Privacy Policy
Last updated: August 2026
1. Who we are
Alder CRM is operated by Alder CRM Limited, a company registered in England and Wales (company number 17116559). Registered office: The Brew, 1st Floor, Eagle House, 163 City Road, London, EC1V 1NR.
This policy explains how we handle personal data in connection with our marketing website, the hosted Alder CRM service
(including workspace subdomains such as {organisation}.aldercrm.com), authentication at auth.aldercrm.com,
and our iOS companion app.
For privacy enquiries, contact hello@aldercrm.com.
2. Controller and processor roles
UK GDPR distinguishes different roles depending on whose data is involved:
- Website visitors and marketing enquiries. We are the controller for personal data you submit through our marketing site (for example a contact or interest form).
- Staff users of Alder CRM. We are the controller for account and authentication data needed to operate staff logins (name, email, sign-in provider identifiers, login metadata, and similar).
- People whose details charities store in the CRM (donors, beneficiaries, volunteers, event attendees, and others). The charity organisation is the controller. Alder CRM Limited is the processor, processing that data on the charity’s instructions to provide the service. A separate data processing agreement may apply.
If you are a donor, volunteer, or service user and want to exercise rights over data held about you in a charity’s CRM, please contact that charity first. We will assist the charity with legitimate requests where we are contracted to do so.
3. What we collect from staff users
When you use Alder CRM as a staff user, we typically process:
- Account details: name, email address, and related profile fields you or your organisation set
- Authentication: identifiers from your chosen identity provider (Google, Microsoft, or Apple), and which provider you used
- Login metadata: times of sign-in, IP address, user agent / device information, and session records used for security and audit
- Workspace membership: which organisations you belong to and your role or access level
- Support and operational communications: messages you send us about the product
From Google, Microsoft, or Apple we receive the profile fields those providers release to us — typically email and name. If you use Sign in with Apple with “Hide My Email”, Apple may supply a private relay address instead of your personal email. We do not receive your password for those providers.
iOS companion app. The app loads the same staff admin interface in a secure WebView.
It uses the identifiers needed to maintain your signed-in session (such as session cookies for *.aldercrm.com).
We do not currently collect push notification tokens, because push notifications are not shipped in the app today.
If we add push later, we will update this policy before collecting device tokens for that purpose.
Staff accounts are invite-only. Your organisation decides who is invited.
4. What we collect from website visitors
If you register interest or contact us via the marketing website, we may collect:
- Name, email address, charity name, role, current CRM (if any), and your message
The marketing website uses Plausible Analytics, a privacy-friendly, cookieless analytics service. Plausible does not set cookies, does not collect personal data, and does not track individuals across sites or devices. See our Cookie Policy for more detail on the marketing site.
5. Direct outreach to charities
From time to time we may contact UK charities about Alder CRM using publicly available contact information from the Charity Commission for England and Wales (CCEW) register.
Before we send any outreach communication, we:
- Check that the email address appears on the charity's public CCEW record as an official contact
-
Check the part of the address before the @ symbol, and only contact addresses that identify the
organisation itself or a role within it (for example
info@,chair@, ortreasurer@). Addresses that identify a named individual — two names separated by a dot (for examplejohn.smith@), or an initial and a surname (for examplej.smith@) — are excluded, whatever email provider they use. We know a great many small charities run their organisational inbox on Gmail or a similar consumer service, so we do not treat the provider as a signal either way. - Only contact charities registered as a Charitable Incorporated Organisation (CIO) or a charitable company. Charity law treats these as legal entities separate from the people who run them, and email marketing law (PECR) does not restrict unsolicited email to a corporate body in the way it restricts email to an individual. Unincorporated charities (associations and trusts) sit in a greyer area of that law, so we do not contact them through this route at all.
- Limit outreach to registered charities where the product would be relevant to their stated activities
Every outreach email includes a clear unsubscribe link. You can also ask us to stop contacting your organisation at any time by emailing hello@aldercrm.com.
