Last updated: 28 August 2026
This policy explains what Argento Solutions, LLC (“Argento”, “we”, “us”) collects when you use Argento CRM at argentocrm.com and app.argentocrm.com (the “Service”), why we collect it, who we share it with, and what you can ask us to do about it.
This distinction matters throughout, so it comes first.
You control customer data. We process it on your instructions to provide the Service, and we do not sell it, mine it to build profiles, or use it to train machine learning models. Where privacy law uses the terms, you are the controller of customer data and we are the processor. For account data, we are the controller.
| Category | Examples | Why |
|---|---|---|
| Account | Name, email, hashed password, display name, workspace and role | Create your account, sign you in, and control who sees what |
| Billing | Plan, subscription status, trial and renewal dates, invoice history, the last four digits and expiry of your card | Take payment and manage your subscription |
| Customer data | Whatever you enter or upload into your workspace | Provide the Service to you |
| Usage | Record and storage counts, feature usage, timestamps | Enforce plan limits, show usage meters, keep the Service running |
| Technical | IP address, browser type, log and error data | Security, abuse prevention and debugging |
| Enquiries | What you send through our contact form | Reply to you |
We do not sell personal information, and we do not share it with third parties for their own advertising.
We use a small number of subprocessors to run the Service. Each is bound by contract to protect the data and use it only to provide their service to us.
| Provider | Purpose | Data |
|---|---|---|
| Supabase | Database, authentication, file storage and serverless functions | Account data, customer data, usage and technical data |
| Stripe | Payment processing and subscription billing | Name, email, billing details, card tokens |
| Hostinger | Website hosting for argentocrm.com and app.argentocrm.com | Technical and log data |
| Emailit | Outbound email delivery — reminders, password resets, billing notices | Recipient address, subject and message content, delivery status |
| Microsoft 365 | Our own business mailbox, which receives your enquiries and replies | Anything you email us |
| Google Analytics | Visitor measurement on our public marketing pages only — see section 9 | Page views, referrer, IP address, device and browser information |
| Meta (Facebook/Instagram) | Advertising measurement on our public marketing pages only — see section 9. Not loaded inside the CRM | Page views, signup and checkout events, IP address, device and browser information |
| Microsoft Clarity | Session recording and heatmaps on our public marketing pages only — see section 9. Not loaded inside the CRM | Pages viewed, mouse movement, clicks, scrolling, IP address, device and browser information. Text you type is masked |
We keep this list current. If we add or replace a subprocessor that handles customer data, we will update this page, and where the change is material we will tell customers by email or in the app before it takes effect, so you have a chance to object.
We may also disclose information if we are legally required to, or to protect our rights, users or the public. If our business is sold or merged, information may transfer as part of that transaction; we will tell you first.
Argento CRM can be connected to an AI assistant — such as Claude, or any tool that supports the Model Context Protocol — from Settings → MCP Server. This is entirely optional and off unless you turn it on.
Each person connects their own assistant under their own login, and the connection can only reach the workspaces that person already belongs to. Records you ask it about are sent to whichever assistant you chose, and from that point that provider's own privacy terms apply to what you send them. The connection can read, create and update records; it cannot delete anything, see a workspace you are not a member of, or change users, roles or billing. You can revoke it at any time from the same screen, which takes effect immediately.
We are not a party to your relationship with that assistant's provider. If you handle sensitive personal data in your CRM, check that provider's terms before connecting.
The Service is hosted in the United States (Supabase, US East). If you use it from outside the US, you are sending your information to the US, where privacy laws differ from those in your country.
If you are in the UK, EU, EEA or Switzerland and the GDPR applies to you, transfers to us rely on the Standard Contractual Clauses approved by the European Commission, together with the UK Addendum where relevant. Our infrastructure and payment providers maintain their own transfer mechanisms, including certification under the EU–US Data Privacy Framework where applicable.
For customer data we act as your processor. If your own compliance obligations require a signed Data Processing Agreement under Article 28 of the GDPR — including the Standard Contractual Clauses and our current subprocessor list — email info@argentocrm.com and we will put one in place at no charge.
We are a small company and do not currently hold SOC 2 or ISO 27001 certification. We would rather say so plainly than imply otherwise: section 7 describes the specific controls we do operate, so you can judge them for yourself.
