Legal
Privacy Policy
Effective Date: May 3, 2026 · Last Updated: June 27, 2026
1. Introduction
ShineCRM ("ShineCRM," "we," "us," or "our") is a software-as-a-service customer relationship management platform designed for exterior cleaning businesses. This Privacy Policy explains how we collect, use, share, store, and protect personal information when you use our mobile application, web dashboard, websites, and related services (collectively, the "Service").
ShineCRM is currently operated by Sean van Gessel as a sole proprietorship based in Victoria, British Columbia, Canada. References to "ShineCRM" in this policy refer to this business and any successor entity.
This policy applies to:
- Customers: Businesses and individuals who sign up for and use ShineCRM (typically exterior cleaning companies, sole proprietors, and their employees).
- End Clients: The customers of our Customers, whose information our Customers enter into the Service (homeowners, property managers, etc.).
- Website Visitors: Anyone who visits our marketing website at shinecx.com or related domains.
By using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.
2. Plain-Language Summary
We've written this policy in detail to be transparent and legally complete. Here's the short version:
- ShineCRM is early-access, experimental software run by a solo developer, provided as-is and at your own risk. Protections are expected to grow as the product matures.
- To support you and improve the product, our founder and authorized personnel may access your data and your customers' data, including the content of messages, at the operator's discretion, for support, debugging, product development, and other operational purposes. The AI activity log below is one example of that access.
- We collect what we need to run the Service: your account info, the data you put into ShineCRM, and standard technical data like IP addresses and device info.
- We use Stripe for payments. We never see, store, or handle your credit card numbers directly.
- AI is a core part of the Service. We use AI to read, analyze, and generate responses to all communications processed through ShineCRM, and we use that data to operate and improve our AI models.
- Customers can opt out of AI training at any time. AI inference (using AI to help with your work) cannot be disabled while using AI features.
- We do not sell your personal information.
- Our founder and authorized support personnel may access Customer Data, including the content of your customers' messages, to operate, debug, and support the Service. To run and support our AI features, the full text we send to our AI providers and the full text they send back is recorded in an internal AI activity log that authorized ShineCRM staff can review across organizations. Those raw AI logs are automatically deleted 30 days after each AI call, leaving only metadata (organization, model, token counts, cost, and outcome). Other cross-tenant administrative dashboards continue to show metadata only. Every staff access to your records is recorded in an audit log that your administrators can review. See Sections 7.6 and 15.1.
- We use trusted third-party services (Supabase, Stripe, Twilio, Resend, Anthropic, OpenAI, Google, Cloudflare, GitHub, Cursor, and others) to operate. They process data on our behalf.
- When you report a bug, we collect what you write plus technical context and a link to the relevant session replay, and we may use development tools (including GitHub for issue tracking and AI coding assistants such as Cursor) to diagnose and fix it. Please do not include your End Clients' personal details in bug reports. See Section 4.4.
- Our servers are currently located in the United States.
- You have rights over your data: access, correction, deletion, portability, and more. Email sean@shinecx.com to exercise them.
- You must be 18 or older to use the Service.
3. Who We Are and How to Contact Us
Business Name: ShineCRM (operated by Sean van Gessel)
Mailing Address: 1279 Derby Rd, Victoria, BC, Canada
Privacy Contact Email: sean@shinecx.com
For all privacy-related questions, requests, or complaints, email sean@shinecx.com. We respond to verified requests within 30 days.
4. Information We Collect
4.1 Information You Provide to Us (Customer Account Data)
When you sign up for and use ShineCRM as a Customer, we collect:
- Identity Information: Name, business name, job title.
- Contact Information: Email address, phone number, business address, mailing address.
- Account Credentials: Username, password (stored as a salted hash, never in plain text).
- Billing Information: Subscription tier, billing history, and limited payment metadata. Full payment card details are collected and stored by Stripe, not by ShineCRM. We receive only tokenized references and basic transaction data from Stripe.
