Version 1.2 | Last updated: May 2026 | Effective upon acceptance

Your privacy matters. This policy explains what data we collect, why, and what we do with it.

1. Who We Are

Collab Cowboy LLC is a Georgia limited liability company that develops and sells the Collab Cowboy Toolkit, a software product for managing Cisco Unified Communications Manager (CUCM) systems.

  • Website: collabcowboy.net
  • Contact: support@collabcowboy.net
  • Location: Concord, Georgia, USA

2. What We Collect

Information You Provide

  • Name and email address — when you accept our EULA, make a purchase, schedule a demo, request a quote, or contact support
  • Company name and role — associated with your license record or lead record
  • Sizing information — phone counts, cluster counts, and the brief environment description you optionally provide when scheduling a demo or requesting a quote
  • Payment information — processed by Stripe, Inc. We do not store your credit card details.
  • Optional marketing-attribution parameters — UTM tags present in URLs you arrive at the site through

Information Collected Automatically

When the Collab Cowboy Toolkit connects to our licensing server, it transmits:

  • Hardware ID (HWID) — a one-way SHA-256 hash of machine-id + hostname from your server, formatted as 5 groups of 4 hex characters. The original machine-id and hostname cannot be recovered from the hash. Used to bind your license to a specific install.
  • IP address — recorded during license validation
  • Phone count — the aggregate number of phones configured across your CUCM cluster(s), used to enforce tier limits. We see the count, never the phone records themselves.
  • Cluster count — the number of CUCM and Unity Connection clusters configured
  • Tool usage — which tools are accessed (tool names only — anonymized counters, not user-attributed)
  • Software version — the version of the toolkit installed

MSP Licensees — Additional Measurement Data

For customers operating under an MSP license, each Spoke instance reports its local phone count to the MSP’s Hub at regular check-in intervals. The Hub records these check-ins (timestamp + per-Spoke phone count + total pool usage) for the purposes of pool-size compliance and end-of-term true-up calculation, as described in the EULA’s MSP Licensees section. Check-in history is retained for up to 18 months. Customers may request a copy of their own check-in history at any time.

What We Do NOT Collect

We do NOT access, collect, transmit, or store any data from your Cisco CUCM, Unity Connection, or Expressway systems. All interactions between the toolkit and your Cisco systems occur locally on your server. We never see phone numbers, user names, configurations, call data, voicemails, or any other data stored in your Cisco systems. The metadata above (phone count, cluster count, tool names) is the complete list — there is no record-level CUCM/Unity content in our pipeline.

We Do NOT Use Your Data for AI Training

We do not use Licensee data, configurations, telemetry, or any information collected through the Software or our website to train machine-learning or artificial-intelligence models. We do not share such data with third parties for that purpose.

What the Toolkit Stores on YOUR Server

The toolkit runs entirely on a virtual machine you control. The only data it persists on that VM is:

  • CUCM and Unity connection details you configure in the Admin panel — hostname, application user, password (encrypted at rest with a per-installation encryption key)
  • Toolkit user accounts you create — username, hashed password (PBKDF2), per-tool permissions, MFA secret if enabled (encrypted at rest)
  • Audit log — administrative actions and tool writes, retained for 365 days on the VM
  • Per-tool transient caches — phone caches, DID inventory caches, Bloodhound CDR cache. These are operational scratch space; they are local to your VM, never transmitted off it
  • Backups you create — encrypted .ccbak files you choose to download (the toolkit does not upload these anywhere)

We have no remote access to this data. It lives entirely on your VM, under your network, behind your firewall. If you destroy the VM, all of it goes with it.

3. How We Use Your Data

  • License enforcement — verifying your license is valid and within tier limits, including MSP pool-usage measurement
  • Product improvement — understanding which tools are used and how
  • Customer support — responding to your questions and troubleshooting issues
  • Billing and renewals — processing payments, sending renewal reminders, calculating MSP true-ups
  • Security — detecting unauthorized use or license circumvention

4. Who We Share Data With

We do not sell your data. We share data only with:

  • Stripe, Inc. — payment processing (Stripe Privacy Policy)
  • Law enforcement — only if required by law, subpoena, or court order
  • No one else.

