Privacy Policy - The Viking Stack

Privacy Policy

Last Updated: January 1, 2026

The Viking Stack - Privacy Policy

Welcome to The Viking Stack, operated by Tovsen Development & Technology Solutions LLC ("TDTS," "we," "us," or "our"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use The Viking Stack platform, website, software, mobile applications, SMS services, email services, and related services (collectively, the "Service").

This Privacy Policy applies to all visitors, users, and others who access or use the Service. By using the Service, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy and our Terms of Service.

Changes to this Policy: We may update this Privacy Policy from time to time as the Service changes and privacy laws evolve. We will notify you of material changes by posting a notice on our website or sending you an email. Your continued use of the Service after changes are posted constitutes acceptance of the updated Privacy Policy.

Information We Collect

We collect information that you provide directly to us, information we collect automatically when you use the Service, and information we receive from third parties.

A. Information You Provide to Us

  • Account Registration: When you create an account, we collect your name, email address, phone number, company name, business type, and password.
  • Profile Information: You may provide additional information such as job title, business address, website URL, social media profiles, and profile photo.
  • Billing Information: When you purchase a subscription or services, we collect payment card information, billing address, and transaction details. Payment processing is handled by third-party payment processors.
  • Contact and Lead Data: You may upload or enter contact information about your customers, leads, and contacts, including names, email addresses, phone numbers, addresses, and custom data fields.
  • Communications: When you contact us or communicate through the Service, we collect the contents of your messages, attachments, and any information you provide.
  • SMS and Email Content: We store the content of SMS messages and emails you send through the Service, including message templates, campaign content, and communication logs.
  • User-Generated Content: Any content you create, upload, or share through the Service, including documents, images, videos, notes, and custom fields.

B. Information We Collect Automatically

  • Usage Information: We collect information about your interactions with the Service, including pages viewed, features used, links clicked, search queries, actions taken, and the dates and times of your activity.
  • Device Information: We collect information about the devices you use to access the Service, including device model, operating system, browser type and version, IP address, device identifiers, mobile carrier, screen resolution, and language preferences.
  • Location Information: We may collect general location information based on your IP address. If you use our mobile app, we may collect precise location data with your permission.
  • Cookies and Tracking Technologies: We use cookies, web beacons, pixels, local storage, and similar tracking technologies to collect information about your browsing behavior, remember your preferences, authenticate your sessions, and analyze Service usage. You can control cookies through your browser settings.
  • Log Data: Our servers automatically record log data when you use the Service, including IP addresses, browser types, referring/exit pages, operating system, date/time stamps, and clickstream data.
  • Analytics: We use third-party analytics services (such as Google Analytics) to collect and analyze usage patterns, traffic sources, user demographics, and Service performance.

C. Information We Collect from Third Parties

  • Payment Processors: We receive information from payment processors to verify transactions, process refunds, and detect fraud.
  • Integration Partners: If you connect third-party services to your account (such as email providers, CRMs, social media platforms, or marketing tools), we may receive data from those services according to their terms and your authorization.
  • Public Sources: We may supplement your information with publicly available data to enhance our services and verify information.
  • Business Partners: We may receive information from business partners, affiliates, or resellers who refer you to the Service.

How We Use Your Information

We use the information we collect for the following purposes:

A. Providing and Improving the Service

  • Create, maintain, and authenticate your account
  • Provide, operate, and deliver the Service features and functionality
  • Process transactions and send transaction confirmations
  • Send SMS messages and emails on your behalf through the platform
  • Store and manage your contact lists, campaigns, and content
  • Provide customer support and respond to inquiries
  • Monitor and analyze usage patterns to improve the Service
  • Develop new features, products, and services
  • Personalize your experience and recommend relevant features
  • Optimize Service performance, speed, and reliability

B. Communications and Marketing

  • Send you Service-related announcements, updates, and notifications
  • Send you marketing communications about our products, services, promotions, and events (you can opt out at any time)
  • Conduct surveys and collect feedback
  • Send you educational content, tips, and best practices

C. Security and Fraud Prevention

  • Verify your identity and authenticate your account
  • Detect, prevent, and investigate fraud, abuse, and security incidents
  • Monitor for violations of our Terms of Service and usage policies
  • Protect the rights, property, and safety of TDTS, our users, and the public
  • Enforce our agreements and policies

