Legal
Privacy Policy
There are two very different things at play here: this website, and the plugin you install on your own server. This policy covers both, and the distinction matters.
This page is a plain-language summary of our current terms and is not legal advice.
Last updated: August 2026
The important distinction
Stillpoint CRM is self-hosted software. When you install the plugin, it creates its tables inside your own WordPress database, on your own hosting. Your contacts, companies, deals, quotes, invoices, email records and WooCommerce customer data are stored there and only there. We do not receive, process, store, transmit or have any access to that business data — there is no sync to our servers, because no such connection exists.
That means for your CRM data you are the data controller, and JAK Solutions is not a processor of it. Your own privacy notice, retention policy and lawful basis apply to the customer records you keep in Stillpoint, exactly as they do for the rest of your WordPress installation.
This website (stillpointcrm.com) is separate, and is the only place where we handle any personal data of our own. That is what the rest of this policy describes.
What this website collects
- Contact enquiries. Our contact form opens a draft in your own email client; nothing is submitted to this site. When you email us we receive your name, email address and whatever you choose to tell us, and we keep that correspondence so we can answer you and honour support commitments.
- Analytics. We collect minimal, aggregate usage data — pages viewed, referrer, approximate region, device and browser type — to understand which pages are useful. We do not build advertising profiles and we do not sell data.
- Server logs. Standard request logs, including IP address, kept short-term for security and abuse prevention.
We do not ask for or want any of your customers' personal data. Please don't send us database exports or screenshots containing third parties' personal details unless we specifically ask for them to debug an issue.
Cookies
This site uses only cookies and equivalent local storage that are necessary for it to work or to gather the aggregate analytics described above. We do not run third-party advertising or retargeting cookies. You can block or clear cookies in your browser without losing access to any part of this site. Note that the checkout is hosted by Freemius, which sets its own cookies under its own policy.
Payments — Freemius as merchant of record
Purchases and subscriptions are handled by Freemius, which acts as our merchant of record and payment processor. When you buy a licence you transact with Freemius, not with us. Freemius collects and processes your billing details, including your name, billing address, tax information and payment-card data. We never see or store your full card details. Freemius provides us with order and licence information such as your name, email address, the plan purchased and the status of your subscription, so we can provide support and honour your licence.
Freemius also collects licence and site activation data when the plugin checks your licence: the site URL the licence is activated on, the plugin and WordPress version, and activation/deactivation events. This is what enables site limits, automatic updates and renewal handling. It is licence metadata about the installation — not the CRM records inside it.
How we use and share data
We use the data above to answer enquiries, deliver and support the product, handle licensing and renewals, keep the site secure, and improve our pages. We share it only with the service providers needed to do that — principally Freemius for payments and licensing, plus our website hosting, analytics and email providers — and where the law requires it. We do not sell personal data.
Retention
Support and sales correspondence is kept while your licence is active and for a reasonable period afterwards. Financial records are retained by Freemius and by us for as long as tax and accounting law requires. Analytics data is retained in aggregate form.
Your rights
Depending on where you live — including under the GDPR and UK GDPR, and under South Africa's POPIA — you may have the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent where processing relies on consent. You may also lodge a complaint with your supervisory authority.
For data held about your CRM records, requests should go to the business running that Stillpoint installation — the controller — not to us, because we hold no copy of it.
International transfers
We are based in South Africa and our service providers may process data in other countries, including within the EU and the United States. Where required we rely on appropriate safeguards, such as the European Commission's standard contractual clauses.
Children
Stillpoint CRM is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16 through this website.
Changes and contact
We will update this page when our practices change and revise the “last updated” date above. For any privacy question or data request, including access and erasure, please reach us via the contact page and mark your message “Privacy request”. We aim to respond within 30 days.