We do not share your data with any AI/ML model provider, advertising network, or data broker.

5. Data Retention

  • License records — retained indefinitely so you can renew or transfer the license at any time, even after a long lapse. Hashed HWID, your name and email, purchase history, and license status are all kept until you ask us to delete them.
  • Payment records — retained as required by tax and accounting law (typically seven years).
  • Usage data (HWID, IP, tool counters) — retained for up to 2 years for product improvement, then aggregated or deleted.
  • MSP Spoke check-in history — retained for up to 18 months to support pool-usage compliance and true-up calculation.
  • Support communications — retained for up to 2 years after last contact.
  • In-app feedback submissions — retained until acted upon, then archived per our internal ticketing system.
  • Lead pipeline data (quote requests, demo requests, trial signups) — retained for up to 2 years after last contact for sales-pipeline continuity, then deleted on request.

6. Data Security

We protect your data using:

  • Per-installation encryption keys
  • PBKDF2 password hashing
  • CSRF protection
  • Rate limiting
  • Audit logging
  • HTTPS for all data transmission

No system is 100% secure. We take reasonable measures to protect your data but cannot guarantee absolute security.

7. Your Rights — Including GDPR and CCPA

You have the right to:

  • Access — request a copy of the data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your data (subject to legal retention requirements)
  • Portability — request your data in a portable format
  • Restrict processing — request that we limit how we process your data
  • Object to processing — object to processing based on legitimate interests
  • Non-discrimination — exercise these rights without being penalized for doing so

These rights are available under the EU General Data Protection Regulation (GDPR) to EU residents and under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) to California residents. They are also extended on request to all customers regardless of jurisdiction.

Data Processing Addendum (DPA): customers operating in jurisdictions that require a written DPA may request our standard DPA template by emailing support@collabcowboy.net. We will respond within 30 days.

To exercise any of these rights, contact support@collabcowboy.net. We will respond within 30 days. We will not sell your personal information, and you do not need to opt out of a sale we do not conduct.

8. Cookies and Website Analytics

Our website (collabcowboy.net) uses:

  • Essential cookies — for site functionality and login sessions
  • First-party analytics cookie (cc_v) — a randomly generated visitor ID stored for 30 days, used only to count unique visitors and link pageviews within a single browsing session. SameSite=Lax, not shared with any third party.
  • We do not use advertising, retargeting, or third-party tracking cookies.

First-Party Website Analytics

We run our own lightweight analytics directly on collabcowboy.net — no Google Analytics, no Facebook Pixel, no third-party trackers. For each pageview we record:

  • The page path visited and the referring URL
  • A short user-agent string (browser/OS family only)
  • Your IP address, immediately one-way hashed (SHA-256) with a secret salt unique to our installation. The salt is never logged or transmitted, and the original IP address is never written to disk. The resulting hash cannot be reversed to recover your IP.
  • The first-party cc_v cookie described above
  • UTM campaign parameters if present in the URL
  • Approximate time spent on the page

We use this data only to understand which pages are useful, where visitors come from, and to improve the site. Logged-in admin sessions and visits to /wp-admin are excluded. Raw pageview rows are automatically deleted after 90 days; only anonymous daily totals are kept longer. You can opt out at any time — visit collabcowboy.net and click “Don’t track me” in the site footer to set a permanent opt-out cookie on your browser.

9. Children’s Privacy

Our software is a professional enterprise tool. We do not knowingly collect data from anyone under 16 years of age.

10. International Transfers

Data is stored on servers in the United States. If you access the software or website from outside the United States, your data will be transferred to, processed in, and stored in the United States. By using the software or website, you consent to this transfer. EU/UK customers requesting a DPA will receive Standard Contractual Clauses (SCC) language as part of the DPA template.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be posted on this page with an updated “Last updated” date and version number. Continued use of the software after changes constitutes acceptance.

12. Contact

Questions about this privacy policy? support@collabcowboy.net

Collab Cowboy LLC | Concord, Georgia, USA | collabcowboy.net