D. Compliance and Legal Obligations

  • Comply with applicable laws, regulations, and legal processes
  • Respond to lawful requests from government authorities
  • Enforce our Terms of Service and other agreements
  • Maintain records for accounting, tax, and regulatory purposes

E. Analytics and Research

  • Analyze trends, usage patterns, and Service effectiveness
  • Conduct market research and competitive analysis
  • Generate aggregated, de-identified statistics about Service usage
  • Test new features and improvements

SMS and Phone Number Privacy

A2P 10DLC Compliance and SMS Privacy:

The Viking Stack provides SMS messaging capabilities subject to A2P 10DLC (Application-to-Person 10-Digit Long Code) regulations. This section describes how we handle phone numbers and SMS data.

A. Phone Number Collection and Use

We collect phone numbers in the following ways:

  • Phone numbers you provide during account registration
  • Phone numbers you upload or enter for your contacts and leads
  • Phone numbers collected through forms, integrations, or imports
  • Phone numbers obtained through A2P 10DLC registration for SMS campaigns

We use phone numbers to:

  • Send SMS messages on your behalf to your contacts who have consented to receive messages
  • Verify your identity and account through two-factor authentication
  • Register your business and campaigns with The Campaign Registry (TCR) for A2P 10DLC compliance
  • Contact you about your account, billing, or Service-related issues
  • Enable voice calling features (if applicable)

B. SMS Message Content and Storage

  • We store SMS message templates, campaign content, and sent message logs to provide the Service
  • Message content is used solely to deliver your campaigns and is not shared with third parties except as required to provide the Service (e.g., SMS delivery providers)
  • We may analyze message content in aggregate to improve deliverability and detect spam or abuse
  • Message history is retained according to our data retention policies and may be used for compliance, billing, and support purposes

C. Consent and Opt-Out for SMS

Consent Requirements:

You are responsible for obtaining prior express written consent from recipients before sending them SMS messages through our Service. Recipients must have the ability to opt out of receiving messages at any time.

  • Recipients can opt out by replying with keywords such as STOP, UNSUBSCRIBE, CANCEL, END, or QUIT
  • Opt-out requests are processed automatically and immediately
  • We maintain opt-out lists to prevent future messages to opted-out recipients
  • You may not override opt-out preferences or send messages to opted-out recipients

D. A2P 10DLC Registration Data

To comply with A2P 10DLC requirements, we collect and share certain business information with The Campaign Registry (TCR) and wireless carriers:

  • Business name, address, and tax identification number (EIN)
  • Business type and industry
  • Campaign use case descriptions
  • Sample message content
  • Estimated message volume

This information is required for carrier approval and message delivery. TCR and carriers may use this data for vetting, compliance, and fraud prevention purposes.

E. SMS Delivery and Carrier Sharing

To deliver SMS messages, we share phone numbers and message content with third-party SMS delivery providers and wireless carriers. These providers are contractually obligated to use the data solely for message delivery and may not use it for other purposes.

Email Privacy and Unsubscribe

A. Email Collection and Use

We collect email addresses in the following ways:

  • Email addresses you provide during account registration
  • Email addresses you upload or enter for your contacts and leads
  • Email addresses collected through forms, landing pages, or integrations
  • Email addresses obtained through third-party services or list imports

We use email addresses to:

  • Send transactional emails related to your account (confirmations, receipts, password resets, etc.)
  • Send marketing emails on your behalf to your contact lists
  • Deliver Service notifications, updates, and announcements
  • Provide customer support and respond to inquiries
  • Send you marketing communications about our own products and services

B. Email Content and Storage

  • We store email templates, campaign content, and sent email logs to provide the Service
  • Email content you send through the Service is stored and may be used to provide analytics, track engagement, and improve deliverability
  • We do not sell or share your email content with third parties except as required to deliver emails (e.g., email service providers)
Unsubscribe and Email Preferences:

You have the right to control the emails you receive from us and through the Service. We provide multiple ways to manage your email preferences and unsubscribe from communications.

