What a CRM is, when a spreadsheet is enough, what the system must do, how the revFADP and the UWG shape a customer database, and how to choose one.

A small company's problem is rarely that it has no CRM. The problem is that its customer contacts live in five places at once: the owner's phone, a salesperson's inbox, a spreadsheet somebody set up years ago, a notebook and a chat history. While one person runs everything, this works, because it all sits in that person's head. The trouble starts on the day that person goes on holiday, leaves, or simply forgets to call back.
A CRM for a small business doesn't have to be an elaborate system. It has one job: to make sure that what you know about a customer belongs to the company, not to whoever happened to be talking to them.
We write this from an unusual position. We built our own CRM, and it handles every enquiry that comes through this site. That is exactly why we can say, honestly, that most small businesses are better off with an off-the-shelf system. Below: what a CRM is, when you need one, what it has to do, how to square it with Swiss data protection and advertising law, and how to choose one without reading rankings written by the vendors themselves.
CRM (customer relationship management) is a system for managing your relationships with customers: one place where the company keeps its contacts, the history of every conversation with each of them, and the stage each sale has reached. With it, anyone on the team can see who is a customer, what you last talked about and what is supposed to happen next.
That is the whole definition. In practice, a CRM system answers three questions a small company asks every day: who did we talk to, what about, and whose move is it now? Everything else — reports, automations, sales forecasts — is an add-on that only makes sense once those three answers live in one place.
Most systems today are online CRMs: a service in the browser, paid for by subscription. You install nothing on a server of your own, and the data sits with the provider — we come back to that when we get to choosing one. The acronym is also used in a broader sense, and that is worth knowing when you search for the CRM meaning: a way of working in which the company deliberately looks after its contact with customers before and after a purchase. The system is only the tool of that way of working. Without the habit, even the best CRM ends up as an expensive address book.
The two acronyms often come up together, but they describe different things. An ERP runs what happens inside the company: orders, stock, production, invoices, accounting. A CRM runs what happens between the company and its customer, before and after they buy: enquiries, conversations, quotes, repeat business. An ERP answers "what do we have and what have we shipped"; a CRM answers "who are we talking to and how far have we got". In larger companies the two are connected — an order from the ERP lands in the customer's history in the CRM — but a small business usually starts with one of them.
A spreadsheet with a list of customers is a customer database, not a system for managing relationships. The difference isn't the tool; it is what the tool can record. A spreadsheet holds a state: name, phone number, maybe an amount. It doesn't hold history — who called, when, what they promised — and it won't remind anybody that a quote has to go out on Thursday. As long as that history fits in one person's memory, the spreadsheet is enough. When it stops fitting, you need something more.
Articles like this one usually open with a statistic: so many per cent of companies already use a CRM, so you should too. We don't give one here, for a simple reason. The survey we would otherwise quote — Eurostat's annual survey of how enterprises use ICT, which measures CRM adoption by company size — covers the EU member states and a handful of other European countries, but not Switzerland. We found no current official Swiss figure measured the same way, and we would rather give you no number than one borrowed from another market and presented as yours.
The question the statistic is meant to answer is a poor one anyway. "How many others have a CRM?" tells you nothing about whether you need one. Plenty of well-run small companies work without one for years, and plenty of companies pay for a system nobody opens. Two things are worth keeping in mind instead.
First, having no CRM in a small company is normal, not negligent. There is no reason to adopt one because "everybody has one". A CRM earns its keep by solving a specific problem, and if you don't have the problem, the system is an overhead.
Second, the problem it solves grows with the number of people, not the number of customers. As a company grows, so does the number of colleagues who talk to the same customer: the owner, a salesperson, someone in the back office who picks up the phone. Every additional person is another place where part of the story can get stuck. That is why the question isn't "should we have a CRM", but "has that moment arrived for us yet".
And even where adoption figures exist, they show how many companies use CRM-type software, not how they use it. A system nobody enters conversations into looks, in the statistics, exactly like one that carries the whole sales operation. The signals below are a better test than any average.
A spreadsheet is enough as long as one person handles customers and a sale closes within one or two conversations. A CRM becomes necessary as soon as any one of the four signals below appears — and none of them is about the number of customers. They are about how much information on each customer has to pass between people.
