Privacy Policy

Last updated: 28 August 2026

This policy explains what Argento Solutions, LLC (“Argento”, “we”, “us”) collects when you use Argento CRM at argentocrm.com and app.argentocrm.com (the “Service”), why we collect it, who we share it with, and what you can ask us to do about it.

1. Two different kinds of data

This distinction matters throughout, so it comes first.

You control customer data. We process it on your instructions to provide the Service, and we do not sell it, mine it to build profiles, or use it to train machine learning models. Where privacy law uses the terms, you are the controller of customer data and we are the processor. For account data, we are the controller.

2. What we collect

CategoryExamplesWhy
Account Name, email, hashed password, display name, workspace and role Create your account, sign you in, and control who sees what
Billing Plan, subscription status, trial and renewal dates, invoice history, the last four digits and expiry of your card Take payment and manage your subscription
Customer data Whatever you enter or upload into your workspace Provide the Service to you
Usage Record and storage counts, feature usage, timestamps Enforce plan limits, show usage meters, keep the Service running
Technical IP address, browser type, log and error data Security, abuse prevention and debugging
Enquiries What you send through our contact form Reply to you
We never see your full card number. Card details are entered directly with Stripe and never touch our servers. We receive only a token, the card brand, its last four digits and expiry date.

3. How we use it

We do not sell personal information, and we do not share it with third parties for their own advertising.

4. Who we share it with

We use a small number of subprocessors to run the Service. Each is bound by contract to protect the data and use it only to provide their service to us.

ProviderPurposeData
SupabaseDatabase, authentication, file storage and serverless functionsAccount data, customer data, usage and technical data
StripePayment processing and subscription billingName, email, billing details, card tokens
HostingerWebsite hosting for argentocrm.com and app.argentocrm.comTechnical and log data
EmailitOutbound email delivery — reminders, password resets, billing noticesRecipient address, subject and message content, delivery status
Microsoft 365Our own business mailbox, which receives your enquiries and repliesAnything you email us
Google AnalyticsVisitor measurement on our public marketing pages only — see section 9Page views, referrer, IP address, device and browser information
Meta (Facebook/Instagram)Advertising measurement on our public marketing pages only — see section 9. Not loaded inside the CRMPage views, signup and checkout events, IP address, device and browser information
Microsoft ClaritySession recording and heatmaps on our public marketing pages only — see section 9. Not loaded inside the CRMPages viewed, mouse movement, clicks, scrolling, IP address, device and browser information. Text you type is masked

We keep this list current. If we add or replace a subprocessor that handles customer data, we will update this page, and where the change is material we will tell customers by email or in the app before it takes effect, so you have a chance to object.

We may also disclose information if we are legally required to, or to protect our rights, users or the public. If our business is sold or merged, information may transfer as part of that transaction; we will tell you first.

If you connect an AI assistant

Argento CRM can be connected to an AI assistant — such as Claude, or any tool that supports the Model Context Protocol — from Settings → MCP Server. This is entirely optional and off unless you turn it on.

Each person connects their own assistant under their own login, and the connection can only reach the workspaces that person already belongs to. Records you ask it about are sent to whichever assistant you chose, and from that point that provider's own privacy terms apply to what you send them. The connection can read, create and update records; it cannot delete anything, see a workspace you are not a member of, or change users, roles or billing. You can revoke it at any time from the same screen, which takes effect immediately.

We are not a party to your relationship with that assistant's provider. If you handle sensitive personal data in your CRM, check that provider's terms before connecting.

5. Where your data is held, and transfers

The Service is hosted in the United States (Supabase, US East). If you use it from outside the US, you are sending your information to the US, where privacy laws differ from those in your country.

If you are in the UK, EU, EEA or Switzerland and the GDPR applies to you, transfers to us rely on the Standard Contractual Clauses approved by the European Commission, together with the UK Addendum where relevant. Our infrastructure and payment providers maintain their own transfer mechanisms, including certification under the EU–US Data Privacy Framework where applicable.

Data Processing Agreement

For customer data we act as your processor. If your own compliance obligations require a signed Data Processing Agreement under Article 28 of the GDPR — including the Standard Contractual Clauses and our current subprocessor list — email info@argentocrm.com and we will put one in place at no charge.

We are a small company and do not currently hold SOC 2 or ISO 27001 certification. We would rather say so plainly than imply otherwise: section 7 describes the specific controls we do operate, so you can judge them for yourself.

