Skip to content
NoClutterCRM
Legal & trust

Privacy Policy

How NoClutterCRM handles account information, Chrome extension context, customer communications, and connected-account data.

Effective 4 September 2026 Questions? support@nocluttercrm.com

This policy explains how NoClutterCRM collects, uses, stores and shares personal data when businesses use our sales workspace. We act as a controller for account, billing and service-usage data. For contacts and business communications placed in a customer workspace, we generally process data on that customer’s instructions.

Information we process

NoClutterCRM Chrome extension

If you install the NoClutterCRM Chrome extension, it examines the active HTTP or HTTPS page only while its side panel is open, when the active tab or page changes, or when you choose Refresh page. Deterministic extraction runs inside that active tab. The page text used for extraction is discarded there; only bounded detected fields, such as a person or company name, public profile URL, website, business contact details, and visible Gmail or Google Meet participant names and email addresses, reach the extension service worker.

When the extension checks for an existing CRM match or you choose a CRM action, the relevant detected fields are sent to NoClutterCRM under your authenticated workspace account so that we can search, create, or update the record you selected. The extension does not read browsing history, closed tabs, password or form-field values, or pages while the side panel is closed. It does not send active-page content to an AI provider for extraction.

Chrome stores the extension’s NoClutterCRM authorisation tokens and preferences in extension-local storage. Signing out revokes the server-side authorisation and removes those local tokens. The extension requests access to supported work sites at installation and asks for optional site access only when you choose to scan another site. Its access to the visible Gmail or Google Meet page is separate from any Gmail mailbox, Google Contacts, or Google Calendar connection described below.

Calendar, email and connected accounts

When a workspace uses managed email, we process inbound and outbound message content, headers, recipients, attachments and delivery events so the service can send, receive, thread, secure and display email.

If you choose to connect Google Calendar or Microsoft Calendar, we use the identity and calendar permissions shown on the provider’s consent screen to identify your account, list the calendars available to you, read free/busy availability, and create, update or cancel CRM booking events on the calendar you select. A calendar connection does not grant us access to Gmail or Outlook mail. Calendar access is optional, can be disconnected from the workspace, and can also be revoked from your provider account.

If you separately connect Gmail, we request only the Gmail send permission and use it when an authorised workspace user chooses to send or reply from that account. NoClutterCRM does not request permission to read or synchronize Gmail messages. If you connect Microsoft Outlook, we use delegated mail read permission to synchronize a bounded recent set of inbox and sent messages and mail send permission for user-initiated replies. Neither connection lets NoClutterCRM delete, move or reorganise mail in the provider. Disconnecting removes CRM conversations linked to that connection from the active workspace and leaves provider mail, sign-in, contacts and calendar connections unchanged; you may also revoke the grant in your Google or Microsoft account.

If you separately connect Google Contacts or Microsoft Contacts, we use read-only contact permission to import and periodically synchronize saved contacts into your CRM workspace. Depending on what the provider record contains, this may include names, email addresses, phone numbers, company, job title, city and country. NoClutterCRM does not create, edit or delete contacts in Google or Microsoft. Pausing contact sync or deleting a contact at the provider does not automatically delete the CRM record already created; authorised workspace users can review, edit or delete that CRM record, and provider access can be revoked from the provider account.

If you separately link Google or Microsoft for sign-in, we use basic account identity information to authenticate you. Sign-in does not request calendar or mailbox permissions, and disconnecting sign-in does not disconnect a calendar connection.

Provider authorisations are encrypted at rest. Google user data obtained through these permissions is used only to provide the connected features you choose; it is not sold, used for advertising or used to train general-purpose AI models.

Google user data sharing and Limited Use

We do not sell Google user data. We do not share, transfer or disclose Google user data except in these limited circumstances:

Google Workspace or Microsoft Graph data is not disclosed to Anthropic, OpenAI or other AI or machine-learning providers. We do not use that data to develop, improve or train generalised or non-personalised AI or machine-learning models.

NoClutterCRM’s use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we use information

We use information to operate and secure the service, deliver communications requested by workspace users, maintain CRM history, provide reporting and support, detect abuse, comply with law and improve reliability. We do not sell personal data.

Lawful bases

Where data-protection law requires a lawful basis, we rely on performance of our contract to provide the service, legitimate interests in operating and securing a business platform, compliance with legal obligations, and consent where required. Customers determine the appropriate basis for contact and communication data they place in their workspaces.