More than one person talks to customers. The owner and a salesperson, two salespeople, a salesperson and whoever answers the phone. From that moment, "who talked to them last and what did they promise?" no longer has one obvious answer. This is the most important of the four signals, because the other three can still be held in one person's memory.
Customers come back. If people buy from you a second and a third time, the history of previous orders and conversations starts to have value — and a spreadsheet has nowhere to keep it.
A sale takes longer than a week. Enquiry, conversation, quote, revisions, decision. With several of these running at once, somebody has to remember where each one stands.
Follow-ups get lost. If, even once a month, it turns out that someone was waiting for a quote or a call that never came, this is the moment. Every such case is a customer who could have bought from a competitor in the meantime.
If you don't recognise any of these signals, don't adopt a CRM just because it seems the done thing. A well-kept spreadsheet will last a long time, on three conditions. It has two tabs, contacts and conversations, and every conversation has a date and the name of the person who had it. It has a "next step" column with a date — that column replaces reminders. And it has a single owner who reviews once a week what has got stuck. A spreadsheet like that is, incidentally, the best preparation for a CRM: when the time comes, you move tidy data instead of chaos. If you recognise two signals or more, reach for an off-the-shelf system. Building your own only makes sense at the third threshold, which we describe further down.
Spreadsheet, off-the-shelf CRM or your own — three thresholds
Digital Vantage, based on the signals described in the article
The market sells CRM through feature lists: automations, reports, artificial intelligence, integrations with dozens of services. A small business needs five things, and the rest can wait.
Contact and company. A person with a name, email address and phone number, attached to the company they work for. Each contact should exist in the database once — which means the system needs some key by which it recognises that two records are the same person. Ours is the email address, always stored in lower case and without spaces, because "[email protected]" and "[email protected]" are two different strings to a database and one person to you.
History, including email. A note from a call, a quote that went out, a meeting. Email is what is most often missing here: the most important agreements with a customer sit in an inbox, not in the CRM, because nobody has time to copy them across. That is why, for a small business, email integration isn't an extra. It is the condition for the history being complete.
Stage — with a record of changes. New contact, qualified, customer, repeat customer, lost. The current stage on its own is not enough; the value lies in knowing when a contact moved from one stage to the next. That is what later tells you how long your sales actually take.
Reminders. A task such as "call on Thursday", assigned to a person and a contact. This is the feature that pays for itself fastest, because it is directly responsible for follow-ups not getting lost.
Contact source. Where somebody came from: a form, a referral, a phone call, a trade fair. Without this field, a year from now you won't be able to say which channels bring customers and which only cost money.
A sales pipeline is the sequence of stages a contact goes through from first enquiry to purchase, with fewer people left at each stage than at the one before. A CRM shows it as columns or as a list of stages.
The most common mistake is too many stages at the start. Ten columns look professional, but nobody moves contacts between "needs analysis" and "preparing an initial quote", so the pipeline stops matching reality. Four or five stages are enough to begin with, and each should have a clear condition for moving on: "we sent the quote", not "they seem interested". Add the two stages that people forget: "rejected" and "spam". Contacts that aren't and won't be customers shouldn't disappear, because they will come back with the next form submission. They should drop out of your statistics instead.
If you are looking for a CRM for sales teams, the pipeline is its heart: a salesperson starts the day with the list of contacts that have sat at one stage for too long.
The first name, surname, work email and phone number of a specific person are personal data, even when that person works for a company you are dealing with. Under the revised Federal Act on Data Protection, personal data means information about an identified or identifiable natural person (revFADP, Article 5(a)); a company as such is no longer protected, but everyone you talk to there is. When you set up a CRM, you are therefore setting up a database of personal data, and that comes with a few obligations. We describe them the way they shaped our own system.
The Swiss model works the other way round from the GDPR. Under the EU regulation, every purpose needs a legal basis before you start. The revFADP doesn't ask for one up front: processing is allowed as long as it doesn't unlawfully breach the personality rights of the person concerned (Article 30(1)). It does breach them, in particular, if you process data contrary to the principles of the act or contrary to the person's express wishes (Article 30(2)). A breach can be justified by consent, by an overriding private or public interest, or by law (Article 31(1)) — and the act names processing data about a contracting party in direct connection with concluding or performing a contract as a typical overriding interest (Article 31(2)(a)). Answering an enquiry, preparing a quote and keeping the history of a customer relationship sit comfortably here. If you also serve people in the EU, the GDPR can apply to that part of your business as well (GDPR, Article 3(2)), so a Swiss company with EU customers often ends up working to both.
