Legal
Privacy Policy
How SparrowHawk CRM LLC collects, uses, stores, shares, protects, and retains information across the platform, Aircraft Pricing App, Aviation Partner Program, Marketplace, customer portals, integrations, and AI features.
Effective: July 13, 2026
Last updated: July 13, 2026
- v2.0 · July 13, 2026Legal & Compliance Phase. Preserved every existing section. Added expanded coverage for cookies, analytics, Stripe, Google OAuth, QuickBooks OAuth, Cloudflare, uploaded files, client portal, marketplace, ADA training, FBO leads, referral program, AI processing, device/browser/IP/session information, payment metadata, support and marketing communications, international data transfers, storage, retention, deletion, user rights, security measures, children's privacy, and privacy request handling.
- v1.0 · July 1, 2026Initial published Privacy Policy.
This Privacy Policy explains how SparrowHawk CRM LLC (“SparrowHawk CRM,” “Company,” “we,” “us,” or “our”) collects, uses, stores, shares, protects, and retains information when you access or use SparrowHawk CRM, the SparrowHawk CRM website, the SparrowHawk CRM platform, the Pricing App, the Aviation Partner Program, the Marketplace, customer portals, integrations, APIs, AI features, software tools, and related services.
By accessing or using SparrowHawk CRM, you acknowledge that you have read and understood this Privacy Policy. This Privacy Policy should be read together with our Terms of Service, End User License Agreement, Billing Terms, Acceptable Use Policy, Cookie Policy, Data Processing Addendum, Subprocessor List, Data Retention & Deletion Policy, Security & Trust Center, and AI Usage Policy, together with any applicable order form or subscription terms.
1. Scope of This Privacy Policy
This Privacy Policy applies to information collected from or about website visitors, subscribers, trial users if applicable, organization owners, organization administrators, invited users, customer portal users, aviation partners, service providers, Pricing App users, demo requesters, support contacts, and people whose information is entered into the platform by SparrowHawk CRM customers.
This Privacy Policy applies to information collected through our website, platform, applications, customer portals, checkout flows, signup forms, support communications, integrations, AI tools, analytics tools, billing systems, and other services operated by or on behalf of SparrowHawk CRM LLC.
This Privacy Policy does not apply to third-party websites, services, integrations, or platforms that are not controlled by SparrowHawk CRM LLC, even if those services are linked to or integrated with the platform.
2. Business Customer Data and Processor Role
SparrowHawk CRM is primarily a business software platform. Our customers may use the platform to store and process information about their own customers, aircraft owners, aircraft operators, employees, contractors, vendors, aviation partners, service providers, and other third parties.
For information entered into the platform by a business customer, SparrowHawk CRM generally acts as a service provider or processor on behalf of that customer. The business customer is responsible for determining what information is entered, why it is processed, how long it is retained, who has access to it, and whether the customer has proper legal authority, consent, or permission to process that information.
SparrowHawk CRM LLC is not responsible for a customer entering personal information, aircraft information, employee information, payment-related information, or third-party information into the platform without proper rights, consent, authority, or legal basis.
3. Information We Collect
We may collect information directly from you, automatically through your use of the platform, from your organization, from connected integrations, from payment processors, from customer portal users, from support communications, and from third-party service providers.
The types of information we collect depend on how you use SparrowHawk CRM, what plan or product you use, what integrations you connect, what data you upload, and what features are enabled.
Information collected may include account information, organization information, customer records, aircraft information, payment and subscription information, portal information, integration data, usage data, communications, AI feature data, uploaded files, legal acceptance records, security logs, cookies, and similar technologies.
4. Account Information
We may collect account information such as name, email address, phone number, username, password or authentication information, profile information, user role, organization role, account status, login history, invitation status, and user permissions.
We use account information to create accounts, authenticate users, manage access, provide support, maintain security, enforce permissions, send account notices, and operate the platform.
Passwords may be processed through authentication providers or platform infrastructure. SparrowHawk CRM does not intentionally display or share user passwords.
