Privacy Policy
Last updated: 16 June 2026
1. Who we are
CleanDupTool ("we", "us") provides a CRM data-cleansing service. We act as a data controller for account and analytics data and as a data processor for CRM records you upload. The legal entity and registered address will be confirmed on this page once finalised. For all privacy enquiries contact privacy@cleanduptool.com.
2. Data we collect
- Account data — name, email, organisation name, password hash, role.
- CRM data you upload — Contacts, Companies, Leads or Accounts you choose to deduplicate. Held only as long as needed for processing or as you choose to retain it.
- Billing data — payment metadata via Stripe (we never store full card numbers).
- Audit log — security-relevant actions taken in your account.
- Anonymous product analytics — page path, event name, anonymous session id, and explicit UTM campaign tags only. No IP, no user-agent, no referrer, no user id is stored. Because these records cannot identify you, no consent banner is required.
3. Lawful bases (UK GDPR / EU GDPR Art. 6)
- Contract — providing the deduplication service you signed up for.
- Legitimate interest — security audit logs, anonymous product analytics, fraud prevention.
- Legal obligation — billing records, responding to lawful requests.
- Consent — marketing emails (opt-in only; revoke any time via unsubscribe).
4. Retention
- Analytics events: 90 days, then auto-deleted.
- Audit log: 13 months.
- Email send log: 6 months.
- Suppressed-email list: kept indefinitely so we continue to honour unsubscribes.
- Account and CRM data: kept while your account is active; deleted within 30 days of account closure.
- Billing records: 6 years where required by UK tax law.
5. Your rights
You have the right to access, correct, port, restrict processing of, or erase your personal data. You can:
- Download all your data from Settings → Privacy & your data.
- Delete your account from the same screen — this erases your profile and, if you are the sole member, your organisation's data.
- Email privacy@cleanduptool.com for any other request. We respond within 30 days.
- Lodge a complaint with the UK ICO (ico.org.uk) or your local EU supervisory authority.
6. Sub-processors & transfers
We use a small set of GDPR-compliant sub-processors:
- Supabase (hosted database & auth) — EU region.
- Cloudflare (edge runtime) — global, with EU data localisation where available.
- Stripe (payments).
- Resend / email provider (transactional email).
Where data leaves the UK/EEA, transfers rely on the UK IDTA or EU Standard Contractual Clauses.
7. Security
All traffic is TLS-encrypted. Row-Level Security isolates every workspace at the database layer. Passwords are checked against the Have I Been Pwned database on signup and change. Privileged operations are gated by role checks and logged.
8. Cookies & tracking
We use only strictly-necessary cookies and storage (session, auth token, your theme preference). No third-party advertising cookies. The session id used by our analytics is anonymous and stored in your browser's sessionStorage — it is cleared when you close the tab.
9. Changes
We will post material changes here and notify active users by email.