Open and click tracking. Outreach emails record when a message is opened and when a link inside it is clicked. We use this only to understand which messages are actually useful to the people receiving them, to judge whether a follow-up email is worth sending, and to stop contacting people who have plainly shown no interest. We do not use it to build a profile of you or your organisation, combine it with data from any other source, or share it outside Alder CRM Limited. Most email clients block remote images by default, which stops the open record from being created; a click is recorded regardless of that setting. You can avoid both by asking us to stop contacting your organisation, as above. See also Section 8 for how this relates to cookies and similar technologies.
Our lawful basis for this processing is legitimate interest under UK GDPR — contacting organisations about a service that is directly relevant to their charitable activities. We have assessed that this is a reasonable and proportionate use of publicly available business contact data, balanced against the minimal privacy impact on individuals.
If you believe we have contacted a personal email address in error, please let us know immediately at hello@aldercrm.com and we will remove it and review our filters.
6. What charities store in the CRM
Charities decide what to enter. Categories often include (this list is not exhaustive): contacts and households; donations, Gift Aid, and related fundraising records; case notes and safeguarding information; DBS-related or safer-recruitment records; volunteer details and shifts; event attendance; communications preferences; and governance or compliance records.
The charity is responsible for ensuring it has a lawful basis to collect and keep that data, for informing the people concerned where required, and for its own retention and safeguarding policies. We process this data to provide the service, not for our own marketing.
7. Purposes and lawful bases
We use personal data to:
- Provide, maintain, and secure the Alder CRM service and iOS companion app
- Authenticate users and manage workspace memberships
- Respond to enquiries and provide customer support
- Monitor reliability, prevent abuse, and improve the product (including limited first-party usage analytics in the CRM)
- Bill and administer subscriptions where you have a paid plan
- Comply with legal obligations
We do not sell personal data.
Depending on the context, our lawful bases under UK GDPR include:
- Contract — to provide the service to your organisation and operate your staff account
- Legitimate interests — security, fraud prevention, product reliability, and responding to marketing enquiries (balanced against your rights)
- Consent — where we ask for it (for example optional marketing emails); you may withdraw at any time
- Legal obligation — where the law requires us to retain or disclose information
- For CRM content about donors, beneficiaries, and similar people — we process as processor on the charity’s instructions; the charity determines the lawful basis
8. Cookies and similar technologies
Alder CRM (the product). We use session cookies scoped to .aldercrm.com
so that sign-in at auth.aldercrm.com works across workspace subdomains. These are essential for the service to function.
We may also use first-party cookies or similar storage for session security and limited product analytics (for example visit continuity within the admin interface).
CRM product analytics are configured to avoid geocoding and to mask IP addresses where that tooling is used.
Marketing website. Described separately in our Cookie Policy. We do not currently set analytics or advertising cookies on the marketing site.
Outreach email tracking. The tracking image and tracked links described in Section 5 are, like cookies, a technology that stores or accesses information in connection with your device, so we mention them here too. See Section 5 for what is recorded, what it is used for, and how to avoid it.
Newsletter and campaign emails sent by charities using Alder CRM. Charities using the platform can send their own newsletters and campaign emails to their own supporters using the same open- and click-tracking technology described above. Where a charity uses this, we process it as processor on that charity's instructions (see Section 2) — the charity decides whether and how to tell its own supporters about it. The same technical safeguards apply regardless of who sends the email: we do not record a recipient's IP address, location, or device, and event records are deleted automatically after a period we keep under review.
9. Who we share data with (subprocessors and providers)
We use carefully chosen service providers to run Alder CRM. Categories include:
- Hosting and infrastructure — UK-based servers and related platform services that run the application and databases
- File storage — storage of uploads and backups in UK regions
- Email delivery — all platform mail, transactional and bulk alike, currently via Mailgun’s EU platform. Our own marketing and outreach email (Section 5) is sent via Postmark, which does not carry workspace data
- Error monitoring and performance — application monitoring (currently New Relic) to keep the service reliable
- Website analytics — Plausible Analytics, a privacy-friendly, cookieless analytics service for the marketing website. Plausible does not collect or store personal data and does not use cookies
- Identity providers — Google, Microsoft, and Apple, when you choose to sign in with them
- Payments — Stripe, where your organisation uses card billing or related payment features
Charities may also connect their own integrations (for example their email provider or payment tools). Data shared with those integrations is under the charity’s control and the third party’s terms.
