V1.0 · EFFECTIVE 04/23/2026
RevOps Sherpas — Privacy Policy
1. Introduction
This Privacy Policy explains how RevOps Sherpas, LLC ("RevOps Sherpas," "we," "us") collects, uses, shares, and protects personal data about individuals in connection with our website, our marketing and sales activities, and our services — CRM Connect, Telephony Connect, and Call Migrations (together, the "Services").
RevOps Sherpas, LLC is a Nevada limited liability company with offices at 8360 W Sahara Ave., Suite 260, Las Vegas, NV 89117, USA. For privacy-related questions or to exercise your rights, please contact us at privacy@revopsherpas.com.
This Policy applies to personal data we collect and handle as a data controller — for example, about visitors to our website, people who contact us, prospects, customer account contacts, and personnel — and summarizes our role as a data processor when we process personal data on behalf of our customers through the Services. Where we act as a processor, our customers determine the purposes and means of processing, and our handling of that data is governed by the contract with the customer (typically the RevOps Sherpas Data Processing Addendum, or "DPA").
2. Scope and Roles
- We are the controller for personal data we collect about website visitors, inquirers, prospects, customer account contacts, and our own personnel and applicants.
- We are a processor (or sub-processor) for personal data we process on behalf of our customers through the Services. Our obligations in that role are set out in the DPA and in applicable data-protection laws. If you are an end user of one of our customers, please contact that customer to exercise your rights regarding data they control.
3. Personal Data We Collect
A. Website and general inquiries
- Contact data: name, business email, phone, company, title, country (when you submit a contact form, book a demo, or email us).
- Communications: the content of emails or messages you send us, and our responses.
- Device and technical data: IP address, browser type, device type, referring URL, pages viewed, and similar data we or our analytics providers collect automatically through cookies and similar technologies.
B. Marketing
- Subscription data: email address and preferences when you sign up for newsletters, content, or events.
- Engagement data: whether you open or click our marketing emails; event registrations and attendance.
C. Customer accounts and Services users
- Account data: names, business emails, titles, and roles of your designated administrators and authorized users of the Services.
- Authentication data: credentials, OAuth authorizations, and identifiers required for access to the Services.
- Support data: information you provide when you contact our support, including logs, screenshots, and the content of your request.
- Usage data: logs and telemetry about how the Services are used, including tenant and user identifiers, API endpoints, request metadata, and error details. This may include limited personal data.
D. Recruiting and personnel
- Applicant data: name, contact details, résumé, interview notes, and other information you provide if you apply to work with us.
E. Data processed in the Services on behalf of customers
When we operate the Services for a customer, we process personal data that the customer and its users submit to, or that flows through, the Services. This may include business-contact records from the Customer's CRM, call metadata and media handled by Telephony Connect, and data migrated in Call Migration engagements. The categories and processing of such data are determined by our customer and are described in the DPA and its Annex I. We do not use this data for our own purposes.
4. How We Collect Personal Data
- Directly from you — when you visit our website, submit a form, email us, attend an event, apply for a role, or use the Services.
- Automatically — through cookies and similar technologies on our website; through logs and telemetry in the Services.
- From third parties — including referrers, marketplaces (e.g., Gong Collective), publicly available sources, and sales-intelligence providers that supply business-contact information.
- From our customers — when we process data on their behalf in the Services.
5. Purposes and Legal Bases
Under the EU GDPR, UK GDPR, and Swiss FADP we process personal data only where we have a lawful basis. The purposes below indicate our lawful basis for each activity:
- To provide, operate, secure, and support the Services (legal basis: performance of a contract; legitimate interest).
- To respond to inquiries and provide customer service (legitimate interest; performance of a contract).
- To manage customer and prospect relationships, including proposals and onboarding (legitimate interest; performance of a contract).
- To send marketing communications about our products and services (consent where required; otherwise legitimate interest, with an opt-out in every message).
