Privacy Policy

Last updated: 22 June 2026
This Privacy Policy explains what information The Missing Buttons ("we", "us", "our") collects, how we use it, and the choices you have. The short version: we collect the little we need to run the service, we do not sell your data, and your CRM credentials are not stored unless you deliberately choose to save a connection.
On this page
  1. Who we are
  2. What this policy covers
  3. Information we collect
  4. Your CRM credentials
  5. How we use information
  6. Cookies and similar technologies
  7. Service providers we rely on
  8. Data retention
  9. Security
  10. Your rights
  11. International transfers
  12. Children
  13. Changes to this policy
  14. Contact us

1.Who we are

The Missing Buttons operates the website at themissingbuttons.com and the tools available on it. The business is operated by Zeffl Group, a sole proprietorship based in India. For any privacy question, contact us at hello@themissingbuttons.com.

2.What this policy covers

This policy covers personal information we handle when you visit the site, create an account, run a tool, or buy a fix. It does not cover the CRM or email platforms you connect to; those are controlled by you and governed by their own policies.

3.Information we collect

Account information

When you create an account, we store your email address and the sign-in method you used (a magic link, or Google). We do not set or store a password.

Usage metadata

When you run a tool, we record metadata such as which tool ran, the time, and a record count, so your activity log and your free-download tally work. This metadata never includes the contents of your exports or your keys.

Anonymous device identifier

Before you sign in, we use a randomly generated identifier stored in your browser (in local storage and a first-party cookie) to count free previews. It is not a cross-site tracker and clearing your browser storage resets it.

Payment information

Payments are processed by our payment providers. We receive confirmation that a payment succeeded and which fix it relates to. We do not receive or store your full card details.

Communications

If you email us, we keep that correspondence so we can help and follow up.

4.Your CRM credentials

This is the part people care about most, so we are explicit about it.

Default: not stored

To run a tool once, you provide the credential it needs (such as an API key, domain, or token). By default that credential is held only in memory for the length of that single run, used to perform the action you asked for, and discarded when the run ends. It is not written to our database and not logged.

Saved connections (opt-in only)

If, and only if, you explicitly choose to save a connection, we store that credential so we can run a tool for you again later, including on a schedule, without you re-entering it each time. When you do this:

  • The credential is encrypted at rest, and access is limited to the systems that carry out your runs.
  • It is used only for the actions and schedules you have set up, never for anything else.
  • You can view and delete a saved connection at any time from your account; deleting it removes the stored credential.
  • We will never save a connection without your explicit consent, and saving is never required to use a tool once.

Your responsibility

A saved credential carries whatever access your CRM grants it. You can limit that by issuing a key with only the permissions you need, and you should revoke the key in your CRM if you believe it has been exposed.

5.How we use information

We use the information above to: provide and operate the tools; run scheduled jobs you have set up; enforce free and paid limits; process payments and prevent abuse; send service messages such as sign-in links and receipts; respond to support requests; and improve and secure the service. We do not sell your personal information, and we do not use it for advertising.

6.Cookies and similar technologies

We use a small number of first-party cookies and local-storage items that are essential to the service: keeping you signed in, remembering your theme, and counting free previews via the anonymous device identifier. We also record basic, privacy-preserving page-view counts to understand which pages are used. We do not use third-party advertising or cross-site tracking cookies.

7.Service providers we rely on

We use a few trusted providers to run the service. They process data only on our instructions and for the purposes below:

  • Supabase, database and authentication.
  • Cloudflare, website hosting and edge delivery.
  • Resend, transactional email (sign-in links, receipts).
  • Razorpay, payments for customers in India.
  • Dodo Payments, payments for customers in other regions.
  • Google, only if you choose Google as a sign-in method.

Each provider has its own privacy and security commitments.

8.Data retention

We keep account information for as long as your account exists. Saved connections are kept until you delete them or close your account. Usage metadata is kept for a limited period to power your activity log and limits. When you delete your account, we delete or anonymise your personal information within a reasonable period, except where we must keep records to meet legal, tax, or accounting obligations.

9.Security

We protect information with measures appropriate to its sensitivity, including encryption in transit, encryption at rest for saved credentials, access controls, and the simple principle of collecting as little as possible. No method of transmission or storage is perfectly secure, but the single biggest protection is structural: by default we do not keep your keys at all.

10.Your rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to withdraw consent (for example, by deleting a saved connection). You can exercise most of these directly from your account, or by emailing hello@themissingbuttons.com. We handle requests in line with applicable laws, including India's Digital Personal Data Protection Act, 2023, and the GDPR for users in the EEA and UK.

11.International transfers

Our providers may process data in countries other than yours. Where we transfer personal information across borders, we rely on appropriate safeguards and on providers that commit to recognised data-protection standards.

12.Children

The service is intended for use by businesses and is not directed to children. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided us information, contact us and we will remove it.

13.Changes to this policy

We may update this policy as the service evolves. When we make material changes, we will update the date at the top and, where appropriate, notify you. Continuing to use the service after an update means you accept the revised policy.

14.Contact us

For any question or request about your privacy, email hello@themissingbuttons.com.

The Missing Buttons is an independent product and is not affiliated with, endorsed by, or sponsored by any CRM or email vendor. Product names and trademarks belong to their respective owners.

Questions about this document? Email hello@themissingbuttons.com.