Skip to main content

Legal

Privacy Policy

Last updated 2026-07-23

1. Overview

This Privacy Policy explains how EFFICIO MARKETING LLC, an Ohio limited liability company, operating the Efficio platform (“Efficio,” “we,” “us,” or “our”), collects, uses, shares, and protects personal data through the Efficio platform, public platform website, owner dashboard, lead capture tools, generated business websites, Call Confirmation features (also called call-tracking features), billing workflows, and related services (the “Platform”).

The Platform helps business owners create and operate public business websites optimized for search, AI-search visibility, and conversion. This means we process data about business owners and team members, people who visit Efficio’s public website, support contacts, people who visit websites created with Efficio, and people who submit or trigger leads on those websites.

2. Our privacy roles

For account, dashboard, billing, payment, security, support, legal, product improvement, platform website, and business operations data, EFFICIO MARKETING LLC acts as the controller, business, or equivalent decision-maker and data custodian.

For personal data about Visitors to a business owner’s Published Site that is captured as leads, appointment requests, chat messages, direct CTA Interactions, Confirmed Calls, and related metadata, the business owner is the controller, business, or equivalent decision-maker. Efficio processes that data as the owner’s processor, service provider, contractor, or equivalent role, except where we process it for our own security, billing, fraud prevention, abuse prevention, legal compliance, service improvement, dispute handling, or other independent purposes described in this Policy.

The Data Processing Addendum governs Efficio’s processing of Customer Personal Data for a business owner. The owner is responsible for identifying its business and privacy contact, explaining its own collection and use, establishing a legal basis, obtaining required consent, and responding to rights requests for data it controls. This Policy supplements but does not replace an owner’s legally required privacy notice.

If you are a Visitor to a Published Site and have a privacy request about your lead, appointment, message, phone call, or business relationship with that site, you should contact the business owner first. If you contact Efficio, we may forward the request to the owner, respond about Efficio-controlled data, or assist the owner in responding where required.

3. Data we collect from business owners and dashboard users

We collect data that business owners, admins, editors, viewers, invitees, and support contacts provide or create, including:

  • name, email address, password credentials or authentication data, role, organization, invitations, and consent version;
  • business name, business type, public phone number, public email, location, service area, opening hours, team, reviews, pricing, services, menus, projects, FAQs, blog posts, credentials, offers, and other business profile data;
  • website content, SEO titles and descriptions, language settings, style choices, color choices, CTAs, booking settings, order links, availability slots, custom domains, DNS verification records, publication status, and action-report settings;
  • uploaded images, pasted image URLs, imported source-site images, image alt text, logos, source URLs, content hashes, storage keys, and platform storage URLs;
  • support messages, feedback, admin actions, spam reports, billing requests, legal notices, and communications with us;
  • billing identifiers, subscription status, Stripe customer and subscription references, invoice and meter-event records, free-trial settings, lead pricing, billing-start settings, payment portal activity, and billing usage-sync status. We do not store full card numbers; Stripe processes payment details;
  • Call Confirmation settings (also called call-tracking settings), such as the public business phone number, provisioned forwarding or tracking number, Telnyx number resource identifiers, TeXML connection identifiers, minimum billable duration, caller deduplication settings, and caller blocklist entries; and
  • technical data such as session cookies, device and browser signals, IP-derived security signals, logs, error reports, user agent, request headers, rate-limit hashes, and audit or worker activity.

4. Data we collect from public platform visitors

When someone visits Efficio’s public platform website, legal pages, help pages, sign-in pages, onboarding pages, invite pages, or related public pages, we may collect contact information submitted through forms, account signup data, authentication state, cookies, device information, IP address or hashed IP signals, user agent, referrer, acquisition channel, approximate location from infrastructure headers, page and request information, error information, and security and rate-limit data. While public onboarding is paused, a person may optionally submit one email address or phone number to ask about private-beta availability; that submission does not create an account, website, lead, or payment obligation.