- To analyze and improve our website and Services, including product analytics and aggregated usage statistics (consent for non-essential cookies; legitimate interest for essential analytics).
- To recruit and evaluate applicants (legitimate interest; consent where required; performance of pre-contractual steps).
- To comply with legal obligations, respond to legal process, and defend our rights (legal obligation; legitimate interest).
- To detect, prevent, and respond to security incidents and fraud (legitimate interest; legal obligation).
- Where we process special-category personal data (which we do not do as a normal course of business), we will only do so with explicit consent or where another specific GDPR Article 9 condition applies.
6. California and Other U.S. State Law Notices
This section provides disclosures required by the California Consumer Privacy Act (as amended by the California Privacy Rights Act) and, as applicable, the privacy laws of Colorado, Connecticut, Virginia, Utah, Texas, and other U.S. states with analogous laws (collectively, "U.S. State Privacy Laws").
A. Categories of Personal Information we collect
In the past 12 months we have collected the following categories of Personal Information (as defined by the CCPA): identifiers (such as name and email address); customer records; commercial information; internet or other electronic network activity information; professional or employment-related information; and inferences drawn from these.
B. Sources
We collect Personal Information directly from you, automatically from your interactions with our website and Services, from our customers, and from third-party sales-intelligence and marketplace providers.
C. Business or commercial purposes
We use Personal Information for the purposes described in Section 5 above (provide Services, respond to inquiries, manage relationships, marketing, analytics, recruiting, legal compliance, and security).
D. No sale; no sharing for cross-context behavioral advertising
We do not sell Personal Information, and we do not share Personal Information for cross-context behavioral advertising, as those terms are defined under the CCPA. We have not done so in the past 12 months.
E. Sensitive Personal Information
We do not use or disclose Sensitive Personal Information (as defined under the CCPA) for any purpose other than those that are permitted without a consumer's right to limit such use.
F. Your U.S. State Privacy Law rights
- Right to know / access — request disclosure of the categories and specific pieces of Personal Information we have collected about you and how we have handled it.
- Right to delete — request deletion of Personal Information we have collected from you, subject to exceptions.
- Right to correct — request correction of inaccurate Personal Information.
- Right to opt out of sale or sharing for cross-context behavioral advertising — as stated above, we do not sell or share, so there is nothing to opt out of; this right is preserved if our practices ever change.
- Right to limit use of Sensitive Personal Information.
- Right not to receive discriminatory treatment for exercising these rights.
To exercise any of these rights, email privacy@revopsherpas.com. We will verify your identity using information reasonably available to us (for example, an email address on file) before responding. Authorized agents may submit requests on your behalf with written authorization.
7. How We Share Personal Data
- Service providers and sub-processors — we share personal data with vendors that host, secure, monitor, or support our Services and operations, under contracts that restrict their use of the data to providing services to us. Our current sub-processors for the Services are listed in the RevOps Sherpas Sub-Processor List (available on request).
- Professional advisors — accountants, auditors, lawyers, and insurers, under confidentiality obligations.
- Acquirers and successors — in connection with a merger, acquisition, financing, reorganization, or sale of assets.
- Legal obligations and defense — to comply with applicable law, respond to valid legal process, or protect our rights, property, or safety, or that of others.
- With your consent — where we ask and receive your permission.
We do not sell personal data and we do not use personal data for third-party advertising.
8. International Transfers
RevOps Sherpas is based in the United States. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States or other jurisdictions that are not determined to provide an adequate level of protection, we rely on appropriate transfer mechanisms. For transfers of personal data we process on behalf of customers through the Services, those mechanisms are set out in the DPA (including the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and, where applicable, the Swiss addendum to the EU Standard Contractual Clauses). For transfers of personal data we collect as a controller, we rely on the same mechanisms where required. You may request a copy of the safeguards in place by contacting us.
