Privacy Policy
Thought Leader System Privacy Policy
Last updated: August 27, 2026
Thought Leader System (“Thought Leader System,” “TLS,” the “Platform,” or the “Services”) is a software platform and related service provided by Rock Ridge Media LLC (“RRM,” “we,” “us,” or “our”).
This Privacy Policy explains how RRM collects, uses, discloses, stores, and protects personal information in connection with TLS, including our websites, applications, communications, customer support, marketing activities, and other related services.
This Privacy Policy also explains the distinction between information RRM collects for its own business purposes and information that TLS customers collect, store, or process through the Platform.
By accessing or using the Services, you acknowledge the practices described in this Privacy Policy.
Our Terms of Service govern use of TLS and should be reviewed together with this Privacy Policy.
1. Scope of This Privacy Policy
This Privacy Policy applies to personal information RRM processes in connection with:
visitors to RRM- or TLS-operated websites and marketing pages;
prospective customers;
TLS customers;
Authorized Users of customer Accounts;
people who communicate directly with RRM;
people who receive communications sent directly by RRM;
purchasers of TLS subscriptions, products, or services; and
individuals whose information is otherwise processed by RRM for RRM's own business purposes.
TLS customers may also use the Platform to collect and process information relating to their own leads, contacts, customers, clients, members, students, subscribers, registrants, purchasers, community participants, and other individuals (“End Users”).
When RRM processes that information solely on behalf of a TLS customer, the customer generally determines why the information is being collected and how it will be used. In those circumstances, the customer's own privacy policy and practices apply to its relationship with the End User, subject to applicable law.
This Privacy Policy does not replace the privacy policy, notices, disclosures, or consent obligations of a TLS customer.
2. Definitions
For purposes of this Privacy Policy:
“Account” means a customer account established to access TLS.
“Authorized User” means an owner, employee, contractor, team member, or other person authorized by a Customer to access its Account.
“Customer” means the person or business that purchases, subscribes to, or controls an Account.
“Customer Content” means content, materials, files, text, images, video, audio, documents, community posts, course materials, communications, prompts, forms, templates, and other materials submitted to or created through TLS by or on behalf of Customer.
“Customer Data” means information Customer or its Authorized Users submit to, collect through, store within, or process using TLS, including information concerning Customer's End Users.
“End User” means a person who interacts with a Customer through the Services, including a lead, contact, customer, client, member, student, subscriber, registrant, purchaser, community participant, or communications recipient.
“Personal Information” means information that identifies, relates to, describes, can reasonably be associated with, or can reasonably be linked to an identifiable individual, to the extent that definition applies under applicable privacy law.
“Third-Party Service” means a service, platform, application, API, telecommunications provider, payment processor, hosting provider, artificial-intelligence provider, analytics provider, advertising provider, or other third-party product or service used by, connected to, or integrated with TLS.
3. Information We Collect
The information we collect depends upon how a person interacts with TLS and whether RRM is processing the information for its own purposes or on behalf of a Customer.
3.1 Account and Contact Information
We may collect information such as:
name;
business name;
email address;
telephone number;
mailing or business address;
Account username or identifier;
job title or business role;
Account preferences; and
other information supplied when creating or maintaining an Account.
3.2 Billing and Transaction Information
When a Customer purchases TLS or another RRM service, we may collect information relating to:
subscription plan;
purchases;
invoices;
payment status;
billing history;
refunds;
chargebacks;
transaction identifiers; and
limited payment-method information supplied by payment processors.
Complete payment-card information may be collected directly by a Third-Party Service rather than by RRM.
3.3 Customer Data
Customers may submit, import, create, collect, or process information through TLS, including:
CRM records;
names and contact details;
customer and lead records;
membership information;
course participation information;
webinar registrations;
appointments;
forms;
surveys;
quizzes;
purchases;
communications;
notes;
tags;
custom fields;
consent records;
community activity;
uploaded files;
images;
audio and video;
recordings;
transcripts;
Customer Content;
marketing information; and
other information configured or collected by Customer.
The nature of Customer Data is primarily determined by Customer.