Data is encrypted in transit with TLS and at rest by our hosting provider. Access to your workspace is enforced in the database itself through row-level security, so records are separated by workspace rather than only by application code. Passwords are stored hashed. Payment card data never reaches our systems.
Backups are taken on a rolling basis by our hosting provider and are retained for up to 30 days. Because of this, deleted data may persist in a backup for a short period after it disappears from the Service; it is not restored to your workspace and expires with the backup.
No service can promise perfect security. If a breach affects your personal information, we will notify you without undue delay and within 72 hours of becoming aware of it where the GDPR applies, and any regulator as the law requires. If we are your processor, we will tell you promptly so you can meet your own notification duties.
You can, at any time:
Depending on where you live — for example under the GDPR in the UK and EU, or the CCPA/CPRA in California — you may also have rights to object to or restrict processing, to data portability, and to complain to your data protection authority. California residents have the right not to be discriminated against for exercising these rights; we do not sell or share personal information as those laws define it.
To exercise any of these, email info@argentocrm.com. We will verify your identity before acting and respond within the time the law allows.
If you are one of our customer's contacts and want your details changed or removed, please contact that business directly — they control that data, and we act on their instructions.
We use four kinds of cookies and browser storage, and they are worth separating: what the app needs to work, what measures our website, what measures our advertising, and what records how people use the site. Only the first runs inside the CRM itself — the other three are limited to our public marketing pages.
A session cookie or token to keep you signed in, and local browser storage for preferences such as your current workspace and a local cache of your own records so the app loads quickly. Clearing these signs you out. The app itself does not run advertising or cross-site tracking cookies.
Our marketing pages at argentocrm.com use
Google Analytics 4 (measurement ID G-LM0Z2JDDJ4). It sets
first-party cookies, typically named _ga and
_ga_<container>, which are used to tell one visit from another,
measure which pages and referral sources are working, and count sign-ups. Google
Analytics also processes your IP address and general device and browser
information. Google's default retention for this data is 14 months.
We do not use Google Ads remarketing, and we do not enable Google Signals or ads personalisation.
You can opt out of Google Analytics in any of these ways, and nothing on our site stops working if you do:
Analytics runs on our public marketing pages, not inside your workspace. We do not load Google Analytics on app.argentocrm.com, so your day-to-day use of the CRM and the customer data inside it are not tracked by Google.
Our marketing pages also use the Meta Pixel (ID 2204318120351696), which is advertising technology rather than analytics. It tells us whether someone who clicked one of our Facebook or Instagram ads went on to visit the site, start a trial, or reach checkout, so we can measure whether our advertising works and show ads to people more likely to find Argento CRM useful.
The pixel sends Meta your IP address, browser and device information, the pages you
viewed on our site, and whether you began a signup. It sets cookies (typically
_fbp) and may match this activity to your Facebook or Instagram account
if you have one. Meta acts as an independent controller for this data and processes
it under its own terms.
Under California and several other US state privacy laws, this counts as “sharing” personal information for cross-context behavioural advertising. We do not sell personal information for money.
You can opt out. Any of these work, and nothing on our site breaks if you do:
The pixel runs on our public marketing pages only. It is not loaded on app.argentocrm.com, so your CRM records, your customers’ data and your day-to-day use of the product are never sent to Meta.
Our marketing pages use Microsoft Clarity (project ID y9mm6x4qda). This is different in kind from the analytics above and we want to be plain about it: Clarity records your session. It captures the pages you view, where you move your mouse, what you click and tap, how far you scroll, and how long you stay — and reconstructs that as a playback we can watch, along with aggregate heatmaps.
We use it for one purpose: working out where our website confuses people so we can fix it. We are a small company and this is the most direct way we have of seeing which parts of the site do not make sense.
Microsoft acts as our processor for this and also uses the data in accordance with its own privacy statement. Recordings are retained for up to 30 days.
What it does not capture. Clarity masks text input by default, so what you type into a form — including passwords, email addresses and any message — is not recorded. We have not turned that masking off, and we do not use Clarity to identify individual visitors.
You can opt out in any of these ways:
Like the analytics and advertising tools above, Clarity runs on our public marketing pages only. It is not loaded on app.argentocrm.com, so your work inside the CRM — and your customers’ data — is never recorded.
The Service is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
If we make a material change we will update the date above and, where the change significantly affects you, notify you by email or in the app before it takes effect.
Argento Solutions, LLC
Email: info@argentocrm.com