5. Data we collect from visitors to Published Sites

Published Sites are designed to capture conversions. Depending on the site configuration and Visitor action, we may process:

  • form details such as name, first name, last name, email, phone, contact field, message, and honeypot anti-spam field;
  • appointment request details such as requested slot, reserved slot, location ID, team member ID, name, contact field, and message;
  • chat details such as question, contact field, honeypot field, and widget metadata;
  • quick-contact details such as phone number or email address;
  • CTA Interaction metadata for call, booking, order, and other clicks, including CTA ID, module ID, placement, provenance, route archetype, action, link kind, clicked href, page path, and current URL;
  • Telnyx Call Confirmation data (also called call-tracking data) for Confirmed Calls (also called tracked calls), such as caller number, dialed forwarding or tracking number, provider call ID, caller name where supplied by the provider, call status, duration, timestamps, forwarding outcome, routing health, and billing qualification state. Call Confirmation is not intended to record call audio;
  • UTM parameters, referrer, document referrer, browser language, timezone, screen size, user agent, forwarded host, and infrastructure-provided geolocation headers such as country, region, city, latitude, and longitude where available;
  • hashed IP signals used for rate limiting, abuse prevention, and lead-source deduplication; and
  • lead status, billing status, spam-review status, timestamps, and dashboard handling history.

Direct CTA Interactions may be captured as analytics-only events by default even when the Visitor does not submit contact details. A connected Confirmed Call may be captured as a distinct phone-call lead when the site and billing settings make that source eligible. Lead notification emails sent to owners are designed not to include lead contact details; owners view those details in the dashboard.

Infrastructure-provided latitude and longitude are derived from network or IP context rather than a Visitor granting browser GPS access. Their accuracy and legal classification can vary by provider, device, network, and jurisdiction. We use this context for attribution, routing, security, abuse prevention, and service analysis and do not represent that it identifies a person’s exact physical location.

6. Source-link crawling, imported content, and AI processing

If an owner provides a source link, including a link to an existing website, a business profile on another platform, or a page with search results related to the business, Efficio may capture content from the linked page or site and crawl associated publicly reachable pages. We may discover sitemap URLs; fetch rendered or static content; and extract titles, descriptions, canonical URLs, robots meta directives, structured data, headings, text blocks, snippets, emails, phone numbers, addresses, links, social URLs, image URLs, alt text, and diagnostics. For AI draft generation, a supplied source must produce at least 80 normalized visible-text characters after the available crawl methods run; otherwise the job fails before the AI provider is invoked. When no source link is supplied, Efficio may generate the draft from onboarding answers instead.

We may send onboarding data, source-site extracts, business facts, media candidates, generated drafts, validation errors, content revision context, and optimization context to OpenAI or another configured AI provider to create website drafts, action reports, recommendations, or content revisions. We may store the resulting drafts, reports, token usage, model and provider identifiers, job status, and validation results for review, support, billing, quality, and audit purposes.

For the current action-report workflow, Efficio excludes raw Visitor-submitted lead messages and direct contact fields from the model payload and permits only limited conversion metadata. Other AI workflows use the business, source, draft, validation, and optimization information needed for their stated purpose. Owners must not place unsupported regulated or highly sensitive information into AI inputs.

When Efficio uses OpenAI’s Responses API, requests are configured with application response storage disabled. This setting is not the same as contractual Zero Data Retention: an AI provider may retain limited data for abuse monitoring, security, legal compliance, or other purposes under its terms. Efficio does not authorize Customer Personal Data to be used to train unrelated generally available models unless that use is separately disclosed and lawfully authorized.

At draft release or during owner upload, Efficio may fetch external images, process them, strip metadata, convert them, store them in Supabase Storage or another storage provider, record source URLs and hashes, and serve them publicly as part of the Published Site.

7. Cookies, storage, and similar technologies

We use cookies and similar technologies for authentication, session management, password reset and sign-in flows, maintenance bypass where configured, security, preferences, and product operation. Published Sites may use browser storage, such as session storage, to remember that a Visitor has seen or dismissed an on-site chat greeting during the current browser session.

You can control cookies through your browser settings. Some Platform features, including sign-in, dashboard access, security checks, and lead submission, may not work correctly without required cookies or storage.

