MyTCRPlus Privacy Policy

Privacy Policy

Explains how myTCRPlus collects, protects, and uses your data while building compliance microsites for messaging programs.

Privacy Policy | MyTCRPlus

Privacy Policy

Effective Date: November 19, 2025
Last Updated: November 19, 2025
Version: 2.0

Company: Native Chaos Holdings LLC (doing business as myTCRPlus)
Address: 1887 Mesa Vista Dr, Henderson, NV 89014
Email: info@mytcrplus.com
Phone: 760-269-8277

1. Introduction

myTCRPlus ("we," "us," "our") is committed to protecting your privacy and safeguarding your personal information. This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal information when you use our websites, microsites, services (including TCR compliance tools, SMS/MMS campaign management platforms, and related offerings), and any other products under myTCRPlus.

By using our services or accessing our site, you agree to the practices described in this Privacy Policy.

2. Information We Collect

We collect the following categories of personal information:

Contact Information

  • Name, business name
  • Email address, phone number
  • Mailing address, business address

Messaging & Compliance Data

  • Phone numbers associated with SMS/MMS campaigns
  • Opt-in confirmation messages and timestamps
  • Campaign registration details (brand names, use case categories, sample messages)
  • Consent records and opt-out requests
  • Message frequency preferences

Usage Data

  • Server logs, analytics data
  • Pages viewed, disclosure page interactions
  • Device information (browser type, operating system, screen resolution)
  • IP addresses, timestamps
  • Session duration, clickstream data

Account & Branding Data

  • Account credentials (username, hashed passwords)
  • Logo files, brand colors, brand identity elements
  • Domain/subdomain mapping information
  • Custom microsite configurations
  • TCR registration identifiers

Payment Information

  • Billing address, company tax identification
  • Payment method data (processed via third-party payment processors)
  • Transaction history, invoice records
  • Note: We do not store full credit card numbers or CVV codes

Compliance & Verification Data

  • Business registration documents
  • EIN/Tax ID verification records
  • DUNS number (if provided)
  • Industry vertical classification
  • TCR trust score data (as provided by The Campaign Registry)

3. How We Collect Information

We collect information through multiple channels:

Directly From You

  • Registration forms, account setup processes
  • Branding uploads, campaign configurations
  • Plan selection, payment processing
  • Support requests, communication with our team
  • Tool usage (validators, calculators, compliance checkers)

Automatically

  • Website analytics tools (Google Analytics, proprietary tracking)
  • Server logs, application performance monitoring
  • Cookies and similar tracking technologies
  • Session replay tools (for UX optimization)

From Third-Party Sources

  • Payment processors (Stripe, PayPal)
  • The Campaign Registry (TCR) verification data
  • Domain registrars, hosting providers
  • Email service providers
  • Credit reporting agencies (for trust score enhancement)

4. How We Use Your Information

We use your personal information for the following purposes:

Service Delivery

  • Provide, maintain, and improve TCR compliance tools and microsite services
  • Process brand and campaign registrations with TCR
  • Host compliance microsites with SSL/HTTPS encryption
  • Manage automated backups and disaster recovery
  • Enable custom domain mapping and branding

Identity & Compliance Verification

  • Verify business credentials for service activation
  • Support TCR trust score improvement initiatives
  • Validate sender identity for carrier approval processes
  • Meet carrier policy requirements (T-Mobile, AT&T, Verizon)

Personalization & Branding

  • Apply custom logos, colors, and brand elements
  • Generate branded compliance disclosure pages
  • Customize tool interfaces to match brand identity

Communication

  • Send transactional communications (confirmations, billing statements, support responses)
  • Deliver platform updates, compliance alerts, regulatory changes
  • Send promotional communications (only with explicit consent)
  • Provide customer support and technical assistance

Analytics & Improvement

  • Monitor site usage, disclosure page views, tool engagement
  • Analyze traffic patterns, conversion metrics
  • Improve service functionality, user experience
  • Develop new compliance features and tools

Legal & Regulatory Compliance

  • Comply with TCPA, CTIA, carrier policy requirements
  • Respond to legal obligations, court orders, regulatory inquiries
  • Support audits, investigations, dispute resolution
  • Enforce Terms of Service, prevent fraud and abuse

Security & Risk Management

  • Detect and prevent unauthorized access
  • Monitor for security threats, suspicious activity
  • Maintain system integrity and data protection
  • Investigate and respond to security incidents

6. Sharing and Disclosure of Information

We share your information with the following categories of recipients:

