Notice at Collection

1. Who collects information and why

CoveCRM, operated by Vault Commerce Group LLC, processes the categories below depending on how you interact with the service and the features a customer uses. For a form or communication operated by an insurance agency or another business customer, that customer also determines relevant purposes and should provide its own identity and notices.

This is a summary of possible collection, not a statement that every field is required. Providing contact details is not blanket permission for marketing, AI calls or recording. Any required specific consent remains separate.

Read the Privacy Policy and California & U.S. State Privacy Supplement for full context. The availability of this page does not mean it is presented in every signup, lead, booking or import flow.

2. Account, authentication, and business details

Categories: name, email, phone, company/role, account credentials in protected form, session and verification information, preferences, IP/device and security information; business/contact and registration information for telecom/A2P onboarding.

Purposes: account administration, authentication, support, security, service delivery and telecom registration. Sources: you, your organization and connected identity/telecom services. Recipients: authorized account users and relevant hosting, identity, communications and support providers.

3. Leads, imports, and insurance information

Categories: names, contact information, addresses/state, lead sources/status, notes, appointments, files, custom fields and imported rows. Customers may include date of birth, health information, income, mortgage, beneficiary and insurance/coverage information where relevant to their workflow.

Purposes: organize customer records, respond to requests, coordinate appointments, perform authorized follow-up and provide selected analysis. Sources: you, customer imports/vendors, forms, spreadsheets and authorized integrations. Recipients: the relevant business customer and its authorized users, relevant service providers, and integrations or communications recipients selected for that workflow. Do not submit unnecessary sensitive information.

4. Communications, AI, and consent records

Categories: SMS/MMS and email content/media, metadata, audio and recordings, transcripts, AI prompts/context/outputs, summaries, support interactions, consent wording/version, choices, source/page, timestamps, IP and user agent.

Purposes: deliver and document communications, provide enabled recording/transcription/AI/support features, and preserve consent or suppression evidence. Sources: participants, users, forms and providers. Recipients: relevant customer users, intended recipients, telecom/email/AI providers and infrastructure providers. Recording and autonomous AI may operate in enabled workflows; required notices and permissions must be addressed separately.

5. Payments and transactions

Categories: subscription, purchase and usage records, invoices, billing/contact details, payment-provider identifiers and payment-method information returned by the provider; affiliate attribution and payment information.

Purposes: payment processing, accounting, renewals, usage billing, fraud prevention, disputes and referral administration. Sources: users and payment providers. Recipients: payment processors, relevant providers, authorized business personnel and advisers as necessary.

6. Website, advertising, and optional prospecting

Categories: IP/device/browser, page and session activity, replay information, cookie/advertising identifiers, referral codes, Meta campaign/form/lead identifiers, conversion outcomes and hashed contact identifiers. Optional recruiting may include professional/public-source and social-profile information and connected browser context.

Purposes: site measurement/improvement, customer-directed advertising attribution/optimization, referral tracking and selected prospecting workflows. Sources: browser activity, customers, connected platforms and permitted customer-selected sources. Recipients: Microsoft Clarity, Meta and other applicable providers/integrations described in the register.

Optional technologies may load before banner acceptance. Cove does not currently provide a preference center or automatic GPC handling. See Cookies and Subprocessors & Integrations.

7. Retention and choices

Retention is based on the service relationship, customer instructions, category and purpose, consent/suppression evidence, and applicable legal, tax, accounting, telecom, security and dispute requirements. Related vendor records and backups may remain after an in-app deletion. No single fixed period applies to every category; see Privacy Policy section 10.

Where applicable law provides sale/sharing, targeted-advertising or sensitive-information choices, you may request them through the privacy contacts. Whether a particular transfer falls within those definitions depends on the actual practice, role and law; this notice does not conclusively classify every transfer. Describing a right here does not implement an automatic tracking opt-out.

Contact support@covecrm.com or legal@covecrm.com for access, correction, deletion or other applicable privacy requests. The state supplement explains verification, authorized agents and appeals where applicable.