Privacy Policy
Last updated: September 4, 2026
This Privacy Policy explains how IT Partners Plus LLC, a Delaware limited liability company (“ITPartners+,” “we,” “us,” or “our”) handles personal data in connection with Current, our software-as-a-service platform at current.day (the “Service”). Current is a business-to-business service for managed services providers and their teams; it is not directed to consumers or to children.
Two roles matter throughout this policy. For the data your organization puts into its workspace (“Customer Data”), your organization is the controller and we act as a processor, handling that data only to provide the Service under your instruction. For the data we collect to run our business — account, billing, and marketing information — we act as the controller. This policy covers customers in the United States, Canada, and the EU/UK.
What we collect
Account and contact information
Names, business email addresses, roles, workspace configuration, and authentication details for the people who administer and use a workspace.
Billing information
Subscription plan, seat counts, and billing contacts. Payments are processed by Stripe; we receive transaction and status information but never store full card numbers.
Customer Data in the workspace
The business records you and your integrations bring into Current — companies, contacts, deals, projects, tasks, time entries, tickets, quotes, communications, and files. This can include personal data about your employees, your clients, and their contacts. You determine what enters your workspace.
Usage and technical data
Log data needed to operate and secure the Service — such as IP address, device and browser type, timestamps, and actions taken in the app — used for security, troubleshooting, and reliability.
Marketing and inquiry data
Information you submit when you request a demo, contact support, or otherwise reach out.
How we use it
- to provide, secure, maintain, and support the Service;
- to process subscriptions, seats, trials, and payments, and to manage dunning;
- to power the features you use, including AI features and the integrations you connect;
- to detect, prevent, and investigate fraud, abuse, and security incidents;
- to communicate with you about your account, service changes, and support; and
- to comply with legal obligations and enforce our agreements.
We do not sell personal data, and we do not use Customer Data for advertising.
AI features
Current includes built-in AI features that generate briefs, drafts, summaries, and analyses from data in your workspace. To provide them, relevant workspace data is processed by our AI subprocessor. AI outputs are drafts for you to review before acting on them. We do not use Customer Data to train our own or any third party’s foundation models.
Integrations you connect
When you connect a third-party service, data flows between it and Current under your instruction, and only as needed to provide the feature. Integrations you may enable include:
- ConnectWise PSA — two-way synchronization, including billing records;
- Kaseya Autotask PSA — two-way synchronization, including billing records;
- Microsoft 365 (via Microsoft Graph) — using delegated permissions your Microsoft administrator grants and can revoke, covering Teams messages, SharePoint files, Outlook calendars, and Microsoft To Do tasks; and, where you explicitly enable mailbox capture, email ingestion limited to messages involving your known CRM contacts;
- HaloPSA — two-way synchronization, including billing records;
- HubSpot — two-way synchronization;
- Seamless.ai — prospecting and contact enrichment, using your own Seamless.ai account and API key. We hold no Seamless.ai account on your behalf. Where prospecting brings personal data into your workspace, you are the controller for it and responsible for the notices data-protection law requires;
- ScalePad Quoter and Lifecycle Manager;
- ConnectWise CPQ — won-quote retrieval and quote-to-project conversion;
- Kaseya Quote Manager — read-only retrieval of quotes, sales orders, payments and delivery details, and quote-to-project conversion in Autotask;
- CrewHu — customer-satisfaction feedback;
- Handwrytten — physical direct mail; to fulfill a card, the recipient name and mailing address you provide are shared with Handwrytten;
- NeverBounce — email verification, using your own key; and
- View-only reporting feeds — ConnectWise RMM, Datto RMM, NinjaOne, Datto Backup, Backup Radar, Veeam Service Provider Console, Axcient x360Recover, Slide, Datto EDR, Huntress, SentinelOne, ThreatLocker, CyberFOX AutoElevate, Auvik, RocketCyber, UniFi, Cisco Meraki, Fortinet FortiCloud, KnowBe4, Duo, Addigy, and Inky.