5. Organization Information
We may collect information about organizations using SparrowHawk CRM, including business name, business address, phone number, email address, website, industry type, organization logo, branding settings, subscription plan, billing settings, team members, role assignments, business preferences, CRM configuration, service catalog settings, portal settings, and integration settings.
We use organization information to provide account administration, subscriptions, billing, team access, business settings, platform configuration, and customer support.
6. Customer Records
Customers may enter records about their own customers, clients, aircraft owners, aircraft operators, vendors, or other third parties.
Customer records may include names, email addresses, phone numbers, addresses, company names, aircraft information, quote history, invoice history, payment status, job history, service requests, notes, uploaded photos, uploaded documents, customer portal activity, approvals, signatures or acknowledgments if used, scheduling details, and communication history.
Business customers are responsible for ensuring they have permission and legal authority to enter and process this information.
7. Aircraft Information
SparrowHawk CRM may collect and process aircraft-related information entered by users. This may include tail numbers, aircraft make, model, year, type, manufacturer, serial numbers if entered, owner or operator information, service history, job history, photos, documents, maintenance-related data if enabled, inspection due dates if entered, aircraft profile details, location information, quote history, and invoice history.
Aircraft information may be used to support quotes, scheduling, jobs, customer portals, aircraft profiles, reports, service history, Pricing App features, Aviation Partner Program workflows, and future maintenance-shop workflow tools.
SparrowHawk CRM LLC does not verify the accuracy, completeness, ownership, airworthiness, maintenance status, regulatory compliance, or legal status of aircraft information entered by users.
8. Payment and Subscription Information
We may collect and process payment and subscription information such as Stripe customer IDs, subscription IDs, plan type, subscription status, billing email, billing address, invoice history, payment history, checkout metadata, transaction metadata, coupon or discount information, tax-related fields if entered, and limited payment method details such as card brand and last four digits when provided by a payment processor.
SparrowHawk CRM LLC does not store full credit card numbers, bank account numbers, or complete payment card security codes. Payment card information is processed by third-party payment processors such as Stripe under their own terms and privacy policies.
We use payment and subscription information to manage billing, subscriptions, renewals, cancellations, access entitlements, invoices, tax settings, payment disputes, fraud prevention, and account status.
9. Customer Portal Information
If customer portals are used, we may collect information from portal users, including quote views, invoice views, approvals, acceptances, uploaded files, messages, payment actions, timestamps, IP address, user agent, signatures or acknowledgments if used, and portal interaction history.
This information may be made available to the organization that invited or served the portal user.
Customer portal users should contact the business organization that invited them if they have questions about the records, services, quotes, invoices, or customer relationship involved.
10. Integration Data
SparrowHawk CRM may allow customers to connect third-party integrations such as Stripe, QuickBooks, Google Calendar, Google OAuth, Microsoft services, email providers, SMS providers, mapping providers, AI providers, analytics tools, storage providers, and other services.
When integrations are connected, we may receive or process information necessary to provide those integrations, such as account identifiers, tokens, calendar event details, customer records, invoice data, payment metadata, sync logs, error messages, status updates, and configuration settings.
Customers are responsible for authorizing integrations, managing third-party permissions, reviewing third-party privacy policies, and ensuring they have authority to connect and sync information.
11. Usage Data
We may collect usage information automatically when you access or use SparrowHawk CRM. This may include IP address, device information, browser type, operating system, pages viewed, features used, buttons clicked, session duration, login activity, referral pages, timestamps, error logs, audit logs, security logs, API activity, and performance data.
We use usage data to operate the platform, troubleshoot issues, improve features, monitor system performance, detect abuse, prevent fraud, secure accounts, enforce plan limits, and understand how users interact with SparrowHawk CRM.
12. Communications
We may collect information from communications with us, including support emails, chat messages, onboarding messages, demo requests, billing questions, feedback, issue reports, phone call notes if entered, business inquiries, product requests, and other communications.