Service Providers

  • Hosting infrastructure providers (AWS, Google Cloud, etc.)
  • Domain registrars, DNS management services
  • Analytics providers (Google Analytics, proprietary tools)
  • Payment processors (Stripe, PayPal)
  • Email delivery services (SendGrid, Mailgun)
  • SMS/MMS gateway providers (for campaign transmission)
  • Backup and disaster recovery services

TCR & Carrier Ecosystem

  • The Campaign Registry (TCR) for brand/campaign verification
  • Carrier aggregators and downstream messaging partners
  • Industry verification services (DUNS, business registration databases)

Legal & Regulatory Authorities

  • Law enforcement agencies (in response to valid legal requests)
  • Regulatory bodies (FCC, FTC, state attorneys general)
  • Courts, arbitration forums (in legal proceedings)
  • Tax authorities, auditing bodies

Business Partners

  • Acquirers, merger partners (in the event of business combination)
  • Strategic partners (with appropriate data protection agreements)
  • Affiliates within Native Chaos Holdings LLC corporate structure

CRITICAL RESTRICTION: We do not sell your personal data to marketers, data brokers, or unrelated third parties for their own purposes. SMS consent records and phone numbers are not shared with affiliates or partners for marketing purposes.

7. Cookies, Tracking & Similar Technologies

We use cookies and similar tracking technologies to:

Essential Functions

  • Maintain session state, authentication
  • Remember user preferences, settings
  • Enable shopping cart, checkout processes

Analytics & Performance

  • Measure traffic, engagement, conversion rates
  • Identify popular content, navigation patterns
  • Diagnose technical issues, optimize performance

Security

  • Detect fraud, unauthorized access attempts
  • Monitor for suspicious activity patterns
  • Enforce rate limiting, abuse prevention

Cookie Types

  • First-party cookies: Set by myTCRPlus for site functionality
  • Third-party cookies: Set by analytics providers (Google Analytics), advertising platforms

Your Choices

Browser settings allow cookie control (block, delete, restrict). Some site features may not function properly if cookies are disabled. Do Not Track signals are honored where technically feasible.

8. Your Rights: Opt-In, Opt-Out & Data Control

Marketing Communications

  • Promotional emails: Opt out via "unsubscribe" link in any message
  • SMS messages: Reply "STOP" (or other designated keyword) to opt out
  • We will process opt-out requests within 10 business days
  • Transactional messages (billing, support) are not affected by marketing opt-outs

Your Data Rights (Jurisdiction-Dependent)

Right Description
Access Request a copy of personal information we hold about you
Correction Update inaccurate or incomplete data
Deletion Request deletion of your data (subject to legal retention requirements)
Portability Receive your data in machine-readable format
Restriction Limit how we process your data
Objection Object to processing based on legitimate interests
Withdraw Consent Revoke previously granted consent

California Residents (CCPA/CPRA)

  • Right to know what personal information we collect, use, disclose
  • Right to delete personal information (with exceptions)
  • Right to opt out of sale/sharing (we do not sell personal information)
  • Right to correct inaccurate information
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising privacy rights

How to Exercise Your Rights

Email

info@mytcrplus.com

Subject: "Privacy Rights Request"

Phone

760-269-8277

Mail

1887 Mesa Vista Dr
Henderson, NV 89014

Response Timeline: 45 days (may extend to 90 days for complex requests). We will verify your identity before processing requests.

9. Data Retention

We retain your personal information only as long as necessary for:

Data Category Retention Period Rationale
Account data Active account duration + 90 days Service delivery, transition support
TCPA consent records 4 years from last message Statute of limitations coverage
Tax/financial records 7 years IRS requirement, accounting standards
Audit logs 2 years Security best practice
Campaign data Active campaign lifecycle Service delivery
Backup systems 30-90 days Disaster recovery
Anonymized analytics Indefinitely Business intelligence (non-identifiable)

Deletion Methods

When retention is no longer required:

  • Secure deletion via cryptographic erasure
  • Overwriting with random data (multiple passes)
  • Physical destruction of storage media (where applicable)
  • Anonymization rendering data non-identifiable

10. Security Measures

We employ administrative, technical, and physical safeguards to protect the confidentiality, integrity, and availability of your information:

Technical Safeguards

  • SSL/TLS encryption for all data transmission (HTTPS mandatory)
  • AES-256 encryption for data at rest
  • Database encryption with key rotation
  • Secure API authentication (OAuth 2.0, API keys with rate limiting)
  • Web application firewall (WAF) protection
  • DDoS mitigation systems

