Skip to content
FiggyCRM

Legal

Privacy Policy

Last updated: August 21, 2026

FIGGYCRM, LLC (“FiggyCRM,” “we,” “us,” or “our”) is a Connecticut limited liability company with its principal place of business in Wallingford, Connecticut. This policy explains what personal information we handle, why, and what choices you have.

Questions: hello@figgycrm.com.

Two kinds of data, two different roles

This distinction matters, so we will start with it.

Your account data

Information about you and the people on your team who use FiggyCRM: names, email addresses, billing details, and how you use the product. We decide how this is handled, which makes us the controller. This policy covers it.

Your workspace data

The contacts, deals, projects, tasks, notes, and files you store in FiggyCRM. This is your data about your own clients and contacts. You decide what goes in and what happens to it. You are the controller; we are the processor, and we handle it only on your instructions. Our Data Processing Agreement governs it.

If you are someone whose details appear in a FiggyCRM workspace because a business you deal with put them there, we cannot help you directly. Contact that business. If you reach us instead, we will forward your request to them.

What we collect

You give us

  • Name and email address, when you create an account
  • Workspace and company name
  • Billing information, which goes to Stripe. Card numbers never reach our servers.
  • Anything you send us in a support email

We collect automatically

  • Standard server logs from hosting: IP address, browser type, date and time of access, pages requested. Used to operate and secure the Service.
  • Aggregate website analytics through Simple Analytics, which sets no cookies, stores nothing on your device, collects no personal data, and does not track you across sites.
  • Application errors through Sentry, configured to scrub personal information before it is stored.

We do not collect: social media profile data, advertising identifiers, cross-site tracking data, or location data beyond what an IP address implies.

Cookies

This website sets no cookies. No first-party cookies, no third-party cookies, no pixels, no local storage.

The application at app.figgycrm.com uses strictly necessary cookies to keep you signed in and secure your session. These are required for the product to work and are not used for advertising or tracking. Payment pages served by Stripe may set cookies necessary to process payments.

See our Cookie Policy for detail.

Why we use your account data

  • To create and run your account
  • To bill you and process refunds
  • To answer your support requests
  • To send service messages: security notices, billing problems, material changes to this policy or our Terms of Service
  • To secure the Service and investigate abuse
  • To meet legal obligations

If you have opted in, we may send product updates. Every one has an unsubscribe link. Service messages are not optional while you have an account.

Under GDPR terms, our legal bases are performance of a contract, our legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where you have given it.

What we do not do

We do not sell your personal information. We do not share it for cross-context behavioral advertising. We do not use third-party advertising networks or targeted advertising anywhere on this site or in the product.

We do not use your workspace data for our own purposes: not for advertising, not for profiling, and not to train machine learning models.

We may produce aggregate, de-identified statistics about how the Service is used. These contain no personal data and we do not attempt to re-identify them.

Who we share account data with

Only the service providers we need to run FiggyCRM:

ProviderPurposeLocation
SupabaseDatabase, authentication, file storageUnited States
VercelWebsite and application hostingUnited States
Amazon Web ServicesInfrastructure underlying SupabaseUnited States
StripePayment processingUnited States
ResendTransactional emailUnited States
SentryError monitoringUnited States

Each is bound by a data processing agreement. The same list applies to workspace data and appears in Annex III of our DPA.

Beyond those, we share personal information only:

  • When the law requires it: a valid subpoena, court order, or legal process. Where we are permitted to tell you, we will.
  • To protect rights and safety, including investigating fraud or abuse of the Service.
  • With your consent.

If FiggyCRM is acquired or merges, personal information may transfer to the acquiring entity. We will give you notice. The successor will remain bound by this policy for information collected under it until it provides you notice of a material change, at which point you may delete your account before the change takes effect.

How long we keep it

Account data lives as long as your account does. Delete your account and it goes, except where we must keep records, such as tax and payment records, for the period the law requires.

Workspace data follows the deletion terms in our Terms of Service and DPA: removed from the live Service immediately on deletion, with copies persisting in routine encrypted backups for up to 30 days before being overwritten in the ordinary course.

Retention periods by system:

  • Hosting (Vercel Pro): runtime logs, 1 day
  • Database (Supabase Pro): server and auth logs, 7 days; vendor backups, 7 days
  • Application backups (FiggyCRM): 30 days per workspace
  • Error reporting (Sentry): 30 days
  • Customer data: retained until the customer deletes it or their account

Your rights

Depending on where you live, you may have the right to:

  • Get a copy of the personal information we hold about you
  • Correct information that is wrong
  • Delete your information
  • Receive it in a portable, machine-readable format
  • Object to or restrict certain processing
  • Withdraw consent you previously gave
  • Not be discriminated against for exercising any of these

Email hello@figgycrm.com. We respond within the time the applicable law requires (30 days under GDPR, 45 days under the CCPA), and we may need to verify your identity first. There is no charge, unless a request is manifestly unfounded or excessive, in which case we will tell you before doing anything.

Most of this you can do yourself: export and delete workspace data from Settings, and delete your account without contacting us.

California residents

We do not sell or share personal information as the CCPA defines those terms, and we have not in the preceding twelve months. We do not knowingly collect or sell the personal information of anyone under 16. You may exercise CCPA rights at the address above, and you may use an authorized agent.

EEA, UK, and Swiss residents

You may complain to your local supervisory authority. We would rather you contact us first so we can put it right.

Connecticut residents

The Connecticut Data Privacy Act gives you rights similar to those above, including the right to appeal a refused request. To appeal, reply to our response and say so. We will respond within 60 days, and if we deny the appeal we will tell you how to contact the Connecticut Attorney General.

International transfers

Our servers are in the United States. If you use FiggyCRM from outside the US, your information is transferred here.

For workspace data subject to GDPR or UK GDPR, the transfer mechanisms in Section 11 of our DPA apply. For account data, we rely on the same protections.

Security

We describe our technical and organizational measures on our Security page and in Annex II of our DPA. In summary: encryption in transit and at rest, workspace isolation enforced at the database level, two-factor authentication available to all users and enforced for administrative accounts, daily backups, and payment data handled entirely by Stripe.

No system is perfectly secure, and we cannot guarantee that information transmitted over the internet is immune from interception.

If a breach affects your personal information, we will notify you without undue delay and as applicable law requires, and we will notify regulators where required.

Children

FiggyCRM is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, email us and we will delete it.

Sensitive information does not belong here

Our Terms of Service prohibit storing special categories of personal data in FiggyCRM: health and medical information, biometric or genetic data, and data revealing racial or ethnic origin, religious beliefs, or sexual orientation. We are not built for regulated data, we do not sign HIPAA business associate agreements, and we are not a consumer reporting agency under the Fair Credit Reporting Act.

Changes

We may update this policy. If a change materially affects your rights, we will give you at least 30 days' notice by email or in the product before it takes effect. Other changes take effect when posted, and the date at the top tells you when we last changed anything.

Contact

hello@figgycrm.com, or FIGGYCRM, LLC, Wallingford, Connecticut.

Security issues: security@figgycrm.com.

See also our Terms of Service, Data Processing Agreement, Cookie Policy, and Security page.