3.4 Communications
We may collect communications and related information when a person:
contacts customer support;
sends us email;
calls us;
communicates with us by SMS or another messaging system;
submits feedback;
participates in onboarding;
requests assistance; or
otherwise communicates with RRM.
These records may include the contents of communications, attachments, timestamps, telephone numbers, email addresses, and support history.
3.5 Artificial Intelligence and Automated Processing Information
When AI Features are used, information processed may include:
prompts;
instructions;
Customer Content;
Customer Data selected for processing;
uploaded materials;
knowledge-base content;
audio;
video;
recordings;
transcripts;
generated drafts;
generated images or other media;
AI-generated output; and
contextual information reasonably necessary to perform the requested function.
3.6 Technical and Usage Information
We and our service providers may automatically collect information such as:
Internet Protocol address;
browser type;
device type;
operating system;
device identifiers;
session identifiers;
approximate geographic location derived from an IP address;
referring page or website;
pages or features viewed;
links clicked;
dates and times of activity;
authentication activity;
log information;
error and diagnostic information;
feature usage;
storage or resource usage;
communications delivery information; and
other information concerning interaction with the Services.
3.7 Information From Integrations
When a Customer connects a Third-Party Service to TLS, RRM may receive or transmit information necessary to establish and operate that integration.
The information involved depends upon the integration and permissions granted by Customer.
3.8 Marketing and Advertising Information
When a person visits RRM- or TLS-operated websites or marketing pages, we may collect information relating to:
advertisements viewed;
pages visited;
marketing campaigns;
referral sources;
conversion activity;
interactions with advertisements or marketing pages;
device and browser identifiers; and
other information used to measure or improve advertising and marketing.
4. Sources of Information
We may receive Personal Information:
directly from the individual;
from a Customer or Authorized User;
through use of TLS;
through forms, websites, communities, courses, webinars, and other Customer-configured functionality;
automatically through cookies and similar technologies;
from payment processors;
from telecommunications or communications providers;
from integrations selected by Customer;
from analytics and advertising providers;
from publicly available sources;
from vendors and service providers; and
where permitted by law, from other legitimate business sources.
5. How We Use Information
RRM may use Personal Information for purposes reasonably related to operating TLS and conducting our business, including to:
create and administer Accounts;
authenticate users;
provide the Services;
operate CRM functionality;
operate communities, courses, webinars, memberships, forms, quizzes, surveys, calendars, and other Platform features;
process Customer-directed automations;
transmit Customer-directed communications;
provide AI, transcription, voice, and content-generation features;
process payments and maintain billing records;
provide customer service and technical support;
communicate about Accounts, subscriptions, transactions, security, and service changes;
provide onboarding and implementation assistance;
maintain, diagnose, troubleshoot, and improve the Platform;
measure Platform usage and performance;
maintain security;
detect and prevent fraud, misuse, spam, abuse, and unauthorized access;
enforce our Terms of Service and other agreements;
maintain appropriate business and financial records;
comply with applicable law and lawful legal process;
establish, exercise, or defend legal rights;
analyze marketing effectiveness;
advertise and market TLS;
personalize website or marketing experiences;
develop and plan Platform features and capacity; and
carry out other purposes reasonably disclosed at the time information is collected.
6. Customer Data and Our Role as a Service Provider
As between Customer and RRM, Customer retains its rights in Customer Data and Customer Content.
Customer determines the purposes for which Customer collects and uses Personal Information relating to its End Users.
When RRM processes Personal Information contained in Customer Data solely to provide TLS to Customer, RRM acts as Customer's service provider, processor, contractor, or comparable role to the extent those terms are defined by applicable privacy law.
RRM may process Customer Data as reasonably necessary to:
host, store, retrieve, organize, and back up data;
provide CRM and contact-management functionality;
transmit Customer-directed communications;
operate Customer-configured communities, courses, forms, webinars, memberships, automations, and other features;
provide Customer-requested AI or transcription functions;
provide Customer-requested integrations;
provide support;
maintain security and reliability;
detect or investigate fraud, abuse, or technical problems;
comply with lawful obligations; and
carry out Customer's lawful instructions consistent with the Services.
