● LEGAL

Data Processing & Security

Effective July 10, 2026. ShiftScale Digital LLC. Headquartered in Michigan, US.

Effective date: July 10, 2026
Last updated: July 10, 2026

This page explains how ShiftScale Digital LLC ("ShiftScale," "we," "us") accesses, processes, and protects data in connection with the ShiftScale Digital agency services and the ShiftScale CRM platform (the "Services"), including data drawn from a Customer's connected business systems. It supplements our Privacy Policy.

1. Our role

For data about a Customer's own consumers ("Consumer Data"), the Customer is the controller and ShiftScale is a service provider / processor. We process Consumer Data only:

  • On the Customer's documented instructions;
  • To provide, maintain, secure, and improve the Services for that Customer; and
  • As required by applicable law.

We do not sell Consumer Data, do not use it for our own independent marketing, and do not use it to build profiles for purposes unrelated to serving that Customer.

2. Data from connected systems

With the Customer's authorization, the Services connect to third-party CRM, calendar, ad platform, analytics, email, and communications systems.

  • Least-privilege access. We request only data fields and permissions necessary for enabled features.
  • Purpose limitation. Data retrieved from a connected system is used solely to provide the Services to that Customer.
  • Direction of flow. We may read data from and/or write data back to connected systems, at the Customer's direction.
  • Authorization and revocation. The Customer controls the connection and may revoke it at any time.
  • No onward misuse. We do not repackage or resell connected-system data.

3. Categories of data processed

Depending on enabled features: business and account details; user credentials/identifiers; consumer contact details; sales, service, and appointment records; communications content and metadata (calls, texts, emails, chat); ad-platform performance data; website analytics data; and usage/technical data.

4. Sub-processors (by category)

We engage vetted third parties to help deliver the Services. They may process data only to perform services for us and are bound by confidentiality and data-protection obligations. Categories include:

  • Cloud hosting and database infrastructure (United States).
  • Communications infrastructure for voice, SMS, and email delivery.
  • AI/model providers that generate messages, summaries, and recommendations from provided content.
  • Advertising platforms (Google Ads, Meta, and similar) for campaign management on behalf of Customers.
  • Payment processing for billing.
  • Analytics, logging, and error-monitoring to operate and secure the Services.

We identify sub-processors by category rather than by name. A named, itemized sub-processor list is available on request where required by a Customer agreement or applicable law.

5. Security measures

We maintain administrative, technical, and organizational safeguards appropriate to the nature of the data, including:

  • Encryption of data in transit (TLS) and at rest;
  • Access controls — role-based, least-privilege access for our personnel, and per-Customer data isolation;
  • Secrets management for credentials and API keys;
  • Authentication controls for platform access;
  • Auditing and logging of significant actions;
  • Network and application controls with reputable U.S.-based infrastructure providers; and
  • Change management and monitoring.

No safeguards can guarantee absolute security. We do not currently claim any third-party security certification (such as SOC 2, ISO 27001, PCI DSS, or HIPAA); we describe our actual operational controls above and will update this page if our certifications change.

6. Data retention and deletion

Consumer Data is retained for the duration of the Customer's engagement and deleted or returned upon termination as set out in the applicable agreement, subject to legal retention requirements and routine, time-limited backups. Customers may request export or deletion of their data by contacting us.

7. Incident response

We maintain procedures to detect, investigate, and respond to security incidents. If we become aware of a breach affecting Consumer Data, we will notify the affected Customer(s) without undue delay and cooperate as required by applicable law and our agreements.

8. International processing

The Services are hosted and operated in the United States. By using the Services, Customers acknowledge that data is processed in the United States.

9. Contact

Security or data-processing questions: support@shiftscaledigital.com · (810) 788-7810
ShiftScale Digital LLC, headquartered in Michigan, US.

This page is provided for general informational purposes and does not constitute legal advice.