Legal

Privacy Policy

Plain English, short version first. Effective July 31, 2026.

Effective date: July 31, 2026.

Eco Systems CRM & More ("Eco Systems," "we," "us") provides loyalty, CRM, SMS, and store-operations software to independent retail stores. This policy explains, in plain English, what data we handle and how. It covers this website (ecosystemscrm.com) and the Eco Systems platform, including store subdomains.

The short version

  • On the platform, your store's customer data belongs to your store. We process it to run your loyalty program — we don't sell it, rent it, or use it to market to your members ourselves.
  • This marketing site loads no third-party analytics, ad trackers, or external scripts. The only data it collects is what you type into the demo form.
  • SMS consent is recorded only from explicit opt-ins, and opt-outs are honored immediately and permanently.

Two roles: our website vs. the platform

Website visitors. If you submit the demo form, we receive the fields you enter (name, email, store name, phone, message) and use them to respond to you. That's it — no tracking pixels, no analytics cookies, no data brokers.

Platform data (we act as a processor). When a store runs its loyalty program on Eco Systems, the store is the controller of its member data and we process it on the store's behalf. This includes member names, phone numbers, email addresses, points balances, visit check-ins, purchase activity synced from Shopify, reward redemptions, and SMS consent records (including source and timestamp). We use this data to operate the program that store configured — and for nothing else.

SMS consent and messaging (TCPA)

  • Members opt in through an explicit action — typically the consent checkbox on the store's check-in kiosk — and each consent is logged with its source and timestamp.
  • Consent is never assumed, purchased, or bulk-applied, including during migrations from other platforms. Opt-out lists migrate first and absolutely.
  • Replying STOP to any message opts the member out immediately and permanently for that store. Marketing messages include opt-out language.
  • Messages are sent via Twilio under each store's registered A2P 10DLC brand and campaign.

Who we share data with (subprocessors)

We use a small set of infrastructure providers to run the service: Cloudflare (hosting, storage, and network infrastructure), Twilio (SMS delivery), Stripe (billing — we never see full card numbers), and Shopify (order and POS data for stores that connect it). Each receives only what its function requires. We do not sell personal data to anyone, and there are no advertising partners.

Data ownership and export

Your data is yours. Stores can export their member list, balances, history, and consent records at any time, including on the way out — no plan-tier gate, no exit fee. If a store closes its account, we delete its tenant data after a reasonable wind-down period, except records we must retain (for example, billing records and opt-out lists, which persist so departed members stay opted out).

Security

Each store's data lives in its own isolated database. Credentials for connected services are write-only in our systems — never displayed back, never logged. Access to production data is limited to what operating the service requires.

Retention, your rights, and contact

We keep platform data for as long as the store's account is active. Members who want their data corrected or deleted should contact their store (the controller); we assist stores in honoring those requests. Website form submissions are kept only as long as the conversation warrants. For anything in this policy — questions, export requests, deletion requests — email info@sid-shoots.com.

Changes

If we change this policy, we'll update the effective date at the top and, for material changes affecting stores, notify store owners directly.

This document is a working draft prepared for owner review. Questions? info@sid-shoots.com.