RRM does not sell Customer Data.
When RRM acts as Customer's service provider, processor, or contractor, RRM does not use Customer Data for cross-context behavioral advertising or unrelated commercial purposes except as permitted by applicable law.
Customer is responsible for:
having a lawful basis to collect and process its Customer Data;
providing privacy notices required for its own End Users;
obtaining required permissions and consents;
responding to applicable privacy requests;
complying with communications and marketing laws;
determining what information is appropriate to collect; and
configuring TLS consistently with Customer's obligations.
7. Cookies, Analytics, Advertising, and Similar Technologies
RRM and its service providers may use cookies, pixels, tags, scripts, software-development kits, local storage, and similar technologies on RRM- or TLS-operated websites and services.
These technologies may be used to:
keep users signed in;
maintain sessions;
remember preferences;
provide security;
prevent fraud;
measure website and Platform performance;
diagnose technical problems;
understand website traffic and user behavior;
measure marketing performance;
identify referral sources;
measure advertising conversions;
personalize marketing;
create or measure advertising audiences; and
provide interest-based or targeted advertising.
We may use services provided by companies such as advertising networks, social-media platforms, search engines, and analytics providers.
Information disclosed through advertising technologies may include identifiers, browser or device information, IP address, pages viewed, interactions, referral information, and advertising or conversion activity.
RRM does not sell Personal Information in exchange for money.
However, certain privacy laws may define the disclosure of Personal Information to advertising or analytics providers as a “sale,” “sharing,” or use for “targeted advertising” even where no money is exchanged.
Where applicable law provides a right to opt out of such activity, RRM will provide or honor applicable privacy choices as required by law.
Where required by applicable law, RRM will also honor legally recognized browser-based opt-out preference signals, such as Global Privacy Control.
Users may also control certain cookies through browser settings or privacy controls made available on our websites. Blocking or disabling some technologies may interfere with website or Platform functionality.
The advertising practices described in this Section relate to RRM's own websites, audiences, and marketing activities.
RRM does not use Customer Data stored within a Customer's TLS Account for RRM's cross-context behavioral advertising.
A Customer may independently choose to connect advertising platforms or transmit its own Customer Data to advertising services through TLS. Such activity is performed at Customer's direction and is governed by Customer's obligations and the applicable Third-Party Service's terms and privacy practices.
8. How We Disclose Information
RRM may disclose information to third parties when reasonably necessary for legitimate business or legal purposes.
8.1 Service Providers and Subprocessors
We may disclose or make information available to providers that assist with services such as:
cloud hosting;
databases and storage;
content delivery;
authentication;
cybersecurity;
communications;
email delivery;
SMS and MMS;
telephone and voice services;
transcription;
artificial intelligence;
payment processing;
analytics;
website hosting;
advertising;
customer support;
error monitoring;
software infrastructure; and
other functionality reasonably necessary to operate TLS.
Where required by applicable law, subprocessors processing Personal Information on our behalf will be subject to appropriate contractual privacy, security, confidentiality, and data-processing obligations.
8.2 Customer-Directed Integrations
If Customer enables an integration or directs TLS to interact with a Third-Party Service, we may transmit information to or receive information from that service as reasonably necessary to perform Customer's request.
8.3 Legal and Safety Reasons
We may disclose information when we reasonably believe disclosure is necessary to:
comply with law;
respond to a subpoena, court order, warrant, or other lawful process;
respond to a lawful governmental request;
enforce agreements;
investigate fraud or abuse;
protect the security or integrity of TLS;
protect RRM, Customers, End Users, or third parties;
establish or defend legal claims; or
prevent reasonably suspected unlawful activity.
8.4 Corporate Transactions
Information may be disclosed or transferred in connection with an actual or proposed:
merger;
acquisition;
financing;
reorganization;
sale of assets;
sale or transfer of the TLS business; or
similar corporate transaction.
Any successor receiving Personal Information remains subject to applicable legal obligations concerning that information.
