1. Scope
This Privacy Policy applies to Agency OS, its related websites, support, and integrations (collectively, the “Service”). Agency OS is operated by Vicarious LLC d.b.a. Crown Social (“Crown,” “we,” “us,” or “our”).
This policy does not govern Crown's client-service work outside Agency OS or a third-party service's own processing. Third-party products, including QuickBooks Online, are governed by their providers' privacy notices and terms.
2. Our role and your organization
When an organization uses Agency OS for its workforce, clients, and operations, that organization generally decides what information is placed in the Service, which integrations are connected, who may access the information, and how long it is retained. Crown processes that information to provide the Service on the organization's behalf, subject to our agreement with the organization and applicable law.
We may act as the organization responsible for processing limited information used for our own account administration, security, billing, support, legal compliance, and product communications.
If you use Agency OS through an employer or other organization, direct requests about workspace records to that organization first. Its administrators may access, export, correct, restrict, or delete information in the workspace.
3. Information we collect
Account and identity information
We collect information such as name, business email address, profile image, organization, role, account identifiers, authentication events, and administrator-assigned permissions. If you sign in through an identity provider, we receive the identifiers and profile details the provider and you authorize.
Organization and operational information
Depending on features used, the Service may process information about agencies, legal entities, clients, contacts, engagements, projects, tasks, staffing, capacity, schedules, time entries, rates, budgets, retainers, invoices, payments, expenses, documents, communications metadata, notes, approvals, and operational decisions.
Connected-service information
When an authorized user connects a provider, we receive provider account identifiers, authorization details, granted scopes, connection status, and the provider data needed for enabled features. Providers may include accounting, time tracking, project management, payroll, communications, storage, social media, contract, and analytics services.
Usage, device, and diagnostic information
We collect browser and device type, operating system, IP address, approximate location derived from IP, pages and features used, timestamps, referral information, application events, error information, performance data, and security logs. We may record support communications and information you choose to provide when requesting help.
Billing information
We may collect billing contacts, subscription status, transaction identifiers, and invoice records. Payment card details, if required, are ordinarily collected and processed by a payment provider rather than stored by Agency OS.
4. QuickBooks Online information
If you connect QuickBooks Online, Agency OS receives the QuickBooks company identifier (realmId), connection and authorization records, and the data required for the integration features you enable. Depending on the scopes and current product functionality, this may include:
- company profile and settings;
- customers, vendors, employees, and related business contact information;
- accounts, classes, departments, items, and tax-related classifications;
- estimates, invoices, credit memos, bills, purchases, expenses, payments, deposits, and related transaction details;
- balances, reporting data, references, attachments, and synchronization metadata; and
- records Agency OS creates or updates in QuickBooks at an authorized user's direction where write features are enabled.
Agency OS uses QuickBooks information to connect financial records with authorized operational records; support invoice preparation and synchronization; show revenue, cost, margin, retainer, and profitability information; reconcile provider records; detect synchronization errors; and provide features the organization enables.
We do not use connected QuickBooks information for advertising, sell it, use it to determine consumer creditworthiness, or treat it as a consumer report. We access and process it only within the user's authorization and for the Service's functionality, security, support, and legal compliance.
You can disconnect a QuickBooks company from Agency OS in Settings → Integrations → QuickBooks or through QuickBooks. Disconnecting invalidates or revokes provider access and stops future synchronization for that connection. Signing out of Agency OS does not disconnect QuickBooks.
5. How we use information
We use information to:
- provide, personalize, synchronize, and maintain the Service;
- authenticate Users and enforce organization, application, and record-level permissions;
- process authorized imports, exports, calculations, mappings, commands, and provider writes;
- operate dashboards, reports, forecasts, notifications, audit histories, and workflow features;
- provide support and communicate about the Service;
- monitor performance, debug errors, and improve usability and reliability;
- protect accounts, investigate abuse, prevent fraud, and respond to security incidents;
- administer subscriptions and billing;
- comply with law, enforce agreements, and protect rights and safety; and
- create aggregated or de-identified insights that do not reasonably identify a person or Customer.
Where law requires a legal basis, our bases may include performing a contract, following instructions from the organization responsible for the workspace, legitimate interests in operating and securing the Service, consent, and compliance with legal obligations.
7. AI-assisted features
Agency OS may offer AI-assisted search, summarization, classification, recommendation, extraction, drafting, or automation. When an enabled feature requires Customer Data, we process only the information reasonably needed to provide that feature and apply the workspace's access controls.
Unless we provide a separate clear disclosure and obtain any required authorization, we do not use identifiable Customer Data or connected QuickBooks information to train generalized AI models for use by unrelated customers. AI outputs may be inaccurate or incomplete and should be reviewed by a qualified person before action is taken.
9. Retention, disconnection, and deletion
We retain information for as long as reasonably necessary to provide the Service, maintain the Customer's account, fulfill the purposes described in this policy, comply with law and contractual obligations, resolve disputes, enforce agreements, and protect the Service.
Retention depends on the record type, workspace settings, Customer instructions, provider behavior, legal requirements, and backup cycles. Authentication and security logs may be retained for a limited period after account closure. Financial, contractual, audit, or tax-related records may be retained when required by law or a legitimate recordkeeping obligation.
When QuickBooks is disconnected, Agency OS immediately stops using the revoked connection for new API access and deletes active provider credentials. Previously synchronized records may remain in Agency OS so the organization retains operational history unless the organization deletes them, requests their deletion, or its retention settings require deletion.
An authorized administrator may request export or deletion of Customer Data by contacting us. We will securely delete eligible information from active systems and allow it to age out of backups according to our backup cycle, except for information we must retain by law or for a narrowly limited security, fraud-prevention, dispute, or recordkeeping purpose. Retained information remains protected and is not used for other purposes.
10. Security
We use administrative, technical, and organizational safeguards designed to protect information. These include access controls, least-privilege practices, encryption in transit, protection of provider credentials, logging, monitoring, change controls, backups, and incident-response procedures appropriate to the Service.
No system can guarantee absolute security. Customers are responsible for choosing appropriate Users and administrators, protecting their identity-provider accounts, reviewing permissions, and promptly reporting suspected compromise to hello@crownsocialagency.com.
11. Choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection; withdraw consent; or appeal a denied request. These rights may be limited by law and by the organization responsible for an Agency OS workspace.
To exercise a right regarding workspace information, contact your organization's Agency OS administrator first. You may also contact us at hello@crownsocialagency.com. We may verify your identity and authority before acting. Authorized agents may submit requests where permitted by law, subject to verification.
You may opt out of non-essential product communications using the unsubscribe mechanism in the message. We may still send security, transactional, account, and legal notices.
We will not discriminate against you for exercising a privacy right.
12. International data transfers
The Service is operated from the United States, and information may be processed in the United States and other countries where Crown or its service providers operate. Those countries may have different data-protection laws. Where required, we use appropriate safeguards for cross-border transfers.
13. Children
Agency OS is a business service and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided information to Agency OS without appropriate authorization, contact us so we can investigate and delete it as required.
14. Changes to this policy
We may update this Privacy Policy as the Service, law, or our practices change. We will change the “last updated” date and provide additional notice when a change is material. If a change materially affects how we use Customer Data, we will provide notice before the change takes effect when reasonably practicable.
15. Contact
Questions, requests, or complaints may be sent to:
Vicarious LLC d.b.a. Crown Social
Seattle, Washington, United States
hello@crownsocialagency.com
crownsocial.com
You may also contact your local data-protection authority where applicable.