We use communications to provide support, respond to inquiries, troubleshoot issues, improve the platform, maintain records, enforce legal terms, and communicate with users.
13. AI Feature Data
If AI features are used, we may collect and process prompts, instructions, generated outputs, user-submitted context, account context provided to AI tools, troubleshooting logs, and interaction metadata.
AI features may generate drafts, summaries, pricing suggestions, customer messages, workflow recommendations, quote language, maintenance wording, or other outputs.
Users should not submit sensitive information to AI features unless necessary for the intended business purpose. Users are responsible for reviewing and verifying all AI-generated output before using it.
AI interactions may be logged for troubleshooting, security, abuse prevention, quality improvement, and feature performance.
14. Legal Acceptance Records
We may collect and store records showing that users accepted legal terms or subscription notices. These records may include user ID, email address, organization ID if applicable, accepted Terms of Service status, accepted Privacy Policy status, accepted EULA status, accepted subscription notice status, document version, effective date, timestamp, IP address if available, and user agent if available.
We use legal acceptance records to document consent, enforce agreements, manage access, support billing and subscription flows, and maintain compliance records.
15. Cookies and Similar Technologies
SparrowHawk CRM may use cookies, local storage, session storage, pixels, analytics tools, and similar technologies.
These technologies may be used for login sessions, authentication, account security, remembering preferences, analytics, performance monitoring, fraud prevention, debugging, product improvement, and maintaining user sessions.
You may be able to control cookies through your browser settings, but disabling cookies or local storage may affect your ability to log in or use the platform.
16. Information Customers Provide About Others
Business customers may enter information about other people or entities, including customers, employees, contractors, vendors, aircraft owners, aircraft operators, aviation partners, service providers, and portal users.
Customers represent that they have the necessary rights, consents, permissions, notices, and legal authority to provide this information to SparrowHawk CRM.
SparrowHawk CRM LLC is not responsible for a customer's failure to provide required notices or obtain required permissions from individuals or third parties whose information is entered into the platform.
17. How We Use Information
We may use collected information to provide, operate, secure, maintain, and improve SparrowHawk CRM.
This includes using information to create accounts, authenticate users, manage subscriptions, process billing, provide quotes, invoices, scheduling, payments, customer portals, aircraft profiles, job tracking, reports, Pricing App access, Aviation Partner Program workflows, integrations, training access, support, troubleshooting, security, audit logs, fraud prevention, abuse detection, product improvement, analytics, legal compliance, and enforcement of our terms.
We may also use information to send service messages, account notices, billing notices, security alerts, product updates, administrative messages, and support communications.
18. AI Features and Privacy
AI features may process information submitted by users or selected from user accounts to generate useful outputs. This may include customer messages, pricing guidance, quote language, job summaries, workflow recommendations, support responses, or other content.
AI-generated content may be inaccurate or incomplete. Users are responsible for reviewing and verifying AI outputs before using them.
SparrowHawk CRM may use AI-related logs and metadata for safety, abuse prevention, troubleshooting, platform improvement, and performance monitoring.
SparrowHawk CRM does not use AI output as a substitute for professional legal, tax, accounting, aviation, FAA, maintenance, safety, insurance, employment, or financial advice.
19. Legal Bases and Business Purposes
Where applicable law requires a legal basis for processing, SparrowHawk CRM may process information based on contract performance, legitimate business interests, consent, legal obligations, fraud prevention, security, compliance, customer instructions, and operation of the platform.
Our legitimate business interests may include providing software services, securing accounts, preventing abuse, improving the platform, communicating with users, supporting customers, enforcing terms, preventing fraud, maintaining records, and operating our business.
20. How We Share Information
SparrowHawk CRM may share information with third parties as necessary to operate, support, secure, and improve the platform.
We may share information with hosting providers, database providers, authentication providers, payment processors, email providers, SMS providers, analytics providers, customer support tools, AI service providers, storage providers, security providers, integration providers, legal advisors, accountants, consultants, contractors, and other service providers working on our behalf.