9. Artificial Intelligence and Customer Data
TLS may use third-party artificial-intelligence providers to provide AI Features.
Information submitted to an AI Feature may be transmitted to a Third-Party Service as reasonably necessary to perform the Customer-requested function.
RRM does not use Customer Content, Customer Data, Customer prompts, or Customer communications to train generalized artificial-intelligence models for RRM's unrelated purposes.
For third-party AI providers selected or configured by RRM, RRM makes good-faith efforts, including through available vendor settings, contractual restrictions, or provider terms where reasonably appropriate, to prevent Customer Content and Customer Data submitted through TLS from being used to train generalized AI models for the provider's unrelated purposes.
RRM cannot guarantee that an independent third-party provider will never violate its own commitments, contractual obligations, security obligations, privacy policies, or applicable law.
AI providers may process and temporarily retain information as reasonably necessary to:
provide requested functionality;
prevent fraud or abuse;
maintain security;
diagnose technical issues; or
comply with legal obligations.
When Customer independently chooses, connects, or enables a third-party AI provider, that provider's own terms and privacy practices may apply.
10. Aggregated and De-Identified Information
RRM may create or use aggregated or de-identified information that does not reasonably identify a Customer or End User.
Such information may be used to:
operate TLS;
analyze usage;
measure performance;
improve reliability;
diagnose technical issues;
prevent abuse;
plan capacity;
understand general usage patterns; and
improve or develop Platform functionality.
RRM will not attempt to re-identify de-identified information except where reasonably necessary for security, fraud prevention, abuse investigation, or another purpose permitted by applicable law.
11. Email and Other Direct Communications From RRM
RRM may send transactional or service-related communications concerning:
Accounts;
purchases;
subscriptions;
billing;
security;
support;
service availability;
policy changes;
Account activity; and
other matters reasonably related to the Services.
Where permitted by law, RRM may also send marketing or promotional email.
Recipients may opt out of marketing email by using the unsubscribe mechanism contained in the message or by contacting us.
Opting out of marketing communications does not prevent RRM from sending transactional, security, billing, support, or other non-marketing communications reasonably necessary to administer an Account or provide the Services.
12. Important Notices Regarding SMS and MMS Messaging
TLS may facilitate SMS and MMS messaging both on behalf of RRM and on behalf of Customers.
12.1 Messages Sent by RRM
When a person provides a mobile telephone number and consents to receive SMS or MMS messages directly from RRM, RRM may send communications such as:
Account notifications;
appointment information;
support communications;
service updates;
reminders;
offers;
promotions; and
other messages consistent with the consent provided.
Message frequency varies.
Message and data rates may apply.
Consent to receive promotional text messages is not a condition of purchasing TLS unless expressly permitted by applicable law.
Recipients may opt out of RRM marketing SMS communications at any time by replying STOP or using another opt-out method provided in the message.
Where supported, recipients may reply HELP for assistance.
RRM may maintain records of opt-in, opt-out, and consent activity, including timestamps and related information.
12.2 Protection of Mobile Opt-In Information
RRM does not sell or provide mobile telephone numbers, SMS opt-in information, or messaging consent records to third parties or affiliates for their own marketing or promotional purposes.
SMS consent is specific to the person or entity to whom the consent was provided and is not automatically transferable to another business.
RRM may disclose mobile information to telecommunications providers, messaging vendors, subcontractors, and other service providers as reasonably necessary to operate and support the messaging program.
Such disclosures do not authorize those providers to use the information for their own unrelated marketing purposes.
12.3 Messages Sent by TLS Customers
Customers may use TLS to send SMS, MMS, telephone, or other communications to their own End Users.
When Customer directs such communications, Customer, not RRM, is the sender, advertiser, caller, or initiator of the communication, except where RRM expressly communicates on its own behalf.
Customer is responsible for:
obtaining legally sufficient consent where required;
maintaining evidence of consent;
honoring revocations and opt-outs;
complying with the Telephone Consumer Protection Act and other applicable laws;
complying with carrier requirements;
complying with do-not-call requirements;
complying with calling-hour restrictions;
complying with artificial or prerecorded voice requirements; and
maintaining appropriate privacy notices.
