Privacy Policy
Last Updated: August 24, 2026
The Solo Software Group LLC (“TSSG,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains what personal data we collect, why, and what you can do about it, in connection with the TSSG CRM Pro plugin (“Plugin”), the TSSG Managed AI Service, and our website at www.thesolosoftwaregroup.com (collectively, the “Service”).
Who This Policy Is About
This policy covers you: our customers, trial users, prospective buyers, newsletter subscribers, and anyone who contacts us.
It does not cover your clients. If you use the Plugin to manage your own customers, their personal data lives in your database on your server, under your control. For that data, you are the controller and this policy does not apply to it. Your clients should be looking at your privacy notice, not ours. The one exception is the Managed AI Service, where we do process some of that data on your behalf; see Section 4.
We say this plainly because conflating the two is the most common error in plugin privacy policies, and it would misdescribe what actually happens.
1. The Plugin Is Self-Hosted
TSSG CRM Pro installs on your own WordPress site and stores every record you create in your own database, on your own hosting.
We do not receive, host, access, or store your business data. Your clients, contacts, proposals, jobs, invoices, payments, messages, signatures, files, and activity logs never reach us. We have no ability to read them, no copy of them, and nothing to hand over if someone asks us for them.
There are exactly three narrow paths by which any data reaches us, each described below: licence and update checks, the optional Managed AI Service, and support correspondence you choose to send.
2. Information We Collect
Purchase and Account Data
When you buy a paid tier, the transaction is handled by Freemius, Inc., our reseller and merchant of record. Freemius collects your name, email address, billing address, tax information, and payment details, and processes payment through its own payment providers.
We never see or store your payment card number. From Freemius we receive your name, email address, country, licence key, purchase and renewal history, and subscription status, which we use to deliver entitlement, updates, and support. Freemius handles this data under its own privacy policy and terms.
Licence Validation and Update Checks
Your installation periodically contacts our licensing infrastructure to confirm entitlement and check for updates. These requests transmit your site URL, licence key, plugin version, and the IP address the request originates from. This is necessary for the Service to function and cannot be switched off while a paid licence is active. It carries no business data.
Optional Usage Analytics
If you opt in, we collect anonymized, aggregated usage signals such as which features are exercised and which errors occur, so we can prioritize development. This is off by default, opt-in only, carries no client data, and can be switched off at any time in the Plugin settings.
Managed AI Service Data (Sovereign Tier, If Enabled)
See Section 4. This is the only path by which your clients’ personal data can reach us, and only if you turn it on.
Support Correspondence
When you email support, we receive whatever you send, including any screenshots, log excerpts, or exports you attach. Please redact client personal data before sending it. We keep support correspondence for as long as needed to resolve the matter and for a reasonable period afterwards for context on future requests.
Website Data
Our website collects standard server log data (IP address, browser type, referring page, timestamps) and may use cookies or similar technology for functional purposes and, where applicable, basic analytics. Where required by law, we ask for consent before setting non-essential cookies.
What the Plugin Stores Locally
For completeness, and because it is often asked: the Plugin uses cookies and browser local storage on your own site for functional purposes such as preserving in-progress edits, remembering interface preferences, and managing session state. That data stays in your browser and on your server. It does not come to us.
The Plugin also maintains a consent ledger in your database, recording each time one of your clients or your staff gives or withdraws consent to be contacted: the date and time, how it was captured, the exact disclosure shown, the name, email address, and telephone number as they stood at that moment, and the staff member who recorded it. That ledger is append-only, and it is deliberately retained after the record it concerns has been deleted, because claims about unlawful contact can be brought for years afterwards and evidence that expires first is no evidence at all. It is yours, it stays on your server, and no copy comes to us. If you operate the Plugin, this is data you control, and your own privacy notice and your handling of erasure requests should account for it.
3. Third-Party Integrations You Configure
The Plugin can connect to Stripe (payments), Twilio (SMS and MMS), your email or SMTP provider, and AI providers whose API keys you supply.
