sessionStorage — it is cleared when you close the tab.

9. Changes

We will post material changes here and notify active users by email.