The purpose has to be recognisable. Data may only be collected for a specific purpose that the person can recognise, and further processed only in a way compatible with it (revFADP, Article 6(3)). Contact details someone left with a quote request are there for the quote, not automatically for a newsletter.
Mass advertising needs prior consent — and consent is best recorded per channel. Here the rule comes not from data protection law but from the Unfair Competition Act (UWG), Article 3(1)(o). Sending mass advertising by telecommunication — email, SMS — that has no direct connection with content the recipient asked for is unfair unless you have their prior consent, state the correct sender and offer a simple way to refuse that costs nothing. There is an exception for existing customers: if you received a customer's contact details when selling them goods, work or services, and pointed out the option to refuse at that moment, you may send them advertising for your own similar offers without consent. Note that the provision speaks of mass advertising; a one-off personal email to a business contact is a different situation, and where exactly the line runs is a question for a lawyer, not for a CRM vendor. For advertising calls, the same act adds separate rules (Article 3(1)(u) and (v)): respect the note in the telephone directory that someone doesn't want advertising calls from companies they have no business relationship with — people with no directory entry are treated as if they had that note — and call from a number that is displayed and listed in the directory. Whatever the channel, your CRM should show which channel someone agreed to, when, and with what wording. Consent to a newsletter is not consent to a phone call.
Refusing must be simple and free. The UWG requires "a simple and free of charge option of refusal" in every mass advertising message. The revFADP adds the other half: once a person has told you they don't want their data used for advertising, carrying on is processing contrary to their express wishes (Article 30(2)(b)). In practice that means an unsubscribe link that works without logging in, and a CRM that remembers the refusal.
Proportionality and retention. Processing must be proportionate (Article 6(2)) — a date of birth or a social insurance number in the CRM of a service company is a warning sign. And data must be "destroyed or anonymised as soon as they are no longer required for the purpose of processing" (Article 6(4)). Where consent is required, it is only valid if it is given voluntarily, for specific processing and on the basis of appropriate information (Article 6(6)). In practice: every contact should have a date until which you keep it, and the database needs someone who reviews it from time to time.
We quote the revised Federal Act on Data Protection and the Unfair Competition Act from the English translations on fedlex, checked on 22 September 2026 (FADP translation status 1 September 2023, UWG status 1 January 2025). The English texts are for information only; the binding versions are German, French and Italian. We are not a law firm. Agree the justification for your processing, the wording of consents and the retention periods for your CRM with a lawyer or your data protection advisor: what is sufficient depends on the specific purpose and the way data is processed, not on the system you choose.
We have our own CRM because our case is unusual: every form, calculator, quiz and meeting booking on this site is a separate source of contacts, and we want to know which ad brought in the person who later called us. An off-the-shelf system wouldn't have given us that link without stitching together data from several places. Below are the solutions that will be useful to you when choosing an off-the-shelf CRM too, because they are questions to put to the vendor.
Login separate, CRM separate. The account somebody signs into on the website and the contact in the CRM are two different things, only linked when they concern the same person. That lets us develop the CRM without risk to the login, and the other way round.
Email as the key, phone as a supplement. We merge contacts on the email address, normalised to lower case and without spaces. We store phone numbers in international format (+41…), with the country code taken from the market the enquiry came from — on this site, Switzerland. That matters more than it sounds: written without its prefix, a Swiss mobile number is nine digits long, like numbers in other countries, so a system that guesses the country from the length can turn a Swiss lead into somebody else's number. The phone merges nothing, though; it only fills an empty field. Every contact keeps its source: a form, a tool, a brief, a meeting, the mailbox, an import or a manual entry.
Consent stored with the text the person read. The marketing consent field never blocks a form from being sent, because consent has to be freely given. When somebody ticks it, we store not just "yes" but the exact wording of the consent, in the language they saw it in. A later form without the box ticked withdraws nothing — withdrawal works only through the unsubscribe link.
One-click unsubscribe. The link in every marketing email withdraws consent without a login and without a form. The response is always the same, whether or not the link matched anyone, so it can't be used to check who is in the database.
One place that enforces consent. Every action aimed at people — email, SMS, an audience list for ads — builds its recipients through the same filter, which requires consent for the specific channel and excludes contacts marked as spam, rejected or excluded. Nobody has to remember this before the next campaign.