- Communications with Us: Support emails, chat messages, survey responses, and feedback.
- Marketing Preferences: Whether you have opted in to marketing emails.
4.2 Information You Enter Into ShineCRM (End Client Data)
As a Customer, you may enter, upload, or generate the following information about your End Clients:
- Names, addresses, email addresses, phone numbers.
- Property photos and job-site images.
- Service history, estimates, invoices, and payment history.
- Notes, tags, and custom fields you create.
- SMS message content and metadata exchanged with End Clients via the Service.
- Call recordings and call metadata, where the calling feature is used.
- Email content and metadata exchanged through the Service.
- Job schedules, location data tied to jobs, and route information.
You are the controller of this End Client data. ShineCRM acts as your processor and handles this data on your behalf, in accordance with your instructions and this policy.
4.3 Information Collected Automatically
When you or your End Clients interact with the Service, we automatically collect:
- Device Information: Device type, operating system, OS version, app version, browser type and version, screen size, language, and time zone.
- Network Information: IP address, internet service provider, approximate geographic location derived from IP address.
- Usage Data: Pages visited, features used, buttons clicked, session duration, referral source, error logs, crash reports, and timestamps of activity.
- Session Replay: Within the signed-in dashboard and mobile app, we use session replay technology (currently PostHog) to record how the interface is used — screens visited, taps, clicks, and the content displayed on screen — so we can diagnose problems and improve usability. In the web dashboard, text you type into input fields is masked on your device before recording. Recordings may include business data shown on screen; they are processed by PostHog on our behalf as a service provider, retained for a limited period, and accessible only to authorized ShineCRM personnel. We do not record sessions on our public marketing website.
- Mobile Location Data: Precise GPS location, when you grant the mobile app permission, used to support job routing, check-ins, and time tracking.
- Web Location Data: Approximate location derived from IP address, and precise location if you grant browser permission.
- Push Notification Tokens: Device-level identifiers used to deliver in-app and system notifications.
- Cookies and Similar Technologies: See Section 9.
4.4 Bug Reports and Diagnostic Data
When you submit a bug report through the Service, we collect the title, description, and reproduction steps you provide, together with technical context (the screen or route you were on, platform, operating system, device model, and app version), the email address associated with your account, and a link to the relevant session replay described in Section 4.3. To investigate and resolve reported issues, this information may be recorded in our internal issue-tracking and source-code tools (including GitHub) and processed by AI-assisted debugging and code-fixing tools (including Cursor) and the AI providers listed in Section 7.1, each acting as a service provider on our behalf. Bug reports are accessible only to authorized ShineCRM personnel and the service providers described above. Because the free-text fields of a bug report are written by you, you should not include End Client personal information or other sensitive data in them; the Service captures the necessary technical context automatically. See Section 18 (Customer Responsibilities).
4.5 Mobile Device Permissions
When you use the ShineCRM mobile app, we may request the following device permissions. Each permission is requested only when needed for the relevant feature, and you may revoke any of them at any time through your device's system settings.
- Camera: To capture photos of job sites, before/after shots, receipts, and other work-related images. Photos are only created and stored when you explicitly take or attach them.
- Microphone: To make and receive business phone calls through our in-app calling feature (powered by Twilio), and to record calls where the call recording feature is enabled and used.
- Photos and Media Library: To attach existing images from your device's photo library to jobs, estimates, invoices, and messages.
- Location: To support job routing, on-site check-ins, and time tracking. Precise location is only collected when you grant permission and only while the relevant feature is in use. See also Section 4.3 (Mobile Location Data).
- Notifications: To deliver alerts for incoming calls, SMS messages, job updates, payment events, and other Service activity.
- Contacts (optional): If you choose to import contacts from your device, we use this permission to read selected contact entries you choose to import. We do not upload your full address book without your action.
- Phone State: On Android, used by the in-app calling feature so the app can manage call audio routing and respond appropriately when a native phone call interrupts an in-app call.
