My Command Center
Privacy Policy
1. Introduction
My Command Center, LLC (“MCC,” “we,” “us”) provides an AI-powered business operations platform. This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you.
This Policy covers our website, our web application, and our mobile applications for iOS and Android (each, an “App”), together the Services. It does not cover third-party services you connect to the Services, which are governed by their own policies.
A note on our affiliates. MCC is affiliated with National Crime Search, LLC (“NCS”), a consumer reporting agency providing background screening, and NCSPays, LLC (“NCSPays”), a merchant services provider. These are separate companies under common brand and partial common ownership. Section 6 explains how information is shared among them.
2. Information We Collect
2.1 Information you provide.
- Account and contact information — name, business name, email, phone, billing address.
- Billing information — billing contact details and the payment details you provide. Where a third-party payment processor handles payment details on our behalf, it is listed on our Subprocessors page. We do not store full payment card numbers.
- Customer Data — documents, records, policies, messages, workflows, prompts, and other content you or your users submit to the Services, including through connected integrations.
- Support and communications — messages you send us and, if you call us, recordings and transcripts of the call.
2.2 Information collected automatically.
- Usage data — features accessed, actions taken, agent and workflow activity, timestamps.
- Device and log data — IP address, browser type, operating system, referring pages, error logs.
- Cookies and similar technologies — see Section 10.
2.3 Information collected through our mobile applications.
Accounts cannot be created through an App — you sign in to an account created on the web. When you use an App, our servers receive the same account, usage, and log information described above. The App may include our analytics software to measure usage and diagnose problems, as described in Section 10. It does not include advertising software, does not read advertising identifiers, and does not collect your location. Apple or Google may share crash and usage diagnostics with us if you have chosen to share analytics with app developers in your device settings.
Information available only with your permission. Depending on the features you use and the permissions you grant, the App may access:
- Camera and photo library — to capture or upload documents and images (for example, business cards) to your account. Captured images are uploaded to our servers and may be read by AI features to extract text.
- Microphone and speech recognition — to dictate notes. Where your device supports it, speech is transcribed on your device; on devices that do not, Apple’s speech recognition service may process the audio. Only the resulting text is sent to us. We do not receive audio recordings.
- Biometric authentication — Face ID, Touch ID, or your device passcode, to unlock the App. Biometric data is processed by your device and is never transmitted to or stored by us.
- Notifications — notifications currently appear within the App only. If we add push notifications, we will collect a push notification token so we can deliver them.
- Files, storage, and location — only where a feature you use requires it. The App does not currently request these permissions.
Your sign-in credentials are stored in your device’s secure keychain and are removed when you sign out. You control these permissions and can grant or revoke them at any time in your device settings. Declining a permission may limit the related feature but will not prevent you from using the App generally.
Tracking. We do not track you across other companies’ apps or websites, and we do not share your information with data brokers or for cross-app advertising.
2.4 Information from third parties and integrations. When you authorize an integration, we receive data from that system as configured by you — for example, calendar events, email content, documents, customer records, transaction data, or communications.
Some platforms impose their own requirements on how their data may be used, stored, and deleted. For those integrations we publish a short data notice describing what we receive, how we use and store it, and how to disconnect and delete it, at /integrations/data-notices. Those notices are incorporated into this Policy by reference and are shown to you when you connect the integration. Where we receive information from Google APIs, our use and transfer of that information adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2.5 Background screening information. Where you use background screening through the Services, information relating to screening orders and results is handled by NCS as a consumer reporting agency and is subject to the Fair Credit Reporting Act (“FCRA”) and NCS’s own privacy practices. See Section 7.
3. How We Use Information
We use information to:
- provide, operate, maintain, and secure the Services;
- create and provision accounts, authenticate users, and process transactions;
- generate AI Output, run agents, and execute workflows you configure;
- provide support and respond to requests;
- monitor performance, detect abuse, and prevent fraud;
- comply with legal obligations and enforce our Terms;
- communicate about the Services, including service notices and, where permitted, marketing; and
- analyze usage in aggregated or de-identified form to improve the Services.