C. Unsubscribe from Your Marketing Emails

If you receive marketing emails sent through The Viking Stack by one of our users:

  • Every marketing email includes a clear and conspicuous unsubscribe link in the footer
  • Clicking the unsubscribe link will immediately remove you from that sender's mailing list
  • You will receive a confirmation that you have been unsubscribed
  • The sender is required to honor your unsubscribe request within 10 business days as required by CAN-SPAM
  • You can also reply to the email requesting to be removed from the list

D. Unsubscribe from TDTS/Viking Stack Marketing Emails

If you receive marketing emails from The Viking Stack about our own products and services:

  • Click the unsubscribe link at the bottom of any marketing email
  • Log into your account settings and update your email preferences
  • Contact us at [email protected] with your unsubscribe request
  • Note: You cannot opt out of transactional or Service-related emails (such as account notifications, receipts, or security alerts)

E. Email Deliverability and Tracking

  • We use email tracking technologies such as pixels and open tracking to measure email performance and engagement
  • We track email opens, clicks, bounces, and unsubscribes to provide you with campaign analytics
  • We monitor sender reputation and deliverability rates to optimize email delivery
  • Recipients can disable email tracking by disabling images in their email client

F. CAN-SPAM Compliance

All commercial emails sent through The Viking Stack comply with the CAN-SPAM Act:

  • Accurate "From," "To," and "Reply-To" information
  • Clear identification of the message as an advertisement (when applicable)
  • Valid physical postal address of the sender
  • Clear and conspicuous unsubscribe mechanism
  • Prompt honoring of opt-out requests (within 10 business days)

How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

A. Service Providers and Business Partners

We share information with third-party service providers who perform services on our behalf, including:

  • SMS Delivery Providers: To deliver SMS messages on your behalf
  • Email Service Providers: To deliver emails on your behalf
  • Payment Processors: To process payments and prevent fraud (e.g., Stripe, PayPal)
  • Cloud Hosting Providers: To store data and host the Service (e.g., AWS, Google Cloud)
  • Analytics Providers: To analyze Service usage and performance (e.g., Google Analytics)
  • Customer Support Tools: To provide customer support services
  • Marketing and Advertising Partners: To deliver targeted advertising and measure campaign effectiveness
  • The Campaign Registry (TCR): For A2P 10DLC registration and compliance verification
  • Wireless Carriers: For SMS message delivery and compliance with carrier requirements

These service providers are contractually obligated to use your information only for the purposes we specify and to protect your information.

B. Legal and Compliance Purposes

We may disclose your information if required by law or if we believe in good faith that such disclosure is necessary to:

  • Comply with applicable laws, regulations, legal processes, or enforceable governmental requests
  • Respond to subpoenas, court orders, or other legal demands
  • Enforce our Terms of Service, Privacy Policy, or other agreements
  • Investigate and prevent fraud, security incidents, or illegal activities
  • Protect the rights, property, safety, or security of TDTS, our users, or the public
  • Cooperate with law enforcement or regulatory investigations

C. Business Transfers

If TDTS is involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or use of your personal information.

D. With Your Consent

We may share your information with third parties when you have given us your explicit consent to do so, such as when you authorize integrations with third-party services.

E. Aggregated and De-Identified Data

We may share aggregated, de-identified, or anonymized data that does not identify you personally. This data may be used for research, analytics, marketing, or other business purposes.

Data Retention and Storage

Retention Periods: We retain your personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.

  • Account Data: Retained while your account is active and for a reasonable period after account closure for backup, legal, and business purposes
  • Transaction Data: Retained for up to seven (7) years to comply with tax, accounting, and regulatory requirements
  • Communication Logs: SMS and email logs retained for up to two (2) years for compliance and support purposes
  • Usage Data: Retained for up to one (1) year for analytics and Service improvement
  • Marketing Data: Retained until you opt out or request deletion
Data Deletion Requests:

You may request deletion of your account and personal data at any time by contacting us at [email protected]. We will process your request within ninety (90) days, subject to legal and contractual retention requirements.

Data Storage Location: Your data is stored on secure servers located in the United States. By using the Service, you consent to the transfer and storage of your data in the United States.

Data Backup: We maintain regular backups of data for disaster recovery purposes. Backup data may be retained for up to ninety (90) days after deletion from production systems.

Data Security

We implement commercially reasonable technical and organizational security measures designed to protect your personal information from unauthorized access, disclosure, alteration, and destruction.

Security Measures Include:

  • Encryption of data in transit using TLS/SSL protocols
  • Encryption of sensitive data at rest
  • Secure authentication and access controls
  • Regular security audits and vulnerability assessments
  • Firewalls and intrusion detection systems
  • Employee training on data security and privacy
  • Restricted access to personal information on a need-to-know basis
  • Multi-factor authentication for account access
  • Regular security updates and patches

Your Responsibility: You are responsible for maintaining the security of your account credentials. Do not share your password with others, and notify us immediately if you suspect unauthorized access to your account.

