Security and Privacy at Salesmsg

At Salesmsg, we know how valuable your work is to you — after all, what's more important than Data you upload to Salesmsg everyday? That's why we work hard to respect your privacy and ensure that your data is always safe with us. Here are some of the ways in which we keep your Data private and your work secure.

Salesmsg and the EU General Data Protection Regulation (GDPR)

At Salesmsg, we’re committed to privacy—that's why our privacy policies are already consistent with the high standard of the new European data protection law known as GDPR, and why we’re ensuring we maintain those rights and extend them to all our users, inside and outside the EU.

How is my data safe?

Complete control over who can access your Data

All entered Data is private by default. Accessing your Data requires a user to have a Salesmsg account and be invited to view and modify your Data by an authorized user of your account.

You have a right to request deletion of your personal information by us. Deletion of the information is accomplished by the one way obfuscation. If you would like to request your personal information deletion, please contact us at support@salesmessage.com

Where is my data stored, and how long is it retained?

All Salesmsg data is stored in the US (AWS datacenter). More on AWS security. Salesmsg uses Amazon Relational Database Service (Amazon RDS) to store user data in the cloud. Salesmsg encrypts the database data stored on Salesmsg’s Amazon RDS DB instance under a customer master key (CMK) in AWS KMS. User data is retained only as long as it is necessary to properly operate Salesmsg application.

Is my data secure?

  • All of our servers are within our own virtual private cloud (VPC) with network access control lists (ACL’s) that prevent unauthorized requests getting to our internal network.
  • We have data encryption in transit, meaning all our data in the database, underlying storage, backups, replicas and snapshots passes through the encrypted channel.
  • Only a handful of people can access data and they only do so in order to improve the services we provide.
  • We monitor and audit our usage logs.

What Third Party services do you use?

We use a number of third parties to store user data in order to provide/improve our services:

  • We send a monthly newsletter using Hubspot. This newsletter is only sent to customers who signed up specifically to receive the newsletter.
  • We send transactional and administrative emails through Mailchimp.
  • We use Google Analytics to track page views to improve usability of our marketing website and Web Salesmsg App.
  • We use DataDog to track errors that occur within Web DataDog App and the API. This also includes certain data that correlates with the error, but does not include sensitive customer information (passwords, tokens etc).
  • We use CloudFlare (as CDN) to distribute our resources for our marketing website
  • All payments are processed by Stripe. We don’t currently store any payment information or customer data from these transactions.
  • Our search functionality on Web Salesmsg App is powered by Amazon Elastic Search.
  • Our Customer Support team use Mailchimp and HubSpot to provide email and social media support for users.

Compliance

The environment that hosts the Salesmsg services maintains multiple certifications for its data centers, including ISO 27001 compliance, PCI Certification, and SOC reports. For more information about their certification and compliance, please visit the AWS Security website and the AWS Compliance website.

Salesmsg maintains robust controls and processes aligned with the AICPA Trust Services Criteria for Security. We are in the process of completing SOC 2 Type II compliance. These attestations reflect our ongoing commitment to safeguarding customer data and maintaining secure operations.

For more details about our security practices and compliance posture, please visit our Trust Center.

You can find out more about our policies in our Terms of Service and Privacy Statement. If you have any questions about security at Salesmsg, please contact our Customer Support team.

Cybersecurity Event

In the event of a cybersecurity incident, we are committed to promptly informing our clients to ensure transparency and mitigate potential risks. Upon detecting a breach, we will notify affected clients within 72 hours, detailing the nature and scope of the incident, the data involved, and any immediate actions taken. Clients will also receive recommendations for protective measures and updates on the investigation's progress. Our goal is to provide clear, timely, and actionable information to help safeguard our clients' interests and maintain their trust.

Contact Us

If you have any questions about security or privacy at Salesmsg, please contact us:
📧 support@salesmessage.com
📍 SalesMessage, Inc., 1045 E. Atlantic Ave #202, Delray Beach, FL 33483

Last Updated: October 24, 2025

This policy describes our current practices. We may update it periodically as our security program evolves.