The fact that a telephone number is stored within TLS does not establish consent to contact that person.
The fact that TLS can technically transmit a message does not mean the message is legally permitted.
13. Payment Information
RRM uses Third-Party Services to process payments.
Payment providers may directly collect information such as:
payment-card numbers;
bank information;
billing addresses;
transaction information; and
other information necessary to process a payment.
RRM generally does not independently receive or store complete payment-card numbers submitted directly to a payment processor.
Payment processors process information under their own terms and privacy practices.
Customers may also connect their own payment-processing accounts to TLS for transactions between Customer and its End Users.
For Customer sales conducted through Customer-connected payment providers, Customer is responsible for its own transactions and privacy obligations.
14. Data Retention and Deletion
RRM retains Personal Information for periods reasonably necessary to:
provide the Services;
maintain Accounts;
fulfill the purpose for which information was collected;
comply with legal obligations;
maintain financial and transaction records;
resolve disputes;
prevent fraud or abuse;
maintain security;
enforce agreements; and
satisfy legitimate operational requirements.
Retention periods vary according to the nature of the information and the reason it is maintained.
14.1 Customer Data After Termination
Following ordinary expiration or termination of a TLS subscription, RRM may make Customer Data available for retrieval for up to thirty (30) days after the effective termination date.
This is a courtesy retrieval period and is not a guaranteed archival or backup service.
Customers should export information they wish to retain before termination whenever possible.
For Accounts terminated following payment delinquency, the applicable period may be measured from the original payment due date as described in the TLS Terms of Service.
After the applicable retrieval period expires, RRM may permanently delete Customer Data and Customer Content without further obligation to Customer.
14.2 Residual Copies
Deleted information may temporarily remain in:
backups;
disaster-recovery systems;
security logs;
fraud-prevention systems;
legal archives;
financial records; or
other systems where immediate deletion is technically impracticable or retention remains reasonably necessary.
Such information remains subject to applicable confidentiality and data-protection obligations until deleted in the ordinary course.
15. Data Security
RRM maintains reasonable administrative, technical, and organizational safeguards appropriate to the nature of the Personal Information we process.
Measures may include protections designed to address:
unauthorized access;
unauthorized disclosure;
loss;
alteration;
misuse;
credential compromise;
fraud;
malicious activity; and
other reasonably foreseeable security risks.
RRM may use service providers and subprocessors to help maintain the security and operation of TLS.
No method of transmission over the Internet, electronic communication, or electronic storage can be guaranteed to be completely secure.
Accordingly, RRM cannot guarantee that Personal Information will never be accessed, disclosed, altered, lost, or destroyed despite reasonable safeguards.
Customers are also responsible for protecting their Accounts, passwords, authentication credentials, API keys, connected services, Authorized User access, and other security controls under their control.
Where required by applicable law, RRM will provide legally required notices concerning qualifying security incidents.
16. Sensitive and Regulated Information
Unless a feature is expressly designed to support such information and RRM has expressly agreed to the applicable requirements, Customers should not use TLS to store or process:
protected health information regulated by HIPAA;
full payment-card data outside designated payment-processing fields;
Social Security numbers;
government identification credentials;
End User passwords or authentication secrets;
biometric identifiers used for unique identification;
highly sensitive financial credentials; or
information subject to specialized regulatory requirements that TLS has not expressly agreed to support.
Customer is responsible for determining whether information it submits to TLS is appropriate for the Services.
17. Privacy Rights
Depending upon where a person resides and which laws apply, that person may have rights concerning Personal Information, including the right to:
request access to Personal Information;
request information concerning categories of Personal Information collected;
request information concerning sources and purposes of collection;
request correction of inaccurate Personal Information;
request deletion of Personal Information;
obtain a portable copy of certain Personal Information;
opt out of certain sales or disclosures of Personal Information;
opt out of sharing for cross-context behavioral advertising;
opt out of targeted advertising;
limit certain uses or disclosures of sensitive Personal Information;
withdraw consent where processing is based upon consent;
appeal certain decisions concerning privacy requests; and
exercise privacy rights without unlawful discrimination or retaliation.