4.6 Information from Third Parties
We may receive information about you from:
- Stripe: Subscription status, payment outcomes, refund records.
- Analytics and Error Tracking Tools: Data about Service performance and usage, including aggregated statistics and the session replay recordings described in Section 4.3.
- Marketing and Referral Sources: If a third party refers you to us, we may receive limited information from that referral.
4.7 AI and Machine Learning Data
The Service includes AI-powered features (automated message drafting, summarization, transcription, lead scoring, scheduling assistance, and similar functions). To deliver these features, we send relevant data to AI service providers including Anthropic, OpenAI, and Google (Gemini). See Sections 7 and 8 for details on how AI inference and training work.
To operate, monitor, debug, and support these AI features, we record the full text we send to the AI provider and the full text it returns in an internal AI activity log. Authorized ShineCRM personnel can review this log across organizations for those limited purposes. Every such review is recorded in the audit log described in Section 15.1 (which your administrators can review), and the raw request and response text is automatically deleted 30 days after each call, leaving only metadata. See Sections 7.6, 14, and 15.1 for the access controls, audit logging, retention, and lawful basis that apply.
5. How We Use Your Information
5.1 To Provide the Service
- Create and manage your account.
- Process payments and subscriptions through Stripe.
- Deliver core features: contacts, estimates, jobs, invoices, scheduling, messaging, and reporting.
- Send transactional notifications (account updates, payment receipts, security alerts, service announcements).
- Provide customer support.
- Sync data between mobile and web platforms.
5.2 To Operate AI Features (Inference)
- Read, analyze, and process all inbound and outbound communications (SMS, email, calls, voicemails, notes) handled through the Service.
- Generate suggested replies, drafts, summaries, transcripts, lead scores, scheduling suggestions, and other AI-assisted outputs.
- Detect anomalies and flag items needing attention.
- Record the request text we send to AI providers and the response text they return in an internal AI activity log, so that authorized ShineCRM personnel can operate, monitor, debug, and support the AI features. See Sections 7.6 and 15.1 for the access controls, audit logging, and 30-day retention that apply to this log.
AI inference is a core part of the Service and cannot be disabled while using AI-dependent features.
5.3 To Train and Improve AI Models (Future Use)
We currently use third-party AI APIs (Anthropic, OpenAI, and Google) to power AI features. Under those providers' API terms, data submitted via their APIs is not retained for model training by default.
We may, in the future, use Customer Data (including communications processed through the Service) to train and improve AI models that power ShineCRM, but only using (a) data that has been de-identified, anonymized, or aggregated so that it no longer identifies any individual, and/or (b) Customer Data of Customers who have opted in to AI training and have not opted out. For personal information of End Clients who are residents of California, the EEA, or the UK, ShineCRM acts solely as a service provider and processor and does not use that personal information for AI training or any other purpose of its own, except in de-identified, anonymized, or aggregated form (see our Data Processing Agreement and Section 6.3 of the Terms of Service). Trained models may be used to benefit all ShineCRM users. We are disclosing this intent in advance so that ongoing use of the Service constitutes notice; if this practice begins, we will update this policy with the effective date.
Customers can opt out of AI training at any time through account settings or by emailing sean@shinecx.com. Opting out applies to future training; we cannot retrain or roll back models that have already incorporated data, as this is not technically feasible.
Where Customers have not opted out, the use of Customer Data for AI training is permitted under our Terms of Service. Customers represent and warrant that their own privacy notices and agreements with End Clients permit this processing. See Section 18 for Customer responsibilities.
ShineCRM (and any successor entity) owns all AI models, including any models trained or improved using Customer Data.
5.4 To Improve and Develop the Service
- Analyze how Customers use the Service to identify bugs, performance issues, and feature opportunities.
- Conduct internal research and product development.
- Test new features.
5.5 To Communicate with You
- Send transactional messages required to operate your account.
- Send marketing emails about new features, tips, and offers, only if you have opted in. You can unsubscribe at any time using the link in any marketing email.
