Effective Date: August 1, 2026
Last updated: August 26, 2026
This Privacy Policy describes how SHIFT Solutions LLC ("SHIFT," "we," "our," or "us") collects, uses, discloses, retains, and protects personal information in connection with SHIFT Operating System ("SHIFT OS"). SHIFT OS is provided primarily to U.S.-based business clients as part of professional services.
This Policy applies to SHIFT OS and related portals, CRM functions, forms, calendars, websites, workflows, communications, documents, reporting, AI-assisted features, support, and service-delivery tools. It is separate from any privacy policy for SHIFT's general public website.
In many cases, a SHIFT client decides what information to collect and how to use it. For that information, the client generally acts as the business or controller and SHIFT generally acts as its service provider or processor. The client's privacy policy governs the client's own practices. SHIFT may also process limited information for its own account administration, billing, security, support, legal compliance, and service operations.
Information may come from clients, Authorized Users, customers, leads, forms, calendars, websites, communications, connected accounts, integrations, service providers, and the operation of SHIFT OS. Clients decide which supported data sources and integrations to connect.
We may disclose information to the applicable client and its Authorized Users; HighLevel, LeadConnector, and other providers supporting hosting, CRM, communications, payments, analytics, AI, integrations, security, storage, and support; professional advisers, insurers, and auditors; a buyer or successor in a business transaction; and government or legal recipients when required or reasonably necessary to protect rights and safety.
Providers are authorized to process information as needed to support the requested services, security, troubleshooting, and legal compliance. We do not authorize them to use Client Personal Data for unrelated marketing. We do not sell Client Personal Data or use it for unrelated cross-context behavioral advertising.
Overseas production contractors may receive limited account permissions to build non-CRM assets such as sites, emails, templates, or creative materials. They are not authorized to access CRM contact records or Client Personal Data. Technology providers may process information from locations determined by their infrastructure and policies.
We do not share mobile information with third parties or affiliates for their own marketing or promotional purposes. We may disclose information to subcontractors and service providers supporting communications and customer service. Text-messaging originator opt-in data and consent will not be sold or shared for unrelated marketing. Aggregators, carriers, and communications providers may process that information only as necessary to provide or support messaging services.
These features are used only when requested and enabled for the applicable client. Message frequency varies. Message and data rates may apply. SMS recipients may reply STOP to opt out and HELP for assistance unless the message flow clearly provides another lawful method. Commercial email recipients may use the provided unsubscribe method. Calls may be recorded or transcribed only when enabled; the client is responsible for required notices and consent.
AI features may process prompts, instructions, messages, CRM context, contact information, brand materials, and generated outputs to provide requested functionality. AI can produce inaccurate, incomplete, biased, or inappropriate output. Clients are responsible for appropriate review and human oversight. SHIFT does not use Client Personal Data to train an unrelated model for other clients unless the client expressly agrees in writing.
SHIFT OS and related tools may use cookies, pixels, logs, analytics, and similar technologies to operate features, remember preferences, measure engagement, support workflows, improve performance, and secure accounts. Available browser or device controls may limit some technologies, but disabling them may affect functionality.
We retain information for as long as reasonably necessary to provide services, maintain accounts and records, comply with legal and contractual obligations, resolve disputes, enforce agreements, support security, and prevent fraud. Retention varies by information type, client instructions, platform capability, and legal requirements.
After the applicable service ends, the client ordinarily has 30 days to request or complete a standard available export, subject to payment, security, technical availability, provider capabilities, and the agreement. SHIFT may then delete Client Data from active systems. Information may remain for a limited period in routine backups or be retained for legal, tax, accounting, security, dispute, audit, or fraud-prevention purposes.
We use reasonable administrative, technical, and organizational measures designed to protect information. Measures may include access controls, role-limited permissions, authentication, vendor controls, confidentiality requirements, data minimization, and security monitoring appropriate to our services and risk profile. No system or transmission method is completely secure. Clients and users must protect credentials and promptly report suspected unauthorized access.
SHIFT OS is intended for general business use and is not approved for protected health information subject to HIPAA, children's data, biometric identifiers, consumer financial account credentials, government identifiers collected for high-risk purposes, or other specially regulated or highly sensitive data unless SHIFT expressly agrees in a signed addendum. SHIFT OS is not directed to children under 13, and we do not knowingly collect their personal information through SHIFT OS.
Depending on applicable law and the context, individuals may have rights to request access, correction, deletion, portability, or information about processing, or to opt out of certain uses. Requests may be sent to [email protected]. We may verify identity and authority before acting.
If the information is controlled by a SHIFT client, we may refer the request to that client or assist the client under our agreement. The client remains responsible for deciding and responding to requests concerning its own practices unless law requires SHIFT to act directly. Rights may be subject to exceptions and may differ by state.
SHIFT is based in Nebraska and primarily serves U.S. businesses. SHIFT OS providers may store or process information in the United States or other locations under their terms and safeguards. This Policy and the standard DPA are not intended by themselves to provide GDPR, UK GDPR, data-localization, or international transfer terms. Clients must notify SHIFT before processing that requires such terms.
We may update this Policy to reflect changes in law, technology, services, providers, or practices. The current version will be posted with its effective date. When appropriate, we will provide additional notice of material changes.
SHIFT OS Terms of Service: [SHIFT OS TERMS URL].
Data Processing Addendum: [DPA URL].
Contact:
SHIFT Solutions LLC
200 S 21st St, Ste 400A, Lincoln, NE 68510
[email protected]