Privacy Policy

Last updated:

1. Introduction and Scope

Stetson Digital (“Company,” “we,” “us,” or “our”) operates as a white-label reseller of HighLevel CRM platform services. This Data Privacy Compliance Policy details how we collect, process, store, and disclose Personal Data when you interact with our platform, website, and services.

This policy applies to:

  • Account Owners & Clients: Entities or individuals purchasing CRM reseller services directly from Stetson Digital.
  • End Leads & Contacts: Individuals whose data is imported or collected into the HighLevel CRM instance by our clients.
  • Website Visitors: Individuals accessing our public-facing digital properties.

Data Roles: Under the General Data Protection Regulation (GDPR) and similar frameworks, Stetson Digital acts as a Data Controller for account creation, direct billing, and marketing data. Stetson Digital acts as a Data Processor (or “Service Provider” under the California Consumer Privacy Act) regarding customer leads and communications stored inside the CRM by our clients. Clients retain primary Data Controller obligations for their respective customer databases.

2. Data We Collect and Why

Data CategorySpecific Data ExamplesProcessing PurposeGDPR Lawful Basis
Account & Billing DataName, business email, phone number, billing address, credit card payment metadata.Account creation, billing processing, customer support, contract management.Performance of a Contract (Art. 6(1)(b))
CRM & Communication DataContact details, conversation logs (SMS, email, webchat), workflow tags, opportunity pipelines.Providing CRM features, automation, message delivery via HighLevel backend.Performance of a Contract / Data Processing Agreement (DPA)
Technical & Usage DataIP address, login logs, device characteristics, browser type, platform telemetry.Security auditing, error debugging, system integrity, fraud prevention.Legitimate Interests (Art. 6(1)(f))*
Marketing & Analytics DataPage interactions, referrer URLs, tracking pixel data, session analytics via Google Analytics.Audience measurement, site optimization, performance marketing tracking.Consent (Art. 6(1)(a))

*Note: Where “Legitimate Interests” is relied upon as a lawful basis under GDPR, Stetson Digital must conduct and document a formal Legitimate Interests Assessment (LIA) balancing business necessity against individual privacy rights.

3. How We Use Your Data

We process collected data strictly to fulfill operational and contractual requirements, including:

  • Provisioning and maintaining your white-label HighLevel CRM instance.
  • Processing subscription billing and managing reseller support requests.
  • Executing automated communication workflows (email, SMS, call routing) configured by clients.
  • Maintaining platform security, monitoring unauthorized access, and debugging system errors.
  • Ensuring compliance with statutory, accounting, tax, and legal obligations.

4. Data Retention

Data is retained only as long as necessary to fulfill the operational purpose for which it was collected:

  • Account & Financial Records: Retained for the life of the active account plus 7 years post-termination to satisfy US federal/state tax and accounting retention requirements.
  • CRM Client Data: Stored during the active subscription period. Upon account cancellation or contract termination, CRM database records are queued for complete purging within 30 to 60 days, subject to the terms of the underlying HighLevel platform infrastructure.
  • Google Analytics Data: Retained in accordance with GA4 retention schedules (typically 2 to 14 months) or until consent is withdrawn.
  • Server Security Logs: Retained on a rolling 90- to 180-day cycle.

5. Data Sharing and Third Parties

Stetson Digital does not trade or sell customer databases. Personal Data is shared exclusively with necessary infrastructure partners:

  • HighLevel, Inc. (GoHighLevel): Primary infrastructure and underlying software processor executing core CRM, database hosting, and communication routing functions under a strict Data Processing Addendum (DPA).
  • Analytics Providers: Google LLC (Google Analytics) for aggregated web traffic and user activity analysis.
  • Payment Processors: PCI-compliant third-party gateways (e.g., Stripe) for recurring subscription processing.

CCPA Statutory “Sale” Clarification: The CCPA/CPRA defines a “sale” broadly as disclosing or transferring personal information to a third party for monetary or other valuable consideration. Stetson Digital does not exchange consumer personal data for monetary payments. However, the deployment of third-party tracking scripts (such as Google Analytics) may meet the statutory CCPA definitions of “selling” or “sharing” (for cross-context behavioral advertising). Users may exercise opt-out rights as detailed below.

6. Your Rights

Data Subject Rights refer to statutory entitlements granted to individuals to monitor, restrict, and direct how businesses handle their personal data.

GDPR Rights (EU/UK Residents)

  • Access & Portability: Request copies of your personal data in a structured, machine-readable format.
  • Rectification: Request correction of inaccurate or incomplete personal records.
  • Erasure (“Right to be Forgotten”): Request deletion of personal data where no overriding legal basis exists.
  • Object to Processing: Object to processing grounded in “Legitimate Interests” or direct marketing.
  • Restriction of Processing: Request temporary suspension of data processing under specific legal disputes.

CCPA / CPRA Rights (California Residents)

  • Right to Know: Request disclosure of categories and specific pieces of personal information collected.
  • Right to Delete: Request deletion of personal information maintained by the business.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out: Opt out of the “sale” or “sharing” of personal data for cross-context behavioral advertising.
  • Right to Non-Discrimination: Stetson Digital will not deny services, charge different prices, or provide a lower quality of service to consumers exercising their privacy rights.

Procedure to Exercise Rights: Submit a verified request to privacy@stetsondigital.com. Stetson Digital will confirm identity before processing any data access or deletion requests. Requests are processed within 30 days (GDPR) or 45 days (CCPA). Where Stetson Digital acts merely as a Processor (e.g., handling CRM contacts on behalf of a reseller client), we will forward the request to the relevant Client (Data Controller).

7. Security Measures

Stetson Digital relies on robust administrative, technical, and physical safeguards inherited from and enhanced by our HighLevel infrastructure, including:

  • Data encryption in transit using Transport Layer Security (TLS 1.2+).
  • Data encryption at rest using Advanced Encryption Standard (AES-256).
  • Role-based access controls and mandatory Multi-Factor Authentication (MFA) for administrative staff.
  • Routine platform vulnerability monitoring and system patch management.

8. Breach Notification

  • GDPR Requirements: In the event of a personal data breach impacting EU/UK subjects, Stetson Digital (or our primary processor, HighLevel) will report the incident to the appropriate Supervisory Authority within 72 hours of confirmation, where feasible. If the breach poses a high risk to individual rights, affected data subjects will be notified without undue delay.
  • US & Florida State Requirements: Pursuant to the Florida Information Protection Act (FIPA – Fla. Stat. § 501.171), Stetson Digital will notify affected Florida residents and the Florida Department of Legal Affairs of any security breach compromising unencrypted personal information without unreasonable delay, and no later than 30 days after determination of the breach.

9. Contact and DPO Information

For privacy questions, opt-out requests, or rights enforcement:

Stetson Digital

Attn: Data Privacy Officer / Compliance

Citrus County, Florida, USA

Email: privacy@stetsondigital.com

(Note: Stetson Digital is not required under GDPR Art. 37 to maintain a formal Data Protection Officer (DPO), as core operations do not involve large-scale regular monitoring or processing of special categories of sensitive data. However, our designated compliance contact manages all privacy inquiries.)

10. Policy Updates

This policy is reviewed annually or whenever material changes occur in our data processing practices or legal requirements. Material updates will be posted directly to this page with a revised “Effective Date.”

This policy template requires review and customization by qualified data privacy legal counsel. Privacy law requirements vary by jurisdiction and change frequently. Not legal advice.