We may also share information with connected integrations authorized by the customer, with organization admins, with customer portal users as directed by the organization, with legal authorities when required, and with buyers or successors in connection with a business transfer.
21. Sharing With Organization Admins
If your account is part of an organization, organization owners and admins may be able to access information related to your account activity, role, permissions, customer records, quotes, invoices, jobs, uploaded files, and actions taken within that organization.
SparrowHawk CRM LLC is not responsible for how an organization's admins use, view, export, share, delete, or manage organization data.
22. Sharing With Customer Portal Users
If an organization uses customer portals, selected information may be visible to portal users. This may include quotes, invoices, payment links, aircraft information, job status, uploaded images, documents, approvals, service history, and messages.
Organizations are responsible for deciding what information is shared through customer portals and for ensuring they have authority to share that information.
23. Sharing With Integration Providers
When a customer connects an integration, information may be shared with or received from that third-party provider. For example, payment information may be processed by Stripe, accounting information may sync with QuickBooks, calendar information may sync with Google Calendar, and authentication may occur through Google OAuth or other providers.
SparrowHawk CRM LLC is not responsible for the privacy practices, security practices, outages, data handling, terms, or decisions of third-party integration providers.
24. No Sale of Personal Information
SparrowHawk CRM LLC does not sell personal information for money.
We do not intend to sell personal information as that term is commonly understood. If we later use advertising technologies, targeted advertising, or cross-context behavioral advertising in a way that requires additional disclosures or opt-out rights, we will update this Privacy Policy and provide required choices where applicable.
25. Payment Data
Payment card data is processed by third-party payment processors such as Stripe. SparrowHawk CRM LLC does not store full credit card numbers, full bank account numbers, or card security codes.
Payment processors may collect, store, and process payment information according to their own terms, privacy policies, and security standards.
SparrowHawk CRM may store payment metadata such as payment status, invoice ID, subscription ID, customer ID, transaction ID, card brand, last four digits, billing email, and related records for billing, access control, dispute resolution, support, fraud prevention, and accounting purposes.
26. Data Retention
We retain information for as long as reasonably necessary to provide the platform, maintain accounts, manage subscriptions, process billing, provide support, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud, secure the platform, maintain audit logs, and operate our business.
Some information may be retained after account cancellation or termination for legal, billing, tax, security, fraud prevention, backup, dispute resolution, and compliance purposes.
Deleted information may remain for a limited period in backups, logs, archives, or disaster recovery systems before being deleted according to our retention practices.
27. Data Security
SparrowHawk CRM uses reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
However, no internet-based system, software platform, hosting environment, database, integration, or transmission method is 100% secure.
Users are responsible for securing their passwords, devices, email accounts, integrations, user permissions, admin accounts, employee access, and internal processes.
SparrowHawk CRM LLC is not responsible for unauthorized access caused by user-side credential compromise, weak passwords, shared accounts, compromised devices, internal employee misuse, former employee access, or failure to manage permissions.
28. Security Incidents
If SparrowHawk CRM becomes aware of a security incident, we will evaluate the situation and provide notices where required by applicable law.
Not every security event is a legally reportable breach. SparrowHawk CRM may investigate, remediate, restrict access, reset credentials, suspend accounts, or take other reasonable steps to protect the platform and users.
Users agree to promptly notify SparrowHawk CRM if they suspect unauthorized access, account compromise, integration compromise, or misuse of the platform.
29. Data Export and Backups
SparrowHawk CRM may provide tools to export certain data, but users are responsible for maintaining independent copies of important business records.
Important records may include invoices, receipts, tax records, aircraft records, maintenance records, customer approvals, contracts, legal records, payment records, photos, documents, customer communications, and service histories.
SparrowHawk CRM LLC does not guarantee restoration of any specific data, file, record, upload, log, or backup.
