Privacy Policy
unLocked CRM privacy policy. How we collect, use, and protect your personal information.
Privacy Policy
Last updated: February 20, 2026
unLocked CRM LLC ("Provider," "we," "our," or "us") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with unLocked CRM and related services (collectively, the "Service"). By accessing or using the Service, you agree to the practices described in this Privacy Policy.
1. Information We Collect
We may collect the following categories of information:
- Account Information: Name, email address, phone number, company name, and billing details when you register for the Service.
- Usage Data: Log data, device information, browser type, IP address, operating system, referring URLs, pages viewed, and interactions with the platform.
- Customer/Lead Data: Information you upload, input, or store in unLocked CRM, including but not limited to contacts, emails, phone numbers, policy details, and licensing information.
- Payment Information: Payment card details and billing information, processed securely through PCI-compliant third-party payment processors (we do not store full credit card numbers on our servers).
- Communications: Records of your communications with us, including support tickets, emails, and chat messages.
- Cookies & Tracking Technologies: We use cookies, web beacons, pixels, and similar technologies to collect information about your browsing activity. See Section 10 for details.
2. Legal Basis for Processing
We process personal information based on the following legal grounds:
- Contract Performance: Processing necessary to provide the Service you have subscribed to.
- Legitimate Interests: Processing for our legitimate business purposes, such as improving the Service, fraud prevention, and security.
- Consent: Where you have given explicit consent, such as for marketing communications.
- Legal Obligation: Processing necessary to comply with applicable laws and regulations.
3. How We Use Information
We use collected information to:
- Provide, operate, and maintain the Service.
- Process payments and manage subscriptions.
- Communicate with you about updates, support, and service-related notices.
- Send marketing and promotional communications (with your consent, where required).
- Improve security, functionality, and performance of the Service.
- Monitor and analyze usage trends and preferences.
- Detect, prevent, and address fraud, abuse, and technical issues.
- Comply with legal, regulatory, or contractual obligations.
- Provide automated alerts and notifications, including license expiration reminders.
4. Sharing of Information
We do not sell, rent, or trade personal information. We may share data with:
- Service Providers: Third-party vendors who assist in providing the Service (e.g., Twilio, Stripe, Google, Meta), subject to contractual data protection obligations.
- AI & Analytics Providers: We may use artificial intelligence and machine learning services to enhance features such as lead scoring, quoting, and policy analysis. Data shared with these providers is processed solely to return results to you and is subject to strict contractual usage limitations. We do not use — and our AI providers are contractually prohibited from using — your Customer/Lead Data, PHI, communications, or documents to train, fine-tune, or improve any AI or machine learning model. We do not train AI on customer data in any form. The only data used to improve the Service is anonymized, aggregated usage telemetry that contains no customer content and cannot identify any individual.
- Legal Authorities: When required by law, subpoena, or legal process, or to protect our rights, property, or safety.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the successor entity.
Data Processor Role: With respect to Customer/Lead Data that you store in the Service, we act as a data processor on your behalf. You, as the data controller, are solely responsible for complying with applicable data privacy laws (e.g., HIPAA, TCPA, GDPR, CCPA) when using customer/lead data inside unLocked CRM. For details on our data processing obligations, please refer to our Data Processing Agreement.
HIPAA Notice: unLocked CRM is HIPAA-compliant and will execute a Business Associate Agreement (BAA) with covered entities and business associates upon request. The Service is administered with the administrative, physical, and technical safeguards required to handle Protected Health Information (PHI). If you are a HIPAA-covered entity or business associate, a signed BAA must be in place before you upload any PHI to the Service; absent an executed BAA, you must not upload PHI. Where a BAA is executed, it governs all PHI and controls over any conflicting term in this Privacy Policy or the Data Processing Agreement. Contact info@unlockedcrm.ai to request a BAA.
Order Of Precedence: This Privacy Policy describes our general privacy practices. For Customer/Lead Data processed on your behalf, the Data Processing Agreement governs, and for PHI an executed BAA governs. In the event of a conflict, the order of precedence is: (1) BAA, (2) Data Processing Agreement, (3) this Privacy Policy.
5. Data Security
We implement industry-standard technical and organizational measures to protect your information, including AES-256 encryption at rest, TLS encryption in transit, access controls, regular security audits, and intrusion monitoring. However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute protection against unauthorized access, alteration, or destruction.
6. Data Retention
We retain personal data only as long as necessary to fulfill the purposes for which it was collected, including to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Upon termination of your account, we will delete or anonymize your data within 30 days, unless retention is required by law or for legitimate business purposes (e.g., fraud prevention, record-keeping).
7. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Restriction: Request restriction of processing in certain circumstances.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests or for direct marketing.
- Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise these rights, contact us at info@unlockedcrm.ai . We will respond within 30 days (or as required by applicable law).
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions.
- Right to Opt-Out: We do not sell or share personal information for cross-context behavioral advertising. If this changes, we will provide a "Do Not Sell or Share My Personal Information" link.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Personal Information: We do not use or disclose sensitive personal information for purposes other than those permitted under the CPRA.
Sensitive Personal Information: In the context of insurance services, certain data you provide or store — such as social security numbers, health information, financial account details, or precise geolocation — may constitute sensitive personal information under the CPRA. We process such data solely to provide the Service as directed by you.
Do Not Track Signals: Our Service does not currently respond to "Do Not Track" (DNT) browser signals. However, you can manage tracking preferences through browser settings and our cookie controls as described in Section 10.
To submit a CCPA/CPRA request, email info@unlockedcrm.ai. We will verify your identity before processing any request and respond within 45 days as required by law.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from the laws of your jurisdiction. We take appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy, including the use of Standard Contractual Clauses or other approved transfer mechanisms where required.
10. Cookies & Tracking Technologies
We use the following types of cookies and similar technologies:
- Essential Cookies: Required for the Service to function properly (e.g., session management, authentication).
- Analytics Cookies: Help us understand how users interact with the Service (e.g., Google Analytics).
- Marketing Cookies: Used to deliver relevant advertisements and measure campaign effectiveness (e.g., Meta Pixel, Google Ads).
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of the Service.
11. Automated Decision-Making & AI
The Service may use automated decision-making processes, including artificial intelligence and machine learning, for features such as lead scoring, quoting engines, and policy analysis. These processes do not produce legal or similarly significant effects on individuals without human oversight. You have the right to request human review of any automated decision that significantly affects you.
12. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy policies of any third-party sites you visit.
13. Children's Privacy
The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child under 18, we will take steps to delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on this page and updating the "Last Updated" date. For significant changes, we may also provide notice via email or in-app notification. Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.
15. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
📧 Privacy & general inquiries: info@unlockedcrm.ai