← Command Center

Updated September 28, 2026

Privacy Policy

1. Information We Collect

We may collect contact information, business information, account information, request details, connected-system content you authorize, content processed through locally-installed features you run (such as message drafts and thread text used for outreach composition), usage records, device and browser information, support communications, and consent metadata such as timestamp, policy version, and acknowledgement status.

2. Connected Systems

If you authorize integrations such as Microsoft, Google, email, calendar, documents, CRM, accounting, messaging, browser automation software you run on your own device, or other business tools, we may process data from those systems only as reasonably necessary to provide the requested Command Center functionality, support, security, and maintenance.

3. How We Use Information

We use information to provide and improve the service, organize work, prepare review-ready outputs including drafted communications for your review and approval, meter and display usage against your plan's allowances, maintain account access, respond to requests, secure the platform, troubleshoot issues, comply with legal obligations, and evaluate early-access fit.

4. AI-Enabled and Automated Processing

Some features may route data — including profile information and message-thread content — through AI-enabled, automated, rules-based, or third-party processing services to generate summaries, drafts, classifications, recommendations, or workflow suggestions. Where a feature composes messages on your behalf, that processing occurs on our servers using an AI provider account associated with your account, and usage is metered against your plan. Users remain responsible for reviewing and approving outputs before use.

5. Sharing and Subprocessors

We may share information with hosting providers, identity providers, analytics providers, AI or automation processors (including the AI provider that composes drafted messages on your behalf), integration platforms, professional advisors, and service providers who help operate Command Center. When you provide feedback indicating a methodology issue with an AI-generated draft, authorized Triumph Business Solutions staff may review the associated draft and message content, across customer accounts, to correct and improve the shared prompts and methodology the service uses. We may also disclose information when required by law, to protect rights and security, or in connection with a business transfer.

6. Prospect and Third-Party Information

Some features, including outreach and relationship-building tools, collect and store information about individuals who are not Command Center users, such as a prospect's name, title, company, publicly available profile information, and the message-thread content generated through your outreach with them. This information is drawn from publicly available profiles and platforms and from your own conversations conducted through the service; we do not knowingly collect financial account information, payment credentials, or other sensitive personal data about a non-user, and we are not responsible for such information where it appears on that individual's own public profile or platform. You are solely responsible for the information you or your connected accounts submit about any individual and for what you choose to share with AI-enabled processing and connected automation. We do not sell this information. We store it only as necessary to provide the requested functionality, subject to the retention limits below, and do not use it for any purpose beyond operating and improving the service, including the AI-enabled processing and methodology review described elsewhere in this policy. Retention is tied to your plan: Creator-tier accounts may maintain up to 2,000 prospect records and Professional-tier accounts up to 7,500; a record is removed after 12 months with no contact or relationship progress, and if your membership ends, associated prospect records remain accessible for 60 days after cancellation and are then deleted. An individual who believes we hold information about them may contact us; requests are handled as described in the User Choices section below.

7. Microsoft App Registration

Command Center may use Microsoft identity or API permissions when a user authorizes access. Microsoft data is used only for the authorized functionality and is handled according to this Privacy Policy and applicable Microsoft platform requirements.

8. Data Retention

We retain information for as long as reasonably necessary to provide the service, maintain records, satisfy legal obligations, resolve disputes, enforce agreements, and support security. Early-access request information may be retained to manage review, onboarding, and follow-up. Prospect and third-party information follows the retention limits described above.

9. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. User Choices

You may request access, correction, deletion, or disconnection of certain information by emailing support@tbscommandcenter.com. Some requests may be limited by legal, security, technical, contractual, or operational requirements.

11. Cookies and Analytics

The service may use cookies, local storage, logs, or analytics technologies to maintain sessions, improve performance, understand usage, and protect the service.

12. Children

Command Center is intended for business use and is not directed to children. We do not knowingly collect personal information from children.

13. International Processing

Information may be processed in the United States or other locations where we or our service providers operate.

14. Data Incidents

If we become aware of a data incident affecting personal information, we will evaluate the incident and provide notices when required by applicable law.

15. Client Accounting Connections and Consent Records

Where you connect a client's or another business's accounting system to the service, we access, process, and store the connection information reasonably necessary to provide the requested functionality, including financial data available through the connected system's API and encrypted connection tokens. We also record consent metadata for this specific acknowledgement — timestamp, policy version, and the account that accepted it — as described in the Information We Collect section above. You are responsible for the accuracy of your representation that you are authorized to connect the client's system; we do not independently verify that authorization.

16. Google User Data

When you connect a Google account, Command Center requests access to Gmail, Google Calendar, Google Drive, and your Google account email address, and uses that data only to provide the features you use. Gmail (read, modify, send, and basic settings such as filters) is used to show and sort your inbox, summarize threads, prepare reply and follow-up drafts for your review, send messages only after you approve them, apply labels or archive when you ask, and send from your verified Gmail addresses. Google Calendar (read and events) is used to show your schedule, prepare meeting briefs, and create or change events and focus time only when you approve. Google Drive (read-only, and access to files Command Center creates) is used to find meeting notes, transcripts, and documents you choose to use or attach, and to save documents Command Center creates for you. Your account email identifies which Google account is connected. Command Center's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to develop, improve, or train generalized artificial-intelligence or machine-learning models. Google user data may be processed by AI providers only to produce the outputs you request. Our staff do not read Google user data unless you permit it for a specific item (for example, when you ask for support or submit feedback on a draft), it is necessary for security or to comply with law, or the data has been aggregated and anonymized. You can remove Command Center's access at any time with Disconnect in Settings or at https://myaccount.google.com/permissions, and you can ask us to delete Google user data we have stored by emailing support@tbscommandcenter.com.

17. How We Store and Protect Google User Data

Google user data that Command Center stores, such as authorization tokens, message and calendar details needed for the features you use, and the drafts, summaries, and briefs prepared from them, is kept in Google Cloud (Firebase) data centers in the United States, where it is encrypted at rest. It is transmitted only over encrypted (HTTPS/TLS) connections. Access is limited to your signed-in account and to Command Center's servers acting on your requests; other Command Center customers cannot access it. Google user data is shared only with the service providers needed to run the features you use: Google Cloud and Firebase for hosting and storage, Vercel for application hosting, and our AI providers (OpenRouter, routing only to providers that do not train on or collect request data, such as Anthropic) to prepare summaries and drafts. We do not share Google user data with any other third party except as required by law.

18. Retention and Deletion of Google User Data

We keep Google user data only for as long as it is needed to provide the features you use. Summaries, drafts, and records derived from it follow your plan's retention limits described in this policy. When you remove Command Center's access in your Google account, we can no longer read new data from Google. You can ask us to delete Google user data we have stored at any time by emailing support@tbscommandcenter.com; we delete it within 30 days of a verified request, except where we must keep limited records to comply with law. When your account is closed, stored Google user data is deleted on the same schedule.

19. Who We Are and How to Contact Us

TBS Command Center is provided by Triumph Business Solutions. For privacy questions, data access or deletion requests, or anything else about this policy, email support@tbscommandcenter.com.