Privacy Policy — Craton Systems
CRATON SYSTEMS

Privacy Policy

Effective date: July 27, 2026

This Privacy Policy describes how Craton Systems LLC ("Craton," "we," "us," or "our"), a Wyoming limited liability company, collects, uses, discloses, and safeguards personal information in connection with our white-label software platform deployment and agency services, our websites, and related tools (the "Services"). By using the Services, you agree to this Policy.

1. Our Role: Controller vs. Service Provider

We act as a controller/business for information about our own clients, prospects, and website visitors. Where we host or process data on a client's behalf inside the Services (for example, the client's own end-customer contacts), the client is the controller/business and we act as a service provider/processor, handling that data only per our agreement with the client and their instructions — not for our own purposes. If you are an end customer of one of our clients, please review that client's privacy notice.

2. Information We Collect

Information you provide

  • Identifiers and account data — name, business name, email, phone, mailing address, and login credentials.
  • Commercial and billing data — subscription and transaction records, EIN/tax identifiers, and billing details processed by our payment processors (we do not store full card numbers).
  • Communications — messages, support tickets, and information you submit through forms, calls, or email.
  • Content — data, files, and contacts you upload or generate in the Services.

Information collected automatically

  • Internet/device activity — IP address, browser and device type, pages viewed, actions, and timestamps.
  • Approximate location — general location inferred from IP address.
  • Cookies and similar technologies — see Section 10.

Information from third parties

We may receive data from our technology, analytics, advertising, and payment providers, and combine it with information we hold.

3. Statutory Categories, Sources, Purposes, and Disclosures

The table below maps the categories of personal information we handle (using the categories under the California Consumer Privacy Act, as amended) to their sources, our purposes, and whether we disclose them. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws. In particular, we do not sell or share mobile phone opt-in information or SMS consent with third parties for their own marketing; if you opt in to texts, you can reply STOP to opt out at any time.

CategoryExamplesSourcesPurposeSold / Shared
IdentifiersName, business name, email, phone, address, IP, account IDYou; your devices; our providersProvide, secure, and support the Services; account managementNo
Commercial informationSubscription, transaction, and billing recordsYou; payment processorsProcess payments, subscriptions, and usage chargesNo
Internet/electronic activityUsage, pages viewed, actions, device/browser dataAutomaticallyOperate, measure, secure, and improve the ServicesNo
Geolocation (approximate)General location from IPAutomaticallySecurity, fraud prevention, localizationNo
Professional/business infoBusiness name, role/titleYouAccount setup and B2B servicingNo
Sensitive personal informationAccount log-in credentialsYouAuthentication and account security onlyNo
Inferences (limited)Preferences derived to improve/personalizeDerivedService improvement and personalizationNo

4. Sensitive Personal Information

The only sensitive personal information we routinely collect is your account log-in credentials, which we use solely to authenticate and secure your account. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for purposes other than those permitted under applicable law. You may request that we limit our use of sensitive personal information as described in Section 11. Payment card details are handled by our payment processors and are not stored on our systems.

5. Sub-processors and Service Providers

We engage vetted service providers and sub-processors under contracts requiring them to protect information and use it only to provide services to us. These include: cloud hosting and infrastructure (such as Vercel and Railway); our underlying CRM and marketing-automation platform; payment processing (PowerPay Direct and its licensed processing partners for client and subscription payments; and the usage-billing processor required by our underlying platform for incidental charges such as SMS, telephony, and AI); communications delivery (SMS, email, and telephony providers); and analytics (such as Google Analytics). A current list of named sub-processors is available to clients under a data-processing agreement on request. We may update our providers from time to time.

6. Payment Processing

Client and subscription payments are processed through PowerPay Direct and its licensed payment-processing partners and gateways. Incidental platform usage charges (such as SMS, telephony, and AI usage) are billed through a third-party processor required by our underlying software platform. All payment providers operate under their own terms, privacy policies, and PCI-DSS obligations. Card details are entered directly into the processor's or gateway's secure systems; we receive only limited transaction information (such as the last four digits of a card, authorization results, and subscription status) and do not receive or store complete card numbers.

