1. Scope
This Privacy Policy applies to Agency OS, GoldShoes product services where this policy is linked, related websites, support, and integrations (collectively, the “Service”). Agency OS is operated by Vicarious LLC d.b.a. Crown Social (“Crown,” “we,” “us,” or “our”).
This policy does not govern Crown's client-service work outside Agency OS or a third-party service's own processing. Third-party products, including QuickBooks Online, are governed by their providers' privacy notices and terms.
2. Our role and your organization
When an organization uses Agency OS for its workforce, clients, and operations, that organization generally decides what information is placed in the Service, which integrations are connected, who may access the information, and how long it is retained. Crown processes that information to provide the Service on the organization's behalf, subject to our agreement with the organization and applicable law.
We may act as the organization responsible for processing limited information used for our own account administration, security, billing, support, legal compliance, product communications, and privacy-minimized product analytics. The exact role may depend on the relationship, agreement, and applicable law.
If you use Agency OS through an employer or other organization, direct requests about workspace records to that organization first. Its administrators may access, export, correct, restrict, or delete information in the workspace.
3. Information we collect
Account and identity information
We collect information such as name, business email address, profile image, organization, role, account identifiers, authentication events, and administrator-assigned permissions. If you sign in through an identity provider, we receive the identifiers and profile details the provider and you authorize.
Organization and operational information
Depending on features used, the Service may process information about agencies, legal entities, clients, contacts, engagements, projects, tasks, staffing, capacity, schedules, time entries, rates, budgets, retainers, invoices, payments, expenses, documents, communications metadata, notes, approvals, and operational decisions.
Connected-service information
When an authorized user connects a provider, we receive provider account identifiers, authorization details, granted scopes, connection status, and the provider data needed for enabled features. Providers may include accounting, time tracking, project management, payroll, communications, storage, social media, contract, and analytics services.
Usage, device, and diagnostic information
We collect browser and device type, operating system, IP address, approximate location derived from IP, pages and features used, timestamps, referral information, application events, error information, performance data, and security logs. We may record support communications and information you choose to provide when requesting help.
Privacy-minimized product analytics
When product analytics is enabled, we collect limited technical and usage information such as a pseudonymous internal user or agency identifier, application and release, environment, feature or surface identifier, semantic action, timestamp, broad outcome or safe error category, bounded count or duration, integration provider category, and correlation references. This information helps us understand whether features work and are being used, identify friction, and improve reliability.
We do not intentionally send customer content to product analytics. This includes names, email addresses, phone numbers, domains, email or message bodies and subjects, meeting or transcript content, documents and filenames, search queries, prompts or AI responses, proposal, agreement, invoice, or financial content or amounts, raw provider identifiers or payloads, URLs with query strings, raw error messages, credentials, tokens, cookies, authorization headers, cursors, or arbitrary metadata.
Billing information
We may collect billing contacts, subscription status, transaction identifiers, and invoice records. Payment card details, if required, are ordinarily collected and processed by a payment provider rather than stored by Agency OS.
4. QuickBooks Online information
If you connect QuickBooks Online, Agency OS receives the QuickBooks company identifier (realmId), connection and authorization records, and the data required for the integration features you enable. Depending on the scopes and current product functionality, this may include:
- company profile and settings;
- customers, vendors, employees, and related business contact information;
- accounts, classes, departments, items, and tax-related classifications;
- estimates, invoices, credit memos, bills, purchases, expenses, payments, deposits, and related transaction details;
- balances, reporting data, references, attachments, and synchronization metadata; and
- records Agency OS creates or updates in QuickBooks at an authorized user's direction where write features are enabled.
Agency OS uses QuickBooks information to connect financial records with authorized operational records; support invoice preparation and synchronization; show revenue, cost, margin, retainer, and profitability information; reconcile provider records; detect synchronization errors; and provide features the organization enables.
We do not use connected QuickBooks information for advertising, sell it, use it to determine consumer creditworthiness, or treat it as a consumer report. We access and process it only within the user's authorization and for the Service's functionality, security, support, and legal compliance.
You can disconnect a QuickBooks company from Agency OS in Settings → Integrations → QuickBooks or through QuickBooks. Disconnecting invalidates or revokes provider access and stops future synchronization for that connection. Signing out of Agency OS does not disconnect QuickBooks.
5. How we use information
We use information to:
- provide, personalize, synchronize, and maintain the Service;
- authenticate Users and enforce organization, application, and record-level permissions;
- process authorized imports, exports, calculations, mappings, commands, and provider writes;
- operate dashboards, reports, forecasts, notifications, audit histories, and workflow features;
- provide support and communicate about the Service;
- monitor performance, debug errors, and improve usability and reliability;
- protect accounts, investigate abuse, prevent fraud, and respond to security incidents;
- administer subscriptions and billing;
- comply with law, enforce agreements, and protect rights and safety; and
- create aggregated or de-identified insights that do not reasonably identify a person or Customer.
Where law requires a legal basis, our bases may include performing a contract, following instructions from the organization responsible for the workspace, legitimate interests in operating and securing the Service, consent, and compliance with legal obligations.
7. AI-assisted features
Agency OS may offer AI-assisted search, summarization, classification, recommendation, extraction, drafting, or automation. When an enabled feature requires Customer Data, we process only the information reasonably needed to provide that feature and apply the workspace's access controls.
Unless we provide a separate clear disclosure and obtain any required authorization, we do not use identifiable Customer Data or connected QuickBooks information to train generalized AI models for use by unrelated customers. AI outputs may be inaccurate or incomplete and should be reviewed by a qualified person before action is taken.