Cookies and local storage

We use essential cookies and similar browser storage for secure sessions, authentication, preferences and service operation. We do not use customer email or CRM content for advertising.

Our Brand Site Tag can provide optional advertising measurement on specifically configured pages. It does not activate those capabilities merely because the tag is installed. Before advertising consent, it does not send a campaign page-arrival event, request Meta's Pixel script, or emit Meta PageView or Lead events.

If you allow advertising measurement, NoClutterCRM may count a privacy-minimised campaign page arrival after an exact campaign destination renders. We retain the campaign, brand, date and aggregate count, not a visitor profile, IP address, user agent, referrer, full URL, form answers or contact details. The aggregate may include repeat page loads and cannot reconstruct activity from before measurement began. Where a managed Meta Pixel is also enabled, Meta may receive PageView and, after a new private-beta request succeeds, Lead plus ordinary browser and network information available to the Pixel. We do not include form answers, email addresses or CRM content in those browser events. Rejecting optional measurement does not affect the form. You can reopen “Cookie and tracking choices” to change your choice.

On websites where a workspace owner enables it, the Brand Site Tag can load Microsoft Clarity on the configured URL paths after you allow Analytics. Clarity helps the website owner understand page use through aggregated interaction metrics, heatmaps and session recordings. NoClutterCRM does not send Clarity custom user identifiers, form answers, email addresses or CRM content, and Clarity masks input content and other content it classifies as sensitive by default. If you reject Analytics, the Clarity script is not requested. If you later withdraw Analytics consent, we send Clarity a denied consent signal and request deletion of its browser cookies.

AI processing

Message content, approved knowledge and call transcripts may be processed by contracted AI providers, such as Anthropic or OpenAI, to generate replies, summaries, qualification and coaching for the relevant workspace. We do not use customer conversation content to train our own general-purpose models. These AI features do not receive data obtained from connected Google Workspace or Microsoft Graph integrations. Workspace users remain responsible for reviewing AI output before relying on it.

Service providers and international processing

We use contracted providers to operate infrastructure, communications and security. Depending on the features used, these may include Amazon Web Services and Amazon SES, Cloudflare, Google, Microsoft, Meta/WhatsApp, telephony providers and AI providers. Data may be processed in countries other than your own. Where required, we use contractual and organisational safeguards for international transfers.

Security and email safety

We apply tenant isolation, access controls, encryption of provider authorisations, signed inbound delivery, rate limits and audit logging. Incoming email is treated as untrusted: content is quarantined for processing, HTML is sanitised, remote images are blocked or fetched through a controlled proxy, external links are disclosed before opening, and attachments are served with restrictive controls. No system can eliminate every risk, so customers must also manage user access and endpoint security.

Call recording and communications compliance

Calls placed through the platform may be recorded and transcribed. Customers are responsible for giving notices and obtaining consent where required. Customers are also responsible for having a lawful basis to contact recipients and for honouring applicable marketing and communications laws.

Retention, export and deletion

We retain workspace data while the account is active and for limited periods afterwards where needed for security, legal obligations, dispute resolution and backups. Disconnecting Gmail removes CRM email conversations linked to that send-only connection; disconnecting Outlook deletes its synchronized messages from the active workspace. Pausing contact sync or deleting a provider contact retains the CRM contact already imported until an authorised workspace user deletes it or the workspace owner requests deletion. Raw inbound email and other high-risk source files may use shorter retention than the safe content shown in the workspace. Workspace owners may request an export or deletion; verified deletion requests are normally completed within 30 days, subject to legal retention requirements and backup expiry. Requests concerning a Meta Ads connection can follow our dedicated Meta Data Deletion Instructions.

Your choices and rights

Workspace owners can manage team access, sender identities, communication settings and connected providers. Calendar and mailbox connections can be disconnected in the workspace, contact synchronization can be paused, and provider access may also be revoked from the provider account. Imported CRM contacts remain available until an authorised workspace user deletes them or the workspace owner requests deletion. Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, or receive a portable copy of personal data. We may need to verify your identity and, for workspace-controlled data, refer the request to the relevant customer. You also have the right to lodge a complaint with your data-protection supervisory authority — in the United Kingdom, the Information Commissioner’s Office (ICO); elsewhere, the authority in your country — though we would welcome the chance to address your concern first.

Children

The service is intended for businesses and is not directed to children under 16.

Changes and contact

We may update this policy as the service changes and will post the updated date on this page. For privacy questions, data requests or complaints, email support@nocluttercrm.com.