Legal
Privacy Policy
Effective date: 7 September 2026
The privacy of your data — and it is your data, not ours! — is a big deal to us. In this policy we lay out what we collect and why, how your data is handled, where it is stored, and your rights with respect to it. We promise we never sell your data: never have, never will.
This policy is the notification required by section 18 of the Protection of Personal Information Act 4 of 2013 (“POPIA”). The responsible party is Propagated Gradients (Pty) Ltd (reg. 2024/567783/07), trading as Pinion CRM, of 3 Macbeth Avenue, Witkoppen, Johannesburg, 2191, South Africa. Our Information Officer is Sholto Armstrong, reachable at privacy@pinioncrm.com or 072 139 5000.
Two roles: your data, and your clients' data
This policy covers the information we hold about you — site visitors, prospective customers, and account holders.
It does not cover the personal information about your clients that you store inside your Pinion account (their names, contact details, job and invoice records, photos). For that information, you are the responsible party and we are your operator under POPIA: we process it only on your instructions, to provide the service to you, under our Operator Agreement. If you are a client of one of our customers and have questions about how your information is handled, please contact the business that put it into Pinion.
What we collect and why
Our guiding principle is to collect only what we need. In practice that means:
- Identity and access. When you sign up we ask for an email address (and, if you sign in with Google, the name and email address Google shares with us). That's so you can log in securely and we can send you essential account and billing information. We won't send you marketing email without your consent, and any marketing email will always contain a working unsubscribe option, as sections 69 of POPIA and 45 of the Electronic Communications and Transactions Act require.
- Billing information. If you upgrade to a paid plan, your card details are submitted directly to our payment processor, Paystack — they never touch our servers. We keep a record of each transaction (amount, date, masked card details) for account history, receipts, and billing support.
- Product content. We store the content you and your team create in your account — clients, jobs, invoices, stock, photos — so the product works. We keep it as long as your account is active, and we access it only as described below.
- Access logs. Our infrastructure logs IP addresses and authentication events for security and fraud prevention.
- Voluntary correspondence. When you email us with a question, we keep the correspondence so we have history to reference if you contact us again.
We run no analytics trackers, no advertising scripts, and no third-party cookies on this website or in the app. The app stores a session token and a local cache in your browser's storage because the product cannot work without them; nothing in that storage is used to track you. If this ever changes, we will update this policy and, where required, ask for your consent first.
When we access or disclose your information
- To provide the service. We use a small set of third-party sub-processors — for hosting, database, authentication, and payments — listed with their locations on our sub-processor page.
- To help you, with your permission. If we need to look at your account content to resolve a support request, we ask first.
- When something breaks. On the rare occasion an automated process fails partway, we may need to look at a minimal amount of data to fix it.
- To investigate abuse. Accessing an account while investigating a violation of our use restrictions is a measure of last resort.
- When required by law. We disclose personal information only if compelled by a court order, warrant, or other legally binding demand under South African law, or the law applicable to where the data is hosted. Our policy is to notify you before disclosing unless we are legally prohibited from doing so. If we are audited by a tax authority, we disclose only the minimum billing information needed.
- If the business changes hands. We don't plan on being acquired, but if it happens, we'll notify you before any of your personal information is transferred or becomes subject to a different privacy policy.
Your rights under POPIA
As a data subject, you have the right to:
- Know what personal information we hold about you, and request access to it.
- Correction of personal information that is inaccurate or out of date.
- Deletion of your personal information, subject to records we must lawfully retain (such as billing records for tax purposes). Because the product cannot work without certain data, a deletion request may mean closing your account.
- Object to processing, including objecting at any time to direct marketing.
- Portability in practice — your content is yours, and you can export it (for example, downloading invoice PDFs) at any time while your account is active.
- Complain to the Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001; inforegulator.org.za; complaints via POPIAComplaints@inforegulator.org.za.
To exercise any of these rights, email privacy@pinioncrm.com. We may need to take reasonable steps to verify your identity before responding. Formal requests for access to records can also be made under our PAIA Manual.
How we secure your data
All data is encrypted with TLS when transmitted between your browser and our servers, and our database provider encrypts data at rest. Every organization's data is isolated with row-level security enforced in the database itself, so one customer can never read another's records. Administrative access to our infrastructure is limited and protected. No method of transmission or storage is 100% secure, and section 19 of POPIA asks for appropriate, reasonable measures — which is what we maintain and keep improving.
If we ever have reasonable grounds to believe your personal information has been accessed by an unauthorised person, we will notify the Information Regulator and affected data subjects as section 22 of POPIA requires.
Data retention and deletion
We keep your information for as long as your account exists. Cancelling a paid plan does not delete anything — your organization moves to the Free plan and your data stays. If you ask us to delete your account, your content is permanently removed from active systems within 30 days and from any provider backups within 60 days, after which it cannot be recovered. We retain billing records for as long as tax law requires.
Where your data lives (transborder flows)
In terms of section 72 of POPIA, we disclose that your data is stored outside South Africa: our database, authentication, and file storage run on Supabase in the eu-west-1 region (Republic of Ireland, European Union), and our website and app are delivered through Cloudflare's global network. The European Union's data protection law (the GDPR) provides a level of protection substantially similar to POPIA's conditions for lawful processing. Payment transactions are processed by Paystack. By using the Services you consent to this transfer and storage.
Changes and questions
We may update this policy as needed to comply with regulations and reflect new practices. Whenever we make a significant change, we will refresh the date at the top of this page and take appropriate steps to notify account holders. Questions? Email privacy@pinioncrm.com and we'll be happy to answer them.
Adapted from the Basecamp open-source policies / CC BY 4.0