1. Who this covers
This policy explains how TacLine LLC, a New York limited liability company doing business as TacLine Technology Solutions (“TacLine“, “we“, “us“), collects, uses, shares and protects personal information.
It applies to taclinetech.com, to our consulting, integration and support engagements, to our SMS and MMS messaging program, and to the software platforms TacLine operates — including ConvivaOS and ONE Travel OS. Where one of those platforms publishes its own supplemental privacy notice, that notice adds detail for that product; this policy describes TacLine’s practices as the operating company behind it.
Two roles matter throughout. When we decide why and how information is processed — our website, our messaging program, our own business records — we are the controller. When we handle records inside a client agency’s systems in the course of an engagement, we are a processor or service provider acting on that agency’s written instructions, and that agency’s own privacy notice governs the individuals in those records.
2. Information we collect
2.1 Information you give us
- Contact and inquiry details — name, agency or organization, role, work email, telephone and mobile number, agency type, timing, and whatever you write in the message field of a contact form.
- Account information — username, credentials, and profile and security settings for a TacLine software platform, including a mobile number registered for security codes.
- Engagement records — correspondence, tickets, notes, meeting records, and the technical detail of your environment that you share with us.
- Billing information — billing contact, purchase order and invoicing details. Card and bank details are handled by our payment processor; we do not store full payment card numbers on our systems.
- Messaging consent records — the mobile number, the date and time of consent, the method used, and the exact disclosure wording shown to you.
2.2 Information collected automatically
- Device and connection data — IP address, user agent, referring page, pages viewed, and timestamps, collected by our web server and security layer.
- Cookies and similar technologies — see section 8.
- Application logs — for TacLine software platforms, authentication events, actions taken, and error diagnostics.
2.3 Information we access in a client’s systems
Integration, migration and support work can give us access to records held in a client agency’s systems, which may include patient care records, incident records, personnel records and law-enforcement-sensitive data. We access the minimum necessary to perform the work, under the agency’s instructions and our contract with it, and we do not use that information for any purpose of our own. Where protected health information is involved, see section 7.
2.4 Information from other sources
We may receive information from a client agency about its staff for support purposes, from our vendors and subprocessors in the course of delivering the Services, and from publicly available sources when verifying an agency or a procurement contact.
3. How we use information
We use personal information to:
- respond to your inquiry and assess whether an engagement is a fit;
- deliver, support, secure and improve the Services;
- authenticate you and protect accounts, including sending security codes;
- send the transactional and account messages you have consented to receive;
- schedule work, manage tickets, and communicate about an engagement;
- invoice, collect payment, and keep accounting records;
- monitor for abuse, investigate incidents, and maintain security and availability;
- meet legal, regulatory, contractual and carrier obligations; and
- establish, exercise or defend legal claims.
Where the EU or UK GDPR applies, we rely on: performance of a contract (delivering the Services); legitimate interests (securing our systems, understanding site usage, pursuing business inquiries); consent (text messaging and non-essential cookies), which you may withdraw at any time; and legal obligation (tax, accounting, and lawful requests).
4. Mobile information and SMS consent
This section describes how we handle mobile telephone numbers and messaging consent. It applies to TacLine’s toll-free number (833) 270-2750 and to the messaging program described in section 10 of our Terms of Service, whether a message is delivered as SMS, MMS or RCS.
4.1 What we collect
Your mobile number; the date and time you consented; which screen you consented on (your portal, onboarding, your profile, or an invitation you accepted); the IP address the consent was submitted from; and a version identifier for the exact consent wording you were shown. Separately, proof that the handset was verified by the six-digit code. We also store the content and delivery status of messages exchanged with you, and any opt-out you send.
4.2 Why we collect it
Only to send you the categories of message you consented to — service and support notifications, account security codes, booking and itinerary alerts, and conversational support — and to keep proof that you consented, which carriers, messaging providers and regulators can require us to produce.
4.3 We do not use it for marketing
TacLine does not send marketing, advertising or promotional messages, and does not use your mobile number to build advertising audiences or profiles.