A person judges the stages. The system records the history of every stage change, but moves only one stage by itself: from "customer" to "repeat customer" when a second project appears. Everything else is judged by a person, and the automation never overwrites a negative stage.
Deletion that doesn't come back. When someone asks for their data to be erased, the record is reduced to a "tombstone": all that remains is a hash of the email address (SHA-256), from which the address can't be read, and all other data is wiped — including in the submissions the contact was created from. Why keep the hash? So that the same person doesn't return to the database with the next import. Every contact also carries a date until which we keep it, pushed forward with each new interaction.
Email and ads. Every ten minutes we synchronise the company mailboxes and attach emails to contacts — we store the subject, a short snippet and a link to the message, never the full content or attachments. We send Google Ads the conversions that happened off the site through a quality gate: spam and rejected contacts aren't reported as conversions, because the ad system would learn to look for more of them.
And the most important point: for most small businesses, all of this is too much. An off-the-shelf CRM will handle contacts, history, the pipeline and reminders better than the first version of your own would. We built ours because our value lies in joining a contact to the data our own website produces. How to decide this for yourself, feature by feature, is covered in our article on off-the-shelf versus custom software.
Most "best CRM for small business" rankings are written by the vendors themselves, so instead of another comparison — five criteria you can check in any offer.
Data export and switching provider. Before you enter the first contact, check how you will get the data out — and in Switzerland, check it in the contract, because that is the only place your exit rights will come from. You may have read that EU law now protects cloud customers from lock-in. It does, but only for customers in the Union: the Data Act (Regulation 2023/2854) applies to providers "providing such services to customers in the Union" (Article 1(3)(f)), and a Swiss company buying a CRM is not one of them. Swiss law has no equivalent for business customers: the right to data portability in the revised Data Protection Act (Article 28) belongs to individuals, for the personal data they have disclosed themselves, not to a company for its business data. The Data Act is still a useful checklist of what to ask for: a notice period for starting a switch of no more than two months, a transition period of up to 30 days during which the provider helps with the move, a complete specification of the data you can take with you (Article 25(2)), and no fee for the switch itself. A provider that sells across Europe may offer you the same terms anyway; ask for them in writing. And ask a concrete question: does the export include contact history and notes, or only the list of names?
Price per seat for the team you are planning. Most systems charge per user. With two people that is a trifle; with ten it isn't. Work out the subscription for the team you expect to have in two or three years, and check which plan contains the features you can't start without.
Email and form integration. A CRM into which enquiries from the website and emails have to be copied by hand is out of date within a month. Check whether the form on your website can write the contact straight into the CRM, and whether the system attaches correspondence from the mailbox. If not, see what can be joined up with automation — we cover that in our article on business process automation.
Where the data lives. An online CRM is a service in which the provider processes your customers' data on your behalf. The revFADP allows that by contract, provided the provider processes the data only in the way you yourself would be permitted to, and you must satisfy yourself that it can guarantee data security; it may pass the work on to a third party only with your prior approval (Article 9). It is also worth knowing which country the servers are in. Data may go abroad without further safeguards only to countries whose protection the Federal Council has recognised as adequate; elsewhere, contractual clauses or similar guarantees are needed (Article 16). A good provider has these documents ready and hands them over without being asked.
The limits of the free plan. A free CRM is usually a plan with a cap: on users, contacts, history or integrations. For a start it can be perfectly adequate. But check which limit will hit you first and how much crossing it will cost — because at that point moving will already be hard, and the data will be with the provider.
And one practical tip: before you sign an annual contract, test two systems for two weeks on real contacts from your current sales, not on sample data. After that you will know which one the team actually opens, and that matters more than the feature list.
The minimum data that has to travel from a form to the CRM
Digital Vantage, based on our own CRM
Rolling out a CRM in a small company rarely fails on technology. It fails because in the first week everyone tries to move everything across and design the perfect process. Three decisions are enough for the first month.
One list. Gather contacts from phones, inboxes and spreadsheets in one place — but only those you have spoken to in the last year. Move older lists later, if at all.
One pipeline. Four or five stages with a clear condition for moving on, one pipeline for the whole company. After a month you will see which stage is missing and which is superfluous.
