Who we are and what this covers
Two kinds of data: yours and your organization’s
Data we control. Your account details, billing information, support conversations and website interactions. For this data, we decide how it is handled, and this policy is the full story. Data your organization controls. Everything inside a workspace: the constituents, voters, donors and volunteers your organization stores, plus notes, donations, form submissions and synced email. Here the organization is the data controller and we are its service provider; we process this data only on the organization’s instructions and never for our own purposes.
What we collect about account holders
Identity and sign-in. Your name, email address and password. Passwords are stored only as an argon2id hash; nobody at pplCRM can see them. If you enable passkeys or two-factor codes, we store the public credential or a hashed one-time code, never a usable secret. Session security data. The IP address and browser signature of your active sessions. We keep these so we can show you where you are signed in and challenge sign-ins from a new device or location. Billing. Paid plans are billed through Stripe. Stripe collects your card details and billing address directly; card numbers never touch our servers. We keep your plan, invoices and billing contact. Phone number. Only if you provide one, for example to verify sending. Every workspace verifies a mobile number once before its first newsletter. Verification codes are sent by SMS and stored hashed. Support. Emails you send to [email protected], so we can answer them and improve the product.
Data your organization stores in its workspace
Addresses and maps. Household addresses can be geocoded so they appear on maps and turfs. Geocoding sends the street address to the Google Maps Geocoding API and stores the resulting coordinates. Volunteer locations during canvassing. While a volunteer walks a turf with the Canvass Companion, the app reports their position to their organization about once a minute, behind a banner on their phone that says so for the whole shift. Positions are visible only to the organization’s admins — never to other volunteers — and are deleted at midnight; only the day’s totals survive (when the shift ran, doors knocked, distance walked). An organization can restrict this to turf-level presence with no coordinates at all, and a volunteer who declines the browser’s location permission can still canvass. Synced mailboxes. If a workspace admin connects Gmail or Microsoft 365, we sync email content into the workspace so conversations sit next to the people they belong to. We take as little as does the job: syncing starts from the last 48 hours — we do not import your mail archive — and attachments are not copied to our servers unless someone opens them, apart from small inline images. Attachments on messages your provider marked as spam are never copied at all. The OAuth tokens for these connections are encrypted at rest with AES-256-GCM, and you can disconnect at any time. Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Newsletter engagement. When an organization sends a newsletter, delivery and engagement events (bounces, unsubscribes, opens and clicks) are recorded so the sender can respect them. Uploaded files. Imports and attachments are stored in Canada with the rest of your workspace data.
Public forms, donations, events, volunteer links and giving pages
How we use personal information
To run the service: signing you in, storing and displaying your workspace, sending the emails and SMS messages you ask it to send. To bill you and send you invoices, receipts and important account notices. To keep the platform safe: rate limiting, new-device challenges, and the sending guards that pause senders whose mail bounces or draws complaints. To answer support requests, using the minimum data needed to help. To comply with the law when we genuinely must, and we will tell you when the law allows it.
What we never do
We never sell, share, rent or trade personal information, yours or your organization’s. To anyone. We never use workspace data for advertising, profiling, or building products for other customers, and we do not use it to train machine-learning models. We run no third-party analytics, advertising pixels or fingerprinting scripts on the website or in the product. We never read workspace content out of curiosity. Access by our team is limited to what a specific support request or safety issue requires.
Service providers we rely on
Microsoft Azure. Hosts the application, database and file storage in Canada. Cloudflare. Serves the marketing site and the public form, donation and companion pages at the network edge. Stripe. Subscription billing, tax calculation, and card donation processing. Stripe stores payment and donor data in the United States. Postmark. Delivers transactional email such as verification links, security codes and account notices. SendGrid. Delivers newsletters and automation emails from your organization’s own verified domain and reports delivery and engagement events. Twilio. Sends SMS one-time codes for volunteer verification and sending verification. Anthropic. Powers the newsletter deliverability check’s AI content review. It receives only the draft being checked (subject, body text and link list) when a check runs — never your contact lists — and under our agreement the content is not used to train models. Sentry. Collects error reports from our backend servers when something breaks, so we can fix it. Reports contain the technical failure details (the error, where in our code it happened, which background job or request type failed) with sign-in cookies, credentials and request bodies stripped before sending — never your contact lists or workspace records. Sentry stores these reports in the United States. Nothing from Sentry runs in your browser. Google Maps. Geocodes household addresses and renders maps. Google and Microsoft. Mailbox sync, only for workspaces that connect them. Zapier. Only if your organization creates an integration; data flows are defined by the workflows you build.
Where your data lives
Retention and deletion
Records you delete are removed from the live database immediately. Automated backups expire within 7 days, at which point deleted data is gone from those too. Workspace deletion can be scheduled by an organization admin. After a 30-day grace window (cancelable at any time), every record in the workspace is permanently deleted, and we confirm by email when it is done. Login deletion (deleting an individual user account) permanently removes the person's email address, name, password and sign-in credentials after the same 30-day cancelable window. Work they contributed inside a workspace (records, notes, activity history) belongs to that organization and stays in its workspace, attributed to “Deleted user”. Activity logs are kept for 90 days, then pruned automatically. Synced mail you archive or move out of a synced folder in your own mail client is hidden from the CRM but kept, so any comments, assignment or triage status your team added to it survive. If nobody ever commented on it, assigned it, starred it or closed it, the copy is deleted 90 days later. Synced mail after a move to the Free plan. The shared inbox is a paid feature. When a workspace moves to the Free plan, mailbox sync stops and its synced email is kept for 30 days, then permanently deleted along with the mailbox connection. Upgrading within those 30 days restores the inbox intact; the originals always remain in your own Gmail or Microsoft mailbox. Export files are downloadable for 30 days, then removed. Import source files are kept for 90 days so you can audit an import, then removed. Donation receipts and giving statements (the PDF documents) are kept for as long as the workspace exists — receipt rules require even cancelled receipts to be retained — and count toward the workspace storage quota. They are permanently deleted with the workspace. Sessions expire after 24 hours, or 30 days if you chose “remember me”. Volunteer device sessions expire after 30 days. Donor giving-page links expire 365 days after they are sent and are stored hashed. An organization can revoke a donor’s links at any time; expired and revoked link records are purged 90 days later. Suppression records (unsubscribes, bounces, complaints) are kept while a workspace is active, because keeping them is what honors the opt-out. Billing records are kept as long as tax and accounting law requires.
How we protect it
Cookies
pc_refresh. Keeps you signed in to the app. HttpOnly and secure, so scripts cannot read it. pc_signed_in. A yes/no flag that lets this website show “Dashboard” instead of “Log in” when you already have a session. It contains no personal data.
Your rights
If you are in one of our customers’ lists
Children
Changes to this policy
Contact
Questions about this document?
Write to [email protected] and a human replies. We are happy to walk through any of it.
