Privacy
TheSalesBeast Privacy Policy
This policy explains what information TheSalesBeast and its operator application TheSalesBeast CRM collect, and how that information is used.
Information We Collect
- Name, phone number, email address, and vehicle request details you submit through TheSalesBeast forms
- Lead-source and marketing attribution details such as campaign, landing page, and ad metadata
- Message history and follow-up activity related to your request
- For social platform integrations connected to TheSalesBeast CRM: public profile information (name, username, account ID), the operator's own posted content (videos, images, captions), and inbound messages, comments, and interactions on the operator's own social accounts
How We Use It
- To respond to your vehicle request
- To send appointment reminders and follow-up messages you opted in to receive
- To improve response handling, lead routing, and CRM reporting
- To surface inbound buyer interactions in TheSalesBeast CRM's unified inbox so the operator can respond
- To draft sales-rep-style replies that the operator reviews before sending
- To track engagement metrics for the operator's own social media content
TheSalesBeast CRM — Connected Operator Application
TheSalesBeast CRM is the internal operator application used by Eugenio at TheSalesBeast.com to organize buyer briefs, respond to messages, and manage social media activity. TheSalesBeast CRM connects to social platforms (Meta / Facebook / Instagram, TikTok, WhatsApp) only via each platform's official APIs, and only with explicit operator authorization.
TheSalesBeast CRM does not collect, sell, or share data about other users of social platforms beyond what is needed to display their messages or comments to the operator for response. It does not train AI models on third-party data and does not redistribute social platform content outside the operator's own communications.
Only the minimum scopes needed for inbox and posting features are requested at OAuth time. Tokens are encrypted at rest using AES-GCM with a key held in the Cloudflare Workers environment.
TikTok Login Kit data handling
When you click "Sign in with TikTok" on our website and approve TikTok's OAuth consent screen, the following data is processed:
- Your TikTok display name, avatar URL, and app-scoped TikTok open_id/union_id, read via the user.info.basic scope at the moment you approve the consent screen.
- The vehicle inquiry you submit on our website after signing in, attached to your TikTok identity so our sales rep can respond with context.
- No TikTok content, no comments you have made, no videos you have posted, no DMs, no follower lists, and no profile information beyond the consented basic Login Kit identity fields.
- Our sales rep reaches out through the channels you consent to on our website, such as email, SMS, or phone. We do not post or message back to you on TikTok itself from this Login Kit integration.
Data retention — specific timelines
- Inbound DM message bodies: 90 days of conversation context, then auto-pruned by a daily sweep (visible in src/runtime/scheduled.js).
- Inbound comments on operator posts: 90 days, then auto-pruned.
- Lead records (buyers who submitted a vehicle request): retained for the duration of the customer relationship; deleted on request.
- Operator-authored outbound replies (audit trail): 365 days, then anonymized (body redacted, send timestamp retained for compliance).
- Aggregate funnel statistics (counts, no PII): retained indefinitely for trend reporting.
- OAuth tokens: encrypted at rest; rotated on platform-side refresh; deleted within 24 hours of OAuth revocation or app removal.
- Data deletion request SLA: 30 days for manual requests via email; 24 hours for automated requests via Meta App Center deauth callback.
Information Sharing
We do not sell your personal information.
We may share your request details with dealership partners or service providers as needed to help respond to your vehicle request and operate our services.
SMS consent applies only to messages sent by TheSalesBeast. SMS opt-in data and consent are not shared with dealership partners, third parties, or affiliates for their own marketing or promotional messaging.
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We may use service providers (cloud hosting, AI inference, transactional email, transactional SMS) that support our website, TheSalesBeast CRM, or messaging operations on our behalf, under standard processor agreements.
SMS Consent
If you choose to opt in to SMS, we retain a record of your consent, including the disclosure presented to you at the time of submission, the date and time of opt-in, and the phone number provided.
Your Choices
Reply STOP to opt out of SMS messages. You can also contact us at eugenio@thesalesbeast.com to request access, correction, or deletion where applicable.
If you are an end-user of a social platform whose interaction with the operator was captured by TheSalesBeast CRM, you can request deletion of your data by visiting our dedicated Data Deletion Request page at https://thesalesbeast.com/data-deletion or by emailing eugenio@thesalesbeast.com.
Facebook and Instagram users: removing TheSalesBeast CRM from your account via Meta's App Center will automatically trigger deletion of all your data within 24 hours — no manual request needed.