Legal
Privacy Policy
The short version: we do not sell, rent, or share your information with anyone. Here's the whole story, in plain language.
Effective date: September 11, 2026
Who we are
UltimateCRM is a client management platform for financial advisors and registered investment advisors, made by AdvisorInfrastructure ("we," "us"). This policy covers this website, the UltimateCRM application, the client portal, and our meeting-booking pages.
The commitment that matters most
We do not sell, rent, trade, or share your personal information — or your clients' information — with anyone. We have no advertising partners, no data brokers, and no third-party analytics watching what you do. Your data exists in UltimateCRM for exactly one purpose: running your practice.
What we collect on this website
- This website sets no cookies and runs no third-party trackers, analytics services, or advertising pixels of any kind.
- We measure our own site ourselves. Each page sends our own server one event: the page's path, the site that referred you, any campaign tags in the link you followed, a screen-size bucket, your IP address, and your browser type. That is the whole record — no cookies, no identifier we plant on your device, and nothing you typed. We keep these events for up to 13 months and then delete them. Nothing about this leaves our infrastructure, ever.
- If you follow a link from this site to create an UltimateCRM account, those same campaign tags travel with you so we know which page brought you — they describe the link, never you.
- Our web servers keep an access log of every request to every site we run — this website, the UltimateCRM application, the client portal, and our booking pages. Each entry records your IP address, the date and time, the page or endpoint requested (never the query string, which is where things like sign-in codes travel), the response status, the referring site, and your browser type. We keep these logs for security, abuse and fraud prevention, troubleshooting, investigating incidents, and meeting our legal obligations. They stay on our servers for up to 13 months and then in a locked, encrypted archive in our own AWS account for up to 7 years, after which they are deleted. We disclose them to no one unless the law requires it.
- If you email us, we receive your email address and whatever you choose to tell us. We use it to reply, and for nothing else.
What we collect in the product
- Account information — your firm's name and the names and email addresses of the advisors and staff who use UltimateCRM.
- Customer content — the contacts, households, notes, documents, financial data, and communications your firm stores in UltimateCRM. This content belongs to your firm, not to us. We process it only to provide the service, and our team accesses it only when needed to support you or keep the service running.
- Connected services — if your firm connects Microsoft 365, Google Workspace, RingCentral, Zoom Phone, or Microsoft Teams, we sync email, calendar, call, and message data into your firm's own records, using only the permissions you grant. Disconnecting stops the sync.
- Sign-in records — each time someone signs in to UltimateCRM, or tries to, we record the time, the IP address, the browser, and whether it succeeded, so that a sign-in that wasn't you can be noticed. Your firm's administrators can see the sign-in history of their own team in Settings, and every member can see their own. These records are kept with the server logs described above, for the same periods.
Google user data
If an advisor connects a Google Workspace or Gmail account, UltimateCRM asks Google for read-only access to that mailbox and read/write access to that calendar, and for nothing else. We use that access for one purpose: to keep a copy of the advisor's client correspondence and meetings inside the advisor's own firm records, where regulators expect advisory firms to keep them.
UltimateCRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We only use Google user data to provide and improve the mailbox and calendar sync features the advisor can see in the product. We do not use it to build or train any model, including any artificial-intelligence or machine-learning model.
- We never sell Google user data, and we never use it for advertising or share it with advertisers, data brokers, or any other third party. It is transferred only to the infrastructure providers that host UltimateCRM, only as needed to run the service, and never for their own purposes.
- No human at AdvisorInfrastructure reads Google user data except with the advisor's explicit permission, when it is necessary for security or to investigate abuse, to comply with the law, or in a form that has been aggregated and anonymized.
- The advisor can disconnect the account in Settings at any time, which stops the sync and discards the credential we held; access can also be removed from the Google Account permissions page. Deleting the firm's account removes every synced message and event and revokes the grant at Google.
If you are a client of a firm that uses UltimateCRM
Your advisor may invite you to the client portal or send you a link to book a meeting. Those visits are recorded in the same server logs described above — your IP address, the time, the page requested, and your browser type — and kept for the same periods: up to 13 months on our servers and up to 7 years in archive, for the same security purposes and no other. We do not measure portal or booking visits for marketing, and we never use them for advertising. Everything else about your relationship with your advisor is governed by your advisor's own privacy policy; ours covers the infrastructure your advisor uses.
How your data is protected
Customer content is encrypted in transit with TLS 1.3 and at rest with AES-256, with a separate data key for each firm and tenant isolation enforced in the database itself. The details are on our Security page.
AES-256 is the algorithm standardized in FIPS 197, and AES-GCM is a FIPS 140-3 approved mode (NIST SP 800-38D). Both NIST and the NSA (CNSA 2.0) rate AES-256 as resistant to attack by quantum computers.
Service providers
We use a small number of infrastructure providers to run UltimateCRM:
- Amazon Web Services — hosting, the database, and encrypted file storage.
- Stripe — subscription billing. Stripe receives your firm's billing contact and payment details directly; we never receive or store card numbers. No client data is sent to Stripe.
- Microsoft, Google, RingCentral, and Zoom — only where your firm connects them, and only for the data your firm chooses to sync.
These providers process data on our behalf to deliver the service; none of them receive your data for their own purposes.
Retention and deletion
We keep your firm's data for as long as your account is active. A firm administrator can request deletion of the entire account from the application's settings; we carry it out after taking an export of the firm's data for the firm to keep. Advisory firms are often required by regulation (for example, SEC books-and-records rules) to retain certain records, so the request includes the firm's confirmation that it has taken custody of anything it must keep. Deletion removes every record, file, and credential the firm stored with us, and revokes the access grants your firm gave us at Microsoft, Google, RingCentral, or Zoom where those providers allow it.
What outlives a deleted account, and for how long: the export we took, for 30 days; our own record that the deletion was requested and carried out, indefinitely; sign-in and security events, for 13 months; the server logs described above, for 13 months on our servers and 7 years in archive; our database backups, for 35 days; deleted files in encrypted storage as recoverable versions, for 30 days; and your firm's billing account and invoices at Stripe, as financial records. The encryption key for a deleted firm is destroyed with it, so files and backups that outlive it cannot be read after the key is gone.
Your rights
You can ask us at any time what information we hold about you, ask us to correct it, or ask us to delete it. Email hello@advisorinfrastructure.com and a real person will handle it.
Changes to this policy
If we change this policy, we'll update the effective date at the top of this page and, for meaningful changes, notify account holders by email. We will never change the core commitment: your data is not for sale, ever.
Contact
Questions about privacy? Email hello@advisorinfrastructure.com.