30. International Access
SparrowHawk CRM is operated primarily from the United States. If you access the platform from outside the United States, your information may be processed in the United States or in other countries where our service providers operate.
By using SparrowHawk CRM, you understand that information may be transferred to, stored in, or processed in locations that may have different data protection laws than your location.
31. Children's Privacy
SparrowHawk CRM is intended for business and professional use and is not directed to children.
Users may not knowingly submit personal information about children under 13 or under the applicable age of consent unless they have legal authority and a valid business reason to do so.
If we learn that we have collected children's information without proper authorization, we may delete or restrict that information.
32. Privacy Rights
Depending on your location and applicable law, you may have rights to request access, correction, deletion, export, restriction, objection, or other privacy choices regarding your personal information.
You may submit privacy requests by contacting support@sparrowhawkcrm.com.
We may need to verify your identity before fulfilling a request. Some requests may be limited by legal obligations, security needs, billing records, fraud prevention, dispute resolution, backup retention, customer instructions, or other lawful reasons.
33. Business Customer Controlled Data
If your information was entered into SparrowHawk CRM by one of our business customers, that customer may control the information.
For example, if an aircraft detailing business, maintenance shop, FBO, aviation partner, or service provider entered your information into SparrowHawk CRM, you may need to contact that business directly to access, correct, delete, or restrict that information.
SparrowHawk CRM may forward your request to the relevant customer or coordinate with the customer where appropriate.
34. Marketing Communications
We may send marketing communications, product updates, educational content, promotions, or other non-essential messages where permitted by law.
You may opt out of marketing emails by following unsubscribe instructions or contacting us.
Even if you opt out of marketing communications, we may still send transactional, billing, legal, account, security, support, and service-related messages.
35. Service Communications
We may send important service communications related to your account, subscription, billing, security, legal terms, platform updates, downtime, feature changes, product notices, or support requests.
These communications are not marketing and may be necessary for use of the platform.
36. Third-Party Links and Services
The platform may contain links to third-party websites or services, and the platform may integrate with third-party tools.
SparrowHawk CRM LLC is not responsible for the privacy practices, content, security, policies, outages, decisions, or data handling of third-party websites, services, or integrations.
Users should review the privacy policies and terms of any third-party services they use or connect.
37. Business Transfers
Information may be transferred, disclosed, or assigned in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, change of control, or similar business transaction.
If such a transfer occurs, the receiving entity may continue to process information consistent with this Privacy Policy unless otherwise stated.
38. Legal Compliance and Protection
We may access, preserve, use, or disclose information if we believe it is reasonably necessary to comply with law, legal process, court orders, subpoenas, government requests, law enforcement requests, regulatory obligations, tax obligations, or other legal requirements.
We may also use or disclose information to enforce our Terms, protect SparrowHawk CRM LLC, protect users, prevent fraud, investigate abuse, respond to security issues, protect rights or property, and defend against legal claims.
39. Aggregated and De-Identified Information
We may use aggregated, anonymized, or de-identified information for analytics, product improvement, reporting, benchmarking, research, security, business planning, and other lawful purposes.
We will not attempt to re-identify de-identified information except where permitted by law or necessary for security, legal, or operational reasons.
40. Data Processing Addendum
If required by a business customer or applicable law, SparrowHawk CRM may provide or enter into a Data Processing Addendum.
A Data Processing Addendum may apply to certain business customer data and may describe additional processor obligations, security measures, subprocessors, international transfer terms, and customer instructions.
If there is a conflict between this Privacy Policy and a signed Data Processing Addendum, the signed Data Processing Addendum will control only for the specific customer and data covered by that agreement.
41. Cookie Policy
If a separate Cookie Policy is available, it provides additional information about cookies, local storage, analytics, tracking technologies, and user choices.
If there is no separate Cookie Policy, the cookie-related sections of this Privacy Policy explain our general use of cookies and similar technologies.
42. Changes to This Privacy Policy
SparrowHawk CRM may update this Privacy Policy from time to time.
