Breakthrough OS

Privacy Policy

Version: 2026-09-06 · Effective date: September 6, 2026 · Last updated: September 6, 2026. This policy explains the information Breakthrough OS may process to provide campaign operations services.

Information we may process

Depending on the services used, Breakthrough OS may process account information; business contact and company information; campaign plans and status; public form submissions and campaign responses; QR or tracking activity; package and delivery activity; notes and activity history; pipeline information; manually entered revenue, cost, or outcome information; and technical, authentication, and security logs.

Where business contact information comes from

Business contact information may come from client-provided lists, business or public sources, campaign responses, authorized integrations, and direct submissions. Clients are responsible for ensuring they have appropriate rights and authority to provide and use campaign data.

Why information is processed

Information is processed to operate and secure accounts; organize client workspaces; research, plan, run, and measure campaigns; manage contacts, packages, responses, follow-up, pipelines, and outcomes; respond to inquiries; support users; maintain records and audit history; prevent misuse; and improve the service.

Client data and sale of data

Clients retain ownership and control of the campaign and contact data they provide, subject to the applicable service agreement. Smittinn Consulting and Breakthrough OS process that information to provide the requested service.

Breakthrough OS does not sell client campaign or contact data. Information may still be processed by service providers and authorized integrations as necessary to operate the service.

Customer workspace and data isolation

Private customer information is maintained within the customer's authorized workspace and is not made available to unrelated Breakthrough OS customers. This includes, where applicable, private company lists, contact lists, CRM records, campaign data, research requests, candidate findings, approved Sales Intelligence, notes, communications, form submissions, uploaded or private files, connected Gmail data, connected HubSpot data, connected ShipStation data, and other API or integration data. Access and processing may still occur for authorized users, requested integrations, service providers, support and security operations, legal requirements, and customer-directed activity.

One customer's private CRM, list, or intelligence data is not used to personalize or generate another customer's outreach. Breakthrough OS applies workspace-scoped access controls intended to maintain these boundaries without claiming that any technical system is free from all security risk.

Service providers

Infrastructure, hosting, database, email, analytics, CRM, calendar, form, and shipping providers may process relevant information on our behalf or at a client's direction. These providers are used to operate requested features and are not treated as purchasers of client campaign data.

Optional third-party integrations

When a client intentionally connects a service such as Gmail or another Google service, HubSpot, ShipStation, OpenAI, or a future integration, Breakthrough OS may process and exchange relevant information with that provider as needed for the requested functionality. The external provider's own privacy and security terms apply to its service. OAuth authorization is separate from acceptance of the Breakthrough OS Terms of Service.

Tracking and form privacy

Campaign tracking may record that an opaque campaign link was accessed, along with operational details such as time, device category, reduced referrer information, and a hashed duplicate-detection value. Forms collect the fields needed for the applicable inquiry or campaign. Public pages are not intended to reveal private CRM notes, another recipient's information, internal database identifiers, credentials, sessions, or secret tokens.

Retention and deletion

Information is retained as needed to provide the service, maintain appropriate business and security records, preserve authorized archive and audit history, resolve disputes, and satisfy applicable obligations. Deletion requests may be subject to backups, security records, legal requirements, contractual duties, and technically necessary retention periods.

Security and choices

We use access controls and operational safeguards described on our Security & Privacy page. Authorized users may request appropriate access, correction, export, archive, or deletion assistance, subject to identity verification and applicable obligations.

Contact

Privacy questions or requests may be sent to info@smittinn.com.