Skip to content
Second ShiftSolutions

Privacy Policy

Last updated: August 2026

This policy explains what Second Shift Solutions collects, why, how long we keep it, and how to get it deleted. It covers both this website and the lead recovery services we run for our clients.

1. Who we are

Second Shift Solutions (“we”, “us”) provides AI-assisted lead recovery services to businesses. You can reach us at our contact form or .

We act in two different roles, and which one applies changes your rights:

  • As a controller — for information you give us directly through this website, such as an audit request or a contact form submission.
  • As a processor — for contact data our clients provide so we can run campaigns on their behalf. In that case our client is the controller, and requests about that data should go to them. We will help them fulfil it.

2. What we collect from this website

  • Information you submit: name, email address, phone number, company, website, industry, database size, CRM, and anything you write in the message field.
  • Attribution data: the page you submitted from, the referring site, and UTM parameters, so we know which channels work.
  • Technical data: your browser user agent, an approximate country from your connection, and a salted, truncated one-way hash of your IP address. We use the hash for rate limiting and abuse prevention. We do not store your raw IP address.

We do not use advertising cookies or third-party tracking pixels on this site. The only browser storage we use is a single session-storage entry holding the attribution values above, which your browser clears when you close the tab.

3. Why we use it

  • To respond to your enquiry and prepare your recovery audit.
  • To provide, support, and improve our services.
  • To protect the site from spam, abuse, and automated attacks.
  • To meet legal, tax, and record-keeping obligations.

Where the law requires a lawful basis, we rely on your consent (for submissions you send us), our legitimate interests in operating and securing the business, and compliance with legal obligations.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

4. Service providers

We share data only with providers that help us deliver the service, each bound by contract to protect it: our hosting provider, our database provider, our transactional email provider, and — for client campaigns — our email sending provider, and the telephony provider that hosts the phone number used for missed-call alerting.

We do not permit any of these providers to use your data for their own purposes. We never use one client’s data to train, tune, or improve models or campaigns for any other client.

5. How long we keep it

  • Website submissions: up to 24 months from your last contact with us, then deleted.
  • Client campaign data: for the length of the engagement, then deleted within 30 days of termination unless the client asks us to return it first.
  • Message and reply logs: retained for the engagement plus 12 months, because they are the audit trail for what was sent to whom.
  • Voicemail recordings: automatically deleted 30 days after they are left. No exceptions and no archive.

6. Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict processing, and to withdraw consent. Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have specific rights including the right to opt out of sale or sharing — which, as noted above, we do not do.

Email our contact form to make a request. We will verify your identity and respond within 45 days. We will not discriminate against you for exercising any of these rights.

7. Email outreach and how to opt out

We operate one outbound channel on behalf of clients: email. We do not place automated outbound calls and we do not send text messages.

Separately, we monitor a client’s business phone line for calls that go unanswered. If nobody picks up, the line answers with a short recorded greeting and invites you to leave a voicemail. We then alert the business owner so they can call you back themselves.

We never record live conversations. The only audio that exists is a voicemail you chose to leave, after being told you were leaving one. Once the business owner calls you back, that conversation is between you and them — we are not on the line, and nothing about it is captured.

Voicemails are automatically deleted after 30 days. This runs on a schedule, not on request: recordings older than 30 days are removed from the telephony account daily. We do not keep an archive of customer audio, and we do not transcribe voicemails.

We email only people the client already holds a relationship with, and every message identifies the business it is sent on behalf of and includes an unsubscribe link. Anyone on the client’s suppression list is excluded before a campaign begins.

Clicking unsubscribe in any email suppresses you immediately and permanently across every campaign we run for that business. You may also email us at our contact form to be removed from all campaigns we operate.

8. Security

Data is encrypted in transit and at rest. Access is limited to the people who need it, protected by strong authentication, and scoped per client. We log administrative access. No system is perfectly secure, but if a breach affects your information we will notify you and the relevant regulators as required by law.

9. Children

This is a service sold to businesses. It is not directed to children, and we do not knowingly collect information from anyone under 16. If you believe we have, contact us and we will delete it.

10. Changes

If we change this policy we will update the date at the top of the page. Material changes will be communicated directly to active clients.

Please note: this document is a starting template that reflects how the service is built and operated. It is not legal advice, and it has not been reviewed by an attorney. Have counsel review and adapt it before relying on it — particularly the sections covering outbound messaging consent, data processing, and state-specific privacy rights.