When we update the Privacy Policy, we may revise the "Last Updated" date. Material changes may be communicated through the website, dashboard notice, email, or other reasonable method.
Continued use of SparrowHawk CRM after the updated Privacy Policy becomes effective means you acknowledge the updated policy, where permitted by law.
43. Governing Law
This Privacy Policy is governed by the laws of the State of New Mexico, without regard to conflict of law principles.
44. Venue
Any dispute arising out of or relating to this Privacy Policy, privacy practices, data processing, the platform, or related services shall be brought exclusively in the state or federal courts located in New Mexico, unless a separate written agreement signed by SparrowHawk CRM LLC states otherwise.
45. Contact
Questions, requests, or concerns about this Privacy Policy may be sent to:
SparrowHawk CRM LLC — support@sparrowhawkcrm.com
46. Cookies and Similar Technologies (Expanded)
SparrowHawk CRM uses cookies, local storage, session storage, and similar technologies to (a) keep users signed in, (b) remember preferences such as theme and language, (c) protect against fraud and abuse, (d) measure performance and reliability, and (e) support essential platform functionality.
Categories of cookies and storage used include strictly necessary session and authentication cookies, functional preference cookies, security cookies used for CSRF protection and rate limiting, and analytics cookies used to measure aggregate platform usage.
The Cookie Policy describes the specific categories of cookies used, their purpose, and how the Customer or its users can control cookies through their browsers.
47. Analytics
SparrowHawk CRM LLC uses first-party analytics to understand how the platform is used, identify performance and reliability issues, and prioritize improvements. Analytics data is aggregated and does not target individual end users for advertising.
The Customer may also connect its own analytics tools to its customer-facing website or portal, in which case those third-party analytics providers are governed by their own privacy policies.
48. Stripe
Stripe processes payments, payouts, and card data for SparrowHawk CRM and for Customers who enable Stripe Connect. SparrowHawk CRM LLC does not store full card numbers, full bank account numbers, or card security codes; those values are handled by Stripe under the PCI DSS.
SparrowHawk CRM may store payment metadata received from Stripe (customer ID, subscription ID, invoice ID, payment intent ID, transaction status, card brand, last four digits, billing email, tax registration details when provided) for the purposes of billing, entitlement enforcement, fraud prevention, support, reconciliation, and accounting.
Stripe's use of personal data is governed by Stripe's own privacy policy.
49. Google OAuth (Sign-In and Calendar)
When a Customer or user connects a Google account for sign-in or calendar synchronization, SparrowHawk CRM receives limited profile information (name, email, avatar) and, where the Customer authorizes it, access to Google Calendar events for scheduling.
SparrowHawk CRM LLC requests only the scopes necessary for the connected feature, stores refresh tokens in encrypted form, and uses Google user data only as described in this Privacy Policy and in accordance with the Google API Services User Data Policy, including the Limited Use requirements.
The Customer or user can disconnect Google access at any time from account settings or from the Google account permissions page. Disconnection revokes tokens and stops future synchronization; calendar events already imported may remain until deleted.
50. QuickBooks OAuth (Accounting Sync)
Customers who connect QuickBooks Online authorize SparrowHawk CRM to read and write accounting entities on their behalf, which may include customers, invoices, payments, items, taxes, and reference data.
SparrowHawk CRM LLC uses QuickBooks connection tokens only to perform the syncs the Customer has configured, logs sync activity for troubleshooting and audit, and stores tokens in encrypted form.
The Customer can disconnect QuickBooks at any time in accounting settings; disconnection stops future syncs and revokes stored tokens.
51. Cloudflare
SparrowHawk CRM uses Cloudflare for edge networking, DDoS mitigation, content delivery, TLS termination, WAF rules, and bot detection. Requests to the platform pass through Cloudflare's global network. Cloudflare receives request metadata (IP address, TLS parameters, user agent, request path, response status) and processes it under its own agreements with SparrowHawk CRM LLC as a subprocessor.