Each of these services is independently controlled by its provider and governed by that provider’s own privacy terms.
Subprocessors
We use a limited set of vendors to run the Service. They process personal data only on our instructions and under contractual data-protection commitments. Our current categories of subprocessors are:
- Cloud infrastructure and database hosting (Supabase, running on Microsoft Azure) — hosting the application and its database;
- Bot protection (Cloudflare Turnstile) — protecting our public lead forms, booking pages, and Help Center question box from automated abuse;
- Payment processing (Stripe) — billing and payments; ITPartners+ never stores full card numbers;
- Transactional email (Resend) — sending account and system emails;
- AI processing (Anthropic) — generating briefs, drafts, and analyses from your workspace data, which you review as drafts;
- Microsoft (Graph API) — where you connect Microsoft 365.
The full, named list — including our cloud infrastructure provider, the bot-protection service on our public forms, and the country each vendor processes in — is published at current.day/subprocessors. We give at least 30 days’ notice before adding or replacing a subprocessor that can process Customer Data, and you may object on reasonable data-protection grounds.
A third-party service you connect using your own account and credentials — your PSA, HubSpot, a prospecting tool, an email verifier, a reporting feed — is not our subprocessor. We exchange data with it under your instruction, and your relationship with that vendor is governed by your contract with them.
Security
We take security seriously. ITPartners+ maintains a SOC 2 Type II audit attestation of its controls. We enforce per-tenant isolation using database row-level security so tenants cannot access each other’s data, encrypt data in transit, and apply role-based access controls. No method of transmission or storage is perfectly secure, but we work to protect your data using appropriate technical and organizational measures. Our SOC 2 report is available under NDA on request.
Data retention & deletion
We retain Customer Data for as long as your workspace is active. You can request an export of your Customer Data at any time during your subscription, in a commonly used, machine-readable format, and we will provide it within 30 days.
Our retention schedule:
- After termination — 30 days. Your Customer Data stays available for export on request for 30 days after your subscription ends.
- Deletion from live systems — within 30 days of that window closing, and in any event no later than 60 days after it closes.
- Backups — no later than 90 days. Deleted data persists in encrypted, rolling backups until they age out on their normal cycle. Backups are not selectively edited, are restored only to recover from an incident, and anything restored is re-deleted on the same basis.
- Billing and tax records — as long as law requires, typically seven years. These hold company and billing-contact details, not workspace records.
- Security and audit logs — kept on a rolling basis for security investigation and our own audit obligations.
- Synchronized ticket and time data — kept on the schedule shown in your workspace’s retention settings.
You may also request deletion of specific personal data, subject to those legal retention requirements, and we will confirm deletion in writing on request. Deleting a Current workspace does not delete anything from your PSA, your Microsoft 365 tenant, or any other system you connect — those stay entirely under your control.
If something goes wrong
If we become aware of a personal data breach affecting Customer Data, we notify the affected workspace’s administrators without undue delay and within 72 hours of becoming aware, with what we know about the nature of the breach, the data and people affected, the likely consequences, and what we are doing about it. We then assist with any notification you have to make to a regulator or to individuals. Keep an administrator email address current — that is where the notice goes.
Your rights — GDPR / UK
If you are in the EEA or the UK, the EU GDPR and UK GDPR apply. For Customer Data, your organization is the controller and we act as its processor; if you are an individual whose data appears in a customer’s workspace, please direct requests to that organization, and we will assist it as processor. For data where we are the controller (account, billing, and marketing data), we rely on these legal bases: performance of a contract (to provide the Service and process billing), our legitimate interests (to secure, support, and improve the Service, and for business communications), consent (where required, such as certain marketing), and compliance with legal obligations.
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- delete data (the “right to be forgotten”);
- restrict or object to certain processing;
- data portability; and
- withdraw consent where processing is based on consent.