7. Protected Health Information (HIPAA)

For clients in healthcare-related verticals, where we handle Protected Health Information (PHI) on a client's behalf, we do so as a Business Associate under a signed Business Associate Agreement (BAA), which — not this Policy — governs PHI. PHI is used only as permitted by the BAA and law.

8. Automated Processing and Personalization

The Services include personalization and AI-assisted features that use automated processing to tailor content, recommendations, and communications. We do not use automated decision-making that produces legal or similarly significant effects about you without human involvement. Where you are an end user of one of our clients, that client controls the personalization applied to you and is responsible for its own disclosures. You may contact us with questions about our automated processing, and, where applicable, exercise the rights described in Section 11.

9. How Long We Keep Information

We retain personal information for as long as needed to provide the Services and for legitimate business and legal purposes, then delete or de-identify it. Our retention criteria include the duration of your account, the period required for tax, accounting, and legal obligations, the need to resolve disputes and enforce agreements, and routine backup cycles. In general: account and billing records are retained for the life of the account plus the period required by law; support communications for a reasonable period after resolution; and Client Content per our client agreements (typically available for export for 30 days after termination, then deleted subject to legal retention and backups).

10. Cookies, Tracking, and Opt-Out Signals

We and our providers use cookies, pixels, and similar technologies to keep you signed in, remember settings, measure performance, and understand usage. You can control cookies through your browser and, where offered, our cookie controls; disabling some cookies may affect functionality. We honor the Global Privacy Control (GPC) and similar opt-out preference signals where required by applicable law. If we later introduce advertising cookies or pixels whose use results in a "sale" or "sharing" of personal information under applicable law, we will update this Policy and provide a clear opt-out.

11. Your U.S. State Privacy Rights

Residents of U.S. states with comprehensive privacy laws — including California, Virginia, Colorado, Connecticut, Utah, Texas, and other states as their laws take effect — may have the rights below, subject to the specifics and exceptions of their state's law:

  • Know/Access the personal information we process and obtain a copy.
  • Correct inaccurate personal information.
  • Delete personal information.
  • Portability — receive your information in a portable format.
  • Opt out of sale, sharing/targeted advertising, and certain profiling (note: we do not sell or share personal information).
  • Limit the use of sensitive personal information.
  • Non-discrimination for exercising your rights.

How to exercise. Submit a request to [email protected]. We will verify your identity before responding and will respond within the timeframe required by law. You may use an authorized agent to submit a request, subject to verification. If we decline a request, you may appeal by replying to our decision, and we will respond as required by applicable law. If your data was provided to us by one of our clients, please direct your request to that client; we will assist them as their processor.

12. Data Location

We are based in and process personal information in the United States. The Services are intended for users in the United States. If you access the Services from outside the United States, you understand your information will be processed in the United States.

13. Security

We use administrative, technical, and physical safeguards designed to protect information appropriate to its sensitivity, including encryption in transit, access controls, and least-privilege practices. If we become aware of a security breach affecting your personal information, we will notify you and any affected clients as required by law and without undue delay. No system is completely secure, and we cannot guarantee absolute security.

14. Children's Privacy

The Services are intended for businesses and users 18 or older. We do not knowingly collect personal information from children. If you believe a child provided us information, contact us and we will delete it.

15. Contact Us

Craton Systems LLC
Attn: Privacy
Wyoming, USA
Email: [email protected]

16. Changes to This Policy

We may update this Policy from time to time. We will revise the "Effective date" above and, for material changes, provide additional notice. Your continued use of the Services after changes take effect constitutes acceptance.

17. Governing Law

This Policy is governed by the laws of the State of Wyoming, without regard to its conflict-of-laws principles, except where a mandatory privacy law of your jurisdiction applies.

© 2026 Craton Systems LLC. All rights reserved.  •  Wyoming, USA  •  [email protected]