Chamber Culture CRM

Privacy Policy

What personal data the platform holds, who is responsible for it, and who ever sees it.

Last updated 11 August 2026

The short version

Contents

  1. Two different relationships
  2. Data your chamber holds in the platform
  3. Data we collect for ourselves
  4. Email and text messaging
  5. Directory analytics, cookies and website measurement
  6. Who else sees data, and why
  7. Artificial intelligence features
  8. If you are a member, a rep or a subscriber
  9. How long we keep things
  10. Security and incidents
  11. Location, children, changes and contact

1. Two different relationships

This policy covers Chamber Culture CRM, the Chamber Culture Sites website included with it, and the member portal. It is published by Champlin Enterprises, LLC.

Keeping two things apart makes the rest of this page make sense:

Chamber Culture Surveys is a different product with its own privacy policy at chamberculture.com/privacy. It describes anonymous employee survey responses, which is not what the CRM holds. Neither policy applies to the other product.

2. Data your chamber holds in the platform

Exactly what is stored is the chamber's choice, including any custom fields it adds. In practice it is:

Consent provenance

When someone joins a mailing list, the platform records when they opted in, by what method, and from which page, plus a one-way hash of the IP address. The raw IP is never stored. This exists so a chamber can prove consent, and so the list stays lawfully usable if the chamber ever moves to another system.

What we never do with it

We do not use member, contact or subscriber data for research, benchmarking, market analysis, advertising, resale or to train AI models, and that includes anonymised and aggregated forms. We do not sell personal information. The only uses beyond running the service are the four disclosed in section 2 of our terms: counting members for billing, logged support access, reviewing questions staff type into the in-app help assistant, and legal compulsion.

3. Data we collect for ourselves

4. Email and text messaging

Email sent through the platform is delivered by Mailgun, and the platform records delivery, opens, clicks, bounces and spam complaints per recipient so a chamber can see how a newsletter performed. Open tracking works with a small invisible image; blocking remote images in your mail client prevents it.

Unsubscribing is one click and permanent. A hard bounce or a spam complaint suppresses an address automatically, on the same footing as an unsubscribe. Suppression is stored in the platform itself, not only at the mail provider, and it is enforced on every send. Chamber staff cannot work around it.

Text messages send through the chamber's own Twilio account and number, with STOP and START handled automatically.

5. Directory analytics, cookies and website measurement

Directory analytics, deliberately privacy-first

When a visitor views a member listing or clicks through to a phone number, website or directions, the platform records that so the member can see the business the directory sent them. It stores no cookie, no IP address and no user agent. Repeat visits are grouped by a hash that rotates daily, which is enough to count a visitor twice in one day and impossible to follow across days or across sites.

Cookies

Signing in sets a session cookie and a security token cookie. Both are strictly necessary and there is no way to use an account without them.

On crm.chamberculture.com we also run Google Analytics 4 and our own Pulse analytics to measure how our product pages perform. These set analytics cookies. They are limited to that host, and they are our own measurement of our own marketing, not a profile of your members.

Being straight about the current state: those two analytics tools load on our pages without a cookie banner today. If you would rather not be measured, browser tracking protection or an ad blocker stops both, and nothing on the site breaks. A consent banner for our own pages is on our list.

A chamber's own public website is separate. What loads there is controlled by the chamber in its own settings, including its own analytics tags and its own consent banner, and that is the chamber's disclosure to make.

6. Who else sees data, and why

A short list, and it is the whole list. Each one performs a specific function and is not permitted to use the data for anything else.

WhoWhat they doWhat reaches them
Our hosting providerRuns the servers and stores the databaseEverything, at rest, encrypted in backups
MailgunDelivers email and reports engagementRecipient addresses and message content
TwilioDelivers text messagesRecipient numbers and message content
Your payment processor
Stripe, PayPal, Authorize.net or Elavon
Takes card paymentsCard details, entered directly into their hosted fields. Never our servers
Intuit QuickBooks OnlineAccounting sync, only if the chamber connects itCustomers, invoices and payments
AnthropicPowers the AI featuresSee section 7
CloudflareContent delivery and caching for chamber websitesPublic page content and standard request data
Google Translate
only if your chamber turns on the language switcher
Machine translation of your public pages when a visitor picks a languageThe public page text being translated, and the visitor's request. No member contact details, and nothing from behind a login
Our own error tracker and analytics
Champlin Enterprises tools
Fault diagnosis, and measurement of our own marketing pagesScrubbed diagnostics, and page analytics on crm.chamberculture.com

We also disclose data where the law requires it, and we will tell the affected chamber before we do unless the law forbids it. If our business were ever sold, the continuity commitments in section 7 of our terms apply, including the case where a buyer will not take on our obligations.

7. Artificial intelligence features

AI features run through Anthropic's API under terms that do not permit your content to be used to train models, and we do not train any model of our own on your data.

The public Directory Concierge, the chat a visitor can use on a chamber website, only ever receives listings, events and deals that are already publicly visible on that chamber's directory. It cannot see contacts, invoices, payments or anything hidden. Staff-facing AI features see only the records of the chamber whose staff invoked them.

8. If you are a member, a rep or a subscriber

Your information is held by your chamber, and the chamber decides what it keeps and for how long. We hold it for them.

Members with a portal login can also see and edit their own business listing and contact details directly.

9. How long we keep things

10. Security and incidents

How data is protected, how backups work and what our infrastructure runs is set out at /security.

If we confirm that chamber or member data has been affected by a security incident, we notify every affected chamber by email within 72 hours of that confirmation, with what happened, what data was involved, what we did about it, and what we recommend. Chambers are responsible for notifying their own members where the law requires, and we give them what they need to do it.

11. Location, children, changes and contact

Where data lives. The platform runs on servers in the United States. If you are outside the US, your information is processed there.

Children. The platform is business software and is not directed at children. We do not knowingly collect information from anyone under 13. If a chamber runs a program involving young people, that data is the chamber's to justify and its own privacy notice should cover it.

Changes. If we change this policy in a way that materially affects how personal data is handled, we give subscribing chambers 60 days written notice by email, matching the terms. The date at the top always reflects the current version.

Contact. Privacy questions, requests, or anything on this page you want explained: [email protected]. Champlin Enterprises, LLC.