9. Retention
We retain personal data only as long as necessary to fulfill the purposes for which it was collected, to comply with legal obligations, to resolve disputes, and to enforce our agreements. Typical retention periods:
- Website analytics and session data — up to 14 months (or shorter, as our analytics configuration permits).
- Contact-form submissions and prospect data — up to 24 months after last interaction, unless you ask us to delete sooner.
- Marketing subscription data — until you unsubscribe, and then we may retain a suppression record to honor your opt-out.
- Customer account and billing records — for the term of your relationship with us and for up to seven (7) years afterward for tax, audit, and legal purposes.
- Operational logs from the Services — up to 12 months, with shorter retention for certain categories (for example, event logs in OneUptime are retained for 60 days).
- Applicant data — up to 24 months after the application decision, unless you consent to longer retention in a talent pool.
- Personal data processed on behalf of customers — governed by the customer's instructions and the DPA; on termination of the customer relationship, data is returned or deleted within thirty (30) days unless applicable law requires longer retention.
10. Your Rights (GDPR / UK GDPR / Swiss FADP)
If you are in the EEA, the UK, or Switzerland, you have the following rights with respect to personal data we hold as a controller:
- Access — a copy of the personal data we hold about you.
- Rectification — correction of inaccurate or incomplete personal data.
- Erasure — deletion of your personal data in certain circumstances.
- Restriction — restriction of processing in certain circumstances.
- Portability — a copy of your personal data in a commonly used, machine-readable format, where applicable.
- Objection — objection to processing based on legitimate interest (including for direct marketing).
- Withdraw consent — where processing is based on consent, you may withdraw at any time without affecting the lawfulness of prior processing.
- Complain to a supervisory authority — you may lodge a complaint with the supervisory authority in your jurisdiction (in the UK, the Information Commissioner's Office; in the EEA, the authority in your country of residence; in Switzerland, the Federal Data Protection and Information Commissioner).
To exercise these rights, email privacy@revopsherpas.com. We will respond within the time required by applicable law (typically one month under GDPR).
11. Cookies and Similar Technologies
Our website uses cookies and similar technologies. We use only essential cookies by default (required for the site to function). We may use analytics and marketing cookies with your consent, where required by applicable law. You can control cookies through your browser settings and, where we provide one, our cookie-preferences tool on the website. For details of specific cookies used, please see our cookie notice on the website or contact privacy@revopsherpas.com.
12. Security
We maintain administrative, technical, and physical safeguards to protect personal data, including access controls, encryption in transit and at rest, logging and monitoring, personnel training, and vendor due diligence. Our security program is summarized in the RevOps Sherpas Information Security Practices Overview (available on request). No system is perfectly secure; we will notify affected individuals or customers of personal data breaches as required by applicable law and our contracts.
13. Children
Our website and Services are directed to businesses. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided personal data to us, please contact privacy@revopsherpas.com and we will take appropriate steps to delete it.
14. Third-Party Sites and Services
Our website and Services may link to or integrate with third-party sites and services (for example, the connected CRM platform, Gong, Microsoft Azure, Amazon Web Services, OneUptime). Those third parties are responsible for their own privacy practices. We encourage you to review their privacy policies.
15. EU and UK Representatives
Where required under Article 27 of the GDPR and the UK GDPR, we appoint a representative in the European Union and the United Kingdom to act as a point of contact for data subjects and supervisory authorities. Our representatives' details are as set forth below (or "to be appointed" if not yet in place).
- EU Representative: [to be appointed]
- UK Representative: [to be appointed]
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the Effective Date at the top of this Policy and, where appropriate, provide additional notice (for example, on our website or by email). Please check this page periodically.
17. Contact Us
- Email — privacy@revopsherpas.com (privacy requests); legal@revopsherpas.com (legal notices).
- Postal — RevOps Sherpas, LLC, 8360 W Sahara Ave., Suite 260, Las Vegas, NV 89117, USA.
- Security incidents — security@revopsherpas.com.
— End of RevOps Sherpas Privacy Policy v1.0 —