One source of truth. Agree that a conversation that isn't in the CRM didn't happen. It is the only rule that keeps the system up to date three months in.
If, after that month, it turns out that the off-the-shelf system can't handle something that is central for you — such as joining contacts to data from your website or your order system — that is when a CRM built for you, or your own module bolted onto an off-the-shelf tool, is worth considering; this is part of our custom software development work. For the wider picture, which business applications solve which problem, see our guide to business software.
CRM (customer relationship management) is a system for managing your relationships with customers. It keeps contacts, the history of conversations with each of them and the stage of each sale in one place, so everyone on the team knows who is a customer, what you last talked about and what should happen next.
Not always. Having no CRM in a small company is normal, and there is no reason to adopt one because others have. A spreadsheet is enough while one person talks to customers. A CRM becomes necessary when more people do, customers come back, a sale takes longer than a week, or follow-ups start getting lost.
An ERP runs the processes inside the company: orders, stock, invoices and accounting. A CRM runs the relationship with the customer: enquiries, conversations, quotes and repeat business. In larger companies the two systems are connected; a small business usually starts with one of them.
Often, to begin with. Free plans do have limits on users, contacts, history or integrations. Before you choose, check which limit you will hit first, what crossing it costs and how you would export the data if you wanted to change systems.
Answering an enquiry and sending a quote someone asked for don't require marketing consent. Sending mass advertising by email or SMS on your own initiative does, under Article 3(1)(o) of the Unfair Competition Act — with an exception for existing customers whose details you received when selling to them and whom you told how to refuse. Every such message must name the correct sender and offer a simple, free way to refuse. Advertising calls follow separate rules on directory entries. Check the details with a lawyer.
Tell us where you keep your contacts today and what gets lost. We will help
you judge whether an off-the-shelf system, some automation or a module of
your own is what you need. If an off-the-shelf CRM will do — we will say so.
Business software is chosen one function at a time: accounting, CRM, ERP, booking, your own tools. A map of situations, the order to go in and the costs.
What an ERP system is, when a small business needs one, what it costs beyond the price list, how bexio fits in, and where implementations go wrong.
Low code and no code explained: who a citizen developer is, what a low code platform suits, its price limits and what you can take with you when you leave.
When a free booking calendar is enough, what an online booking system must handle and when a custom module pays off. Vendor prices and our estimate.
Off-the-shelf or custom software is decided one function at a time. Four questions, a five-year TCO with our own prices, and vendor lock-in both ways.
Business process automation: how it differs from RPA and AI, the QR-bill as a first step, our hands-off funnel, examples by department.
What a mobile application is and how it differs from a website and a PWA. The frequency test, loyalty apps, working offline and app store costs.
Your Partner in Business, Digital Vantage Team
Digital Vantage team is a group of experienced professionals combining expertise in web development, software engineering, DevOps, UX/UI design and digital marketing. Together we carry out projects from concept to implementation - websites, e-commerce stores, dedicated applications and digital strategies. Our team combines years of experience from technology corporations with the flexibility and immediacy of working in a smaller, close-knit structure. We work in agile methodologies, focus on transparent communication and treat each project as if it were our own business. The strength of the team is the diversity of perspectives - from systems architecture and infrastructure, frontend and design, to SEO and content marketing strategy. As a result, the client receives a cohesive solution where technology, aesthetics and business goals go hand in hand.
Rate this article
Back to the guide: Business software — which tools a company needs, function by function

What an ERP system is, when a small business needs one, what it costs beyond the price list, how bexio fits in, and where implementations go wrong.

Low code and no code explained: who a citizen developer is, what a low code platform suits, its price limits and what you can take with you when you leave.

When a free booking calendar is enough, what an online booking system must handle and when a custom module pays off. Vendor prices and our estimate.

A practical guide for entrepreneurs: how to use QR Code and Short Link, specific uses, creation instructions, analytics and pitfalls to avoid.

Kiedy wejść na marketplace, jak synchronizować oferty, ceny i zamówienia bez chaosu.

Why nobody can give you a Swiss price for app development, what the one published rate reference actually covers, our own prices, and cost after launch.

How to make an app for your business with a contractor: brief, prototype, sprint development, UAT and go-live. How long each stage takes and where you decide.

Off-the-shelf or custom software is decided one function at a time. Four questions, a five-year TCO with our own prices, and vendor lock-in both ways.

Business process automation: how it differs from RPA and AI, the QR-bill as a first step, our hands-off funnel, examples by department.