HodorSolutions

Privacy Policy

Hodor Solutions LLC — Hodor CRM

DRAFT — pending legal review. This is a working draft for review and approval by qualified legal counsel. Bracketed [COUNSEL: …] notes flag decisions for your attorney.

Last updated: July 13, 2026 · Version: 1.0 (Draft)


1. Who We Are

Hodor Solutions LLC ("Hodor," "we," "us") is a United States software company headquartered in Tampa, Florida. This Privacy Policy explains how we handle personal information in connection with Hodor CRM (the "Service"). For account holders, we generally act as a service provider / processor for the personal information you upload about your leads and contacts, and as a business / controller for the account and usage information we collect about your organization and its users.

Questions? Contact us at privacy@hodorsolutions.com. [COUNSEL: confirm privacy contact mailbox.]

2. Information We Collect

  • Account information: name, work email, organization, role, and credentials.
  • Customer Data you submit: leads, contacts, addresses, notes, canvassing and route activity, and related records you enter into the Service.
  • Usage & device data: log data, IP address, browser/device information, and actions taken in the Service.
  • Location data: approximate or precise location associated with field activity, where your users’ devices provide it.
  • Communications: messages you send to us (e.g., support requests).

3. Where Information Comes From

We collect information directly from you and your users, automatically as you use the Service, and — for Customer Data — from the records your organization chooses to enter or import.

4. How We Use Information

We use personal information to: provide, maintain, and secure the Service; authenticate users; process payments; provide support; monitor and improve performance and reliability; detect and prevent fraud, abuse, and security incidents; and comply with legal obligations. We do not sell personal information, and we do not use Customer Data for advertising.

5. How We Share Information

We share personal information with: service providers / sub-processors who help us run the Service (e.g., cloud hosting, email delivery) under contract; as required by law or to protect rights and safety; and in connection with a merger, acquisition, or sale of assets (with notice as required). We do not sell or "share" personal information for cross-context behavioral advertising as those terms are defined under California law.

A current list of sub-processors is available on request. [COUNSEL: decide whether to publish a sub-processor list page.]

6. Data Location

Personal information is stored and processed on infrastructure located in the United States. The Service is intended for U.S.-based organizations. [COUNSEL: confirm hosting region(s) and any international-transfer posture as the business grows — see internal LEGAL-TODO.]

7. How Long We Keep Information

We retain personal information for as long as your account is active and as needed to provide the Service, then delete or de-identify it in the ordinary course, subject to backups and legal retention requirements. Customer Data is handled per the Terms of Service (export available for 30 days after termination).

8. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to appeal a denied request. For personal information we process on behalf of an organization (Customer Data), please direct requests to that organization; we will assist them as their service provider.

To exercise rights, contact privacy@hodorsolutions.com. We will verify your request and respond within the timeframe required by applicable law. We will not discriminate against you for exercising your rights.

9. California Privacy (CCPA/CPRA)

If you are a California resident, you have the right to know, delete, and correct personal information, and to opt out of "sale" or "sharing" — we do not sell or share personal information as those terms are defined by the CCPA/CPRA. We do not use or disclose sensitive personal information for purposes that require an opt-out. The categories of personal information we collect and our purposes are described in Sections 2 and 4. [COUNSEL: confirm CCPA/CPRA category mapping and any "notice at collection" requirements.]

10. Other U.S. State Privacy Laws

Residents of states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, and others) may have similar rights to access, correct, delete, and obtain a copy of their personal information, and to appeal. We honor these rights as applicable. [COUNSEL: confirm the current list of in-scope states and appeal mechanics.]

11. Cookies & Similar Technologies

We use strictly necessary cookies to operate the Service (for example, to keep you signed in) and limited analytics to understand and improve usage. We do not use advertising cookies. [COUNSEL: confirm cookie inventory and whether a banner is required.]

12. Security

We protect personal information with encryption in transit and at rest, role-based access controls, tenant isolation, and audit logging. No system is perfectly secure, but we work to protect your information and to respond promptly to incidents.

13. Children’s Privacy

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.

14. Changes to This Policy

We may update this Policy. For material changes, we will provide notice and, where appropriate, ask you to review the updated Policy. The current version and its effective date are always available in the Service.