These rights are subject to applicable law, verification requirements, exceptions, and limitations.
17.1 Requests Concerning Information RRM Controls
Privacy requests concerning information collected by RRM for RRM's own purposes may be submitted using the contact information in Section 23.
RRM may take reasonable steps to verify the identity and authority of a person making a request where permitted or required by law.
RRM may deny or limit a request where permitted by applicable law and will provide information concerning that decision where required.
17.2 Requests Concerning Customer Data
If an individual's Personal Information is contained in Customer Data because that individual interacted with a TLS Customer, the individual should ordinarily direct the privacy request to that Customer.
For example, a person who:
joined a Customer's community;
enrolled in a Customer's course;
submitted a Customer's form;
registered for a Customer's webinar;
purchased from a Customer;
became a Customer's CRM contact; or
received communications from a Customer
should generally contact that Customer regarding the Customer's collection and use of the information.
Where required by applicable privacy law, RRM will reasonably assist Customers in responding to legally valid requests involving Personal Information RRM processes on the Customer's behalf.
17.3 Advertising Privacy Choices
Where applicable law provides a right to opt out of sale, sharing, cross-context behavioral advertising, or targeted advertising, RRM will provide or recognize applicable methods for exercising that right.
Where required by law, qualifying browser-based opt-out preference signals will be treated as a request to opt out with respect to the browser or device transmitting the signal.
18. Third-Party Services and Links
TLS may contain links to, integrate with, or rely upon Third-Party Services.
Those services may collect and process information under their own terms and privacy policies.
RRM does not control the independent privacy practices of Third-Party Services.
When Customer intentionally connects an integration or directs information to a third party, the third party's privacy practices may govern its subsequent processing of that information.
Customers should review the terms and privacy practices of services they choose to connect to TLS.
19. Minors
TLS is intended exclusively for adults engaged in legitimate business or professional activities.
Persons under eighteen (18) years of age may not purchase TLS, create or control a TLS Account, or participate in communities, courses, webinars, memberships, or other End User experiences provided through TLS.
Customers may not knowingly use TLS to collect Personal Information from, market to, sell to, enroll, admit, or otherwise provide Platform participation to a person under eighteen (18).
RRM does not knowingly seek to collect Personal Information from minors.
If RRM learns that a person under eighteen has created an Account or participated through TLS contrary to this policy, RRM may restrict or terminate access and may delete the related information where appropriate.
If you believe a minor has provided Personal Information through TLS, please contact us using the information in Section 23.
20. International Processing
RRM operates TLS from the United States.
Personal Information may be processed or stored in the United States or other locations in which RRM's service providers or subprocessors operate.
Those jurisdictions may have privacy laws that differ from the laws of the location where the information was originally collected.
Where applicable law imposes requirements concerning international transfers of Personal Information, RRM will use legally appropriate measures to the extent required.
Customer remains responsible for determining whether its own collection or transfer of Customer Data complies with laws applicable to Customer and its End Users.
21. Business and Professional Use
TLS is offered for business and professional purposes and is not intended for personal, family, or household use.
Customers must be at least eighteen years old and otherwise satisfy the eligibility requirements contained in the TLS Terms of Service.
22. Changes to This Privacy Policy
RRM may update this Privacy Policy periodically as TLS, our business practices, applicable laws, or Third-Party Services change.
When we update this Privacy Policy, we will revise the “Last updated” date shown above.
Nonmaterial changes, clarifications, corrections, or changes that do not materially reduce privacy protections may become effective when posted.
Where required by law, or where RRM determines appropriate, we will provide additional notice before material changes become effective.
The version of this Privacy Policy posted through TLS or our website is the current version.
23. Contact Information
Questions, concerns, or privacy requests concerning Thought Leader System may be directed to:
Rock Ridge Media LLC
Operator of Thought Leader System
329 Lake Side View Lane
Suite 221B
Saint Peters, MO 63376
Email: support@thoughtleadersystem.com
Phone: +1 (636) 378-3337