Legal

Privacy Policy

Effective July 10, 2026·Last updated July 10, 2026

Introduction

CRM Leaderboards, accessible at https://crmleaderboards.com, is a sales leaderboard application that connects to your Pipedrive CRM to display goals and standings for your team. This Privacy Policy describes what personal data we collect, why we collect it, how we use and protect it, and the rights and choices you have.

This policy covers the CRM Leaderboards website and application. It does not cover Pipedrive itself or any other third-party service that links to or from our Service, each of which is governed by its own privacy policy.

By accessing or using CRM Leaderboards, you acknowledge that you have read and agree to this Privacy Policy. Questions or requests may be sent to support@crmleaderboards.com.

Definitions

  • Personal Data: Any information relating to an identified or identifiable person, including name, email, IP address, and online identifiers.
  • Processing: Any operation on personal data, including collection, storage, use, transfer, and deletion.
  • Data Controller: Good Software Company, which determines the purposes and means of processing personal data on CRM Leaderboards.
  • CRM Data: Data we read from your connected Pipedrive account on your behalf to render leaderboards; see “Data From Your Pipedrive Account” below.
  • You / User: Any individual accessing or using CRM Leaderboards.

Information We Collect

1. Account & Sign-In Data

You sign in to CRM Leaderboards exclusively through Pipedrive OAuth. We do not offer password-based accounts and we never receive or store a password. From the Pipedrive sign-in we receive and store:

  • Your name, email address, and profile image
  • Your Pipedrive user and company identifiers
  • Your Pipedrive account time zone (used for goal-period math)
  • OAuth access and refresh tokens, which are encrypted at rest and used only to read your CRM data and to create and manage goals on your behalf

2. Data From Your Pipedrive Account (CRM Data)

With your authorization, we read the following from Pipedrive to build and update your leaderboards, and we create, update, and delete goals in your Pipedrive account when you create or edit them through the Service. We do not otherwise modify your CRM records:

  • Goals and aggregate goal progress (results for the selected periods). Progress is read as totals; we do not read the underlying deal or activity records themselves.
  • Pipeline, stage, activity-type, and currency metadata used to define and measure goals
  • The names and email addresses of the Pipedrive users you add to a board or import as team members, so they can be shown and counted as participants

Historic standings are captured as periodic snapshots so past periods remain viewable after they close.

To keep boards current, we register a webhook in your Pipedrive account. Pipedrive then notifies us when relevant data changes so standings refresh in real time. The notification is a change signal only; we re-read the data from Pipedrive rather than trusting the notification’s contents.

3. Billing Data

  • Subscription and seat information, and a Stripe customer identifier. Payments are handled by Stripe; we never receive or store full payment card numbers.

4. Automatically Collected Data

  • IP address, browser type and version, operating system, and device type
  • Pages visited, time and date of visit, duration, and referring URL (product analytics)
  • Session metadata (a session token, IP address, and user agent) used to keep you signed in securely
  • Application and server logs used for debugging and security

How We Use Your Information

PurposeExamplesLegal Basis (GDPR)
Service DeliveryReading your Pipedrive data to render leaderboards; creating and managing goals in Pipedrive at your request; registering a webhook so boards update in real time; maintaining your account and organization; responding to support requests, including live chat (Tawk.to)Contract
BillingProcessing subscriptions, seats, trials, and renewals via StripeContract
Transactional EmailWelcome messages and organization invitations sent via ResendContract / Legitimate Interests
Analytics & ImprovementUnderstanding in-app usage patterns and improving features (PostHog, in-browser)Consent
Service Lifecycle EventsRecording a small number of server-side milestones (account sign-up, CRM connection, and organization creation) in PostHog to measure activation and keep operational counts accurateLegitimate Interests
Security, Logging & ReliabilityError monitoring (Sentry), application logs (Axiom), and abuse preventionLegitimate Interests
Legal ComplianceMeeting tax, accounting, and regulatory obligationsLegal Obligation

Cookies and Similar Technologies

CRM Leaderboards uses a small number of cookies and browser storage keys. We do not use advertising or cross-site tracking cookies.

