Legal
Privacy Policy
How Saintcode collects, uses, stores, and protects information when you use SaintCRM, including admin access, customer accounts, and connected social and email integrations.
Last updated: June 18, 2026
Overview
This Privacy Policy describes how Saintcode (“we”, “us”, “our”) collects, uses, and protects information when you use SaintCRM, including the public website, customer dashboard, and admin application at crm.saintcode.com and related subdomains (the “Service”).
SaintCRM is a business CRM platform operated by Saintcode. By using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.
Who this policy applies to
We process information for different types of users:
- Saintcode staff and authorized administrators who access the private admin CRM.
- Customer account owners and team members who use the customer dashboard (when enabled).
- Visitors to public pages such as the product overview, features, login, and signup previews.
- Businesses whose data is stored in the CRM by our customers (your end customers and contacts).
Information we collect
Depending on how you use the Service, we may collect:
- Account and profile data: name, email address, workspace or business name, role, and authentication identifiers.
- CRM content you or your team enter: customers, contacts, leads, deals, activities, quotes, invoices, email content, notes, and uploaded files.
- Connected integration data: when you connect third-party services (for example social media, email, or advertising platforms), we receive OAuth tokens, account identifiers, and data those platforms provide according to the permissions you grant.
- Usage and technical data: IP address, browser type, device information, pages viewed, timestamps, and diagnostic logs needed to operate and secure the Service.
- Communications: support requests and messages you send to us.
How we use information
We use information to:
- Provide, maintain, and improve the Service.
- Authenticate users and enforce access controls within workspaces and business profiles.
- Process CRM workflows you configure: leads, email, quotes, invoicing, social publishing, and reporting.
- Send transactional notices related to the Service (for example security alerts or account messages).
- Monitor performance, prevent abuse, and protect the security of the Service.
- Comply with law and respond to lawful requests.
Legal bases (where applicable)
If you are in the European Economic Area, United Kingdom, or similar jurisdictions, we rely on one or more of the following legal bases: performance of a contract with you or your organization; legitimate interests in operating and securing the Service; compliance with legal obligations; and consent where required (for example optional marketing or certain integrations).
Data retention
We retain information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. CRM records you create remain until you or an authorized admin deletes them or closes the account, subject to backup and audit retention windows.
OAuth tokens are retained while a connection remains active and for a limited period after disconnect for security and recovery purposes.
Security
We use administrative, technical, and organizational measures designed to protect information, including access controls, encrypted transport (HTTPS), and encrypted storage for sensitive integration tokens where implemented. No method of transmission or storage is completely secure; you are responsible for safeguarding your account credentials.
Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal information, or to object to certain processing. You may also withdraw consent where processing is consent-based.
Workspace administrators can manage many team and CRM records directly in the Service. For other requests, contact us at hello@saintcode.com. We may need to verify your identity before responding.
International transfers
We may process and store information in Canada and other countries where we or our service providers operate. Where required, we use appropriate safeguards for cross-border transfers.
Children
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may be communicated through the Service or by email where appropriate.
Contact
Saintcode — Privacy inquiries: hello@saintcode.com. Website: https://saintcode.com. CRM Service: https://crm.saintcode.com.
Questions? Contact hello@saintcode.com. See also Privacy Policy and Terms of Service.
Social media and OAuth connections
When you connect a social account (such as a Facebook Page, Instagram Business profile, or LinkedIn Company Page), you authorize SaintCRM through the platform’s OAuth flow. We store encrypted access tokens and related account metadata needed to schedule posts, read analytics, or manage inbox items you enable.
We access only the data and actions permitted by the scopes you approve in each platform’s consent screen. You can disconnect an integration from your brand settings; disconnecting stops new API access and removes or invalidates stored tokens according to our retention practices.
Social platforms are independent controllers or processors of data they hold. Their use of your data is also governed by their own policies (for example Meta, LinkedIn, Google, or TikTok).