Privacy Notice
This notice describes what SMP Consulting LLC collects when you use SMP CRM, why we collect it, and who else sees it.
Two Different Roles
Everything below turns on a distinction worth stating first.
Your account information is ours to look after. Your name, your email address, your organization, your sign-in records and your billing details are data we hold about you, and we decide how they are used.
Your customers' information is yours to look after. The customer records, notes, quotes and contracts you put into SMP CRM are your data. We hold and process it on your instructions, we do not decide what it is used for, and we do not use it for anything of our own. If somebody in your customers' records asks us about their information, we will point them at you, because you are the one who holds the relationship.
What We Collect About You
- Account details: name, work email address, organization name, and the roles you hold.
- Sign-in records: when you signed in, from what network address, and whether it succeeded. We keep these because they are how an account compromise is discovered.
- What you did in the product: an audit record of changes to money, to access, and to configuration. This is deliberately not deletable by the people it records, and it is the reason a commission figure can be traced back to who changed what.
- Billing details: what plan you are on and what you have been charged. Card details are handled by our payment processor and never reach our servers.
What We Do Not Do
- We do not sell your data or your customers' data.
- We do not use your data to train models.
- We do not run advertising trackers or third-party analytics on our pages. The public pages of this product load no third-party script at all.
- We do not access your organization's records for support work as a matter of routine. Where staff access is genuinely needed, it is recorded in an audit trail you can read.
Who Else Sees It
- Our hosting provider, which runs the servers the product sits on.
- Our payment processor, which holds card details we never see.
- Your own connected services, where you choose to connect them: your accounting system, your email provider, and SMP eSign for signatures. What crosses is what you configured to cross.
- An outside sales agency you have granted access to, and only within the areas you turned on.
We do not otherwise disclose data except where the law requires it. Where we are legally able to tell you about such a request, we will.
How Long We Keep It
- Your records stay for as long as your organization has an account, and for thirty days after it closes so a closure made in error can be undone. After that they are deleted.
- Audit and sign-in records are kept longer, because their whole purpose is to answer a question asked after the fact.
- A record that somebody accepted these terms is kept even after the account is gone, because the fact that an agreement was made does not stop being true.
Your Rights
Depending on where you live you may have rights to see, correct, export or delete the personal data we hold about you. Write to us and we will answer. Where the data in question belongs to one of your customers rather than to you, we will pass the request to you.
Security, Stated Plainly
Data is encrypted in transit and at rest. Credentials we hold for your connected services are encrypted with a key held outside the database. Every organization's data is isolated at the data access layer rather than by individual queries remembering to filter, and a query that cannot establish which organization is asking returns nothing rather than everything.
What we do not have: a SOC 2 report, a HIPAA attestation, or any third-party audit. Nobody has assessed us. We will say so here when that changes, and we would rather tell you now than have you assume otherwise.
Changes
We will publish a new version of this notice when it changes and show what changed.
Contacting Us
Write to SMP Consulting LLC. Contact details are on our website.