For Ask GoldShoes, submitted questions are encrypted and retained for 90 days so an authorized Customer administrator can diagnose retrieval quality and failures. We do not retain the generated answer, cited source passages, or browser conversation history in that diagnostic record, and we do not send the question text to product analytics.
9. Product analytics notice
We use PostHog as a service provider for limited product analytics. The Agency OS PostHog project is configured for PostHog's EU cloud region. PostHog receives only the privacy-minimized event categories described in Section 3 and not Customer content.
Product analytics is not the authoritative record of an agency, user, integration, synchronization, or Customer Data. We use it to understand behavior and improve the Service; authoritative state remains in GoldShoes systems. We do not enable automatic click or form capture, heatmaps, console or network payload capture, or session replay in the initial analytics implementation. If we later propose a materially different analytics practice, we will apply appropriate notice and choice requirements before enabling it.
The browser preference contains only a version, allow-or-deny choice, choice source, and decision time. It is stored locally on that browser and is not Customer content. A changed analytics policy requires a new affirmative choice before optional browser capture can resume; an earlier denial remains a denial.
10. Retention, disconnection, and deletion
We retain information for as long as reasonably necessary to provide the Service, maintain the Customer's account, fulfill the purposes described in this policy, comply with law and contractual obligations, resolve disputes, enforce agreements, and protect the Service.
Retention depends on the record type, workspace settings, Customer instructions, provider behavior, legal requirements, and backup cycles. Authentication and security logs may be retained for a limited period after account closure. Financial, contractual, audit, or tax-related records may be retained when required by law or a legitimate recordkeeping obligation.
More specifically, we retain account, identity, and permission data while an account is active and as needed after closure for security, legal, and recordkeeping purposes; Customer workspace data according to Customer instructions, the applicable agreement, configured retention, and legal requirements; active connection credentials only while a connection remains authorized; and security, diagnostic, and product-analytics data for the period reasonably necessary to operate, secure, troubleshoot, and improve the Service. Where a fixed period is not stated, these are our retention criteria rather than an indefinite retention commitment.
When QuickBooks is disconnected, Agency OS immediately stops using the revoked connection for new API access and deletes active provider credentials. Previously synchronized records may remain in Agency OS so the organization retains operational history unless the organization deletes them, requests their deletion, or its retention settings require deletion.
An authorized administrator may request export or deletion of Customer Data by contacting us. We will securely delete eligible information from active systems and allow it to age out of backups according to our backup cycle, except for information we must retain by law or for a narrowly limited security, fraud-prevention, dispute, or recordkeeping purpose. Retained information remains protected and is not used for other purposes.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information. These include access controls, least-privilege practices, encryption in transit, protection of provider credentials, logging, monitoring, change controls, backups, and incident-response procedures appropriate to the Service.
No system can guarantee absolute security. Customers are responsible for choosing appropriate Users and administrators, protecting their identity-provider accounts, reviewing permissions, and promptly reporting suspected compromise to hello@crownsocialagency.com.
12. Choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection; withdraw consent; opt out of certain processing; or appeal a denied request. These rights may be limited by law and by the organization responsible for an Agency OS workspace.
To exercise a right regarding workspace information, contact your organization's Agency OS administrator first. You may also contact us at hello@crownsocialagency.com. We may verify your identity and authority before acting. Authorized agents may submit requests where permitted by law, subject to verification.
You may opt out of non-essential product communications using the unsubscribe mechanism in the message. We may still send security, transactional, account, and legal notices.
We will not discriminate against you for exercising a privacy right.
13. California notice and rights
This section is intended to serve as a Notice at Collection for California residents where applicable. We collect the categories of personal information described in Section 3, including identifiers and account information; professional or employment-related information; commercial, financial, and transaction information where a Customer enables relevant features; internet, device, and usage information; approximate location derived from IP; and, where necessary for the Service, limited sensitive personal information such as account-access credentials and financial information. We use these categories for the purposes in Section 5 and retain them under the criteria in Section 10.
We do not sell or share personal information as those terms are defined by California law. We do not use or disclose sensitive personal information to infer characteristics about a consumer. If either practice changes, we will provide the required notice and choice mechanism before the change takes effect.
Subject to applicable exceptions, California residents may request to know/access, correct, delete, or receive a portable copy of personal information; may use an authorized agent where permitted; and may appeal a response where applicable. Submit requests using the contact information in Section 17. We may verify a request and an authorized agent's authority before responding. If we process workspace data on behalf of an organization, we may direct the request to that organization or assist it as required by applicable law.
14. International data transfers
The Service is operated from the United States, and information may be processed in the United States and other countries where Crown or its service providers operate. Those countries may have different data-protection laws. Product-analytics event data is configured for PostHog's EU cloud region, but other processing may still involve Crown or service providers in other locations. Where required, we use appropriate safeguards for cross-border transfers.
15. Children
Agency OS is a business service and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided information to Agency OS without appropriate authorization, contact us so we can investigate and delete it as required.
16. Changes to this policy
We may update this Privacy Policy as the Service, law, or our practices change. We will change the “last updated” date and provide additional notice when a change is material. If a change materially affects how we use Customer Data, we will provide notice before the change takes effect when reasonably practicable.
17. Contact
Questions, requests, or complaints may be sent to:
Vicarious LLC d.b.a. Crown Social
Seattle, Washington, United States
hello@crownsocialagency.com
crownsocial.com
You may also contact your local data-protection authority where applicable.