6. How long we keep it

7. Security

Data is encrypted in transit with TLS and at rest by our hosting provider. Access to your workspace is enforced in the database itself through row-level security, so records are separated by workspace rather than only by application code. Passwords are stored hashed. Payment card data never reaches our systems.

Backups are taken on a rolling basis by our hosting provider and are retained for up to 30 days. Because of this, deleted data may persist in a backup for a short period after it disappears from the Service; it is not restored to your workspace and expires with the backup.

No service can promise perfect security. If a breach affects your personal information, we will notify you without undue delay and within 72 hours of becoming aware of it where the GDPR applies, and any regulator as the law requires. If we are your processor, we will tell you promptly so you can meet your own notification duties.

8. Your choices and rights

You can, at any time:

Depending on where you live — for example under the GDPR in the UK and EU, or the CCPA/CPRA in California — you may also have rights to object to or restrict processing, to data portability, and to complain to your data protection authority. California residents have the right not to be discriminated against for exercising these rights; we do not sell or share personal information as those laws define it.

To exercise any of these, email info@argentocrm.com. We will verify your identity before acting and respond within the time the law allows.

If you are one of our customer's contacts and want your details changed or removed, please contact that business directly — they control that data, and we act on their instructions.

9. Cookies and similar technologies

We use four kinds of cookies and browser storage, and they are worth separating: what the app needs to work, what measures our website, what measures our advertising, and what records how people use the site. Only the first runs inside the CRM itself — the other three are limited to our public marketing pages.

Strictly necessary — inside the app

A session cookie or token to keep you signed in, and local browser storage for preferences such as your current workspace and a local cache of your own records so the app loads quickly. Clearing these signs you out. The app itself does not run advertising or cross-site tracking cookies.

Analytics — on our public website

Our marketing pages at argentocrm.com use Google Analytics 4 (measurement ID G-LM0Z2JDDJ4). It sets first-party cookies, typically named _ga and _ga_<container>, which are used to tell one visit from another, measure which pages and referral sources are working, and count sign-ups. Google Analytics also processes your IP address and general device and browser information. Google's default retention for this data is 14 months.

We do not use Google Ads remarketing, and we do not enable Google Signals or ads personalisation.

You can opt out of Google Analytics in any of these ways, and nothing on our site stops working if you do:

Analytics runs on our public marketing pages, not inside your workspace. We do not load Google Analytics on app.argentocrm.com, so your day-to-day use of the CRM and the customer data inside it are not tracked by Google.

Advertising — on our public website

Our marketing pages also use the Meta Pixel (ID 2204318120351696), which is advertising technology rather than analytics. It tells us whether someone who clicked one of our Facebook or Instagram ads went on to visit the site, start a trial, or reach checkout, so we can measure whether our advertising works and show ads to people more likely to find Argento CRM useful.

The pixel sends Meta your IP address, browser and device information, the pages you viewed on our site, and whether you began a signup. It sets cookies (typically _fbp) and may match this activity to your Facebook or Instagram account if you have one. Meta acts as an independent controller for this data and processes it under its own terms.

Under California and several other US state privacy laws, this counts as “sharing” personal information for cross-context behavioural advertising. We do not sell personal information for money.

You can opt out. Any of these work, and nothing on our site breaks if you do:

The pixel runs on our public marketing pages only. It is not loaded on app.argentocrm.com, so your CRM records, your customers’ data and your day-to-day use of the product are never sent to Meta.

Session recording — on our public website

Our marketing pages use Microsoft Clarity (project ID y9mm6x4qda). This is different in kind from the analytics above and we want to be plain about it: Clarity records your session. It captures the pages you view, where you move your mouse, what you click and tap, how far you scroll, and how long you stay — and reconstructs that as a playback we can watch, along with aggregate heatmaps.

We use it for one purpose: working out where our website confuses people so we can fix it. We are a small company and this is the most direct way we have of seeing which parts of the site do not make sense.

Microsoft acts as our processor for this and also uses the data in accordance with its own privacy statement. Recordings are retained for up to 30 days.

What it does not capture. Clarity masks text input by default, so what you type into a form — including passwords, email addresses and any message — is not recorded. We have not turned that masking off, and we do not use Clarity to identify individual visitors.

You can opt out in any of these ways:

Like the analytics and advertising tools above, Clarity runs on our public marketing pages only. It is not loaded on app.argentocrm.com, so your work inside the CRM — and your customers’ data — is never recorded.

10. Children

The Service is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.

11. Changes to this policy

If we make a material change we will update the date above and, where the change significantly affects you, notify you by email or in the app before it takes effect.

12. Contact

Argento Solutions, LLC
Email: info@argentocrm.com