Skip to content
Legal

Privacy policy

This explains what we collect, why, who else handles it, and what you can ask us to do about it. It covers this website, the client portal, and the online store.

Last updated 23 August 2026

1. Who we are

ClearPath MSP LLC, trading as ClearPath MSP, provides managed IT, cybersecurity, and support services from offices in Austin, Texas and Colorado Springs, Colorado. In this policy, “we” and “us” mean ClearPath MSP LLC, and “you” means anybody using this website, our client portal, or our online store.

ClearPath MSP LLC is the controller of the personal information described here. If you are a client, we also handle information inside the systems we manage for you. We do that on your instructions as your service provider, and your service agreement governs it rather than this policy.

To reach us about anything in this policy, email ContactUs@ClearPathMSP.com or call (512) 481-4017.

2. What we collect

We collect different things depending on how you interact with us. Each of the following is a separate case, and most people will only ever be in the first.

When you send us an enquiry

Our contact, quote, and newsletter forms ask for what we need to reply and nothing else. First name and email address are required on a quote or an enquiry. A last name, company, phone number, website, and the message itself are optional, and we only ever store the fields the form actually asks for.

We also store a one-way cryptographic hash of the network address the submission came from, so we can stop the same source flooding the form. We do not store the address itself, and the hash cannot be turned back into one.

When you subscribe to our writing

We store your email address, whether you have confirmed it, and two single-purpose tokens: one that confirms the subscription and one that ends it. Nothing is sent to you until you click the confirmation link, so somebody cannot sign you up using your address.

When you create an account

We store your name, email address, and a hashed password. We never store the password itself and cannot recover it. We record whether your email has been verified, and we keep a record of your active sign-in sessions so you can be signed out.

If you sign in with Microsoft or Google instead, we hold no password at all. We receive your name, email address, and the identifier that provider uses for you, and nothing more. We do not request access to your mailbox, files, calendar, or directory.

If you switch on two-step sign-in, the shared secret and your backup codes are stored encrypted, not in readable form.

When you buy something

We store what you ordered, what it cost, the tax and any processing fee, your billing and delivery address, a contact phone number for the courier, and a reference to your customer record at our payment processor.

Card details never reach our servers. The card fields on our checkout are served and handled by Stripe, our payment processor, and the card number is submitted directly to them. We receive a confirmation, the card brand, and the last four digits, which is what appears on your receipt.

The address recorded against an order is a snapshot taken at the time of the order. Changing your address later does not rewrite where something was actually sent. An address you enter at checkout is saved as private to you unless we mark it as a shared company address, so a delivery to your home is not exposed to colleagues.

When we deliver services to you as a client

The portal shows information drawn from the systems we run for you. Depending on what you buy from us, that includes:

  • Support tickets you raise, and the contact details on them.
  • Quotes, invoices, sales orders, and pre-paid contract balances, imported from our service desk.
  • Time logged against your contracts, including the engineer and the work described.
  • The status of backup jobs and protected machines, imported from the backup platforms we manage.
  • Files uploaded in either direction, and who uploaded each one.
  • A record of administrative actions taken in your account, so questions about who changed what are answerable.

When you request out-of-hours emergency support

We store what you told us was wrong, a number to call you back on, and the timeline of the response, including who was paged and when they answered. If the callout is chargeable, we also store the figures you agreed to and the charge taken.

3. What we do not do

This is a short list on purpose, because the things on it are the ones people most reasonably assume a website does.

  • We run no analytics. There is no Google Analytics, no tag manager, and no third-party measurement product of any kind on this site. We cannot see which pages you visited or how you got here.
  • We set no advertising or cross-site tracking cookies, and there are no advertising pixels, social tracking scripts, or session recorders anywhere on the site. See our cookie notice for the short list of what we do set.
  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done either, and there is nothing to opt out of.
  • We do not build profiles about you or make automated decisions that have a legal effect on you.
  • We do not use your data to train machine learning models, ours or anybody else's.
  • We do not read the contents of files you upload, beyond checking that the first few bytes match the file type claimed.

4. Why we use it

We use personal information to do the thing you asked us to do, and to run the business behind it. Specifically:

  • To answer an enquiry or prepare a quote.
  • To create and secure your account, and to let you sign in.
  • To take payment, fulfil an order, and send you a receipt.
  • To deliver, support, and bill for the services you buy from us.
  • To send transactional messages you cannot reasonably be asked to opt out of, such as a receipt, an invoice, a password reset, or notice that an engineer has accepted your emergency.
  • To send our writing, if and only if you have confirmed a subscription.
  • To keep the service secure: rate limiting, blocking abuse, and recording administrative actions.
  • To meet our tax, accounting, and legal obligations.

Where the law requires a legal basis to be named, we rely on performing a contract with you, our legitimate interest in running and securing the service, your consent for our mailing list, and compliance with a legal obligation for records we are required to keep.

