IT Support Depot Privacy Policy
This Privacy Policy explains how IT Support Depot, LLC ("ITSD," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you visit our websites, apply for or use the ITSD Platform and related services, communicate with us, or otherwise interact with ITSD.
1. Scope and our role
This Policy applies to personal information we handle for our websites, trial applications, accounts, billing, sales, support, security, and service operations. For that information, ITSD generally acts as a controller or business. When an MSP or other customer uses the Services to process information about its customers, end users, technicians, contacts, devices, tickets, documentation, credentials, or managed environments ("Customer Data"), ITSD generally acts as a processor or service provider on the customer's instructions. The customer remains responsible for its own privacy notices, legal basis, permissions, and responses to individuals.
2. Information we collect
Depending on how you interact with us and which features your organization enables, we may collect:
- Account and business information: name, business email, telephone number, company, domain, country, job role, user role, site access, and account preferences.
- Authentication and security information: password hashes, multi-factor status, identity-provider identifiers, login times, IP addresses, device and browser information, session records, and security or audit events.
- Subscription and transaction information: plan, license counts, trial status, billing contact, Stripe customer or subscription identifiers, invoices, referral information, and payment status. ITSD does not collect card details on Basic trial signup; payment card data submitted during a purchase is handled by the payment processor.
- Website and usage information: pages viewed, actions taken, approximate location derived from IP address, referral source, diagnostic events, and essential cookie or session identifiers.
- Communications: sales inquiries, support requests, emails, ticket content, feedback, and related attachments.
- Customer Data: device identifiers and telemetry, hardware and software inventory, users, sites, network information, endpoint status, scripts and task results, tickets, contacts, documentation, secrets and credentials, remote-session metadata, audit records, and other content selected by the customer.
3. Sources of information
We collect information directly from you; from your employer, MSP, administrator, or authorized user; automatically from browsers, endpoint agents, portals, and service logs; from integrations you authorize; from payment, identity, email, hosting, security, and support providers; and from lawful public or commercial sources used for business contact and fraud prevention.
4. How we use information
We use personal information to evaluate and create trials; provide, authenticate, administer, and support the Services; route tenant and site access; process subscriptions and referral credits; communicate service and security notices; protect accounts and investigate abuse; maintain auditability; troubleshoot, monitor, and improve reliability; comply with law; enforce agreements; and establish, exercise, or defend legal claims. We may send product or marketing communications where permitted, and you may opt out of marketing without affecting operational messages.
5. Legal bases
Where a legal basis is required, we process information as necessary to perform a contract or take requested pre-contract steps, comply with legal obligations, protect vital or legitimate interests such as securing the Services and operating our business, and based on consent where required. You may withdraw consent for future processing, but withdrawal does not affect earlier lawful processing.
6. Customer Data and sensitive content
Customer administrators decide what Customer Data is collected and how it is used. Customer Data may include confidential or sensitive operational information. ITSD processes that data to provide the enabled features and under the customer's instructions, contract, and applicable law. Secrets and protected credentials should be placed only in designated secured fields. Dashboard, reporting, and audit functions are designed to avoid displaying secret values unnecessarily.
7. How we disclose information
We may disclose relevant information to:
- authorized users, administrators, MSPs, customers, and end users according to configured tenant, site, role, and feature permissions;
- service providers supporting hosting, storage, email delivery, authentication, payments, fraud prevention, logging, monitoring, security, customer support, and professional advice;
- third-party products and integrations that a customer enables;
- a successor or participant in a merger, financing, acquisition, reorganization, or sale, subject to appropriate confidentiality protections; and
- courts, regulators, law enforcement, or other parties when reasonably necessary to comply with law, protect rights or safety, investigate fraud or security incidents, or enforce agreements.
We do not sell personal information for money and do not share personal information for cross-context behavioral advertising. We do not use Customer Data to market unrelated third-party products.
8. Cookies and similar technologies
Our sites and portals use cookies or local storage that are necessary for sign-in, security, fraud prevention, preferences, and session continuity. If we use non-essential analytics or advertising technologies where consent is required, we will provide an appropriate choice. Browser settings may block cookies, but essential features may then stop working.
9. Retention
We retain personal information for as long as needed for the purposes described in this Policy, including the duration of an account or customer relationship, configured product retention periods, security and backup cycles, and legal, tax, accounting, dispute, or enforcement requirements. Retention depends on the data type, sensitivity, customer instructions, legal obligations, and operational need. We delete or de-identify information when it is no longer reasonably required.
10. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, tenant scoping, encryption for appropriate data in transit and at rest, logging, monitoring, backups, and secure development and deployment practices. No transmission or storage method is completely secure. Customers must protect credentials, configure permissions, maintain secure endpoints, and notify us promptly of suspected compromise.
11. International processing
ITSD and its service providers may process information in the United States and other countries where they operate. Those locations may have different privacy laws. Where required, we use contractual or other recognized safeguards for cross-border transfers.
12. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal information, withdraw consent, or appeal a denied request. You may also have the right to opt out of certain sales, sharing, or targeted advertising; ITSD does not currently engage in those activities as described above. We will not discriminate against you for exercising applicable rights.
If your information is managed by an ITSD customer, contact that customer or MSP first because it controls the relevant Customer Data. We will assist customers with verified requests as required. For information ITSD controls, email privacy@itsupportdepot.com. We may verify identity and authority before acting and may retain information needed to document the request.
13. United States state disclosures
Residents of states with comprehensive privacy laws may request the rights available under their state's law. During the preceding 12 months, the categories collected and disclosed for business purposes may include identifiers, customer records, commercial information, internet or network activity, approximate geolocation, professional information, and sensitive information contained in Customer Data. We disclose those categories only for the operational purposes and to the recipients described in this Policy.
14. Children
The Services are designed for businesses and are not directed to children under 13. We do not knowingly collect personal information directly from children through signup. If you believe a child has provided personal information to us, contact us so we can investigate and take appropriate action.
15. External links and third parties
Our sites may link to external services. Their privacy practices are governed by their own policies. This Policy does not apply to information a third party collects independently, including through an integration selected by a customer.
16. Changes to this Policy
We may update this Policy to reflect changes in our Services, practices, or legal obligations. We will post the updated version and effective date and provide additional notice for material changes where required.
17. Contact
Questions, privacy requests, and complaints may be sent to privacy@itsupportdepot.com or IT Support Depot, LLC, Sterling, Virginia, United States. You may also have the right to complain to your local privacy regulator.