CategoryPurposeExamplesDuration
Strictly NecessaryAuthentication, session management, and CSRF protection. Cannot be disabled.Sign-in session cookie, cached-session cookieSession / up to 5 minutes (session cache)
Functional / PreferenceRemembering settings such as theme and language.Theme preference and cookie-consent choice (browser local storage); language preference (cookie)Local storage: until cleared / language cookie: browser session
AnalyticsProduct usage measurement (PostHog). Only enabled after you accept analytics via the consent banner.PostHog identifiersUp to 1 year
Support ChatLive-chat session continuity (Tawk.to). Set only if you open the chat widget; nothing loads before that.Tawk.to session and visitor cookiesSession / up to 6 months

Cookie Consent: On your first visit you are shown a consent banner. Until you accept, analytics run without setting cookies (in-memory only) and you may decline entirely. Your choice is stored and honored on subsequent visits, and you can change it by clearing the stored preference in your browser.

Analytics

We use PostHog for product analytics to understand how the application is used and to improve it. Analytics requests are routed through a first-party reverse proxy on our own domain. PostHog data is processed on PostHog Cloud (United States). In-browser analytics capture is enabled only where you have accepted it via the cookie consent banner; if you decline, product analytics are opted out.

Separately from in-browser analytics, our servers record a small number of lifecycle events directly in PostHog: account sign-up (with your name and email), CRM connection, and organization creation. These server-side events set no cookies in your browser and are not governed by the cookie banner; we process them under our legitimate interest in measuring activation and keeping operational counts accurate. You may object at any time via support@crmleaderboards.com.

Support Chat

In-app support chat is provided by Tawk.to. The chat widget is not loaded when a page opens; it loads only when you click the support chat button. Once opened, Tawk.to receives your IP address, the messages you send, and any contact details you choose to provide, and sets its own cookies to keep the conversation continuous. If you prefer not to use the chat, you can contact us by email at support@crmleaderboards.com instead.

Authentication

Sign-in is provided solely through Pipedrive OAuth. We receive only the profile data Pipedrive shares (name, email, identifier, company, time zone) and the OAuth tokens required to read your CRM data, create and manage goals on your behalf, and register a webhook for real-time updates. We never receive your Pipedrive password. OAuth tokens are encrypted at rest. You can revoke our access at any time from your Pipedrive account settings (Marketplace / connected apps), which stops all future access.

Payments

Payments and subscriptions are processed by Stripe, a PCI-DSS Level 1 certified processor. We do not store, transmit, or access full payment card numbers; card data is tokenized by Stripe. We retain subscription and invoice metadata for accounting and tax purposes.

Third-Party Subprocessors

We rely on the following subprocessors to operate the Service. Each accesses personal data only as necessary to perform its function and is bound by a Data Processing Agreement.

SubprocessorPurposeData Involved
PipedriveCRM data source and sign-in providerProfile data and the CRM records used to render boards
StripePayment and subscription processingBilling contact and tokenized payment methods
ResendTransactional email deliveryName and email address
PostHogProduct analyticsUsage events, IP address, and identifiers
SentryError monitoringError diagnostics, which may include IP address or user id
AxiomApplication loggingRequest and event logs, which may include IP address
AblyRealtime board-update signalsNo personal data (a board-changed notification only)
Tawk.toLive chat support (loads only when you open the chat)Chat messages, IP address, and any name or email you provide in the chat
VercelApplication hosting and computeAll request data in transit
SupabaseDatabase hosting (PostgreSQL)All personal data we store at rest

We will update this list before adding or replacing a subprocessor that processes personal data.