4.4 We do not share it
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors in support services, such as our messaging provider, is permitted solely so we can deliver the messages you asked for. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Text-messaging opt-in data and consent are excluded from every disclosure described in section 5 other than the messaging provider named there, and are excluded entirely from any business transfer, analytics, advertising or partner arrangement.
4.5 How to stop messages
Reply STOP to any message from us; we also honour END, CANCEL, UNSUBSCRIBE and QUIT. We send one confirmation and then stop. An opt-out is recorded against the specific sending number you replied to — replying STOP to platform notifications does not stop messages an individual advisor, agency or business sends you from their own number. Reply HELP for help, or contact us at support@taclinetech.com. Message frequency varies and message and data rates may apply.
4.6 Replies you send us
Inbound replies are logged so we can operate the program and are automatically classified as opt-outs, help requests, or other. Before storage we redact anything matching the pattern of a payment card number. Please do not send payment card details, health information or other sensitive personal information by text message.
4.7 If you change your number
Changing the mobile number on your account clears the consent recorded against the old number and revokes its verification. The new number is not enrolled until you complete both opt-in steps again.
4.8 How long we keep it
We keep consent and opt-out records for as long as the number is enrolled and for at least four years afterwards, because we may be required to evidence a consent or an opt-out. Message content is retained per section 9. Where you exercise a deletion right under section 11, we retain only the minimum record of consent or opt-out we need to demonstrate compliance, and delete the rest.
5. How we share information
We disclose personal information only as described here.
Which subprocessors apply to you depends on which product you are using. Each platform TacLine operates — including ConvivaOS and ONE Travel OS — engages a different set of hosting, storage, email and payment providers, and each publishes its own current subprocessor list in its own terms and privacy notice. Read the notice for the product you actually use; it is the authoritative list for your data.
One subprocessor is common to every TacLine service, because messaging is shared infrastructure:
| Recipient | Why | What |
|---|---|---|
| ClickSend | Delivery of SMS, MMS and RCS messages and receipt of your replies, across all TacLine services | Mobile number, message content, delivery status |
| The subprocessors of the product you use | Hosting, storage, email, payment and related services | Listed in that product’s own privacy notice |
| Professional advisors | Legal, accounting and insurance | Only as needed, under duties of confidence |
| Client agencies and businesses | Where you are that organization’s staff, or its customer using our platform on its behalf | Support tickets and correspondence about their account |
| Authorities | Valid legal process, or to protect rights and safety | Only what the request or the situation requires |
Every subprocessor is bound by a written agreement limiting it to processing on our instructions, requiring appropriate security, and prohibiting use of the data for its own purposes.
Business transfers. If TacLine is involved in a merger, acquisition, financing or sale of assets, information may transfer as part of that transaction, subject to this policy — except text-messaging opt-in data and consent, which are excluded, as stated in section 4.4.
6. We do not sell your information
TacLine does not sell personal information, and does not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act as amended and comparable state laws. We have not done so in the preceding twelve months, including for anyone we know to be under 16. We do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit.
7. Protected health information
When TacLine handles protected health information on behalf of a covered entity, we act as a business associate under HIPAA and the HITECH Act. That relationship is governed by a Business Associate Agreement executed before access begins, which controls over this policy for anything touching PHI. Under it we use and disclose PHI only as the BAA permits, apply administrative, physical and technical safeguards, bind our subcontractors to equivalent terms, and report any breach of unsecured PHI to the covered entity without unreasonable delay.
If you are a patient and want to know how your records are handled, contact the agency or provider that treated you — they are the covered entity and hold the relationship with you. We cannot access or amend an individual’s record except on that agency’s instruction.
8. Cookies and analytics
Our website uses strictly necessary cookies for security and basic operation, and may use analytics cookies to understand which pages are read. We do not use advertising or cross-site tracking cookies. Where required, we ask for consent before setting non-essential cookies, and you can withdraw it at any time. Most browsers let you refuse or delete cookies; blocking strictly necessary cookies may break parts of the site.
