Privacy Policy
This policy explains what personal information IT Pro Services LLC collects when you use ITPS CRM at https://itpscrm.com, why we collect it, and what we do with it.
It covers two different relationships, and the difference matters:
- Our customers. Businesses that subscribe to ITPS CRM. We decide what account data we hold about them, so for that data we are the controller.
- Our customers' contacts. The people whose details a business stores in its own workspace. We hold that data on our customer's instructions and do not decide what goes in it. For that data we are a processor, our customer is the controller, and the Data Processing Addendum sets out the terms.
If you are somebody's contact in a CRM workspace and want your data corrected or deleted, ask the business you dealt with. They control it; we act on their instruction.
Who we are
IT Pro Services LLC
245 Riverside Avenue Suite 100 PMB1016, Jacksonville, FL 32202
Questions about this policy, or about data we hold: legal@it-ps.net
What we collect about our customers
Account information. Company name, your name, work email address, and the password you choose (stored only as a hash — we cannot read it). If you sign in with Google or Microsoft, we receive your name, email address and a provider account identifier instead of a password.
Billing information. Plan, subscription status, invoices and payment history. Card numbers are handled by Stripe and never reach our servers.
Usage and security records. Sign-in history, the IP address and browser used, active sessions, trusted devices you have chosen to remember, and an audit log of significant actions inside a workspace. These exist so an account owner can see who did what, and so we can investigate a compromised account.
Support correspondence. Anything you send us by email, through the feedback form, or in a support conversation.
What we hold on our customers' behalf
A workspace can contain, entirely at the customer's choosing:
- contacts, companies, deals, tasks, notes and custom fields
- email sent and received through the workspace, including messages pulled from a connected Gmail or Microsoft 365 mailbox
- text messages sent and received
- call records, call recordings and voicemail, where the workspace has calling switched on
- website chat transcripts and form submissions from the customer's own website
- files uploaded as attachments
We do not decide what goes into these records, we do not sell them, and we do not use them to train any AI model.
Why we process this data
- To provide the service. Everything above exists because the CRM would not work without it.
- To bill for it. Subscriptions, seats, add-ons and phone numbers.
- To keep accounts secure. Sign-in throttling, two-factor authentication, session and device records.
- To support customers. Answering questions, and — with the account owner's knowledge — looking at a workspace to fix a fault.
- To meet legal obligations. Tax records, and responding to lawful requests.
Where the law requires a lawful basis, ours is the performance of our contract with the customer, our legitimate interest in running and securing the service, and consent where we ask for it.
Who we share it with
We use a small number of service providers, and only for the purpose named:
- Stripe — subscription billing and card payments.
- Twilio — phone numbers, calls, call recordings and text messages, for workspaces using those features.
- Google and Microsoft — sign-in, and reading mail from a mailbox a customer has connected.
- Our hosting provider — where the application and database run.
- An AI provider (OpenAI or Anthropic) — only for workspaces that have switched on the AI agent, and only for the text of the conversation being answered.
We do not sell personal data, and we do not share it for advertising.
We will disclose data if we are legally required to. Where we are permitted to tell the customer first, we will.
AI features
The AI agent is an optional add-on and is off unless a workspace turns it on. When it is on, the text of a website chat conversation is sent to the AI provider configured for the platform so it can draft a reply. We do not send your contact database, your email, or your call recordings to an AI provider, and no customer data is used to train models.
How long we keep things
- Workspace data — for as long as the subscription is active. After an account closes we keep it for 30 days so it can be recovered by mistake-correction, then delete it.
- Deleted records — items deleted inside the CRM go to a recycle bin the customer can empty. Emptying it is permanent.
- Call recordings — kept for the retention window each workspace sets, then deleted automatically from both our records and the telephony provider. The default is 30 days.
- Sign-in and audit records — kept for up to 12 months.
- Invoices and tax records — kept as long as the law requires, typically seven years.
Security
Passwords are hashed. Credentials we store for you — mail, telephony and payment keys — are encrypted at rest. The application is served over HTTPS, sessions are tracked and can be revoked, two-factor authentication is available, and administrative access to production is limited to staff who need it.
No system is perfectly secure. If a breach affects your data we will tell you, and any regulator we must tell, without undue delay.
Your rights
Depending on where you live you may have the right to ask for a copy of your data, to have it corrected, to have it deleted, to object to or restrict processing, and to receive it in a portable form. Write to legal@it-ps.net and we will respond within the period the law allows.
Account owners can export contacts, companies and deals from inside the CRM at any time without asking us.
If you are one of our customers' contacts rather than one of our customers, please raise these requests with the business that holds your details.
International transfers
Our service providers may process data outside your country. Where that happens we rely on the safeguards those providers offer, including standard contractual clauses.
Children
ITPS CRM is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
We will post any change on this page and update the date below. If a change materially affects our customers, we will tell them by email or in the application.