- Respond to your inquiries.
5.6 To Protect the Service and Comply with Law
- Detect, investigate, and prevent fraud, abuse, security incidents, and policy violations.
- Enforce our Terms of Service.
- Comply with legal obligations, court orders, and lawful government requests.
- Establish, exercise, or defend legal claims.
5.7 With Your Consent
For any purpose disclosed to you at the time we collect the information or with your consent.
6. Legal Bases for Processing
(For users in the EEA, UK, and similar jurisdictions)
Where applicable law requires us to identify a legal basis for processing personal information, we rely on:
- Performance of a Contract: To provide the Service you have signed up for.
- Legitimate Interests: To operate, secure, and improve the Service, train and improve AI models that power the Service, prevent fraud, conduct internal analytics, and operate, monitor, debug, and support our AI features, including maintaining the internal AI activity log and providing the staff support access described in Sections 7.6 and 15.1, where these interests are not overridden by your rights. We have assessed that this processing is necessary for these interests and is balanced by the safeguards described in those sections (least-privilege access, audit logging that affected administrators can review, and 30-day deletion of raw AI content).
- Consent: For marketing emails, optional cookies, and any other processing where consent is required. You may withdraw consent at any time.
- Legal Obligation: To comply with applicable laws and regulations.
For End Client data, ShineCRM acts as a processor on behalf of Customers, who are responsible for establishing the legal basis for processing under their own agreements and notices to End Clients. Our processing of End Client data on a Customer's behalf, including the operating and support access and the AI activity log described in Sections 7.6 and 15.1, is carried out on the Customer's documented instructions and is governed by our Data Processing Agreement.
7. How We Share Your Information
We share personal information only as described below. We do not sell personal information.
7.1 Service Providers (Sub-Processors)
We share information with third-party service providers who help us operate the Service. These providers are contractually required to handle data securely and only on our instructions. Our current sub-processors include:
| Provider | Purpose | Data Region |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Stripe | Online payment processing, subscription billing, card-on-file | United States |
| Square | In-person payments (Tap to Pay, Square Reader), card-on-file | United States |
| Twilio | SMS messaging, voice calling, voicemail and call recording storage | United States |
| Resend | Transactional and marketing email delivery, inbound email parsing | United States |
| Anthropic | AI inference (Claude models) | United States |
| OpenAI | AI inference (GPT models) | United States |
| AI inference (Gemini), Google Calendar API integration, infrastructure | United States and global | |
| Attio | Internal CRM sync (ShineCRM Customer organization name and owner identity for sales operations) | United States |
| Cloudflare | Content delivery, DDoS protection, marketing site and operator dashboard hosting | Global |
| Expo (EAS) | Mobile app build infrastructure and over-the-air update delivery | United States |
| Apple (APNs) | Push notification delivery to iOS devices, including VoIP push for incoming calls | United States |
| Google (Firebase Cloud Messaging) | Push notification delivery to Android devices | United States and global |
| Sentry or equivalent | Error tracking and performance monitoring | United States |
| PostHog, Mixpanel, or equivalent | Product analytics | United States |
| LogRocket or equivalent | Session recording and debugging | United States |
| GitHub (a Microsoft company) | Source code hosting and issue tracking for support and bug resolution, including bug reports submitted through the Service | United States |
| Cursor (Anysphere, Inc.) | AI-assisted code review and bug fixing based on issues created from bug reports | United States |
We may add, remove, or replace sub-processors as our infrastructure evolves. We will update this list when material changes occur.
7.2 With Your Customers and Their Authorized Users
If you are a Customer, your authorized team members can access the data in your ShineCRM account. If you are an End Client of one of our Customers, your data is accessible to that Customer and their authorized users.
7.3 Business Transfers
If ShineCRM is acquired, merged, sold, or otherwise transfers ownership or assets, your information may be transferred to the acquiring entity as part of that transaction. We will notify you of any such transfer and your rights regarding your data.
