Privacy Policy
Last updated: February 18, 2026
1. Introduction
SweetSpotCRM Ltd. ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our AI-powered CRM platform ("Service").
This policy applies to all users worldwide and addresses requirements under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the UK Data Protection Act, Brazil's LGPD, and other applicable data protection laws.
2. Data Controller
SweetSpotCRM Ltd. is the data controller responsible for your personal data. For inquiries regarding data protection, contact our Data Protection Officer at:
- Email: dpo@sweetspotcrm.com
- Email: privacy@sweetspotcrm.com
3. Information We Collect
3.1 Information You Provide
- Account Information: Name, email address, phone number, company name, job title, and billing information
- CRM Data: Contacts, leads, deals, activities, notes, and documents you create within the Service
- Communications: Support tickets, feedback, and communications with our team
- Voice Data: Voice commands processed by our AI assistant AleX (transcribed and processed in real-time; raw audio is not stored)
3.2 Information Collected Automatically
- Device Information: Device type, operating system, browser type, screen resolution, and unique device identifiers
- Usage Data: Pages visited, features used, clicks, timestamps, and session duration
- Location Data: Approximate location based on IP address (precise location only with your explicit consent)
- Log Data: IP addresses, access times, error logs, and referring URLs
3.3 Information from Third Parties
- Integrations: Data synced from third-party services you connect (e.g., email, calendar, cloud storage)
- Payment Processor: Stripe provides us with limited billing information (last four digits of card, billing address, transaction status)
4. Legal Bases for Processing (GDPR)
Under the GDPR, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide the Service (Article 6(1)(b))
- Legitimate Interest: Analytics, security, product improvement, and marketing to existing customers (Article 6(1)(f))
- Consent: Marketing emails, non-essential cookies, and optional data processing (Article 6(1)(a))
- Legal Obligation: Tax, accounting, and regulatory compliance (Article 6(1)(c))
5. How We Use Your Information
- Provide, operate, and maintain the Service
- Process your subscription and manage billing
- Power the AleX AI assistant and generate personalized insights
- Generate AI-powered proposals and documents based on your CRM data
- Send transactional emails (account confirmations, invoices, security alerts)
- Send marketing communications (only with your consent; you can opt out anytime)
- Analyze usage patterns to improve the Service
- Detect, prevent, and address fraud, security issues, and technical problems
- Comply with legal obligations
6. AI and Automated Processing
Our AI assistant AleX processes your voice commands and CRM data to provide intelligent assistance. Specifically:
- Voice commands are transcribed in real-time; raw audio recordings are not permanently stored
- AI models may use anonymized and aggregated data to improve accuracy
- AI-generated content (proposals, summaries) is based on your CRM data and does not involve profiling for automated decision-making with legal effects
- You may request human review of any AI-generated output by contacting support
7. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
- Service Providers: Hosting (Vercel), payment processing (Stripe), email delivery (Resend), analytics, and customer support tools -- all bound by data processing agreements
- Legal Requirements: When required by law, legal process, or to protect our rights and safety
- Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified in advance)
- With Your Consent: When you explicitly authorize sharing with a third party
8. International Data Transfers
Your data may be transferred to and processed in countries outside your jurisdiction. When transferring data outside the European Economic Area (EEA) or the United Kingdom, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Binding Corporate Rules for intra-group transfers
9. Data Retention
We retain your personal data only as long as necessary for the purposes set out in this policy:
- Account Data: Retained while your account is active, plus 30 days after deletion
- CRM Data: Retained while your account is active; exportable and deletable on request
- Billing Records: Retained for 7 years for tax and legal compliance
- Usage Analytics: Aggregated and anonymized data may be retained indefinitely
- Marketing Consent Records: Retained for 3 years after last interaction
10. Your Rights
Depending on your jurisdiction, you have the following rights:
GDPR Rights (EEA/UK Residents)
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restriction: Restrict processing of your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interest or for marketing
- Right Not to Be Subject to Automated Decisions: Request human review of automated decisions
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
CCPA Rights (California Residents)
- Right to know what personal information is collected and how it is used
- Right to delete personal information
- Right to opt out of the sale of personal information (we do not sell personal data)
- Right to non-discrimination for exercising privacy rights
To exercise any of these rights, contact us at privacy@sweetspotcrm.com. We will respond within 30 days (or as required by applicable law).
11. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Regular security assessments and penetration testing
- Role-based access controls and multi-factor authentication
- Automated threat detection and monitoring
- Regular data backups with encrypted offsite storage
While we strive to protect your data, no method of transmission or storage is 100% secure. You should take reasonable precautions to safeguard your own credentials and data.
12. Cookies and Tracking
We use cookies and similar technologies as described in our Cookie Policy. You can manage your cookie preferences through the cookie consent banner or your browser settings.
13. Children's Privacy
The Service is not intended for individuals under the age of 18 (or the age of legal majority in your jurisdiction). We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact us and we will promptly delete it.
14. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email and/or a prominent notice on the Service at least 30 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.
15. Supervisory Authority
If you are located in the EEA or UK and believe our processing of your personal data violates applicable data protection laws, you have the right to lodge a complaint with your local supervisory authority.
16. Contact Us
For any questions or concerns about this Privacy Policy or our data practices:
- Data Protection Officer: dpo@sweetspotcrm.com
- Privacy inquiries: privacy@sweetspotcrm.com
- General support: support@sweetspotcrm.com