52. Uploaded Files
Files uploaded through the platform (photos, PDFs, aircraft manuals uploaded by the Customer, documents, signed agreements, before-and-after imagery, marketplace product media) are stored in object storage owned or contracted by SparrowHawk CRM LLC and are encrypted at rest.
SparrowHawk CRM LLC does not intentionally view Customer uploads except (a) as necessary to provide the service (for example, thumbnail generation), (b) as necessary to investigate security or abuse incidents, (c) to respond to legal process, or (d) with the Customer's request or consent.
Uploaded files may be scanned for malware and content that violates the Acceptable Use Policy or the DMCA & Copyright Policy.
53. Client Portal
When the Customer invites its end customers to use the Client Portal, the end customer receives an email link and can create a portal account limited to that Customer's organization. Portal users see the quotes, invoices, files, messages, and job records the Customer has shared with them.
Portal user data is treated as Customer Data of the inviting organization. Portal users with privacy questions should contact the organization that invited them; SparrowHawk CRM LLC will support that organization in responding to lawful requests.
54. Marketplace
The Marketplace collects buyer contact and shipping information necessary to fulfill orders, payment metadata processed by Stripe, and vendor information necessary to operate a listing (business name, tax status where applicable, payout information, service categories).
Marketplace order data may be shared with the relevant vendor to fulfill the order and with logistics or tax service providers as necessary. Vendors are contractually required to handle buyer information consistent with applicable law and the Vendor / Seller Agreement.
55. ADA Training
ADA Training features process learner activity data, quiz responses, completion timestamps, and certification issuance records for the purpose of delivering training, tracking progress, and issuing certifications.
Where a Customer or its employer enrolls a learner, learner progress may be visible to the enrolling organization.
56. FBO Leads and Referral Program
The Aviation Partner Program processes lead and referral data (aircraft owner or operator contact information, aircraft details, requested services, location, timing, notes) supplied by FBOs, referring partners, or the platform, and shares that data with providers dispatched to the request.
Referral tracking data (originating partner, dispatch decisions, acceptance status, outcome, commissionable amounts) is retained to administer the program, calculate commissions, resolve disputes, and detect fraud.
57. AI Processing
AI features may process prompts, selected account context, and generated outputs. Where a first-party or third-party AI provider is used, prompts and context necessary for the feature are transmitted to that provider under contractual obligations that prohibit using SparrowHawk CRM Customer content to train the provider's foundational models unless the Customer opts in.
AI-related logs may include prompt content, response content, provider identifiers, model identifiers, token usage, timestamps, and error metadata. Logs are used for troubleshooting, abuse prevention, safety, and platform improvement, and are retained according to the Data Retention & Deletion Policy.
The AI Usage Policy describes additional rules governing what may be submitted to AI features and the Customer's responsibility to review AI output.
58. Device and Browser Information
SparrowHawk CRM may collect device and browser information such as operating system, browser type and version, device type, screen resolution, timezone, and locale. This information is used to render the platform correctly, troubleshoot compatibility issues, detect fraudulent or automated activity, and prioritize support.
59. IP Address Logging
SparrowHawk CRM logs the IP address of requests to the platform for security, fraud prevention, rate limiting, audit logging, and abuse response. IP addresses may also be captured on legal acceptance records, portal signatures, and other activity where a durable record of the requesting endpoint is important.
IP addresses are retained according to the Data Retention & Deletion Policy.
60. Session Information
SparrowHawk CRM maintains session information (session identifier, session start and refresh times, authenticated user identifier, organization context) as necessary to keep users signed in and to enforce access controls. Sessions may be invalidated by the user on sign-out, by an administrator, or by SparrowHawk CRM LLC in response to suspected compromise.
61. Payment Metadata
SparrowHawk CRM LLC stores payment metadata (subscription IDs, invoice IDs, transaction status, amount, currency, tax details, refund status, chargeback status, card brand, last four digits) necessary to bill Customers, enforce entitlements, reconcile revenue, resolve disputes, and meet accounting obligations. Full card numbers, full bank account numbers, and card security codes are not stored by SparrowHawk CRM LLC.