8. How we use personal data

We use personal data to:

  • create accounts, authenticate users, manage organizations, permissions, invitations, and sessions;
  • create, generate, host, edit, publish, suspend, and delete business websites;
  • capture, validate, display, notify, review, deduplicate, bill for, void, waive, sync, and analyze leads;
  • provision, route, reconcile, monitor, and bill eligible Confirmed Calls where Call Confirmation is enabled;
  • process payments, subscriptions, invoices, usage records, taxes, refunds, credits, and free allowances;
  • provide support, respond to requests, send service messages, and manage feedback;
  • record private-beta interest and contact a submitter about onboarding availability;
  • operate crawlers, AI drafting, action reports, recommendations, image imports, custom domains, revalidation, and automation jobs;
  • secure the Platform, detect abuse, enforce rate limits, prevent fraud, investigate spam reports, and protect rights and safety;
  • improve, test, troubleshoot, monitor, and measure the Platform, including through logs and error reporting;
  • create and use aggregated or deidentified information to understand, secure, and improve the Platform, subject to measures designed to prevent identification and any applicable non-reidentification requirement;
  • comply with legal, tax, accounting, payment, dispute, and regulatory obligations; and
  • enforce our Terms, Content Policy, and agreements.

9. Legal bases for EU/UK processing

Where EU or UK data protection law applies, our legal bases may include performance of a contract, legitimate interests, consent, legal obligation, and, rarely, protection of vital interests. Our legitimate interests include operating and securing the Platform, supporting business owners, preventing abuse, measuring and improving services, billing for services, enforcing agreements, and protecting Efficio, owners, Visitors, and others.

Where we act as a processor for a business owner, the owner determines the lawful basis for processing Visitor lead data. Owners are responsible for providing any required notices and obtaining any required consents from their Visitors.

10. How we share personal data

We may share personal data with:

  • business owners and authorized organization users, so they can view and respond to leads, manage websites, and operate their business;
  • Vercel or other hosting and infrastructure providers that serve the Platform, Published Sites, edge functions, cron jobs, and geolocation headers;
  • Supabase for authentication, database, storage, row-level access controls, and related backend services;
  • Stripe for checkout, subscriptions, billing portal, invoices, payment methods, meter events, tax, fraud, and payment compliance;
  • Telnyx for phone-number provisioning, TeXML call routing, call status callbacks, call metadata, and related telephony services;
  • Supabase Auth for authentication-token generation and verification; Google Workspace for inbound email to Efficio addresses; and configured SMTP or transactional email providers for organization invitations, authentication-link delivery, lead notifications, and operational email handling;
  • OpenAI or other AI providers where configured for website drafts, action reports, validation, and optimization suggestions;
  • Sentry or other logging, monitoring, and error-reporting providers where configured;
  • DNS, domain, browser rendering, image processing, and storage providers used to operate custom domains, crawls, and media features;
  • professional advisers, insurers, auditors, legal counsel, payment partners, and security consultants;
  • law enforcement, regulators, courts, emergency responders, or dispute bodies when disclosure is permitted or required on the grounds described below; and
  • successors or counterparties in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction.

We do not sell personal information or share it for cross-context behavioral advertising as those terms are commonly used under California privacy law. If our practices change, we will update this Policy and provide any required opt-out mechanism.

Providers that may process Customer Personal Data for business owners are described in the Subprocessor Notice. A listed provider applies only when the relevant feature and production configuration cause that provider to process the data.

We may preserve or disclose personal data when we reasonably and in good faith believe it is required by valid legal process or applicable law; authorized by lawful consent from a person with authority; necessary to address an emergency involving danger of death or serious physical injury; permitted to protect the rights, property, security, or integrity of Efficio, owners, Visitors, or the Platform; or part of a reporting or preservation duty expressly permitted or required by law. We seek to review the scope of a request and disclose only information reasonably necessary or legally required.

Where lawful and appropriate, we may notify the affected owner or person before disclosure. Notice may be withheld or delayed when prohibited by law, inconsistent with an emergency, unsafe, likely to frustrate a lawful investigation, or impracticable. We may challenge a facially invalid or materially overbroad demand where reasonably appropriate, but we do not promise to challenge every request.

