Legal

Privacy Policy

Effective date: 13 July 2026 · Last updated: 13 July 2026

Stamter CRM ("Stamter", "we", "us") is a workspace-scoped CRM. This policy explains how we handle personal data across the whole product, and includes a dedicated section on the optional Gmail integration (§4). See also our Terms of Service.

Data controller: Ilan JOURNO, sole proprietor (Osek / registered business, Israel), Harav Kuk 55, Netanya 42100, Israel. Privacy contact & Data Protection Officer: Ilan Journo — privacy@stamter.ai (DPO: ilan@stamter.ai).

1. Our two roles: controller and processor

Controller — for data about you, our customer (account, billing, usage). We decide how it is processed; this policy governs it.

Processor— for the content you put into the CRM ("Customer Data": your contacts, companies, records, files, form submissions, call data, etc.). Here you are the controller and we process it on your behalf and instructions, under a Data Processing Agreement. If you are an individual whose data a Stamter customer holds in their CRM, please direct privacy requests to that customer; we assist them as their processor.

2. Data we collect and process

a) Account & billing data (controller). Name, email, workspace details, authentication data, and — where you subscribe to a paid plan — billing information. Stamter is currently offered free of charge.

b) Customer Data you input (processor). The CRM records and content you create or import — which may include personal data about your own contacts/clients (names, emails, phone numbers, notes, uploaded files, form submissions). We process it only to provide the CRM to you; we do not use it for our own purposes.

c) Technical & usage data. Device, browser, IP address, and in-app actions, used to run, secure, and improve the service.

3. Product features that process personal data

Depending on the features you use:

  • Telephony & call intelligence. Calls are placed and received through our telephony partner Kavkom (kavkom.com); outbound calling campaigns use Telnyx. Where you enable it, calls are recorded and transcribed (via Deepgram) and an AI (the provider you select) generates a summary. Call recording is subject to applicable consent/notice laws — you are responsible for obtaining any required consent from call participants.
  • AI assistance.Optional AI features (in-app assistant, call summaries) process the relevant content through the AI provider you select — which may include Anthropic (Claude), OpenAI, Google, or Stamter's own model — solely to provide the feature to you. We do not use your data to train generalized/non-personalized AI or ML models.
  • Email & messaging. Transactional and, where you use them, campaign emails are sent via our email provider.
  • Forms, documents & files. Form submissions, generated PDFs, and files you upload are stored to provide those features.
  • Search. Your CRM data is indexed to power in-app search.
  • Integrations you connect. Optional integrations you explicitly connect — Gmail (§4) and HubSpot — access data from those providers to bring it into your CRM.

4. Gmail integration — Google user data

This section applies only if you connect a Google/Gmail account. A connected mailbox is private to the user who connected it and is never shared with other workspace members.

Scopes we request (only what the in-CRM mailbox needs):

.../auth/gmail.modify

Read your messages to display your inbox and content, and modify message state on your behalf (read/unread, star, labels, archive, trash, drafts, send replies). We request this single minimal scope, and do not request https://mail.google.com/ (no permanent deletion).

.../auth/gmail.settings.basic

Read and update your primary send-as signature from the CRM composer.

.../auth/userinfo.email + openid

Identify the connected mailbox address (account key). No other profile data.

Limited Use.Stamter's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data is used solely to provide the in-CRM mailbox feature to the user who connected the account. It is not transferred to third parties except as necessary to provide this user-facing feature, is not used for advertising, and is not read by humans except with the user's explicit consent, for security purposes, to comply with applicable law, or as part of aggregated/anonymized operations. No email content, sender, or subject is ever stored at rest — only encrypted OAuth tokens (in a secrets vault).

AI & Gmail. By default, no AI processes your Gmail data. Any optional AI feature that reads mailbox content runs only if you explicitly opt in, only to provide that feature back to you, and we record proof of consent. Stamter does not use restricted-scope Gmail data to develop, improve, or train generalized/non-personalized AI/ML models.