We do not sell personal information.
4. AI Processing and Service Providers
4.1 How AI processing works. To provide AI features, we transmit relevant portions of Customer Data to artificial intelligence model providers, which process it and return Output. Processing may occur on infrastructure operated by those providers.
4.2 Our providers change over time. We use a range of AI model providers, cloud infrastructure, integration middleware, communications, analytics, and payment providers. Because our provider mix evolves, we maintain a current list of subprocessors at /subprocessors, which is incorporated into this Policy by reference. We update that page when our providers change and encourage you to review it periodically.
4.3 Model training. We do not use Customer Data to train foundation models, and we contractually require our AI providers not to use Customer Data submitted through the Services to train their models.
4.4 Review for support, quality, and safety. We access and review Customer Data and AI conversations — including through automated and AI-assisted tools — to provide support, troubleshoot, monitor and improve quality and safety, refine agent configurations and workflows, detect abuse, and comply with law. Access is limited to authorized personnel on a need-to-know basis and is logged. We may derive aggregated and de-identified insights from this review to improve the Services.
4.4.1 Data from connected platforms. Where information reaches the Services through an integration whose provider imposes stricter handling requirements — such as Google, LinkedIn, or Meta — those requirements govern and override Section 4.4 for that information. We access such information only (a) with your affirmative agreement to view specific items, (b) as necessary for security, abuse prevention, or legal compliance, or (c) in aggregated or de-identified form for internal operations. We do not review it to improve the Services, refine agent configurations, or develop features. The data notices described in Section 2.4 identify these platforms.
4.5 Your control. You determine what data is submitted to the Services and which integrations are connected. You may disconnect an integration at any time.
5. How We Share Information
We share information with:
- Service providers and subprocessors — as described in Section 4 and listed at /subprocessors.
- Integrations you authorize — data is transmitted to those systems at your direction.
- Our affiliates — as described in Section 6.
- App store platforms — where you obtain an App, Apple or Google may receive information about your download and use of the App under their own privacy policies. We do not control their processing.
- Professional advisors — auditors, accountants, and lawyers under confidentiality.
- Legal and safety — where required by law, subpoena, or legal process, or to protect rights, safety, or property.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or notice of any material change.
6. Sharing With Our Affiliates
MCC, NCS, and NCSPays operate under a shared brand and offer complementary services.
6.1 How the relationship works. MCC provides technology that powers certain features made available through NCS’s own platform. If you are using those features within an NCS product, MCC is acting as a service provider to NCS, and NCS’s privacy policy governs that use.
This Privacy Policy applies to you when you create your own My Command Center account — for example, when you sign in at our application, set a password, and accept our Terms of Use. At that point, MCC provides the Services to you directly and this Policy governs.
6.2 Transition of existing information. If you previously used MCC-powered features through an NCS product and then create your own MCC account, information associated with that prior use — including configuration, history, and content — may be made available in your MCC account so that your experience continues without interruption. From that point forward, that information is handled under this Policy.
6.3 What is shared among affiliates. Account, contact, and business information may be shared among MCC, NCS, and NCSPays to authenticate users, provision and support the combined services, process transactions, and administer billing and commissions between the companies.
6.4 Limits on consumer report information. Information that constitutes a consumer report or consumer report information under the FCRA is not shared among affiliates except as permitted by the FCRA and applicable law. See Section 7.
6.5 Marketing. We and our affiliates may market our respective products and services to you, including marketing NCS and NCSPays services within the Services and to MCC customers. Where information shared by an affiliate would be used to market to you and applicable law requires notice and an opportunity to opt out — including the FCRA affiliate marketing rule — we provide it.
To opt out of marketing based on information shared by our affiliates, email support@mycommandcenter.com. Opting out does not affect service-related communications about your account.
