Privacy Policy
Last updated: August 4, 2026
HUMBOLDT TECHNOLOGIES LLC (Florida Sunbiz document number L26000107116; filed February 20, 2026; principal office and mailing address: 160 W Evergreen Ave, Suite 290, Longwood, FL 32750) ("HUMBOLDT TECHNOLOGIES LLC", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the Humboldt CRM platform, subject to applicable law.
Information We Collect
We collect the following categories of information, including: Information you provide directly: name, email address, phone number, mailing, property, and billing addresses, and payment information (processed by Stripe; we do not store full card numbers). Account and business records: account and team details; customer, client, contact, employee, and subcontractor records; tax and identity information, including subcontractor tax IDs; custom fields; notes and other free-text content; and information submitted through forms. Service and communications content: scheduling, job, quote, invoice, payment, and request records; message content and delivery information; voice recordings, voice transcriptions, and voice commands; call recordings, call transcripts, and call metadata; electronic signatures; photos; files; documents; and other uploaded content. Location information: browser geolocation used by the web scheduler, mobile-device location used by mobile features, precise technician location history, and coordinates used for scheduling, routing, or mapping. Information collected automatically: usage data, IP addresses, browser type, device information, cookie or storage identifiers, and diagnostic or performance information. Information from integrations and communications providers: calendar, accounting, CRM, email, SMS, voice, push-notification, and payment-related records or identifiers, depending on the features used. Users may submit free text, files, photos, documents, recordings, or other content that contains sensitive information. Some features intentionally collect tax or identity information, such as a subcontractor tax ID, and free-text, upload, and document fields accept content supplied by users. Do not submit Social Security numbers, driver's license numbers, financial account numbers, medical information, biometric data, or other restricted information unless a feature expressly requires it and you are authorized to provide it. We do not guarantee that the Services will detect or reject prohibited information.
How We Use Your Information
We use the information we collect to provide, maintain, secure, and improve the Services; process transactions; send service and account notifications; respond to comments, questions, and support requests; operate optional integrations and communications requested by an Account Owner; monitor reliability and security; and detect, prevent, and address technical, fraud, or security issues. Account Owners are responsible for determining whether marketing communications are permitted by law, obtaining and documenting any consent or other basis required, and honoring applicable opt-out requirements. The Services do not currently validate or enforce consent or suppression status for marketing communications. Do not use the Services to send marketing communications unless you have established the required permissions and controls. We do not sell or share personal information for advertising or marketing purposes. We do not share personal information for monetary consideration, targeted advertising, or cross-context behavioral advertising. We do not use personal information for targeted advertising or profiling. Account Owner Data is handled as described in Section 9.
Data Sharing and Disclosure
We do not sell or share personal information for advertising or marketing purposes. We do not share personal information for targeted or cross-context behavioral advertising. We may disclose information to service and infrastructure providers that process it as needed to provide, secure, support, or improve the Services. Depending on the features used, these providers may include Convex (database and backend); Clerk (authentication); Stripe (payments and billing); Railway (application hosting where configured); Cloudflare (R2 file and object storage plus application-edge, CDN, Bot Fight Mode, and WAF services); Twilio (SMS/MMS); Resend (email); Axiom (application logs and events); Sentry (error, performance, replay, and reliability diagnostics); Inngest (background jobs); Upstash Redis (rate limiting); OpenAI (AI features, live voice conversations, voice transcription, message generation, document/image upload and extraction from uploaded document images and PDFs for bulk customer and business records, including names, contact details, addresses, account information, invoices, job information, and other records contained in those documents); Google Maps Platform (address autocomplete, maps, routing, and route optimization); Google Calendar (calendar synchronization); Google identity sign-in (identity authentication); GoHighLevel/LeadConnector (optional CRM contact synchronization); QuickBooks/Intuit (optional accounting integration for contacts, invoices, estimates, expenses, and time entries); Expo (optional mobile push delivery); OpenStreetMap (public tracking map embeds); Apple (Sign in with Apple and optional Apple Maps navigation); Apple Speech framework or Google Speech Recognition, depending on device configuration (mobile speech recognition); and unpkg (public API documentation assets). Optional providers receive information only when the relevant feature is enabled or used. Before publication, HUMBOLDT TECHNOLOGIES LLC will maintain a current public list of these providers, their functions, and data categories at the /subprocessors page. The list may change as providers or features change, subject to any notice required by law or contract. We may also disclose information to legal authorities when required by law, subpoena, or court order, to protect rights and safety, or in connection with a merger, acquisition, financing, or sale of assets. This general service-provider disclosure does not authorize sharing mobile telephone numbers or SMS opt-in consent with third parties or affiliates for marketing or promotional purposes, or for any purpose unrelated to the consented service. The SMS-specific rules in Section 10 control if there is a conflict.
Data Security
We use security measures intended to protect your information, including role-based access controls, access monitoring, and encryption of certain integration tokens in the application. Named infrastructure providers, including Convex, Cloudflare R2, Clerk, Stripe, and Twilio, may provide additional encryption and transport protections according to their configurations and terms; the application does not independently verify or enforce a single TLS version or encryption standard across every provider. No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
Data Breach Notification
In accordance with the Florida Information Protection Act (FIPA §501.171), if we determine that a security breach has affected your personal information, we will notify you within 30 days after determination of the breach, as required by applicable law. The notification will include a description of the incident, the categories of information affected, the steps we are taking in response, and contact information for inquiries. If the breach affects 500 or more Florida residents, we will also notify the Florida Department of Legal Affairs.
