Back to home

The Standard CRM · Legal

Privacy Policy

Effective Date:June 8, 2026 · Version: 2.0

Applies to www.thestandardcrm.io and related services.

1. Introduction & Our Two Roles

This Privacy Policy describes how LB3 Legacy Group, LLC, an Arizona limited liability company, doing business as The Standard CRM (The Standard, we, us, or our), handles personal information.

We play two different roles, and the role determines who is responsible for a given set of data:

  • As a controller/business. For our own website visitors and for the businesses and individuals who create accounts with us (Customers), we determine how and why we process personal information, and this Policy applies directly.
  • As a service provider/processor. When our Customers use the platform to manage and communicate with their own leads, prospects, and clients (Contacts), we process that Contact information on the Customers behalf and under the Customers instructions. The Customer is the controller/business of that data. If you are a Contact and want to exercise rights over your information, please contact the business that holds the relationship with you; we will assist that business in responding.

For Contact data that we process on behalf of Customers, we act as a service provider/processor under our agreement with the Customer, including any applicable Data Processing Addendum. That addendum may address confidentiality, security, subprocessors, assistance with privacy requests, deletion or return of Customer Data, audit cooperation, and restrictions on using Contact data outside the Customers documented instructions.

By using the Services, you acknowledge this Policy. If you do not agree, do not use the Services.

2. Mobile & SMS Information

Where you provide a mobile phone number to us (for example, for account verification, support, or platform notifications), we use it for those purposes and to operate the Services.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors and service providers is permitted only as needed to provide support services, messaging delivery, platform operations, security, compliance, opt-out processing, or customer service. All sharing categories described in this Privacy Policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties, except aggregators, carriers, and providers of the text messaging services as necessary to provide the Services. Standard message and data rates may apply. You can opt out of our service text messages at any time by replying STOP, and reply HELP for assistance.

When our Customers send messages to their own Contacts through the platform, the Customer is responsible for obtaining the required consent and for honoring opt-outs, as described in our Terms of Service.

3. Information We Collect

3.1 Information you provide to us (Customers & visitors)

  • Account & identity: name, business name, email, phone number, username, password, and role.
  • Billing: billing contact, plan, and transaction history. Card details are collected and processed by our payment processor; we do not store full card numbers.
  • Professional details: information you provide about your business, license, or industry (for example, during onboarding or A2P registration).
  • Support & communications: messages, inquiries, and feedback you send us.

3.2 Contact data we process for our Customers

When Customers use the platform, they submit and generate data about their Contacts, which we process on their behalf. This may include: name and contact details (phone, email, address); lead source and status; consent and opt-out records; property- and policy-related information relevant to the Customers business; notes; and the content, metadata, recordings, and transcripts of calls, texts, and emails sent or received through the platform.

3.3 Information we collect automatically

  • Device & usage: IP address, browser and device type, pages viewed, actions taken, and timestamps.
  • Cookies & similar technologies: see Section 8.
  • Communications logs: records needed to operate, secure, bill, and document the Services (including delivery status and compliance/decision logs).

3.4 Information from third parties

We and our Customers may receive information from integrated third-party services, including the underlying CRM infrastructure (HighLevel / GoHighLevel), data-enrichment providers (such as property-data sources), telephony/messaging carriers, and our payment processor. Customers are responsible for ensuring they have a lawful basis to use any data they obtain from such sources.

4. How We Use Information

We use personal information to:

  • Provide, operate, maintain, and improve the Services and their features;
  • Create and administer accounts, Sub-Accounts, and integrations;
  • Process payments, manage subscriptions, and prevent fraud;
  • Provide support and respond to inquiries;
  • Secure the Services, monitor for abuse, and enforce our Terms;
  • Generate and retain compliance and decision logs that help Customers document consent, opt-outs, and communications activity;
  • Send administrative and service communications (and, where permitted, product updates you can opt out of);
  • Comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims.

We do not use Contact data that we process on a Customers behalf for our own independent marketing purposes.

5. AI Voice, Call Recordings & Transcripts

The platform offers AI-assisted voice calling, transcription, and automated decisioning. When these features are used, audio, transcripts, and related metadata may be processed by us and by our AI and telephony vendors to deliver, summarize, route, and document the communication, and to operate and improve platform functionality.

We do not use Customer call content, Contact communications, call recordings, transcripts, SMS/MMS message content, email message content, or Contact data to train third-party general-purpose AI models. We may process such information to provide, secure, troubleshoot, monitor, support, and improve The Standard CRM Services, including quality assurance, safety, compliance logging, routing, summarization, transcription, and reliability. Any use of Customer Data for product improvement will be limited to providing and improving the Services and, where feasible, will use aggregated, de-identified, or anonymized data. Our AI, telephony, messaging, transcription, and platform vendors may process Customer Data only as our service providers/subprocessors and only as necessary to provide the Services, unless the Customer separately authorizes another use in writing.

Customers control whether and how AI Voice, call recording, call monitoring, transcription, summarization, and automated workflows are used for their Contacts. Customers are responsible for configuring these features lawfully, providing required notices, obtaining required consents, and honoring opt-outs and revocations. The Standard CRM provides software tools and does not determine whether a particular Customer campaign, script, consent flow, or recording practice is lawful.

6. Sensitive & Regulated Information

The Services are not designed to collect or process Social Security numbers, full financial account numbers, government identification numbers, protected health information, consumer credit reports, or other highly sensitive information unless expressly authorized by us in writing and supported by an applicable agreement.

Customers are responsible for ensuring that any sensitive, insurance-related, financial, health-related, real-estate, consumer-reporting, or other regulated information they submit to the Services is collected, used, disclosed, and retained in compliance with applicable law. The Standard CRM does not provide HIPAA, GLBA, FCRA, insurance-regulatory, real-estate-licensing, mortgage, consumer-reporting, or legal compliance services unless expressly stated in a separate written agreement.