Those are your accounts and your relationships. Data flows directly between your WordPress site and those services. We are not in the path, we do not intermediate the traffic, and we retain none of it. Each of those providers is a processor or controller of yours, not of ours, and each should appear in your own privacy notice, not this one.
4. AI Features and the Managed AI Service
4.1 What the AI Actually Receives
We want to be precise here, because this is easy to describe in a way that sounds better than the truth.
The AI assistant operates by calling tools inside the Plugin. It searches your records, reads them, drafts documents, and, on your confirmation, writes changes. The results of those tool calls are sent to the AI model. When you ask the assistant about a client, an invoice, or a proposal, the relevant records, which can include names, addresses, email addresses, phone numbers, and financial figures, are transmitted to the AI provider as part of that request.
The AI has no standing or background access to your database and receives only what a given request causes it to retrieve, plus what you type. But within that scope, real personal data does leave your server and reach the model provider.
4.2 Own-Key Mode
If you supply your own provider API key, your data travels directly from your site to that provider under your own account and agreement. TSSG is not in the path and receives nothing. That provider’s terms, including retention and model training terms, govern the data, and we encourage you to read them before enabling AI.
4.3 Managed AI Service
If you enable Managed AI on the Sovereign tier, your AI requests are transmitted to infrastructure we operate, which forwards them to our model provider and returns the response. In this mode:
- TSSG acts as a processor and you act as the controller for any personal data in those requests. Our obligations are set out in our Data Processing Agreement, which applies automatically when you enable Managed AI.
- Our current model provider and infrastructure sub-processors are published, with a change history, on our Sub-processors page.
- Our model provider does not use requests sent through the paid service to train its models, and does not subject them to human review. Requests are logged transiently for security, abuse prevention, and legal compliance before deletion.
- We record usage metering so we can enforce fair-use limits and manage cost. Each metering row holds a timestamp, your licence identifier, the provider and model used, input, cached and output token counts, the computed cost, the HTTP status, and the round-trip duration. It holds no part of the request or the response.
- Request and response content is never written to storage by TSSG. It exists in memory for the duration of the call and is discarded once the response is returned.
- Requests are processed in the United States and in other countries where our providers operate. We do not offer a data residency guarantee on this service. See Section 10.
Enabling Managed AI has a consequence for your own compliance. It adds a processor to your chain. If you are subject to the GDPR, the UK GDPR, or a comparable law, your own privacy notice needs to disclose it, and your legal basis for the underlying processing needs to cover it. The Plugin tells you this at the point where you switch the mode on, and the Sub-processors page exists so you can name us and our providers accurately.
5. How We Use Information
We use the information described above to: deliver the Service, including licence entitlement, updates, and the Managed AI Service; process and administer your subscription through Freemius; respond to support requests and communicate with you about your account, security matters, and material changes; enforce fair-use limits and prevent abuse of the Managed AI Service; improve the Plugin using opt-in analytics and aggregated data; send product announcements and marketing where you have consented or where permitted by law, always with an unsubscribe link; and comply with legal obligations and enforce our Terms.
We do not sell, rent, or share your personal information for cross-context behavioural advertising, and we do not use your data, or your clients’ data, to train any AI model of our own.
Legal Bases (EEA, UK, and Similar Jurisdictions)
- Contract: delivering the Service, processing your subscription, providing support.
- Legitimate interests: securing the Service, preventing abuse, managing cost, improving the product. We balance these against your rights and you may object.
- Consent: optional analytics, non-essential cookies, and marketing email where consent is required. You may withdraw consent at any time.
- Legal obligation: tax, accounting, and responding to lawful requests.
6. Who We Share It With
Freemius (reseller, merchant of record, licensing) receives and holds purchase and licence data.
Infrastructure and model providers for the Managed AI Service, listed on our Sub-processors page.
Operational service providers for website hosting, transactional email, and similar functions, each under contract and limited to what their function requires.