How We Share Your Information

We do not sell your personal information. Data is shared only in these limited circumstances:

  • Subprocessors: As listed above, under contract and only on our instructions.
  • Within Your Organization: Leaderboard standings, including participant names and progress, are visible to other members of your organization, and to anyone holding a public share link you create.
  • Legal Requirements: Where required by law, regulation, subpoena, or court order.
  • Business Transfers: In a merger, acquisition, or asset sale, with notice where feasible.
  • With Your Consent: For any other purpose with your explicit prior consent.

Public Share Links: You can generate an unguessable link that displays a board on a TV or shared screen without sign-in. Anyone with the link can view that board’s standings until you delete the link. Only share it with people you intend to see the data.

Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • HTTPS/TLS encryption for all data in transit
  • Encryption at rest of stored Pipedrive OAuth tokens
  • OAuth-only authentication; we store no user passwords
  • Access controls limiting data access to authorized personnel
  • Error monitoring and application logging for anomaly detection

In the event of a personal data breach likely to result in a risk to your rights, we will notify affected individuals and the relevant supervisory authority within the legally mandated timeframe (e.g. 72 hours under GDPR).

Data Retention

Data TypeRetention PeriodReason
Account, organization, and board dataLife of the account; deleted or anonymized after closureService delivery
Pipedrive OAuth tokensUntil you disconnect or delete the accountRequired to read CRM data on your behalf
Leaderboard snapshotsLife of the account (or until the board is deleted)Historic standings
Analytics dataAs configured in PostHogTrend analysis
Application and server logsUp to 90 daysSecurity and debugging
Billing and transaction recordsUp to 7 yearsTax and accounting compliance

When you disconnect (uninstall) the app in Pipedrive, we revoke and clear the stored OAuth tokens and schedule your subscription to cancel at the end of the current billing period. Your account and organization data are retained so that reconnecting later restores your boards. To request full erasure of your remaining personal data, contact support@crmleaderboards.com.

Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or transfer your personal data, and to withdraw consent. Exercise these rights by contacting support@crmleaderboards.com. We will respond within the timeframe required by applicable law, and you will never be penalized for exercising your rights.

GDPR: European Union & UK Data Protection Rights

If you are in the EU/EEA or the UK, you have the following rights under the GDPR / UK GDPR:

  • Access (Art. 15): Obtain a copy of the personal data we hold and information about how it is processed.
  • Rectification (Art. 16): Correct inaccurate or incomplete data.
  • Erasure (Art. 17): Request deletion of your data, subject to legal retention obligations.
  • Restriction (Art. 18): Request that we temporarily halt processing in certain circumstances.
  • Portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Object (Art. 21): Object to processing based on legitimate interests.
  • Withdraw Consent (Art. 7(3)): Withdraw consent at any time where processing relies on it, without affecting prior lawful processing.

Legal Bases: Art. 6(1)(a) Consent; Art. 6(1)(b) Contract; Art. 6(1)(c) Legal obligation; Art. 6(1)(f) Legitimate interests.

International Transfers: Where personal data is transferred outside the EEA/UK, we rely on EU Standard Contractual Clauses, the UK International Data Transfer Agreement/Addendum, or other lawful transfer mechanisms.

You may lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office, ico.org.uk).

CCPA / CPRA: California Privacy Rights

California residents may request to know, delete, or correct their personal information, and to opt out of its sale or sharing. We do not sell or share personal information for cross-context behavioral advertising. Submit requests to support@crmleaderboards.com. We will not discriminate against you for exercising these rights. Residents of other US states with comparable laws (Virginia, Colorado, Connecticut, Texas, Oregon, and others) may exercise equivalent rights the same way.

Children’s Privacy

CRM Leaderboards is a business tool not directed to children. The Service is intended for users who are at least 18 years of age, and we do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us data, contact support@crmleaderboards.com and we will delete it.

Changes to This Privacy Policy

We may update this Privacy Policy periodically. Material changes will be reflected in the “Last Updated” date above and, where appropriate, communicated by a notice on the Service or by email. Continued use after changes take effect constitutes acceptance of the revised policy.

Contact Us