7. How We Share Information

We do not sell personal information for money, and we do not share SMS/mobile opt-in data with third parties for their marketing. As stated in Section 2, no mobile information will be shared with third parties or affiliates for marketing or promotional purposes, and all sharing categories described in this Policy exclude text messaging originator opt-in data and consent, which will not be shared with any third parties except aggregators, carriers, and providers of the text messaging services as necessary to provide the Services. We share information only as described below:

7.1 Service providers (subprocessors)

We share information with vendors that perform services for us under contract, only as needed to provide the Services. The categories of subprocessors we use, and representative or named providers, include:

CategoryProvider
CRM & platform infrastructureHighLevel (GoHighLevel)
Telephony, SMS/MMS & dialerOur telephony, messaging, and dialer providers and the carriers that route calls and messages
A2P 10DLC registration & campaign reviewThe Campaign Registry and our messaging provider
AI voiceOur AI voice provider
Language models, transcription & summarizationOur language-model and transcription providers
Hosting, storage & databaseOur cloud hosting and managed-database providers
Payment processingStripe
Email deliveryOur email-delivery provider
Product analyticsOur product-analytics provider
Data enrichmentOur property/contact data-enrichment provider (where used)
Direct mailOur direct-mail provider (where used)

A current list of the specific subprocessors we use is available on request at privacy@thestandardcrm.io. We may update our subprocessors from time to time as our service providers change.

7.2 At a Customers direction

For Contact data, we share or transfer information as the relevant Customer instructs through their use of the Services and integrations they enable.

7.3 Legal & safety

We may disclose information to comply with law, respond to lawful requests and legal process, enforce our Terms, protect our rights, property, and safety or that of others, and detect and prevent fraud or abuse.

7.4 Business transfers

If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

8. Cookies, Tracking & Your Privacy Choices

We use cookies and similar technologies to operate the site, remember preferences, secure sessions, and understand usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.

We do not use our website or the Services to sell personal information or to share it for cross-context behavioral advertising as those terms are defined under applicable state privacy laws. Where applicable, we honor recognized opt-out preference signals such as the Global Privacy Control (GPC). If you would like to make a privacy choice or exercise a right described in Section 11, contact us at privacy@thestandardcrm.io.

9. Data Retention

We retain account, billing, security, support, and administrative records for as long as needed to operate our business and meet legal, tax, accounting, dispute-resolution, and security obligations.

We retain consent records, opt-out records, suppression records, campaign registration records, call/SMS/MMS/email logs, AI decision logs, call recordings, and transcripts for the period needed to provide the Services, document compliance, resolve disputes, and satisfy applicable statutes of limitation, unless a shorter retention period is configured by the Customer or required by law. Following account termination, Customer Data will be made available for export for the period stated in our Terms of Service and then deleted or de-identified in the ordinary course, subject to legal holds and compliance obligations.

10. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, and tenant isolation between Sub-Accounts. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and for the security of data within your own account.

If we become aware of a security incident affecting personal information that requires notice under applicable law or our agreement with a Customer, we will notify the affected Customer or individual as required by applicable law. For Contact data processed on behalf of a Customer, the Customer is responsible for determining whether notice to affected Contacts, regulators, or others is required, and we will reasonably assist the Customer as required by law and our agreement.

11. Your Privacy Rights

Depending on where you live, you may have rights over your personal information. Most U.S. states with comprehensive privacy laws (including California, Virginia, Colorado, Connecticut, Texas, Oregon, and others) provide some combination of the following rights, subject to exceptions:

  • Access / know the personal information we hold about you and how we use and share it;
  • Correct inaccurate personal information;
  • Delete personal information;
  • Portability: receive a copy in a portable format;
  • Opt out of the sale or sharing of personal information, targeted advertising, and certain profiling;
  • Limit use of sensitive personal information, where applicable;
  • Non-discrimination for exercising your rights;
  • Appeal a denial of a request, where the applicable state law provides for an appeal.

11.1 California (CCPA/CPRA)

California residents have the rights to know, access, correct, delete, and to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information. We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are defined under the CCPA. We do not knowingly process the personal information of individuals we know to be under 16 for sale or sharing. You may use an authorized agent to submit a request.

11.2 How to exercise your rights

Submit a request to privacy@thestandardcrm.io. We will verify your request (which may require confirming information that matches our records) and respond within the timeframe required by applicable law. There is no fee for most requests.

11.3 If you are a Contact (lead/client of one of our Customers)

If your information is in our platform because a business you interacted with uses The Standard CRM, that business is the controller of your data. Please direct your privacy request to that business. If you submit a privacy request directly to us, we may ask for information needed to identify the relevant Customer account, such as the phone number, email address, message sender, caller ID, or business that contacted you. If we cannot reasonably identify the Customer, we may be unable to fulfill the request directly and may ask you to contact the business that contacted you. We will refer your request to the relevant Customer and assist them in responding, as required by law.

12. Childrens Privacy

The Services are intended for business use by adults. They are not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

13. Third-Party Links & Services

The Services may link to or integrate with third-party websites and services that we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them. Review those policies before providing information.

14. U.S. Scope

The Services are intended for use by businesses in the United States, and information is processed in the United States. We do not intend to offer the Services to individuals in the European Economic Area, the United Kingdom, or other regions whose laws would attach to that processing. If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with local law.

15. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice (for example, by email or in-app). Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

16. Contact Us

For privacy questions or to exercise your rights:

LB3 Legacy Group, LLC d/b/a The Standard CRM

Attn: Privacy

Email: privacy@thestandardcrm.io