5. Who else handles it

We use other companies to run parts of the service. Each one only receives what it needs for its own job, and none of them is permitted to use it for their own purposes. This is the complete list of those that can receive personal information.

CompanyWhat it can receiveWhy
Netlify (with Neon as the database provider)Anything stored by the site, because they host it and hold the databaseHosting and data storage
StripeCard details, name, email, billing and delivery address, phone numberTaking payment and holding your saved cards
MicrosoftSign-in identity if you use Microsoft to sign in, and the content of email we send youSingle sign-on, and delivering our email
GoogleSign-in identity, if you choose to sign in with GoogleSingle sign-on
HaloPSAClient and contact details, tickets, quotes, invoices, and contractsOur service desk and billing system
CloudflareFiles uploaded to or shared through the portal, and their filenamesFile storage
Veeam and N-ableThe names and status of protected machines in a managed environmentBackup monitoring and reporting
SolarWindsWhat you reported, and a callback number, when you raise an emergencyPaging the on-call engineer
D&H DistributingRecipient name and delivery address, when hardware ships to you directlyFulfilling a hardware order

We may also disclose information where we are legally required to, where it is necessary to establish or defend a legal claim, or to a buyer if the business is sold. If the business changes hands we will say so on this page before it takes effect.

Every company above is either based in the United States or holds the data there. If you contact us from outside the United States, your information will be handled there.

6. How long we keep it

We keep information for as long as we need it for the purpose it was collected for, and then no longer. In practice:

  • Enquiries and quote requests are kept while the conversation is live and for a reasonable period afterwards, so we can pick it up again if you come back to us.
  • Mailing list records are kept until you unsubscribe. We keep a record that you unsubscribed, so we do not add you again by accident.
  • Your account is kept until you or your administrator deletes it. See section 7.
  • Orders, receipts, and invoices are kept for as long as tax and accounting law requires us to, which is longer than the account itself.
  • Daily storage readings for a backup vault are deleted automatically after 90 days.
  • Files attached to an emergency are deleted automatically 30 days after the emergency is closed.
  • The administrative audit record is kept for as long as the account it belongs to, because it is the record of who changed what.

7. Your choices and your rights

You can ask us to give you a copy of what we hold about you, correct it, delete it, or stop using it. You can also ask us to send it to you in a portable form. We will not charge you for asking and we will not treat you differently for having asked.

Things you can do yourself, right now

  • Change your name, email, or password in your account settings.
  • Delete your account from the same page. This removes the account, its sign-in sessions, and its permissions immediately. Orders and invoices survive it, because we are required to keep those, and they stop being linked to a login.
  • Stop receiving our writing using the unsubscribe link at the foot of every one of those emails. It works without signing in.
  • Choose which non-essential notifications you get in your account settings, if you have a portal account.

Things to ask us for

For anything else, email ContactUs@ClearPathMSP.com and say what you want. We will confirm who you are before acting, because doing otherwise would be its own privacy problem, and we will respond within 45 days.

If you are a California resident, this covers your rights to know, delete, correct, and opt out under the CCPA as amended. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no opt-out to exercise, and we do not use or disclose sensitive personal information beyond what is needed to provide the service. You may use an authorised agent to make a request.

If you are in the United Kingdom or the European Economic Area, you also have the right to object to processing, to restrict it, to withdraw consent at any time, and to complain to your data protection authority. We honour these requests wherever you are, whether or not we are strictly required to.

8. How we protect it

No system is perfectly secure, and anybody who tells you otherwise is selling something. These are the specific measures in place rather than a general reassurance:

  • Every page and every request is served over HTTPS.
  • Passwords are hashed, never stored or logged in readable form, and cannot be recovered by us.
  • Two-step sign-in is available on any account with a password, and its secret and backup codes are held encrypted.
  • Repeated failed sign-ins lock an account briefly, so a password cannot be guessed at leisure.
  • Card details are handled entirely by Stripe and never pass through our systems.
  • The portal separates clients from one another at the database query, not in the page, so one client cannot be shown another's data by a display mistake.
  • Files are always served as downloads and never rendered as pages, so an uploaded file cannot execute in your browser.
  • Each system we integrate with is reached using a credential scoped to the least it needs, under a dedicated account rather than a person's.
  • Administrative actions are recorded, and a member of our staff viewing a client's portal to help them cannot change anything while doing so.

If you believe you have found a security problem with this site, please email ContactUs@ClearPathMSP.com with enough detail to reproduce it. We will acknowledge it and we will not pursue you for reporting it in good faith.

9. Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect personal information from anybody under 16. If you believe a child has given us information, email us and we will delete it.

10. Changes to this policy

If we change what we collect or who handles it, we will update this page and change the date at the top. If the change is significant and affects you, we will tell you directly rather than relying on you noticing. We will not apply a materially different use to information we already hold without asking you first.

Something here unclear, or not what you expected? Email ContactUs@ClearPathMSP.com and a person will answer you.