You may also lodge a complaint with your supervisory authority — in the UK, the Information Commissioner’s Office.
You do not have to ask us for a Data Processing Agreement. Our Data Processing Addendum is incorporated into the Terms of Service and applies automatically, from the moment you create a workspace, to every customer subject to the EU GDPR, the UK GDPR, or the Swiss FADP. It carries the Article 28 processing terms, our security measures, the 72-hour breach commitment, the deletion schedule, and the Standard Contractual Clauses with the UK Addendum. If your procurement process needs a counter-signed copy, email us and we will send one.
Your rights — US states
Depending on your state of residence (for example, under the CCPA/CPRA and similar state laws), you may have the right to know what personal information we collect and how we use it, to access and delete your personal information, to correct inaccuracies, and to opt out of the “sale” or “sharing” of personal information and of certain targeted advertising. We do not sell personal information, and we never share Customer Data for advertising of any kind. We do run an advertising conversion pixel on our public website and app pages (see Cookies and tracking), which may constitute “sharing” of website-visitor identifiers for cross-context behavioral advertising under the CCPA/CPRA. To opt out, decline on the cookie banner, use a Global Privacy Control signal, or email us. We will not discriminate against you for exercising these rights. For personal information within a customer’s workspace, we act as a service provider and will route your request to the relevant customer.
Your rights — Canada
For customers and individuals in Canada, we handle personal information consistently with PIPEDA. We collect and use personal information for the purposes described here, obtain consent where required, and give you the ability to access and correct your personal information and to ask questions about our handling of it. For Customer Data, the relevant customer organization is the responsible organization and we act on its behalf.
Where your data is stored
Customer Data is stored in the United States. Our production database, file storage, and backups are hosted in US regions, and our subprocessors process data in the United States unless stated otherwise. If your organization needs its data hosted in another region, contact us through the Help Center contact form and we will tell you what we can support. Regional hosting is not available by default and is arranged case by case.
International transfers
We are based in the United States and may process data in the United States and other countries where we or our subprocessors operate. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), to protect that data.
Cookies and tracking
We use three kinds of cookie and similar technology. Customer Data is never involved in any of them — no workspace records, client data, contracts, or financials are sent to any of these vendors.
- Essential. Required for authentication and to keep you signed in. These always run; disabling them prevents you from signing in.
- Analytics — Google Analytics 4. How our site and app are used, so we can find what is broken and what people cannot find. It records page views, device and browser, and conversion events such as starting a signup.
- Advertising — the Reddit advertising pixel. We run paid campaigns, and this measures which of them lead to a signup, a booked demo, or a started trial.
If you are in the EEA, the UK, or Switzerland, analytics and advertising are off until you say otherwise. Consent signals default to denied, the Reddit pixel is not loaded at all, and Google Analytics sends only cookieless pings, until you accept on the banner we show you. You can decline, and nothing further is set. Your choice is remembered in your browser; clearing your browser storage for current.day brings the banner back so you can change it. Outside those regions, analytics and advertising default to on and you can opt out through your browser or Google’s own opt-out tools.
Our pages also load fonts from Google Fonts, which discloses your browser’s IP address to Google when the fonts are served.
Each of these vendors, and the country it processes in, is named at current.day/subprocessors.
Children
Current is a business service intended for use by adults in a professional capacity. It is not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us and we will delete it.
Changes
We may update this Privacy Policy from time to time. When we do, we will post the updated version with a new “Last updated” date, and for material changes we will provide notice by email or in-product notice. Your continued use of the Service after an update takes effect constitutes acceptance of the updated policy.
Contact
To reach us about this policy or to exercise your rights, use the Help Center contact form at current.day/help/contact. For privacy-specific requests — access, correction, deletion, portability, or a question about this policy — contact privacy@current.day, or write to us at IT Partners Plus LLC, 2851 Charlevoix Dr, Suite 100, Grand Rapids, MI 49512.