Privacy Policy
Last updated: August 2026
This policy explains what Second Shift Solutions collects, why, how long we keep it, and how to get it deleted. It covers both this website and the lead recovery services we run for our clients.
1. Who we are
Second Shift Solutions (“we”, “us”) provides lead recovery services to businesses. You can reach us at jordan@secondshiftsolutions.net or .
We act in two different roles, and which one applies changes your rights:
- As a controller — for information you give us directly through this website, such as an audit request or a contact form submission.
- As a processor — for contact data our clients provide so we can run campaigns on their behalf. In that case our client is the controller, and requests about that data should go to them. We will help them fulfil it.
2. What we collect from this website
- Information you submit: name, email address, phone number, company, website, industry, database size, CRM, and anything you write in the message field.
- Attribution data: the page you submitted from, the referring site, and UTM parameters, so we know which channels work.
- Technical data: your browser user agent, an approximate country from your connection, and a salted, truncated one-way hash of your IP address. We use the hash for rate limiting and abuse prevention. We do not store your raw IP address.
We do not use advertising cookies or third-party tracking pixels on this site. The only browser storage we use is a single session-storage entry holding the attribution values above, which your browser clears when you close the tab.
We do use Cloudflare Web Analytics to count page views, so we can tell how many real people visit rather than how many automated crawlers do. It sets no cookies, stores nothing in your browser, and does not follow you to other websites or build a profile of you. It records the page, the referring site, and general device and country information — never a name, and never anything that identifies you personally.
3. Why we use it
- To respond to your enquiry and prepare your recovery audit.
- To provide, support, and improve our services.
- To protect the site from spam, abuse, and automated attacks.
- To meet legal, tax, and record-keeping obligations.
Where the law requires a lawful basis, we rely on your consent (for submissions you send us), our legitimate interests in operating and securing the business, and compliance with legal obligations.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
4. Service providers
We share data only with providers that help us deliver the service, each bound by contract to protect it: our hosting provider, our database provider, our transactional email provider, and — for client campaigns — our email sending provider, and the telephony provider that hosts the phone number used for missed-call alerting.
We do not permit any of these providers to use your data for their own purposes. We never use one client’s data to train, tune, or improve models or campaigns for any other client.
5. How long we keep it
- Website submissions: up to 24 months from your last contact with us, then deleted.
- Client campaign data: for the length of the engagement, then deleted within 30 days of termination unless the client asks us to return it first.
- Message and reply logs: retained for the engagement plus 12 months, because they are the audit trail for what was sent to whom.
- Voicemail recordings: automatically deleted 30 days after they are left. No exceptions and no archive.
6. Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict processing, and to withdraw consent. Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have specific rights including the right to opt out of sale or sharing — which, as noted above, we do not do.
Email jordan@secondshiftsolutions.net to make a request. We will verify your identity and respond within 45 days. We will not discriminate against you for exercising any of these rights.
7. Outreach, text messages, and how to opt out
We operate two outbound channels on behalf of clients: email, and — where the client has bought the text-message upgrade — a single reply text after a missed call. We do not place automated outbound calls.
How the text message works. It is sent only to a number that has just called the client’s business and not been answered, and it goes back to that same number. You start the conversation by calling; the reply acknowledges the missed call and asks what you need. We do not upload, buy, rent or import phone number lists, and we never text a number that has not called the business first.
We do not sell or share mobile numbers or messaging consent with anyone for marketing. Mobile opt-in data and consent are never shared with third parties or affiliates for their own marketing, and are not disclosed to any party other than the messaging providers that carry the message on our behalf.
Stopping the texts. Reply STOP to any message and you will not receive another. Reply HELP for information. Message and data rates may apply, and message frequency varies — typically one message per missed call.
Separately, we monitor a client’s business phone line for calls that go unanswered. If nobody picks up, the line answers with a short recorded greeting and invites you to leave a voicemail. We then alert the business owner so they can call you back themselves.
We never record live conversations. The only audio that exists is a voicemail you chose to leave, after being told you were leaving one. Once the business owner calls you back, that conversation is between you and them — we are not on the line, and nothing about it is captured.
Voicemails are automatically deleted after 30 days. This runs on a schedule, not on request: recordings older than 30 days are removed from the telephony account daily. We do not keep an archive of customer audio, and we do not transcribe voicemails.
We email only people the client already holds a relationship with, and every message identifies the business it is sent on behalf of and includes an unsubscribe link. Anyone on the client’s suppression list is excluded before a campaign begins.
Clicking unsubscribe in any email suppresses you immediately and permanently across every campaign we run for that business. You may also email us at jordan@secondshiftsolutions.net to be removed from all campaigns we operate.
8. Security
Data is encrypted in transit and at rest. Access is limited to the people who need it, protected by strong authentication, and scoped per client. We log administrative access. No system is perfectly secure, but if a breach affects your information we will notify you and the relevant regulators as required by law.
9. Children
This is a service sold to businesses. It is not directed to children, and we do not knowingly collect information from anyone under 16. If you believe we have, contact us and we will delete it.
10. Changes
If we change this policy we will update the date at the top of the page. Material changes will be communicated directly to active clients.
Please note: this document is a starting template that reflects how the service is built and operated. It is not legal advice, and it has not been reviewed by an attorney. Have counsel review and adapt it before relying on it — particularly the sections covering outbound messaging consent, data processing, and state-specific privacy rights.