7.4 Legal and Safety
We may disclose information when we believe in good faith that disclosure is necessary to comply with applicable law, enforce our Terms of Service, protect the rights or safety of ShineCRM or others, or detect and prevent fraud and security issues.
7.5 With Your Consent
We may share information for any other purpose disclosed to you and with your consent.
7.6 ShineCRM Internal Access
Because ShineCRM is early-access software built and run by a solo developer, ShineCRM's founder, Sean van Gessel, and any authorized support personnel may access Customer Data and End Client Data, including the content of communications processed through the Service, at the operator's discretion, for support, debugging, troubleshooting, monitoring AI behavior, product development and improvement, operating administrative tooling (including the AI activity log described in this Section and Section 15.1), enforcing our Terms of Service, and complying with legal obligations. By using the Service you agree to this access, as set out in Section 6.7 of the Terms of Service. We expect to narrow this access and add further safeguards as the product matures.
We aim to keep this access to what we reasonably need. Most cross-tenant administrative dashboards display aggregate metrics and structural metadata only, for example: organization name, billing usage, AI model identifiers, token counts, decision outcomes, latency, and cost. Raw Customer Data such as SMS and email message bodies and call recordings is not duplicated into those dashboards; it remains in tenant-scoped tables that authorized personnel can access under the controls described below and in Section 15.1.
AI activity log. One specific example of this access is the AI activity log. To operate, monitor, debug, and support our AI features, ShineCRM maintains an internal AI activity log. For every AI feature, this log records the full text we send to the AI provider and the full text the AI provider returns. The text we send can include the content of your customers' messages, your team's notes, call transcripts, and other Customer Data that the relevant feature passes to the AI, and the text returned can include AI-drafted reply bodies. Authorized ShineCRM personnel holding the super-administrator role can view these raw AI request and response records across organizations through the administrative surface, for the limited purposes of operating, supporting, and debugging the AI service on your behalf. We rely on this exception because we cannot reliably diagnose and support AI behavior without seeing what was actually sent to and returned by the AI provider.
We apply specific safeguards to this access:
- Least-privilege gating. Access to Customer Data, and in particular to the AI activity log, is gated behind an explicit super-administrator role. The list of users holding this role is small (initially: the founder only) and is maintained internally.
- Audit logging you can review. Every access by ShineCRM personnel to a specific Customer's records through the administrative surface, including each time a raw AI activity log entry is opened, is recorded in an append-only access log. The log captures the identity of the accessor, the action taken, the table and row identifier accessed, the affected organization, and the time of access. Tenant administrators can view the access log entries that touched their own organization through their account dashboard, and may also request a copy by emailing sean@shinecx.com. We will produce the log in response to a data subject inquiry, a regulator request, or a court order.
- Short retention of raw content. The raw request and response text in the AI activity log is automatically and permanently deleted 30 days after each AI call by a scheduled process, after which only metadata (organization, AI surface, model, token counts, cost, and success or error status) remains.
- Deletion on organization deletion. All AI activity log records for an organization, including any remaining metadata, are deleted when that organization is deleted.
Lawful basis. ShineCRM carries out this access and logging as your service provider and data processor, on your instructions, to provide and support the Service. Where data protection law requires a lawful basis, we rely on the performance of our contract with you and on our legitimate interests (and yours) in operating, securing, debugging, and supporting the AI features, balanced against the rights of affected individuals. This basis is recognized under PIPEDA and BC PIPA, under Quebec Law 25, and under Article 6(1)(f) of the GDPR and UK GDPR (legitimate interests). Under the California Consumer Privacy Act and California Privacy Rights Act, ShineCRM acts as a service provider: we do not sell or share this data and we do not use it for any purpose other than providing the Service. Our processing of End Client Data, including the AI activity log, is governed by our Data Processing Agreement, and you remain responsible for the disclosures and consents your own privacy notice must provide to your End Clients (see Sections 5.3 and 18).