Legal and safety: we may disclose information where required by law, legal process, or a governmental request, or where necessary to establish or defend legal claims, or to protect the rights, safety, or property of TSSG or others.
Business transfer: if TSSG is involved in a merger, acquisition, financing, or sale of assets, customer information may be transferred as part of that transaction. You will be notified, and any acquirer remains bound by this policy or gives notice before materially changing it.
We do not share your data with anyone else.
7. Retention
- Purchase and licence data: for the life of your account and then as long as required for tax, accounting, and legal purposes, generally seven years.
- Support correspondence: typically up to three years after resolution.
- Managed AI usage metering: typically up to 24 months, for billing, capacity, and abuse investigation.
- Managed AI request content: not retained by TSSG beyond the time needed to forward the request and return the response. Retention by our model provider is stated on the Sub-processors page.
- Website logs: typically up to 12 months.
- Your business data: retained by you, on your server, for as long as you choose. We hold no copy and cannot delete it for you. This includes the Plugin’s consent ledger, which is deliberately retained after the record it concerns is deleted, for the reason given in Section 2.
8. Security
We use industry-standard measures to protect the data we hold, including encryption in transit, encryption at rest for credentials and secrets, access controls, and least-privilege administration.
Within the Plugin, credentials you enter (API keys, webhook secrets, provider tokens) are encrypted at rest in your own database.
On the Managed AI Service, every request is authenticated against a valid licence before it reaches a provider, provider endpoints and models are restricted to a fixed allowlist, request size and output length are capped, and rate limits and spend counters are enforced per licence so no customer’s activity can affect another’s.
Your business data is protected by your hosting environment, not ours. Please keep WordPress, your theme, and your plugins updated, use strong credentials and two-factor authentication, run TLS, and maintain your own backups.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affecting your personal data occurs, we will notify you and any regulator as applicable law requires, and within the timeframe stated in the Data Processing Agreement where it applies.
9. Your Rights
Depending on where you live, you may have the right to: access the personal data we hold about you and receive a copy; correct inaccurate or incomplete data; delete your data, subject to legal retention requirements; port your data in a structured, machine-readable format; object to or restrict processing based on legitimate interests; withdraw consent at any time, without affecting processing already carried out; not be discriminated against for exercising these rights; and lodge a complaint with your local supervisory authority (EEA/UK) or Attorney General (California).
To exercise any of these, email [email protected]. We will respond within the period applicable law requires, generally 30 days, and may need to verify your identity first.
Marketing: every marketing email carries an unsubscribe link that works without logging in and is honoured promptly.
A note on scope. These rights apply to data we hold about you. If you are one of our customers’ clients and want your data corrected or deleted, we are not the right party to ask, because we do not hold it. Contact the business you dealt with. If you cannot identify them, write to us and we will help you find the right contact where we can.
California residents. We do not sell personal information and do not share it for cross-context behavioural advertising. The categories we collect, the purposes, and the recipients are described in Sections 2, 5, and 6. You may designate an authorized agent to make a request on your behalf.
10. International Transfers and Data Residency
We are based in the United States. If you are outside the US, the data described in this policy may be transferred to and processed in the US and in other countries where our providers operate.
The Managed AI Service does not offer a data residency guarantee. Our model provider’s standard API processes requests across its global infrastructure, and we do not pin processing to a region. If your business requires processing confined to a specific jurisdiction, use own-key mode with a provider configuration that meets your requirement, or contact us to discuss options.
Where required, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures as appropriate. For Managed AI, the transfer terms are set out in the Data Processing Agreement.
11. Children
The Service is a business tool intended for users aged 18 and over. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete it promptly. If you believe a child has provided us with personal data, contact us.
12. Changes
We may update this policy. Material changes will be posted here with a revised date and, for registered customers, announced by email, ordinarily at least 30 days before they take effect. Please review it periodically.
13. Contact
For questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at [email protected], marked “Privacy.”
EEA and UK users may also lodge a complaint with their local supervisory authority.