7. Background Screening and the FCRA
Background screening is provided by NCS, a consumer reporting agency. Consumer reports are governed by the FCRA and applicable state law. MCC is not a consumer reporting agency and is not the end user of any consumer report — MCC provides the interface through which our customers order screening and view results from NCS, acting at the customer’s direction.
- If you are an employer or other user of screening services, you are responsible for certifying a permissible purpose, obtaining required disclosures and authorizations, and following adverse action procedures.
- If you are a subject of a background check, you have rights under the FCRA, including the right to obtain a copy of your report and to dispute inaccurate information. Those rights are administered by NCS, which can be reached at support@nationalcrimesearch.com or 888-427-3282.
8. Financial Account Connections
If you choose to connect a financial account, we use Plaid Inc. (“Plaid”) to establish and maintain that connection. Your banking credentials are entered directly with Plaid or your financial institution and are never seen or stored by MCC.
What we receive. We request Plaid’s Transactions product for the accounts you choose to share. We receive account name, the last four digits of the account number, account type, balances, credit limit where applicable, currency, and your financial institution’s name — together with recent transaction records (date, description, amount, and pending status). Plaid’s transaction records may include additional details, such as a spending category or location; we discard those on receipt. The specific period is described in Plaid’s authorization screen when you connect.
What we do not request or keep. We do not request your account or routing numbers, or your name, address, phone, or email from your financial institution. Plaid’s disclosure screen lists “contact details” alongside its Transactions product; we do not use that category, and any account-holder name that appears in a transaction record is discarded on receipt. We do not receive income, employment, or consumer-reporting information. If you share an investment or loan account, we receive only its name, type, last four digits, and balances, not holdings, interest rates, or payment details. We do not move money.
How we use it. Solely to display and calculate the figures in your dashboard and to support that feature.
How we store it. We retain summary values derived from your account and transaction information, such as balances and period totals, in order to display figures and trends, together with your institution’s name and the name, type, and last four digits of each connected account. Individual transaction records are held only temporarily in memory while your figures are calculated and are not written to our database. The credential maintaining your connection is stored encrypted.
AI features. We do not send your account details or individual transactions to any AI model provider. AI features may read the aggregate figures shown on your dashboard (for example, a total cash balance) and their history, but not your accounts or transactions. We do not sell this information.
It is personal to you. A connection is visible only to the individual who created it and is never shared with your organization, its owner, or its administrators.
Your control. You choose which accounts are included and can change that at any time. Disconnecting revokes our access at Plaid — a real revocation, not just a local deletion. You may also request deletion by emailing support@mycommandcenter.com, and we will delete promptly on request, except where retention is required by law.
Plaid’s own practices. Plaid processes this information as our service provider, and its handling of your information is governed by Plaid’s End User Privacy Policy at https://plaid.com/legal/#end-user-privacy-policy.
Not a consumer report. Information obtained through this feature is not a consumer report and may not be used for credit, lending, employment, tenancy, or insurance decisions. See Schedule 3 of our Terms of Use.
9. Data Retention
We retain information for as long as your account is active and as necessary to provide the Services, and thereafter as required for legal, tax, accounting, audit, dispute-resolution, and security purposes. Customer Data may persist in backups for a limited period after deletion. Consumer report information is retained by NCS in accordance with its own retention practices and applicable law.
Where a connected platform requires us to delete or stop caching its data within a fixed period, or on a member’s request, that requirement governs regardless of your account status. For such platforms we hold content only as long as needed to display it to you or complete the action you requested, and retain only aggregate figures, our own records of actions you took, and the identifiers and credentials needed to maintain the connection.
10. Cookies and Analytics
We use cookies and browser storage to keep you signed in, remember your preferences, secure the Services, and hold a referral or promotion code for up to 30 days so it can be applied when you sign up.
We use first-party analytics on our website and within the Services to understand how they are used and to improve them. This includes recording how visitors and users interact with pages, such as clicks, scrolling, and navigation. Text you type and information displayed in the Services are masked before any recording leaves your browser. The providers we use are listed on our Subprocessors page.