Data Retention and Disposal
We retain personal information for as long as needed to provide the Services, maintain security, comply with legal, tax, accounting, payment-provider, and regulatory obligations, resolve disputes, enforce agreements, and support legitimate business purposes. Retention depends on the type of record, its purpose, Account Owner instructions, legal requirements, and the systems or service providers involved. The application does not currently apply a universal 90-day post-cancellation hard-deletion timer or a universal seven-year timer to all data. We therefore do not promise that all data will be deleted, anonymized, or retained for either period. Financial and billing records may be retained as needed for accounting, tax, payment, legal, dispute, and security purposes; the final period should be confirmed with Florida counsel and an accountant. An Account Owner may request an export or deletion by contacting privacy@usehumboldt.com. We will review the request, applicable law, contractual instructions, backups, audit logs, fraud and security records, legal holds, and other permitted exceptions and communicate the applicable process. Soft-deleted records and copies held by service providers or backups may remain until their applicable lifecycle ends.
Your Rights
You have the right to: access the personal information we hold about you; correct inaccurate information; request deletion of your personal information; object to or restrict certain processing; request portability of your data in a machine-readable format; withdraw your consent at any time; opt out of marketing communications; and opt out of targeted advertising or profiling (though we do not currently engage in either activity). To exercise any of these rights, contact us at privacy@usehumboldt.com. We will respond to your request within 45 days.
Cookies and Tracking
We use cookies and similar storage that are necessary for authentication, security, OAuth state, language, and core functionality. The application does not currently display a cookie consent banner or an in-app preference center. When configured, Sentry may collect error, performance, and replay diagnostics. The application may store conversion and UTM attribution data in sessionStorage and may send a conversion event to a dataLayer only when a host page has supplied one. We did not find an advertising-cookie or cross-site behavioral advertising tag in the application code. You can block or delete cookies and similar storage through your browser or device settings, but Humboldt does not currently provide an in-app cookie-preference control. Blocking essential storage may affect authentication or platform functionality.
Account Owners and End Users
The Humboldt CRM platform lets a contractor or other business (the "Account Owner") upload and manage personal information about its customers, clients, contacts, employees, subcontractors, and other individuals (the "End Users"). For this Account Owner Data, the Account Owner generally decides why and how the information is collected and used. HUMBOLDT TECHNOLOGIES LLC processes Account Owner Data on the Account Owner’s instructions as a service provider or data processor to provide, secure, and support the Services. Each Account Owner represents and warrants that it has the rights, permissions, notices, consents, and lawful bases required to collect, submit, use, and direct HUMBOLDT TECHNOLOGIES LLC to process Account Owner Data, including telephone numbers and any SMS consent information. The Account Owner is responsible for its privacy notices, consent records, messaging practices, and responses to End User requests. If you are an End User, direct an access, correction, deletion, restriction, portability, or marketing/SMS opt-out request to the Account Owner that submitted your information. If you send such a request to HUMBOLDT TECHNOLOGIES LLC, we may direct you to the Account Owner or forward the request as appropriate and assist the Account Owner. HUMBOLDT TECHNOLOGIES LLC may act as an independent controller for its own account, billing, security, support, legal, and business records. The precise roles and obligations should be confirmed in the parties’ agreement or Data Processing Addendum and by counsel.
SMS and Text Messaging
The Services may allow an Account Owner to send and receive SMS or text messages through Twilio or another communications provider. Account Owners are responsible for obtaining and preserving any prior express written consent required before sending marketing or other regulated messages, and for complying with applicable messaging, frequency, content, and opt-out rules. Consent must identify the applicable sender and requested service; Account Owners must not use the Services to send messages to a mobile number without the permission required for that use. Mobile telephone numbers and SMS opt-in consent are not shared with third parties or affiliates for marketing or promotional purposes. Mobile telephone numbers and SMS opt-in consent are not shared for any purpose unrelated to the consented service. We may disclose a mobile number, message content, and delivery information to Twilio or another communications provider only as necessary to deliver, route, secure, troubleshoot, or support the consented SMS service. Those providers may not use that information for their own marketing. This rule controls over the general service-provider disclosure in Section 3. Messages may include appointment reminders, service updates, replies, or marketing messages sent by an Account Owner. Message and data rates may apply, and message frequency varies. The application currently does not maintain a first-party SMS consent or opt-out state and does not implement HELP/STOP keyword handling. Until those controls are live, Account Owners must maintain their own consent and suppression records and must not represent that the Services provide those controls. After the required controls are implemented, the enrollment and message instructions may state: "You are now opted in to receive SMS messages. For help, reply HELP. To opt out, reply STOP. Messages and data rates may apply. Message frequency varies." Recipients should be able to reply HELP for help and STOP, END, CANCEL, UNSUBSCRIBE, or QUIT to opt out, subject to applicable law and the applicable messaging program. For questions about SMS privacy or consent records, contact privacy@usehumboldt.com.
Children's Privacy
The Humboldt CRM Services are not directed to individuals under 18. HUMBOLDT TECHNOLOGIES LLC does not knowingly collect personal information directly from children in violation of applicable law. If we learn that we received personal information from a child when collection was not permitted, we will take reasonable steps to address and delete it as required by law. If you believe a child has provided personal information, contact privacy@usehumboldt.com.
Contact Us
If you have questions about this Privacy Policy, our data practices, or a privacy request, contact: HUMBOLDT TECHNOLOGIES LLC Principal office and mailing address: 160 W Evergreen Ave, Suite 290, Longwood, FL 32750 Email: privacy@usehumboldt.com We will handle privacy requests within the time required by applicable law and will communicate if more time or information is needed.