Privacy notice
What the platform collects, why it is used, and who controls it.
Last updated August 30, 2026. This notice describes the current TAGE Farms Sales Desk service. It is a commercial-launch draft and should be reviewed by qualified privacy counsel before broad public sale.
1. Who controls company data
Each subscribing company controls the customer, sales, manifest, compliance, accounting, product, and team data entered into its private workspace. Authorized company administrators decide who can access that workspace and which state markets and territories are assigned.
2. Data the service handles
- Account and team data, including names, work email addresses, roles, territories, session records, and notification settings.
- Company and regulatory profile data, including business contact information, state license identifiers, and controlled-substance registration identifiers.
- CRM and operations data, including public-license records, customer contacts, call notes, follow-ups, opportunities, orders, pricing, invoices, and payments recorded by the company.
- Uploaded or imported business documents, including manifests, certificates of analysis, forms, labels, and accounting support files.
- Integration and billing data needed to operate read-only Metrc Connect, email, web-push, and Stripe billing. Payment-card data is handled by Stripe rather than stored in the TAGE workspace.
- Technical records used to secure and operate the service, such as request, delivery, sync, audit, and error logs.
3. How data is used
Data is used to authenticate users, isolate company workspaces, operate requested CRM and accounting workflows, import authorized records, generate company documents and reports, deliver requested communications, process subscriptions, secure the service, and diagnose failures. TAGE Farms Sales Desk is not an advertising network and is not designed to sell personal information or use company records for cross-context behavioral advertising.
4. When data is shared
Data may be sent to service providers only as needed to operate requested features, such as Stripe for billing, Resend for transactional email, web-push providers for device notifications, and Metrc for an authorized read-only integration. Data may also be disclosed when required by law, to protect the service or its users, or during a business transaction subject to appropriate safeguards. A company may independently send information to its own customers, accountants, investors, regulators, or other recipients.
5. Security and tenant separation
The service uses company-scoped records, role checks, secure session cookies, protected server configuration, encryption for supported stored credentials and sensitive tax fields, and audit-oriented import and delivery records. No system can guarantee absolute security. Users must protect access codes, email accounts, devices, API credentials, and downloaded files, and should report suspected unauthorized access promptly.
6. Retention and deletion
Business records are retained while a company account is active and as reasonably needed for service operation, security, backup, dispute resolution, and legal obligations. Regulated businesses may have independent record-retention duties. An authorized company administrator may request account export or deletion, subject to required retention and the practical limits of backups and immutable audit evidence.
7. Choices and requests
Users can update many company and profile fields in the service, unsubscribe from eligible marketing notices, revoke browser notifications, and ask their company administrator to correct or remove workspace access. Privacy, access, correction, export, or deletion requests may be sent to jcalvin@2cproduction.com. The requester may need to verify identity and authority over the company workspace.
8. Age and regulated-business use
The service is intended for authorized adults working with licensed businesses. It is not directed to children or consumers purchasing cannabis. Public-license information is provided for business research and must be verified with the responsible regulator before a regulated decision.
9. Changes
This notice may be updated as the service, state coverage, or legal requirements change. Material changes should be communicated through the service or the company contact on file before they take effect when reasonably possible.