62. Support Communications
Support communications (email exchanges, in-app tickets, phone notes, screenshots, screen recordings the Customer shares, and diagnostic logs the Customer authorizes) are retained to resolve the request, improve support quality, and maintain an audit trail.
63. Marketing Communications
SparrowHawk CRM LLC may send product updates, release notes, newsletters, and other marketing communications to Customers and prospective Customers who have opted in or who have an existing business relationship with SparrowHawk CRM LLC.
Every marketing email includes an unsubscribe link. Unsubscribing from marketing does not stop transactional messages such as billing notices, security alerts, and legal notices, which are necessary to operate the service.
64. International Data Transfers
SparrowHawk CRM LLC is based in the United States and its infrastructure is primarily located in the United States. When a Customer or end user accesses the platform from outside the United States, personal data is transferred to and processed in the United States.
Where a signed Data Processing Addendum requires additional safeguards for cross-border transfers (for example, standard contractual clauses for transfers from the European Economic Area, United Kingdom, or Switzerland), SparrowHawk CRM LLC will implement those safeguards for the covered data.
65. Data Storage Locations
Customer Data is stored with vetted cloud infrastructure and managed database subprocessors. A current list of subprocessors is maintained on the Subprocessor List page.
Some derived and administrative data (search indexes, caches, logs, backups) may transit or reside temporarily in different regions operated by the same subprocessors as necessary to deliver the service.
66. Data Retention and Deletion
SparrowHawk CRM LLC retains personal data for as long as necessary to provide the platform, maintain accounts, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention windows for records including audit logs, backups, invoices, payment records, portal messages, uploaded files, AI logs, and support tickets are described in the Data Retention & Deletion Policy.
Customers can request deletion of Customer Data as described in that policy. Where SparrowHawk CRM LLC acts as processor, the Customer is responsible for responding to end-user deletion requests received directly; SparrowHawk CRM LLC will support the Customer as required by the Data Processing Addendum.
67. User Rights
Depending on the Customer's or end user's jurisdiction, applicable law may grant rights to (a) access personal data SparrowHawk CRM LLC holds about the individual, (b) request correction of inaccurate personal data, (c) request deletion, (d) object to or restrict certain processing, (e) request portability of personal data provided by the individual, and (f) opt out of certain processing activities.
SparrowHawk CRM LLC will honor these rights consistent with applicable law and, where SparrowHawk CRM LLC acts as processor, will assist the Customer in responding to end-user requests. Requests may be sent to privacy@sparrowhawkcrm.com (or support@sparrowhawkcrm.com if that address is not yet monitored).
Where a request concerns data submitted by a Customer about its end users, SparrowHawk CRM LLC may redirect the request to the responsible Customer.
68. Security Measures
SparrowHawk CRM LLC implements administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These safeguards are described in more detail on the Security & Trust Center page and include tenant isolation, encryption in transit and at rest, role-based access control, audit logging, secure development practices, dependency monitoring, and vendor risk management.
No security control is perfect. SparrowHawk CRM LLC cannot guarantee that its safeguards will prevent every possible attack.
69. Children's Privacy
SparrowHawk CRM is a business platform and is not directed to children under the age of thirteen. SparrowHawk CRM LLC does not knowingly collect personal information from children under thirteen. If SparrowHawk CRM LLC becomes aware that it has collected personal information from a child under thirteen, it will delete that information promptly.
70. Privacy Requests
Individuals may submit privacy requests, including access, correction, deletion, restriction, portability, and opt-out requests where applicable, by emailing privacy@sparrowhawkcrm.com (or support@sparrowhawkcrm.com if that address is not yet monitored).
SparrowHawk CRM LLC will acknowledge requests within a reasonable time, may verify the requester's identity to prevent unauthorized disclosure, and will respond within the timeframe required by applicable law.