We do not use advertising cookies, we do not track you across other companies’ sites, and we do not sell your information.
You can control cookies and clear stored data through your browser settings. Clearing the application’s storage signs you out. We do not currently display a cookie banner; where the law requires consent for analytics, we obtain it.
11. Security
We maintain commercially reasonable technical and organizational safeguards designed to protect information, including encryption in transit and at rest, access controls, and monitoring. No system is completely secure, and we cannot guarantee absolute security. Notify us immediately at support@mycommandcenter.com if you believe your account has been compromised.
12. Your Rights and Choices
- Access and correction — you may access and update account information in the Services.
- Deletion — you may delete Customer Data through the Services. You may also delete your own user account from within the Services (including from within an App) or by emailing support@mycommandcenter.com. Deleting your user account removes your profile and personal information and ends your access. Information that belongs to the Customer’s workspace — such as documents, conversations, and records created for the business — remains with the Customer. Only the Customer’s owner may request deletion of the workspace itself, by contacting support@mycommandcenter.com.
- Device permissions — you may grant or revoke App permissions at any time in your device settings, and uninstalling an App stops further collection through it.
- Marketing communications — you may opt out using the unsubscribe link or by contacting us. We will still send service-related messages.
- Integrations — you may disconnect at any time.
- State privacy rights — depending on your state of residence, you may have additional rights to access, correct, delete, or obtain a copy of personal information, and to appeal a denial.
To exercise these rights, contact support@mycommandcenter.com. We may need to verify your identity.
13. Children
The Services are not directed to individuals under 18, and we do not knowingly collect personal information from them. If we learn we have, we will delete it.
14. If You Are in the European Economic Area or United Kingdom
We operate from the United States, and information you provide is processed there.
Why we’re allowed to use your information. We rely on one of the following, depending on the situation:
- To provide what you asked for — we need your information to deliver the Services under our agreement with you.
- Our legitimate interests — to keep the Services secure, prevent abuse, provide support, and improve how they work, where that doesn’t override your rights.
- Your consent — where we ask for it, such as for certain cookies or marketing. You can withdraw consent at any time.
- Legal obligations — where the law requires us to keep or disclose information.
Automated decision-making. We don’t use AI to make decisions about people. Our AI features produce suggestions, drafts, summaries, and analyses; a person reviews them and decides. This includes background screening — results are surfaced to our customer, who makes any hiring or eligibility decision. We do not make decisions about any individual, including any person who is the subject of a background check, based solely on automated processing that produces legal effects or similarly significantly affects them. Where a customer configures agents or workflows to take actions automatically, that customer controls the configuration and remains responsible for the results.
Your rights. You can ask us to:
- give you a copy of the personal information we hold about you;
- correct information that is wrong;
- delete your information;
- limit how we use it;
- stop using it for a particular purpose;
- send your information to another provider in a usable format; or
- stop sending you marketing.
To make a request, email support@mycommandcenter.com. We’ll respond within one month.
If you’re not satisfied with how we’ve handled your request, please contact us so we can try to resolve it. You also have the right to lodge a complaint with your local data protection authority.
Sending information to the United States. Because we operate in the U.S., using our Services means your information is transferred there. Where required, we use Standard Contractual Clauses approved by the European Commission, together with appropriate security measures, to protect it.
When you’re our customer’s user. If your employer or another business uses our Services and your information is in their account, they decide how that information is used. We process it on their instructions. Contact them first for requests about that information, and we’ll assist them.
Data breaches. If a breach affects your personal information, we will notify the relevant authority and, where required, you, without undue delay.
15. Changes to This Policy
We may update this Policy. We will post the updated Policy with a revised “Last updated” date and, for material changes, provide reasonable notice.
16. Contact Us
My Command Center, LLC 3452 E Joyce Blvd, Fayetteville, AR 72703 support@mycommandcenter.com