We may disclose information if required by law, or to protect the rights, safety, or security of Alder, our customers, or others. We do not sell, rent, or share personal information for advertising networks.
Our full list of named sub-processors, with the purpose and location of each, is published at aldercrm.com/subprocessors. That list may change as we improve the service; material changes will be reflected there and in updates to this policy.
10. International transfers
Our primary application hosting and file storage are UK-based. Some providers may process data in the European Economic Area (for example EU-region email delivery) or, where a provider operates globally (such as Google, Microsoft, Apple, Stripe, or monitoring tools), outside the UK.
Where personal data is transferred internationally, we rely on appropriate safeguards under UK GDPR — such as adequacy regulations, the provider’s UK/EU standard contractual clauses or international data transfer agreements, and vendor due diligence — as applicable to that transfer.
11. Retention
- Staff accounts. Kept while the account is active. If you delete your account (or we deactivate it), we anonymise account identifiers and remove memberships as described in our Terms. Limited security or audit logs may be retained for a further period where needed for security, dispute resolution, or legal compliance.
- Workspace (CRM) data. Retained for as long as the organisation’s workspace remains active, and thereafter according to our offboarding process and any written agreement with the organisation. Deleting a staff user’s login does not wipe the charity’s CRM database.
- Marketing enquiries. Typically kept for up to two years after last contact, or until you ask us to delete them, unless we need them longer for a legitimate ongoing conversation or legal reason.
- Email engagement records. Records of individual email opens and clicks — for our own outreach (Section 5) and for newsletters or campaign emails sent by charities using Alder CRM (Section 8) — are kept only for as long as we need them to judge whether an email programme is working, and are deleted automatically after a period we keep under review.
12. Your rights
Under UK GDPR, individuals have rights including:
- Access — a copy of personal data we hold about you
- Rectification — correction of inaccurate or incomplete data
- Erasure — deletion in certain circumstances
- Restriction — limiting how we use data in certain circumstances
- Portability — receiving certain data in a portable format
- Objection — objecting to processing based on legitimate interests
- Withdraw consent — where processing is based on consent
Staff users: email hello@aldercrm.com, or use in-product controls where available (including My Profile → Delete account for eligible free-plan users). We aim to respond within one month.
People in a charity’s CRM: contact the charity (the controller) in the first instance. We will help the charity fulfil DSARs and similar requests where we process the data on their behalf.
13. Children
Alder CRM’s staff product is aimed at adult charity workers and is not directed at children. Charities may lawfully hold children’s data in casework or related records; that processing is under the charity’s instructions and safeguarding policies. We do not knowingly market the staff product to children.
14. App Store / Apple
For the iOS companion app:
- Sign in with Apple is offered as an authentication option alongside Google and Microsoft (subject to configuration)
- Account deletion: eligible free-plan users can delete their login from My Profile → Delete account. Others should contact their organisation administrator or hello@aldercrm.com
- App Privacy nutrition labels should match this policy. Today the app involves contact information and identifiers needed for authentication and session continuity, plus diagnostics only to the extent our server-side monitoring receives them through normal use of the service. We do not use the app for third-party advertising, and we do not collect push tokens until push notifications ship
15. Security
We use technical and organisational measures appropriate to a multi-tenant charity CRM, including encrypted transport, access controls, tenant isolation, and audit logging of sensitive actions. No online service is perfectly secure; please protect your devices and sign-in accounts, and tell us promptly of any suspected unauthorised access.
16. How to complain
If you believe we have mishandled your personal data, please contact us first at hello@aldercrm.com so we can try to resolve the issue.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
https://ico.org.uk
Phone: 0303 123 1113 (local rate) or 01625 545 745
Email: casework@ico.org.uk
17. Changes to this policy
We may update this privacy policy from time to time. We will revise the “Last updated” date on this page and, for material changes, take reasonable steps to notify workspace administrators or affected users.
Contact us
Alder CRM Limited
Email: hello@aldercrm.com
Registered office: The Brew, 1st Floor, Eagle House, 163 City Road, London, EC1V 1NR
Company registration: England and Wales, No. 17116559