11. International transfers

Efficio and its service providers may process personal data in the United States, the European Economic Area, the United Kingdom, and other countries where we or our providers operate. Those countries may have data protection laws different from the laws where you live. Where a transfer restriction applies, the relevant parties must put an appropriate transfer mechanism in place, which may include standard contractual clauses, the UK International Data Transfer Addendum, adequacy decisions, or another approved safeguard. The Data Processing Addendum describes the conditional process for Customer Personal Data; this Policy does not represent that a particular transfer mechanism or representative applies in every case.

12. Retention

We retain personal data no longer than reasonably necessary for the purposes described in this Policy, subject to account and site status, owner instructions, available deletion controls, provider lifecycles, security, fraud prevention, billing, legal obligations, disputes, and legal holds. The principal category-specific criteria are:

  • account, organization, membership, site, content, domain, and configuration data are generally retained while the account, organization, or Published Site is active and for a reasonable wind-down, recovery, support, or dispute period afterward;
  • private-beta interest contact information is scheduled for deletion 180 days after its most recent submission;
  • lead, appointment, chat, CTA, and call-routing data are retained while reasonably needed for delivery, owner follow-up, spam review, attribution, service quality, billing, dispute handling, and the site or account lifecycle, subject to owner instructions and applicable law;
  • billing authorizations, prices, invoices, payment references, tax, accounting, consent, and contract records may be retained for the applicable transaction, legal, audit, limitations, and dispute periods;
  • security, rate-limit, authentication, audit, monitoring, and error records are retained according to their operational usefulness, volume, risk, and provider lifecycle and are intended to be shorter-lived where a continuing security, legal, or dispute need does not exist;
  • AI inputs, outputs, validation results, and job records are retained as part of the relevant site, content, support, quality, billing, or audit history; AI providers may retain limited data under their own security, abuse-monitoring, and legal terms; and
  • support, privacy-request, complaint, incident, and legal correspondence is retained as reasonably necessary to respond, demonstrate compliance, prevent fraud, resolve disputes, and satisfy law.

Deletion may mean removal, deidentification, aggregation, or restriction from ordinary use, depending on the category and legal requirements. Pseudonymized information remains personal data where applicable law treats it as such. Data may remain temporarily in backups, logs, invoices, payment or telephony systems, security records, legal archives, or other provider systems until the applicable lifecycle expires.

A valid litigation hold, regulator request, preservation duty, billing dispute, fraud or security investigation, tax or accounting rule, or other legal obligation may delay deletion. While retained for such a purpose, access and further use are limited to that purpose where reasonably practicable. Ordinary disposition resumes when the hold ends. Because these criteria depend on facts and systems, we do not promise a fixed deletion period unless a separate written agreement expressly provides one.

13. Security

We use administrative, technical, and organizational safeguards designed to protect personal data, including authentication, role-based access controls, row-level data restrictions where supported, HTTPS, service-role separation, rate limiting, input validation, logging, monitoring, provider security controls, and limited access to operational secrets. No method of transmission or storage is perfectly secure. You are responsible for strong passwords, account access, invited users, domain configuration, and promptly reporting suspected compromise.

14. Your privacy choices and rights

Depending on where you live and how we process your data, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, information about processing, or non-discrimination for exercising privacy rights. California residents may also have rights to know categories and specific pieces of personal information, request deletion or correction, opt out of sale or sharing, and limit certain sensitive personal information uses where applicable.

To exercise rights for Efficio-controlled data, contact privacy@effic.io or write to 6708 Main Street, Cincinnati, OH 45244, United States with enough information to identify the relevant account, Published Site, interaction, and requested action. We handle requests through available records and reasonable manual processes; this Policy does not promise a self-service request portal, automated export, one-time download system, or other particular technical workflow. We may ask you to avoid including unrelated sensitive information.

Where permitted or required, we may verify identity and authority in a manner proportionate to the sensitivity and risk of the request, including by confirming control of an account or contact channel or requesting additional information. Authorized agents may submit requests where applicable law permits, but we may verify the agent’s authority and, where allowed, the individual’s identity. We will not impose verification on a request when applicable law prohibits it, including certain opt-out requests.