Disconnect / revoke. Disconnecting revokes the OAuth token with Google and deletes the stored tokens. You can also revoke at myaccount.google.com/permissions.

5. How we use data

To provide, secure, and maintain the service; to authenticate you; to provide support; to send service communications; and to comply with law. We improve the service using technical and usage data (§2c) — not the Customer Data you input, which we process solely to provide the service to you. Where we later offer paid plans, we will also use your account data to bill you. We do not sell your data or use it for third-party advertising.

6. Legal basis for processing (GDPR)

For EU/EEA/UK users: consent (e.g., connecting Gmail, enabling AI/call recording), contract (providing the CRM), legitimate interests (security, service improvement), and legal obligation.

7. Retention

  • No email data at rest for the Gmail integration (§4); the mailbox reader is a stateless proxy.
  • OAuth / integration tokens: encrypted in a secrets vault, deleted on disconnect.
  • Call recordings & transcripts: retained per your settings/agreement, then deleted.
  • Customer Data: kept while your account is active. On closure, data is exported and retained 1 month (for your recovery), then the workspace — dedicated per client and isolated from others — is closed and the data deleted/anonymized.
  • Consent records are kept to evidence opt-ins.

8. Sub-processors

We use third parties strictly to run the service, under confidentiality/DPA, processing on our behalf only. Depending on the features you use:

  • Supabase — database, authentication, storage, secrets vault, and hosting (EU / Paris).
  • Vercel (application hosting), Cloudflare (CDN & security), and Railway (background-job worker).
  • Kavkom (kavkom.com) — telephony partner for the softphone; Telnyx — outbound calling campaigns.
  • Deepgram — speech-to-text transcription of recorded calls.
  • Anthropic (Claude), OpenAI, and/or Google — the AI provider you select for AI features.
  • Resend — transactional and campaign email delivery.
  • OpenRouteService — geocoding of addresses (maps / routing).
  • Google (Gmail) and HubSpot — only where you explicitly connect them.

Search is powered by a self-hosted index (Typesense) on our own infrastructure — not a third party. Google user data is never shared for advertising, resale, or model training. A current sub-processor list is available on request.

9. International data transfers

Stamter is established in Israel, which benefits from an EU adequacy decision — so transfers of EU personal data to Stamter in Israel are permitted. Core data is hosted in the EU (Supabase, Paris). Where a sub-processor involves a transfer outside the EEA without adequacy, we rely on Standard Contractual Clauses. As a non-EU controller serving EU residents, Stamter will designate an EU representative (Art. 27 GDPR) where required.

10. Your rights

Subject to law: access, rectify, erase, restrict, object, data portability, and withdraw consent. Contact privacy@stamter.ai — we respond quickly, typically within 1 business day (max: the statutory limit, e.g. 1 month under GDPR). EU/EEA users may complain to their national supervisory authority (e.g., the CNIL in France); Israeli users, to the Israeli Privacy Protection Authority. If your data sits in a customer's CRM, we route your request to that customer (§1).

11. Cookies and tracking

Stamter CRM uses no advertising, analytics, or tracking cookies, and no third-party analytics. Your authentication/session is stored in your browser's local storage, not in cookies. Only strictly necessary technical cookies may be set by our infrastructure/security providers (e.g., Cloudflare's bot-management cookie). No cookie-consent banner is required.

12. Security

Encryption of tokens at rest in a secrets vault; per-client workspace isolation (data never co-mingled); row-level security; HTTPS/TLS in transit; untrusted email HTML sandboxed (scripts disabled); least-privilege backend access; and no logging of secret or message-content values. No system is 100% secure; we maintain an incident-response process.

13. Children

Stamter CRM is a business tool for professional use, not directed to children; we do not knowingly collect their data.

14. Changes to this policy

We may update this policy; material changes are posted here with a new "Last updated" date.

15. Governing law & contact

Governed by the laws of the State of Israel (without prejudice to mandatory GDPR protections for EU/EEA users). Questions or requests: privacy@stamter.ai — Ilan JOURNO, Harav Kuk 55, Netanya 42100, Israel.