Effective August 5, 2026
OvationCRM is operated by Kringle Tracker LLC, a company based in Fowlerville, Michigan, USA. This policy covers both the ovationcrm.com website and the OvationCRM application, including the booking widget, booking pages, calendar feeds, and public invoice and document pages. It is written to be read, not skimmed past.
Two roles matter throughout. For your account and your organization's relationship with us, we decide how data is handled and this policy describes it. For the information you keep about your clients inside OvationCRM, your organization owns that data and decides why it is collected; we process it on your behalf to run the Service, and your use of it is your responsibility. Your client data is yours, not ours; our Terms of Service say so explicitly.
What we collect
Your account. Name, email address, phone number, time zone, avatar, and login records. Passwords are stored only as modern one-way hashes (Argon2id); we cannot read them.
Your organization. Business name, logo, website, phone, postal address (included in the email you send where anti-spam law requires it), billing email, plan and trial status, and the profile you give us at signup (performer type, and optional background such as years performing and what you switched from). Business settings you choose to store, such as tax ID, DBA, and insurance details, are kept for your use on your documents.
Your clients' information. Whatever your organization enters or imports: client and contact names, emails, phones, addresses, notes, bookings and event details, invoices, and lead inquiries submitted through your booking widget (including the inquiry details and standard web attribution such as UTM parameters and referring page). We use this information only to provide the Service to you. We never market to your clients.
Documents and signatures. Contracts and other documents you create and send, and the signing record for each signer: name, email, signing timestamps, and the signer's IP address, kept as an audit trail. Signed PDFs are stored so you and your signers can retrieve them.
Payments. Amounts, dates, methods, and references for payments you record or collect. Card numbers never touch our servers; Stripe handles card data and we store only Stripe's identifiers and receipts. Your Stripe onboarding and payout details are between you and Stripe.
Usage. We run our own first-party product analytics inside the application: which features are used, tied to your organization and user ID. These events do not record your IP address, browser, or pages from outside the app, and no third-party analytics service is involved. The embeddable booking widget records form analytics (views, starts, submissions) with a random session identifier, browser user agent, and a hashed, non-reversible form of the visitor's IP address. Email we send for you records delivery status and opens so you can see whether your client received and opened it.
Security records. Sign-in and account-security events (including IP address and browser) are kept for 90 days. Support requests and feedback you send us, including any screenshots you attach, are kept so we can help you.
On the website. If you join the waitlist we keep your email address for launch invitations. The website uses self-hosted, cookie-free Umami analytics for aggregate page counts; it does not track you across other sites.
What we never do
We do not sell personal information. We do not share it with advertisers or ad networks. We do not use advertising cookies or cross-site trackers, on the website or in the application. We do not use your content to train artificial-intelligence models. The only cookies the application sets are the encrypted session cookies that keep you signed in.
How we use information
To provide and operate the Service; to send the email you ask the Service to send; to bill subscriptions; to secure accounts and investigate abuse; to understand which features are used so we can improve them; to answer support requests; and to meet legal obligations. That is the whole list.
Google Calendar data
If you connect your Google account, OvationCRM requests three narrow permissions and uses them only to run the calendar features you turned on.
What we access. A list of the calendars in your account, so you can choose which ones to check for conflicts. Busy and free time blocks from the calendars you chose, which tell us when you are unavailable but never include event titles, guests, locations, or notes. And a single calendar named "OvationCRM" that the application creates in your account, which it reads and writes so your bookings stay current. We cannot read, edit, or delete events on your personal calendars.
How we use it. Only to put your OvationCRM bookings on your Google calendar and to warn you before you double-book. Nothing else.
How we store it. Your Google access and refresh tokens are encrypted at rest. Busy and free times are used to check for conflicts and are not retained as a copy of your schedule.
What we never do. We do not sell Google user data. We do not transfer it to third parties except as needed to provide the calendar features you asked for, or where the law requires it. We do not use it for advertising. We do not use it to train machine learning or AI models. We do not let humans read it, except where you have given us specific permission, where it is needed for security purposes such as investigating abuse, or where the law requires it.
Turning it off. Disconnect at any time from Settings in the application, or revoke access from your Google account security page. When you disconnect we delete the stored tokens and stop all access. The "OvationCRM" calendar stays in your account until you delete it yourself.
OvationCRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Who we share information with
Only service providers acting on our instructions to run the Service, or where the law requires disclosure. Our providers:
| Provider | What it does | What reaches it |
|---|---|---|
| DigitalOcean (New York, USA) | Hosts the application and databases | All Service data |
| Amazon Web Services (USA) | Delivers email; stores files | Email addresses and message content; uploaded files and signed documents |
| Stripe (USA) | Subscription billing; client payments via Stripe Connect | Organization name and billing email; payment amounts and payer name/email on client payments |
| DocuSeal (USA) | E-signature processing | Signer names and emails, and the documents being signed |
| Google (USA) | Calendar sync, only if you connect it | As described in "Google Calendar data" above |
We do not share your clients' information with anyone else, and we require providers to protect the data they process for us.
How we protect it
All traffic to the Service is encrypted in transit. Google tokens are encrypted at rest with AES-256-GCM. Passwords are hashed with Argon2id, and session and reset tokens are stored hashed. Access inside an organization is controlled by roles and capabilities, and account-security events are logged. No system is perfectly secure, but the Service is built so that the most sensitive material is useless if stolen alone.
How long we keep it
- Your account and organization data: for as long as your account is active. If your subscription lapses, your organization is suspended, not deleted, so returning performers (including seasonal ones) pick up where they left off.
- Security logs: 90 days.
- Reminder and delivery ledgers: up to 12 months.
- Expired sign-in and verification tokens: purged automatically.
- Waitlist emails: until launch invitations complete or you ask to be removed, whichever comes first.
Your rights and choices
Wherever you live, you can ask us to access, correct, export, or delete the personal information we hold about you or your organization. Email hello@ovationcrm.com and we will complete your request within 30 days. Organization owners may request deletion or a full export of their organization's data the same way. If your information is in another performer's OvationCRM account (for example, you are their client), contact that performer first; we will help them honor your request.
You can disconnect Google Calendar, unsubscribe from optional email, and update your account information at any time from within the application.
Children
The Service is for business use and accounts require you to be at least 18. We do not knowingly collect personal information from children. Performers sometimes store family-event details in their own client records; that data belongs to the performer's organization, which is responsible for collecting it lawfully.
Where data lives
The Service is hosted in the United States. If you use it from elsewhere, you understand your information is processed in the US.
Changes to this policy
When we change this policy we will post the new version here with a new effective date, and for significant changes we will email account owners before they take effect.
Contact
hello@ovationcrm.com
Kringle Tracker LLC, Fowlerville, Michigan, USA.