8. International Data Transfers
ShineCRM is operated from Canada, and most of our infrastructure is located in the United States. If you are accessing the Service from outside Canada or the United States, your information will be transferred to, processed in, and stored in the United States and other countries where our service providers operate.
These countries may have data protection laws that differ from those in your country. By using the Service, you acknowledge and agree to the transfer of your information to these jurisdictions.
For users in the European Economic Area, United Kingdom, and Switzerland: where required, we rely on appropriate safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms when transferring personal information internationally.
9. Cookies and Tracking Technologies
We and our service providers use cookies, web beacons, pixels, local storage, and similar technologies on our website and dashboard to keep you signed in, remember your preferences, measure and analyze how the Service is used, detect and prevent fraud, and deliver and measure marketing campaigns.
On our marketing website, analytics cookies are only set if you accept them. When you first visit, a banner asks for your choice. If you decline or make no choice, analytics runs in a cookieless mode: we still measure the visit (pages viewed, referral source), but nothing is stored on your device and you are not recognized across visits. Your choice itself is remembered in local storage, which is strictly necessary and does not require consent. You can change your mind by clearing your browser data for our site.
In the signed-in dashboard and mobile app, we use cookies and local storage to keep you signed in and to operate the analytics and session replay described in Section 4.3, on the legal bases described in Section 6.
You can also control cookies through your browser settings. Disabling certain cookies may affect functionality.
10. Data Retention
We retain personal information for as long as necessary to provide the Service and fulfill the purposes described in this policy.
- Active Accounts: We retain your account data for as long as your account is active.
- Cancelled Accounts: After you cancel or delete your account, we delete or anonymize your account data and End Client data within 30 days, except where retention is required for legitimate business or legal purposes.
- AI Activity Log: The full request and response text recorded in our internal AI activity log (see Sections 7.6 and 15.1) is automatically deleted 30 days after each AI call. After that, only metadata (organization, AI surface, model, token counts, cost, and success or error status) is retained, and all of an organization's AI activity log records are deleted when that organization is deleted.
- Backups: Deleted data may persist in encrypted backups for a limited period before being overwritten.
- Stripe Data: Payment-related records held by Stripe are retained according to Stripe's policies and applicable financial regulations.
- Anonymized and Aggregated Data: Once irreversibly anonymized or aggregated, data may be retained indefinitely for analytics, research, and AI model improvement.
- AI Models: If we use Customer Data to train AI models in the future (see Section 5.3), those models may be retained indefinitely. Account deletion would not remove a Customer's prior data contribution from previously trained models, as retraining or rolling back models is not technically feasible.
- Legal Holds: We may retain information longer when required by law or to establish, exercise, or defend legal claims.
11. Your Privacy Rights
Depending on where you live, you may have the following rights over your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that we correct inaccurate or incomplete information.
- Deletion: Request that we delete your personal information.
- Portability: Request a copy of your data in a structured, machine-readable format.
- Restriction: Request that we limit how we process your information.
- Objection: Object to processing based on legitimate interests or for direct marketing.
- Withdraw Consent: Withdraw consent for processing that is based on consent.
- Opt Out of AI Training: Customers can opt out at any time through account settings or by emailing sean@shinecx.com.
- Automated Decisions: Request human review of significant decisions made solely by automated means.
- Non-Discrimination: Not be discriminated against for exercising your rights.
- Complain to a Regulator: Lodge a complaint with your local data protection authority.
To exercise any of these rights, email sean@shinecx.com. We will respond within 30 days. We may need to verify your identity before fulfilling your request.
If you are an End Client whose data was entered into ShineCRM by one of our Customers, please direct your request to that Customer first, since they control your data. We will assist them in fulfilling valid requests.
