Legal
Privacy policy
How this site handles your information. Last updated 9 September 2026.
CRM Teardown is a one-person consultancy operating this website, run by Alberto Foglietta, who is the controller of the personal data described here. This page describes what the site collects, why, and what happens to it afterwards. If anything here is unclear, ask through the contact form and you will get a straight answer.
What the contact form collects
When you send an enquiry, the form asks for your name, your email address, your website, which service you are asking about, and your message. A phone number is optional and the form works without one. The page you sent it from is recorded alongside the message so I know what you were reading.
That information is emailed to me and used to answer your enquiry. It is not added to a mailing list, not sold, and not passed to any CRM vendor or other third party for marketing. If your enquiry does not turn into work, the message is deleted once the conversation is finished and there is no reason to keep it.
Server logs
The web server records standard request logs: IP address, the page requested, the time, the browser user agent, and the referring page. This happens for every website you visit and it is how a server is operated and secured rather than something specific to this site. These logs are kept for a short period and used to diagnose faults and block abuse.
Analytics
If analytics is running on this site, it is used to count page views and understand which articles people find useful. It is not used to build advertising profiles of individual readers. Where an analytics or advertising tag is active, it is disclosed in the cookie section below.
Cookies
The site itself sets no tracking cookies for ordinary visitors. WordPress may set a session cookie if you log in, which applies only to me. The contact form carries a hidden timestamp field and a hidden field that bots tend to fill in. Neither is stored after the message is sent. The form is also protected by Cloudflare Turnstile, which runs a check in your browser to tell a person from a script. Turnstile may set a short-lived cookie and sends a token to Cloudflare to be verified. It is there to stop spam, not to profile you or follow you to other sites.
Affiliate links are the exception worth knowing about. If you click a link to a CRM vendor and that vendor runs a referral programme, the vendor may set a cookie on your browser to attribute a later signup. That cookie belongs to the vendor, is governed by the vendor’s own privacy policy, and I never see who clicked what as an individual. This is set out further on the affiliate disclosure page.
Who else sees your data
Four parties, all in a processing role:
- The hosting provider, which runs the server the site sits on and therefore holds the request logs.
- Cloudflare, which sits in front of the site as a content delivery network and runs the spam check on the contact form, and therefore sees each request before the server does.
- The email provider that delivers your enquiry to my inbox and stores the resulting conversation.
- The CRM vendor whose affiliate link you clicked, if you clicked one, in which case they hold the click attribution rather than me.
No enquiry data is sold, rented, or shared for advertising purposes with anyone.
How long things are kept
Enquiries that do not become work are deleted once the conversation ends. Correspondence with clients is kept for as long as the working relationship lasts, and afterwards for the period that tax and contractual record keeping requires. Server logs are kept for a short operational period and then rotate out.
Your rights
You can ask what information about you is held, ask for a copy of it, ask for it to be corrected, or ask for it to be deleted. Depending on where you live these may be legal rights rather than courtesies, and they are honoured either way. Send the request through the contact form and it will be dealt with within thirty days, usually much sooner given the volumes involved.
Children
This is a business to business site. It is not directed at children and no information is knowingly collected from anyone under sixteen.
Changes to this policy
If this policy changes, the date at the top of the page changes with it. There is no version history published, so if the specifics matter to you, keep a copy of the version you relied on.
Getting in touch
Questions about this policy, or any request about your data, go through the contact form.