Legal
Privacy policy
How we handle personal data when you visit our website, use MagpieCRM Cloud, or turn up in a MagpieCRM customer's prospect search.
Last updated 27 September 2026
Who we are
MagpieCRM is run by Mr PNA Greenall, trading as MagpieCRM, of 35a Highbury Corner, London N5 1RA ("we", "us"). For the personal data described below, we are the controller. Contact us about anything on this page at pele@magpiecrm.com.
When our customers use MagpieCRM Cloud to hold contacts, find prospects and send email, they decide what happens to that data and we process it for them, under our data processing agreement. Their own privacy notices cover that. What we do for them is described under "People in our customers' workspaces" below.
Visiting our website
- We don't use analytics or advertising trackers, and we don't set cookies on magpiecrm.com. Your browser remembers your light or dark theme, and the last workspace name you signed in to, in its own storage; neither is sent to us.
- Our website is hosted by Cloudflare, which keeps short-lived technical logs (such as IP addresses) to deliver and protect it.
- Our pages load fonts from Google Fonts, so your browser's IP address is sent to Google when they load.
Using MagpieCRM Cloud
| What | Why | Lawful basis |
|---|---|---|
| Your name, email address and organisation, and your sign-in records | To create your account and let you sign in, through our sign-in provider, Kinde | Contract |
| Your billing details and payment history | To take payment, through Stripe. Your card details go to Stripe; we see only what we need, such as the last four digits and your invoices | Contract; legal obligation (keeping accounting records) |
| How much of your plan you use, and your sending volumes, bounce and complaint rates (as counts) | To apply your plan's limits, and to keep the sending service healthy for all customers | Contract; legitimate interests (protecting the Service) |
| Messages you send us | To answer them and help you | Contract; legitimate interests |
| Occasional emails about the Service: changes to terms or prices, security notices | To keep you informed about something you use | Contract; legitimate interests |
People in our customers' workspaces
MagpieCRM customers use prospect search to find people at businesses: name, job title, seniority, company, country and professional profile address, from a third-party data source, SocialFetch, which draws on public professional profiles. They can then find and check a work email address. Each customer is the controller of the people they find and contact, and must have a lawful basis and tell you where they got your details. We process that data for them and don't use it for anything else. Search results aren't stored or shared between customers.
If you don't want to be found or contacted through MagpieCRM, email pele@magpiecrm.com. We'll add you to the suppression list in every MagpieCRM Cloud workspace, so you won't be shown, revealed or saved from prospect search again, and any saved contact that matches you is deleted. The list holds only one-way keyed hashes of what you give us, so we can recognise you without storing your details. You can also unsubscribe from any customer's email with the link in it, and ask that customer directly for access to, or deletion of, your data.
Who we share data with
We use these providers to run MagpieCRM, each under a contract that protects your data:
- Contabo (Germany): our servers.
- OVH (France): the servers email verification connects from.
- Amazon Web Services (UK, London region): email delivery.
- Kinde (UK data region): sign-in.
- Stripe: payments.
- Cloudflare: our website and DNS.
- SocialFetch: prospect data.
- Zoho (EU): our own email.
- [Backup storage provider]: encrypted backups.
The full list for customer data, with locations and safeguards, is on our sub-processor list. We don't sell personal data, and we'll only share it otherwise when the law requires us to.
International transfers
Most of our providers keep data in the UK or EU. Where data goes elsewhere, such as to Stripe, Cloudflare or Google in the United States, it's protected by an adequacy decision, the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.
How long we keep it
- Your account details: while you're a customer, and for up to 12 months afterwards in case you come back.
- Billing records: 6 years after the end of the tax year they relate to, as UK law requires.
- Your workspace's data: deleted within 30 days after your subscription ends; encrypted backups within three months.
- Technical logs: only as long as they're needed for security, normally no more than 90 days.
- Opt-out hashes: kept indefinitely, so your choice lasts.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to move it to another service. Email pele@magpiecrm.com; we'll reply within a month. If you're not happy with how we've handled your data, you can complain to the Information Commissioner's Office at ico.org.uk, or to your local data protection authority.
Changes
If we change this policy in a way that matters, we'll tell customers by email before it takes effect. The date at the top shows when it last changed.