For Visitor data controlled by a business owner, contact that owner first. We may route the request based on account, site, domain, and interaction context; seek clarification where scope or ownership is ambiguous; assist the owner as processor or service provider; or respond separately about Efficio-controlled data. Owners remain responsible for their legal decisions and responses.

We respond within the period required by applicable law, subject to permitted verification, clarification, extensions, exceptions, and preservation duties. A response may be limited or denied to protect another person’s rights, security, privilege, confidential information, fraud-prevention controls, or data we are required or permitted to retain. Where required, we will explain a denial or extension and provide an appeal or regulator-complaint route. An appeal may be submitted by replying to the decision or contacting privacy@effic.io and identifying the earlier request.

Access or portability information may be provided in a reasonable electronic or other feasible format and may be redacted, segmented, staged, or delivered through an alternative method to protect security, third-party rights, and large data volumes. An expired or failed delivery method does not forfeit an applicable right; you may request replacement delivery subject to renewed verification. Deletion may not immediately remove protected backups or provider copies and may be limited by the retention criteria in Section 12.

We do not sell personal information or share it for cross-context behavioral advertising and therefore do not currently provide a sale or sharing opt-out mechanism. If those practices change, we will provide required notices and controls and honor legally recognized preference signals where applicable. We will not discriminate unlawfully against a person for exercising an applicable privacy right.

EU/UK individuals may also have the right to withdraw consent where consent is the legal basis and to complain to a data protection authority. Withdrawing consent does not affect processing supported by another lawful basis or processing completed before withdrawal. You may contact us at privacy@effic.io with questions about an EU/UK representative or data protection contact, if one is legally required and appointed.

15. Sensitive and regulated information

The standard Platform is not designed or approved for protected health information, regulated consumer-health programs, child-directed collection, financial-account credentials, government identifiers, biometric templates, precise GPS or device location, or similarly regulated information. Business owners must not intentionally collect those categories unless Efficio expressly approves the use in writing and the parties put all required compliance terms and safeguards in place before collection.

A Visitor may nevertheless include unexpected sensitive information in free text. If we learn that unsupported regulated information was submitted, we may restrict access, notify or assist the responsible business, preserve information where legally required, and delete or limit further use through methods then reasonably available. Receipt of unexpected information does not mean that Efficio offers a HIPAA-compliant or other regulated workflow.

16. Children

The Platform is intended for business users who are at least 18 years old. It is not directed to children, and we do not knowingly collect personal data from children through the Platform. Business owners must not use the Platform to target children or collect children’s personal data unless they have confirmed with counsel that their use is lawful and Efficio has agreed in writing where required.

A parent or guardian who believes a child submitted personal data may contact privacy@effic.io. We may request information reasonably necessary to identify the data and verify authority and will take action required by applicable law, which may include restricting or deleting the information and notifying the responsible business.

17. Automated processing and AI

Efficio uses automated systems and AI providers to draft website content, classify lead sources, validate click leads, deduplicate certain interactions, recommend actions, detect abuse, monitor call-routing health, and support billing workflows. These systems do not replace owner review, and they are not intended to make legally significant decisions about Visitors without human involvement. Platform admins may make final decisions on spam reports and billing adjustments.

This Policy is a notice, not a request for blanket consent to every described activity. Where Efficio relies on consent as the legal basis for particular processing, consent will be requested separately as required and may be refused or withdrawn. Withdrawal does not affect processing supported by another lawful basis or the lawfulness of processing completed before withdrawal.

18. Changes to this Policy

We may update this Privacy Policy from time to time. The “Last updated” date shows the current version. Material changes may be announced through the Platform, by email, by a dashboard notice, or by other reasonable notice. Where required by applicable law, we will provide additional notice or request consent separately.

19. Contact

Privacy requests and questions may be sent to privacy@effic.io. Legal notices may be sent to legal@effic.io and 6708 Main Street, Cincinnati, OH 45244, United States. General support requests may be sent to support@effic.io.