Privacy Policy
SharpClose is a communications platform, and communications are personal. This policy explains — in plain language — what we collect, why, how we protect it, and the rights you have over it. Compliance isn't a footnote for us; it's the product.
01 Scope & our two roles
This policy applies to sharpclose.com, the SharpClose application, our APIs, and the SMS, voice, and CRM services we provide (together, the "Services"). It covers everyone we interact with: visitors to our site, the businesses that hold SharpClose accounts ("Customers"), the people who use those accounts, and the individuals our Customers communicate with through the platform.
Because we are a communications platform, we handle data in two distinct roles, and your rights depend on which applies:
- As a controller — for information about our Customers and account users: business verification records, login credentials, billing, and how you use the product. We decide how this data is handled, and this policy governs it directly.
- As a processor (service provider) — for the contact lists, message content, and call audio our Customers send through the platform to reach their own audiences. Here the Customer is the controller; they decide what to send and to whom, and their own privacy notice governs those individuals. We process that data only to deliver the Services and under our Customer agreement/Data Processing Addendum.
We deliver messages on our Customers' behalf — we don't choose who they contact. To access, correct, or delete your information, or to stop hearing from them, contact that business directly, or reply STOP to opt out of texts. We'll gladly route your request to the right Customer if you reach us.
02 Information we collect
Account & business-verification (KYB) data
Every SharpClose account is verified before it can send. To do that we collect information about the business and the person opening the account:
- Legal company name, business address, EIN/Tax ID, entity type, formation state and date, industry, and a description of goods and services.
- Supporting documentation you upload, such as an IRS/EIN confirmation letter.
- Contact details for the account owner and authorized signatory (name, title, email, phone).
- A one-time passcode we send by SMS to confirm a reachable phone number, plus the compliance attestations and typed e-signature you provide.
Credentials & profile
- Email address and a password, which we store only as a salted hash — we never store it in plain text.
- Team members you invite, their roles, and their activity within your workspace.
Billing & usage
- Plan, rate card, credit balance, and a metering ledger of the messages and minutes you use.
- Payment is handled by our payment processor; we receive confirmation and limited details (such as card brand and last four digits) but not full card numbers.
Technical & device data
- IP address, browser and device type, timestamps, and diagnostic logs generated when you use the Services — used for security, fraud prevention, and reliability.
03 Message & call content
To deliver the Services, the platform necessarily processes the communications that flow through it:
- SMS/MMS content — the body of the messages sent and received, sender and recipient phone numbers, and delivery status.
- Call data — the phone numbers on a call, timestamps, duration, and outcome (connected, voicemail, no-answer).
- Call recordings and voicemail — captured only when a Customer enables recording for their account, subject to the notice-and-consent requirements described in Section 05.
- Contact lists — the audiences our Customers upload or sync in order to reach them.
For this content we act as a processor on our Customers' behalf. We do not use the content of our Customers' communications, contact lists, or audiences for our own marketing, and we do not sell it.
04 How we use information
We use the information above only for purposes a reasonable person would expect from a communications platform:
- Provide the Services — route messages and calls, provision numbers, run the dialer, and keep your workspace working.
- Verify and secure accounts — perform business verification (KYB), confirm phone numbers, detect fraud and abuse, and protect against unauthorized access.
- Meter and bill — record usage against your rate card and produce the ledger you rebill from.
- Enable compliance — support A2P 10DLC campaign registration, honor Do-Not-Call and opt-out requests, enforce quiet hours, and maintain consent and audit trails.
- Support and communicate — respond to requests, send service and security notices, and share important changes.
- Improve reliability — monitor performance and troubleshoot, using aggregated or de-identified data wherever possible.
- Meet legal obligations — comply with law, lawful requests, tax and telecom recordkeeping, and enforce our terms.
We do not sell personal information, and we do not use the content of Customer communications to train general-purpose AI models.
05 Call recordings & notes
Where a Customer enables call recording or voicemail on their account, the platform captures and stores those recordings, along with call notes and dispositions, inside the Customer's workspace.
- Recording is off by default and captured only when a Customer turns it on for their account.
- Where recording is on, the Customer is responsible for providing any legally required notice and obtaining consent from call participants. Many jurisdictions require all-party consent; our tools support playing a disclosure at the start of a call.
- Recordings, notes, and summaries are stored within the Customer's isolated workspace and treated as Customer content under this policy.
06 Messaging consent & opt-out
Outbound messaging on SharpClose is built to be consent-first and to meet carrier and regulatory requirements, including the TCPA, CTIA guidelines, and A2P 10DLC.
- Recipients can opt out of text messages at any time by replying STOP; HELP returns assistance. We process these keywords automatically and maintain the opt-out.
- Customers are required to obtain proper consent before messaging, honor quiet hours, and scrub against Do-Not-Call lists — the platform provides the tools to do so.
Mobile information and text-messaging opt-in and consent data are never shared with, or sold to, third parties or affiliates for their marketing or promotional purposes. This category of data is excluded from all information-sharing described elsewhere in this policy. Full stop.
08 Data retention
We keep information only as long as we have a reason to — to provide the Services, meet legal and telecom recordkeeping duties, resolve disputes, and enforce our agreements.
When data is no longer needed, we delete or de-identify it. Customers can request deletion of workspace content subject to legal-hold and recordkeeping exceptions.
09 How we protect it
Security is designed into the platform, not added afterward:
- Encryption — data is encrypted in transit (TLS) and at rest (AES-256).
- Tenant isolation — each Customer's data is sealed at the database row so one workspace cannot read another's — isolation enforced in the data layer, not just the application.
- Credential protection — passwords are stored as salted Argon2 hashes; one-time passcodes are hashed, time-limited, and attempt-limited.
- Access controls — role-based permissions, least-privilege internal access, and audit logging of significant actions.
- Verified onboarding — business verification keeps anonymous and fraudulent senders off the platform in the first place.
No system is perfectly secure, but we work continuously to protect your information and to notify affected parties and regulators promptly if a breach ever occurs, as required by law.
10 Your privacy rights
Depending on where you live — including under the California Consumer Privacy Act (CCPA/CPRA), other U.S. state laws, and the EU/UK GDPR — you may have the right to:
- Know and access the personal information we hold about you.
- Correct inaccurate information.
- Delete your information, subject to legal and recordkeeping exceptions.
- Port a copy of your information in a portable format.
- Opt out of "sale" or "sharing" of personal information — which we don't do — and to limit the use of sensitive information.
- Non-discrimination for exercising any of these rights.
- Withdraw consent or object to certain processing where the GDPR applies, and to lodge a complaint with your supervisory authority.
For information we process on a Customer's behalf, we will refer your request to that Customer and support them in responding. To exercise a right, contact us using Section 15. We verify requests before acting and respond within the timeframes the law requires. You may use an authorized agent where permitted.
12 International transfers
We operate in the United States, and information may be processed there and in other countries where we or our subprocessors operate. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with additional measures where needed.
13 Children's privacy
SharpClose is a business tool intended for use by people 18 and older. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
14 Changes to this policy
We may update this policy as the Services and the law evolve. When we make material changes, we'll revise the "Last updated" date above and, where appropriate, notify you in the app or by email. Your continued use of the Services after an update means you accept the revised policy.
15 How to contact us
Questions about this policy, or want to exercise a privacy right? Reach our privacy team:
If you were contacted by a business using SharpClose and want to stop, reply STOP to any text, or contact that business directly — and we'll help route your request.