Your trust is part of the foundation.
A plain-language view of what we collect, why we need it, and the choices available to you.
Who is responsible
Your booking business is the controller of the client and appointment information it collects. ElevateCRM processes that information for the business under its instructions.
ElevateCRM separately controls platform account, first-touch campaign attribution, billing, support, security, and its own operational information.
Information we collect
We collect account information such as your name, email address, authentication details, business profile, services, staff settings, booking records, client information, and communications created through the platform.
When you arrive through a campaign link before signing in, we may collect the bounded campaign source, medium, campaign, content, term, and landing-page pathname. We do not use the full query string, fragment, referrer, IP address, user agent, or authentication callback URL as first-touch attribution.
A temporary first-party, HttpOnly cookie keeps a valid first campaign visit for up to 30 days so it can survive the signup and verification flow. JavaScript on the page cannot read this cookie.
Clinical, diagnostic, treatment, regulated health-record, and other health-record content is prohibited. Appointment notes are optional and must not be used for those purposes.
Abuse controls use a keyed pseudonymous caller identifier; contact submissions do not retain raw IP addresses by default.
Purposes and consent
Required booking information is used to fulfil appointments and deliver confirmations, changes, and reminders. Optional welcome, birthday, win-back, promotional, and similar email requires a separate unchecked marketing opt-in.
ElevateCRM may link the first valid campaign visit to a genuinely new standard owner account so we can understand how new workspaces discovered the platform. This platform-controlled purpose is separate from a business's client analytics and is not used to attribute the business's booking clients.
Withdrawing marketing consent cancels pending marketing but does not stop transactional appointment messages.
Service providers and transfers
We use configured cloud hosting, Firebase authentication and database services, private object storage (Firebase or approved S3-compatible infrastructure), n8n automation, email delivery, backups, logs, and the payment providers a business connects (Stripe, and Square where a workspace uses it). Object storage can contain workspace logos and service images, short-lived privacy exports, and legacy workspace objects; the configured provider depends on the deployment. First-touch campaign metadata and the landing pathname are handled by the configured hosting provider and Google Cloud/Firebase. Only information needed for the relevant service is provided. Review the subprocessor register.
Some providers may process information outside Canada. Information may therefore be subject to the laws of the jurisdiction where it is processed. Workspace booking notices identify the business controller and link to its policy.
We do not sell personal information.
Retention and deletion
We maintain retention schedules based on the purpose of each record, legal obligations, workspace configuration, and documented legal holds. When a verified deletion request is approved, we coordinate deletion or anonymization across applicable systems unless the law or a documented hold requires retention.
If signup is not completed, the temporary attribution cookie expires within 30 days. After account linking reaches a final outcome, the cookie is cleared. Attribution linked to an account follows the workspace/account lifecycle, including a profile created during signup that is not later verified, and is removed through account deletion unless an approved legal hold requires temporary retention.
We minimize records kept for delivery, security, privacy requests, breach response, tax, and accounting purposes and retain them only for the applicable operational or legal period.
Your choices and rights
You may request access, correction, deletion, marketing withdrawal, or make a complaint. This includes campaign attribution that ElevateCRM controls. ElevateCRM uses a non-enumerating portal and a one-time email link so the intake response does not reveal whether a record exists.
The business controller reviews booking-client requests. ElevateCRM responds for platform information it controls. Open the privacy rights centre.
Security
We use access controls, authenticated sessions, workspace permissions, encrypted transport, validated uploads, and monitoring safeguards. No online service can promise absolute security, so account owners should also use strong credentials and grant staff only the permissions they need.
Contact and updates
Privacy and legal questions can be sent to legal@egboinc.com. We may update this policy as our services or legal obligations change and will revise the date shown on this page.
Questions deserve clear answers