Administrative Safeguards

  • Role-based access controls (RBAC)
  • Least-privilege principle enforcement
  • Background checks for personnel with data access
  • Mandatory security awareness training
  • Incident response procedures, breach notification protocols
  • Third-party vendor security assessments

Physical Safeguards

  • Tier III+ data center facilities (for hosted infrastructure)
  • Biometric access controls, 24/7 surveillance
  • Environmental controls (fire suppression, climate management)
  • Redundant power supplies, network connectivity

Monitoring & Response

  • 24/7 security monitoring, intrusion detection systems
  • Automated threat detection, anomaly alerting
  • Regular vulnerability scanning, penetration testing
  • Security patch management, update deployment
  • Incident response team with defined escalation procedures

Limitations: No security system is impenetrable. While we implement industry-standard protections, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

11. International Data Transfers

myTCRPlus operates primarily within the United States. If we transfer your personal information outside the U.S. (for example, to service providers in other jurisdictions), we ensure appropriate safeguards:

Transfer Mechanisms

  • Standard Contractual Clauses (SCCs) approved by European Commission
  • Adequacy decisions recognizing equivalent data protection
  • Binding Corporate Rules (where applicable)
  • Consent-based transfers (where legally permissible)

Cross-Border Transfers

  • Data may be processed in U.S., EU, or other jurisdictions where service providers operate
  • All transfers comply with applicable data protection laws (GDPR Art. 44-50, CCPA provisions)
  • We assess third-country data protection adequacy before transfer

If you are in the EEA or UK and your data is transferred to the U.S., you may contact us for information about safeguards in place.

12. Children's Privacy

Our services are designed for businesses and are not directed to children under 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children.

If We Learn of Child Data Collection

  • Immediate deletion of all collected information
  • Termination of associated account
  • Notification to parent/guardian (where contact information available)

If You Believe We Have Child Data: Contact us immediately at info@mytcrplus.com with subject line "Child Privacy Concern." We will investigate and take appropriate action within 48 hours.

13. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • Changes in our services, features, or business practices
  • New legal, regulatory, or carrier requirements
  • Technological developments affecting data processing
  • Feedback from users, regulators, or legal counsel

Notification Process

  • "Last Updated" date revision at top of policy
  • Email notification to active account holders (for material changes)
  • Prominent notice on website homepage (30 days minimum)
  • Continued use of services after notice period constitutes acceptance

Material Changes Requiring Consent

  • Expansion of data sharing to new third-party categories
  • Changes to legal basis for processing
  • Reduction in data protection safeguards
  • Introduction of automated decision-making affecting user rights

Previous Versions: Prior versions available upon request: info@mytcrplus.com

14. Contact Information

Privacy Inquiries

Email: info@mytcrplus.com

Subject: "Privacy Inquiry"

Phone: 760-269-8277

Mail: Native Chaos Holdings LLC
1887 Mesa Vista Dr
Henderson, NV 89014

Data Protection Officer

For GDPR-related inquiries:

dpo@mytcrplus.com

Response Timeline

General inquiries: 5 business days

Privacy rights requests: 45 days (extendable to 90 days)

Security incidents: 72 hours (where legally required)

Escalation

If you are unsatisfied with our response, you may:

  • Contact your local data protection authority (EEA/UK residents)
  • File a complaint with the California Attorney General (California residents)
  • Pursue dispute resolution per our Terms of Service

15. Additional Disclosures

No Legal Advice

This Privacy Policy describes our data practices and does not constitute legal advice. myTCRPlus provides compliance tools and microsites but does not provide legal advisory services. Organizations should consult qualified legal counsel for guidance specific to their messaging programs and data protection obligations.

Carrier Compliance Support

myTCRPlus microsites include required disclosures, privacy policies, opt-in/opt-out language, and message frequency statements essential for VOIP/CPaaS provider compliance. We monitor regulatory updates and carrier guidelines so your business texting program remains secure, transparent, and provider-approved.

Third-Party Links

Our websites may contain links to third-party sites. We are not responsible for the privacy practices or content of external sites. Review their privacy policies before providing personal information.

Biometric Data

We do not collect biometric information (fingerprints, facial recognition, voiceprints) through our services.

Automated Decision-Making

We do not make automated decisions that significantly affect you without human review, except for fraud detection systems designed to protect our platform and users.

Document Version: 2.0
Last Comprehensive Review: November 19, 2025
Next Scheduled Review: February 19, 2026

```