Objecting to or stopping the AI activity log. The AI activity log records the text exchanged with AI providers as part of operating the AI features on the Customer's instruction. Because the Customer (operator) controls whether AI is used for a given individual, the operative way to stop further AI processing of an individual is for the Customer, as controller, to cease AI processing for that individual (for example, by disabling the relevant AI feature or excluding that End Client) or to delete the organization. ShineCRM will honor a documented controller instruction to stop AI processing for a given End Client. Raw content already recorded is deleted 30 days after each AI call (see Section 10), and all AI activity log records are deleted when the organization is deleted.
Self-Serve Options
You can exercise most rights directly within the Service: export your data from your account dashboard, edit your account information, delete portions of your account data, toggle AI training opt-out, and permanently delete your entire organization and account from the mobile app (Settings → Delete account) or from the web operator dashboard. Deletion is immediate and cascades through all of your organization’s data, cancels any active subscription, and releases any provisioned phone number. If you need help with deletion or want to verify it completed, email sean@shinecx.com.
12. Region-Specific Disclosures
12.1 Canada (PIPEDA, Quebec Law 25, BC PIPA)
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (Law 25), and BC's Personal Information Protection Act (PIPA). You have the right to access and correct your personal information and to file a complaint with the Office of the Privacy Commissioner of Canada or your provincial regulator.
For Quebec residents: ShineCRM's Privacy Officer is Sean van Gessel, reachable at sean@shinecx.com.
12.2 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)
If you are located in the EEA, UK, or Switzerland, you have the rights described in Section 11. You may also lodge a complaint with your local supervisory authority. ShineCRM does not currently maintain an EU representative. For privacy inquiries, contact sean@shinecx.com.
12.3 California (CCPA / CPRA)
California residents have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including the right to know, correct, delete, and opt out of sale or sharing. ShineCRM does not sell or share personal information for cross-context behavioral advertising.
To exercise California rights, email sean@shinecx.com.
12.4 Other US States
Residents of other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and others) may have similar rights. Contact sean@shinecx.com to exercise these rights.
13. Marketing and Anti-Spam Compliance (CASL)
If you are in Canada, we comply with Canada's Anti-Spam Legislation (CASL). We send marketing emails only to recipients who have provided express or implied consent. Every marketing email includes our identity and contact information and a clear and functional unsubscribe link that takes effect within 10 business days.
Transactional and account-related messages are sent regardless of marketing preferences and do not require separate consent. You can opt out of marketing at any time by clicking unsubscribe in any marketing email or emailing sean@shinecx.com.
14. Automated Decision-Making and AI
ShineCRM uses automated processing and AI to support core features, which may include lead scoring and prioritization, automated message drafting and suggested replies, pricing suggestions, schedule optimization and route planning, call transcription and summarization, and anomaly detection.
These features assist Customers in making decisions but do not produce legal or similarly significant effects on End Clients without human review by a Customer. If you believe an automated decision has had a significant effect on you and you would like human review, contact sean@shinecx.com.
To operate, monitor, debug, and support these features, ShineCRM records the text exchanged with AI providers in an internal AI activity log. The least-privilege access controls and audit logging that govern that log are described in Sections 7.6 and 15.1, and the 30-day retention of its raw content is described in Section 10.
15. Security
We take reasonable technical and organizational measures to protect personal information, including encryption of data in transit using HTTPS/TLS, encryption of data at rest, Row-Level Security (RLS) policies in our database, salted password hashing, access controls limiting production database access to authorized personnel, and security monitoring and error tracking.
No security system is perfect. You are responsible for keeping your password secure and notifying us immediately if you suspect unauthorized access. In the event of a data breach, we will notify you and applicable regulators as required by law.
15.1 Internal Access Controls and Audit Logging
Production database access is limited to authorized personnel. Tenant data is segregated by Row-Level Security policies that scope every read and write to the calling user's organization. Cross-tenant access by ShineCRM personnel is gated behind an explicit super-administrator role recorded in a dedicated database table.
