SILVAONE

Privacy Policy

How SilvaOne collects, uses, and protects information within the SilvaOne CRM service.

Last updated: 14 September 2026

Who we are

SilvaOne CRM ("SilvaOne", "we", "us") is a cloud-based CRM and business management platform for small service businesses, operated as a UK-based sole trader trading as SilvaOne. Our business/contact address is: Indigo Point, Cattle Market Road, Peterborough, PE1 1SQ, United Kingdom.

For any privacy question or request, contact us at northstackhq3@gmail.com or via our Contact page.

Scope of this policy

This policy covers the SilvaOne CRM website and application at silvaone.co.uk. It explains what information we collect, why, and how it is handled when you visit our site, sign up, or use SilvaOne CRM as a subscriber.

Information we collect

Account information: when you sign up, we collect the information needed to create and secure your account (such as name and email address) through our authentication provider.

Business and customer data you enter: information you or your team add to SilvaOne CRM, such as customer records, jobs, quotes, invoices, invoice payments, reviews, and company settings. This data is entered by you and belongs to your organisation.

Enquiries you send us: information you provide through our Contact or demo request forms, such as your name, email address, business name, and message.

Technical information: standard information generated by using a web application (such as request and error information), used only to operate, secure, and troubleshoot the service.

How we use this information, and our lawful basis

To provide and operate SilvaOne CRM for you and your organisation (performance of a contract with you).

To process subscription payments and manage billing through Stripe (performance of a contract, and legal obligations relating to payment records).

To send service-related transactional emails, such as quotes, invoices, and review requests you choose to send through the platform (performance of a contract).

To respond to enquiries submitted through our Contact or demo forms (legitimate interests in responding to you, or steps taken at your request before entering a contract).

To maintain the security, integrity, and reliability of the service (legitimate interests in protecting SilvaOne and our customers).

AI features

SilvaOne CRM includes optional AI-assisted features (for example, drafting customer emails, job notes, quotes, and business insights). Where you use these features, relevant account or business data already stored in SilvaOne CRM is sent to our AI provider (OpenAI) to generate a draft or suggestion for your review.

AI-generated drafts and suggestions are not sent to customers or acted upon automatically; you remain in control of reviewing, editing, and approving anything before it is used.

Service providers we use

Supabase: provides our application database, file storage, and authentication, and hosts the underlying infrastructure that SilvaOne CRM runs on.

Stripe: processes subscription payments and manages billing, invoicing, and the customer billing portal for paid plans.

Resend: delivers transactional emails sent from SilvaOne CRM, such as quotes, invoices, and review requests.

OpenAI: powers the optional AI-assisted features described above.

We only share the information with these providers that is necessary for them to perform their function for us. We do not sell personal information.

International data transfers

We use third-party providers, including Supabase, Stripe, Resend, and OpenAI, some of which may process information outside the United Kingdom or European Economic Area. Where this happens, we rely on appropriate contractual and legal transfer safeguards required for such transfers, including standard contractual clauses, the UK Addendum, or another lawful transfer mechanism, as set out in the relevant provider's own terms and data processing arrangements.

Data retention

SilvaOne retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing and securing the Service, maintaining business and financial records, meeting legal and regulatory obligations, resolving disputes and enforcing agreements. Retention periods vary depending on the type of information and the purpose for which it is held. SilvaOne periodically reviews information and deletes or anonymises it when it is no longer required.

Data protection and security

We use access controls and organisation-based data separation designed so that each SilvaOne CRM customer can only access their own organisation's data. We take reasonable steps to protect information against unauthorised access, but no online service can guarantee absolute security.

Cookies and similar technologies

SilvaOne CRM uses strictly necessary cookies set by our authentication provider to keep you securely signed in. We do not currently use analytics, advertising, or tracking cookies, and we do not currently use browser local storage to track you. If this changes in future, we will update this policy accordingly.

Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to our processing of your personal information, and to receive a copy of it in a portable format. To exercise any of these rights, contact us using the details above.

Complaints

If you have concerns about how we handle personal information, please contact us first so we can try to resolve them. UK-based individuals also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

Changes to this policy

We may update this policy from time to time, for example as SilvaOne CRM's features or service providers change. We will update the "last updated" date below when we do.