Legal
Privacy
Last updated .
Two kinds of data
Your customer records — the leads, deals, customers, tickets, products and documents you put into Plio. You control them. We process them to run the service for you and for nothing else. We do not sell them, and we do not use them to train anything.
Your account data — the name, work email, organisation and billing details of the people who sign in, plus ordinary server logs. We use these to run your account, bill you and answer support requests.
Mailbox and calendar access
When a user connects Gmail or Outlook, they grant access through their provider's own OAuth consent screen. The token is stored against that user, and only that user's session can use it. Nobody else in your organisation can read that mailbox through Plio. The grant can be revoked at any time from the user's Google or Microsoft account, or from Plio's settings, and revoking it stops all access immediately.
Plio reads mail to show it in the app and to attach threads to the matching record. It does not forward your mail anywhere else.
Where data lives
Records are stored in a MySQL database and scoped to your organisation at the query level.
How long we keep it
Your records stay until you delete them or close the account. Audit log retention follows your plan. After an account closes we delete customer records within 30 days, apart from anything we have to keep for tax or legal reasons.
Getting your data out
You can export at any time without asking us: CSV export on all 7 record modules, respecting your current filters or checkbox selection, and PDF export from Reports.
Sub-processors
We will list every third party that processes data on our behalf here, and tell you before adding one.
Contact
Privacy questions go to support@pliocrm.com.