We honour Global Privacy Control and other recognized opt-out preference signals where the law requires it.
9. How long we keep information
- Website inquiries — 24 months from the last contact, unless an engagement begins.
- Engagement and ticket records — for the term of the engagement and seven years afterwards, to support warranty, audit and dispute needs.
- Invoices and accounting records — seven years, per tax and accounting rules.
- Messaging consent and opt-out records — at least four years after the number leaves the program; see section 4.8.
- Message content — 12 months, unless it forms part of an engagement record.
- Security and access logs — 12 months.
- PHI — as the applicable Business Associate Agreement requires.
Backups roll off on their own schedule, normally within 90 days, after which deleted data is gone from them too.
10. How we protect information
We maintain a written security program appropriate to our size and the sensitivity of the data we handle. It includes encryption in transit and at rest, multi-factor authentication on administrative access, least-privilege and role-based access control, credential storage in an access-controlled password manager, endpoint protection and patching, logging and monitoring, tested backups, vendor review, and an incident-response procedure. TacLine complies with the New York SHIELD Act’s reasonable-safeguards requirement.
No system is perfectly secure. If a breach affects your personal information we will notify you and any regulator as applicable law and our contracts require. Report a suspected security issue to support@taclinetech.com with “Security” in the subject line.
11. Your privacy rights
Depending on where you live, you may have the right to: know what personal information we hold and how we use it; get a copy, in a portable format; correct inaccurate information; delete information; opt out of sale, sharing, or targeted advertising (we do none of these); limit the use of sensitive information; withdraw consent, including for text messages; and not be discriminated against for exercising a right.
These rights are available to residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws, and — with the additions below — to individuals in the EU and UK.
11.1 How to exercise a right
Email support@taclinetech.com or write to us at the address in section 15. We will verify your identity, usually by confirming details we already hold or by confirming control of the email address or mobile number on file, and respond within 45 days, or tell you why we need up to 45 more. An authorized agent may act for you with written permission and proof of authority. There is no charge unless a request is manifestly unfounded or excessive.
11.2 Appeals
If we decline a request, our response will say why and how to appeal. To appeal, reply to that response within 60 days with “Privacy Appeal” in the subject line. We will answer within 45 days. You may also complain to your state attorney general.
11.3 If you are in the EU or UK
You also have the right to object to processing based on legitimate interests, to restrict processing, and to lodge a complaint with your supervisory authority. Withdrawing consent does not affect processing already carried out.
11.4 If we are a processor
Where we hold your information only inside a client agency’s systems, direct your request to that agency. If you send it to us, we will forward it and support the agency in responding.
12. Children
The Services are for organizations and their staff. They are not directed at children, we do not knowingly collect personal information from anyone under 16, and you must be at least 18 to consent to our messaging program. If you believe a child has given us information, contact us and we will delete it. This does not affect records about minors that may exist inside a client agency’s systems, which that agency controls.
13. International transfers
TacLine operates in the United States and most of our vendors are US-based. Our messaging provider, ClickSend, operates from outside the United States, so mobile numbers, message content and delivery metadata may be processed abroad, including in Australia. If you contact us from outside the United States, your information is transferred to and processed in the United States, where privacy law differs from your own. Where we transfer personal data out of the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with additional safeguards as needed.
14. Changes to this policy
We may update this policy. The “last updated” date at the top shows when. Material changes are announced by notice on this page, and by email to clients with an active engagement, before they take effect. We will not apply a materially different use of your mobile number or messaging consent retroactively; a new message category requires fresh consent.
15. How to contact us
- TacLine LLC (d/b/a TacLine Technology Solutions)
- Business mailing address: 12 Main St #1515, Brewster, NY 10509
- Service of legal process: c/o registered agent, 418 Broadway STE R, Albany, NY 12207
- Privacy, security and general enquiries: support@taclinetech.com
- Toll-free: (833) 270-2750
See also our Terms of Service and the messaging program terms.