Every action taken by a super administrator against tenant-identifiable records through the administrative dashboards, including viewing the AI decisions log, opening a specific decision record, opening a raw AI activity log entry (the full request sent to, or response returned by, an AI provider), editing a global AI prompt or trigger setting, editing a tenant's AI instructions, cancelling a scheduled follow-up, clearing a contact's AI timer, or dismissing a Suds suggestion, is recorded in an append-only audit log. Each entry captures the identity of the accessor (auth user ID and email), the action performed, the table name and row identifier touched, the affected organization identifier, the time of access, and any contextual metadata about the action.
Audit log entries cannot be modified or deleted by any application user, including super administrators. Tenant administrators can view the audit log entries that touched their own organization at any time through their account dashboard, and may request a copy or export by emailing sean@shinecx.com. Audit log entries are retained for a minimum of twenty-four (24) months.
The AI decisions metadata surface stores structural metadata about each autonomous AI decision (model identifier, token counts, decision outcome category, latency, cost, and structural counts of messages and follow-ups passed to the model) and does not by itself store the conversation text.
Separately, to operate, monitor, debug, and support the AI features, ShineCRM maintains an internal AI activity log that, for every AI feature, records the full text sent to the AI provider (which can include conversation text and other Customer Data passed to the AI) and the full text returned (including AI-drafted reply bodies). Authorized personnel holding the super-administrator role can view these raw records across organizations through the administrative surface, for that limited purpose. Every such view is itself recorded in the append-only audit log described above, which the affected tenant's administrators can review. To limit how long this content is retained, the raw request and response text is automatically and permanently deleted 30 days after each AI call by a scheduled process (see Section 10), after which only metadata (organization, AI surface, model, token counts, cost, and success or error status) remains. AI activity log records are restricted to the super-administrator role by Row-Level Security policies, and they are deleted when the related organization is deleted.
16. Children's Privacy
The Service is intended for users 18 years of age or older. We do not knowingly collect personal information from children under 18. If we learn that we have collected information from a child under 18, we will delete it. Contact sean@shinecx.com if you believe a child has provided us with personal information.
17. Third-Party Links and Services
The Service may contain links to third-party websites or integrate with third-party services that we do not operate. This Privacy Policy does not apply to those third parties. We encourage you to review their privacy policies before providing them with personal information.
18. Customer Responsibilities
If you are a Customer using ShineCRM to manage End Client data, you are responsible for maintaining your own privacy notice and service agreements with End Clients that disclose the use of third-party software, AI processing, call recording, and data sharing; obtaining all consents required by applicable law; honoring privacy rights requests from End Clients; and configuring the Service in compliance with applicable law.
You are also responsible for ensuring that any bug reports, support requests, or other free-text submissions you send to us do not include End Client personal information or other sensitive data that is not necessary to resolve your request. The Service automatically captures the technical context needed to diagnose issues, so you do not need to include personal details in a report.
ShineCRM provides template language that Customers may incorporate into their own privacy notices as a starting point. Use of the template does not constitute legal advice; Customers should consult their own counsel.
Our Data Processing Agreement (DPA) governs how ShineCRM processes End Client Data on your behalf as your processor, including the operating and support access, AI activity log, sub-processors, security measures, breach notification, and deletion terms described in this policy. By accepting our Terms of Service at sign-up, you also agree to the DPA. If you require a countersigned copy, email sean@shinecx.com.
19. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 7 days before the changes take effect. For minor changes, we may make changes effective immediately with notice posted in the Service or on our website. For changes required by law or to address urgent security matters, changes may take effect immediately.
Your continued use of the Service after the effective date of an updated policy constitutes acceptance of the changes.
20. Governing Law and Disputes
This Privacy Policy is governed by the laws of the Province of British Columbia and the federal laws of Canada applicable in BC. Any disputes arising out of or related to this Privacy Policy will be resolved in accordance with the dispute resolution provisions of our Terms of Service, except where applicable law provides you with a non-waivable right to seek resolution elsewhere.
21. Contact Us
Email: sean@shinecx.com
Mailing Address: 1279 Derby Rd, Victoria, BC, Canada