AllSportsCRM Privacy Policy
AllSportsCRM LLC ("Company," "we," "our," or "us") provides a business-to-business customer relationship management, sales automation, and lead management software platform (the "Platform" or "Service"). This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our website, subscribe to our software, or interact with communications sent through our Platform.
Scope & Roles (Controller vs. Processor)
- AllSportsCRM as a Data Controller: We collect and process personal data directly from facility owners, coaches, staff, and authorized representatives ("Subscribers") who register, purchase, or administer an AllSportsCRM account.
- AllSportsCRM as a Data Processor: Subscribers ingest, import, and capture personal data concerning their prospective, current, and former clients, parents, athletes, and team managers ("End-Users"). In this capacity, the Subscriber remains the primary Data Controller, and AllSportsCRM processes such data solely on behalf of the Subscriber in accordance with this Policy and our Terms of Service.
Information We Collect
- Account & Billing Data: Name, business name, physical address, business email address, direct telephone number, account credentials, and encrypted billing/payment details processed via third-party PCI-DSS compliant gateways (e.g., Stripe).
- Subscriber Customer Data (Ingested End-User Data): Names, email addresses, mobile phone numbers, athlete profiles, developmental baselines, registration histories, notes, and conversational records collected via web forms, landing pages, QR code scans, manual entries, or integrated application programming interfaces (APIs).
- Communication Content & Metadata: Inbound and outbound Short Message Service (SMS), Multimedia Messaging Service (MMS), email messages, timestamps, message delivery statuses, open rates, and click tracking.
- Technical & Usage Information: IP addresses, browser types, device identifiers, session activity, operating system details, and standard cookie data collected automatically during platform interactions.
How We Use Collected Information
- Providing, maintaining, securing, and optimizing our parallel CRM architecture.
- Executing automated 2-way SMS/MMS messaging, speed-to-lead follow-ups, and email nurture workflows on behalf of Subscribers.
- Processing subscription billing, renewals, invoices, and accounting records.
- Delivering product updates, critical service notifications, onboarding support, and security alerts.
- Enforcing compliance with carrier regulations, industry guidelines (CTIA), and applicable laws (TCPA, CAN-SPAM).
SMS & Mobile Data Privacy (Carrier & A2P 10DLC Compliance)
AllSportsCRM strictly complies with carrier registration frameworks (A2P 10DLC) and cellular guidelines:
- No Selling or Sharing of SMS Data: Mobile information, phone numbers, and text messaging opt-in data will NOT be sold, rented, leased, or shared with third parties or affiliates for marketing or promotional purposes under any circumstances.
- Restricted Data Sharing: Any sharing of telephone numbers with essential infrastructure subprocessors (e.g., telecommunication gateway providers such as Twilio) is conducted strictly to route and deliver your SMS transmissions.
- Opt-In Integrity: Opt-in data is gathered solely through direct consumer interaction with web forms, QR codes, or explicit written consent. Consent to receive promotional texts is never a condition of purchase.
Third-Party Service Providers (Subprocessors)
We partner with specialized third-party vendors to deliver essential software infrastructure:
- Telecommunications & Email Delivery: Cloud communications APIs and SMTP relays for SMS and email transmissions.
- Hosting & Database Infrastructure: Secure cloud hosting environments with physical and logical access controls.
- Payment Gateways: PCI-compliant payment processors. We do not directly store complete credit card numbers on our local servers.
All third-party subprocessors are bound by written data protection agreements requiring compliance with industry security and confidentiality standards.
Data Retention & Account Deletion
- Subscriber account information is retained for the duration of the active subscription plus any statutory retention periods required for tax and financial auditing.
- End-User data stored in a Subscriber’s CRM workspace is retained according to the Subscriber's configuration. Upon termination of an account, Subscribers may export their contact databases within thirty (30) days, after which data will be permanently purged from active databases.
Security Measures
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, alteration, or misuse. These protections include SSL/TLS encryption in transit, encrypted storage protocols, role-based database permissions, and routine infrastructure monitoring.
Your Legal Rights
- Depending on your jurisdiction (such as California under the CCPA/CPRA), you may have the right to request access to, correction of, or deletion of your personal information, or to request data portability.
- Subscribers may exercise these rights directly through account settings or by contacting privacy@allsportscrm.com.
- End-Users whose data was entered into the Platform by a Subscriber should direct requests directly to the respective sports facility (Data Controller).
Privacy requests and questions about this policy can be sent to privacy@allsportscrm.com.