No Guarantee: While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.

Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information:

A. General Rights (All Users)

  • Access: You can access and review your account information by logging into your account settings
  • Correction: You can update or correct your account information through your account settings
  • Deletion: You can request deletion of your account and personal data by contacting us (processed within 90 days)
  • Opt-Out: You can opt out of marketing emails by clicking unsubscribe links or updating your preferences
  • SMS Opt-Out: You can opt out of SMS messages by replying STOP to any message
  • Cookie Controls: You can manage cookies through your browser settings

B. California Residents (CCPA Rights)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You can request information about the personal data we have collected about you in the past 12 months, including categories of data, sources, purposes, and third parties we share data with
  • Right to Delete: You can request deletion of your personal information, subject to certain exceptions
  • Right to Opt-Out of Sale: We do not sell personal information, so this right does not apply
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

To Exercise CCPA Rights: Contact us at [email protected] with your full name, email address, and specific request. We will respond within 45 days.

C. European Users (GDPR Rights)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

  • Right of Access: Request copies of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing of your data for direct marketing or other purposes
  • Right to Withdraw Consent: Withdraw consent for data processing at any time
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

Legal Basis for Processing (GDPR): We process your data based on:

  • Contract performance (to provide the Service)
  • Consent (for marketing communications)
  • Legitimate interests (to improve the Service, prevent fraud, and ensure security)
  • Legal obligations (to comply with laws and regulations)

Cookies and Tracking Technologies

We use cookies, web beacons, pixels, and similar tracking technologies to collect information about your use of the Service.

Types of Cookies We Use:

  • Essential Cookies: Required for the Service to function (authentication, security, session management)
  • Performance Cookies: Collect information about how you use the Service to improve performance
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand user behavior and measure Service effectiveness
  • Advertising Cookies: Deliver personalized ads and measure ad campaign performance

Managing Cookies:

  • You can control cookies through your browser settings (e.g., block, delete, or receive warnings)
  • Disabling cookies may limit your ability to use certain features of the Service
  • Most browsers accept cookies by default; consult your browser's help documentation to learn how to change settings

Do Not Track:

Your browser may offer a "Do Not Track" (DNT) signal. The Service does not currently respond to DNT signals, as there is no industry-wide standard for how to interpret DNT requests.

Third-Party Links and Services

The Service may contain links to third-party websites, applications, or services that are not operated by TDTS. This Privacy Policy does not apply to third-party websites or services.

Third-Party Privacy Practices: We are not responsible for the privacy practices or content of third-party websites or services. We recommend reviewing the privacy policies of any third-party services you interact with.

Integrations: If you connect third-party services to your Viking Stack account (e.g., email providers, CRMs, social media platforms), those services may collect and use your data according to their own privacy policies. Review their privacy policies before connecting integrations.

Children's Privacy

The Service is not directed to children under the age of 13 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children.

If You Are a Parent or Guardian: If you believe we have collected information from a child under 13 without parental consent, please contact us immediately at [email protected]. We will take steps to delete such information promptly.

International Data Transfers

The Service is operated in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States.

Data Protection Standards: The United States may have data protection laws that differ from those in your country. By using the Service, you consent to the transfer of your information to the United States and the processing of your information in accordance with this Privacy Policy and U.S. law.

EU-U.S. Data Transfers: For transfers of personal data from the European Economic Area to the United States, we rely on Standard Contractual Clauses approved by the European Commission and other appropriate safeguards.

Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or legal requirements.

Notice of Changes: We will notify you of material changes by:

  • Posting a notice on our website before the changes take effect
  • Sending you an email notification to the address associated with your account
  • Displaying an in-app notification when you log in

Effective Date: Changes become effective on the date specified in the updated Privacy Policy. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.

Review Regularly: We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Privacy Requests: For data access, correction, deletion, or other privacy rights requests, please email us at [email protected] with "Privacy Request" in the subject line. Include your full name, email address, and detailed description of your request. We will respond within the timeframes required by applicable law.

Data Protection Officer: For GDPR-related inquiries, you may contact our Data Protection Officer at [email protected].