Systems Sort logoSYSTEMSSORT

Privacy Policy

Effective date: August 2, 2026 · Application: Systems Sort · privacy@systemssort.com

Systems Sort is a customer relationship management (CRM) application for insurance agencies, operated by Legacy Financial Planning LLC, doing business as Systems Sort. This policy explains what information Systems Sort collects, how it is used, and how agents can disconnect a mailbox or request deletion of connected-account information.

1. Who this policy covers

Systems Sort is an invite-only application used by licensed insurance agents and their agency administrators. Agents receive access through an invitation from their agency; there is no public self-service signup.

2. Information we collect

  • Account information: name, email address, role, and agency assignment created when an agent is invited.
  • CRM content that agents enter or import: contacts, notes, tasks, pipeline records, call and message logs, and documents they upload.
  • Connected mailbox information: the email address, display name, and OAuth tokens for a Gmail or Microsoft account an agent chooses to connect.
  • Operational data such as authentication events and error logs used to keep the service secure and working.

3. Voluntary Gmail and Microsoft mailbox connections

Connecting a mailbox is entirely optional. Agents may connect a Google (Gmail) or Microsoft (Outlook / Microsoft 365) account so that email they send to their own clients and prospects leaves from their real business address, shows their name, and receives replies in their own inbox.

Systems Sort requests only the minimum permissions required to do that:

  • Google: https://www.googleapis.com/auth/gmail.send (send email only), plus openid, userinfo.email and userinfo.profile to identify the connected mailbox.
  • Microsoft: Mail.Send, plus openid, profile, email, offline_access and User.Read to identify the connected mailbox and keep the connection active.

Systems Sort uses this authorization only to send individual email messages that the agent explicitly initiates inside the application. Systems Sort does not read, index, search, download, or store the agent's inbox, message history, drafts, calendar, contacts, or files, and does not request calendar or file permissions. Appointment scheduling in Systems Sort is handled through each agent's Calendly link, not through Google or Microsoft calendars.

4. Google API Services User Data Policy — Limited Use

Systems Sort's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Systems Sort does not use Google user data for advertising, does not sell Google user data, does not transfer it except as necessary to provide or improve the sending feature, to comply with applicable law, or as part of a merger or acquisition, and does not allow humans to read Google user data except with the user's explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymized.

5. How connection credentials are protected

  • OAuth access and refresh tokens are encrypted at rest with AES-256-GCM before they are stored.
  • Tokens are only ever decrypted by server-side code at the moment a message is sent. They are never sent to the browser and are never visible to any CRM user, including agency administrators.
  • The database table holding tokens grants no access to signed-in application users; administrators can see only connection status (provider, address, connected or needs re-authorization).
  • Systems Sort never asks for or stores an agent's email password, and never sends agent-to-client email from a Systems Sort system address.

6. System email vs. agent email

Transactional messages sent by the platform itself — invitations, password resets, and internal notifications — come from a Systems Sort system address. Email an agent sends to a lead or client is sent only through that agent's own connected or agency-authorized address. If no such address is connected, Systems Sort blocks the send and prompts the agent to connect one.

7. Service providers

Systems Sort relies on a small set of processors to operate: a cloud database and authentication provider, an email delivery provider for system email, a telephony provider for calling and SMS features, and an AI provider for optional assistant features. These providers process data only to deliver their part of the service.

8. Disconnecting a mailbox and deleting data

An agent can disconnect at any time in Systems Sort under Settings → Email Sending → Disconnect. Disconnecting revokes the authorization with the provider where the provider supports revocation, and deletes the stored tokens for that mailbox from Systems Sort.

Google account holders can additionally review or remove access at myaccount.google.com/permissions. Microsoft account holders can do the same at myapps.microsoft.com.

To request deletion of connected-account information, or of your account data generally, email privacy@systemssort.com from the address associated with your account. Agency-owned CRM records may be retained by the agency that invited you, in line with its own recordkeeping obligations.

9. Changes to this policy

If this policy changes, the effective date above is updated. Material changes affecting connected mailboxes will also be communicated in the application.

10. Contact

Questions about this policy or about data handling can be sent to privacy@systemssort.com.