Privacy Policy
Effective Date: June 2, 2026
This Privacy Policy applies to the website and product Inflowence, operated by Inflowence LLC - a Limited Liability Company (LLC) organized under the laws of the State of Wyoming, USA, with its place of management in Germany. References to "we," "us," and "our" refer to Inflowence LLC.
This Privacy Policy explains how Inflowence ("we," "us," or "our") collects, uses, and discloses information. Because we are a B2B SaaS provider, our data processing falls into two categories:
Our Customers: The businesses who buy our software.
End-Users: The customers of our Customers (whose data we process on our Customers' behalf).
Mobile Information & SMS Consent
We collect your phone number to send text messages related to our Services. Our SMS program is a mixed program covering two separately-consented categories:
- Transactional / non-marketing messages: appointment reminders, booking confirmations, lead follow-ups, and service / account notifications.
- Marketing messages: special offers, discounts, and service updates.
You consent to each category separately via distinct opt-in checkboxes and may opt in to one, both, or neither. Information we collect in connection with the SMS program includes your phone number, which category(ies) you consented to, opt-in timestamp, opt-in source (the form or chat widget on Inflowence), IP address at the time of opt-in, and the content of messages you send and receive.
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Opt-Out & Help. You can opt out of our SMS messages at any time by replying STOP to any message (or by replying with any other reasonable opt-out message, such as "unsubscribe," "cancel," "quit," or "end"). You may also opt out by emailing opt-out@inflowence.ai from any address - include the phone number you wish to unsubscribe in the body. Reply HELP for assistance, or contact support@inflowence.ai / (515) 461-7950. Message and data rates may apply. Message frequency varies. Carriers are not liable for delayed or undelivered messages.
Email Communications
When you submit any form on Inflowence - including forms you begin but do not finish - we collect the email address and any other contact details you provide in order to follow up with you. This follow-up may include:
- Transactional email confirming actions you took (booking confirmations, account notifications, support replies).
- Form-completion reminders when you start a form (for example, the demo request) and do not submit it. The email address you typed is retained for this purpose and a short reminder sequence may be sent so you can resume where you left off.
- Relevant marketing email about Inflowence features, offers, and service updates.
Your rights. Every marketing or reminder email we send includes a one-click unsubscribe link. Unsubscribing removes you from marketing and reminder sequences; we will still send purely transactional email tied to an active account or booking. You can also email support@inflowence.ai at any time to have your email address removed from our lists.
Sender identity. All automated email is sent by Inflowence LLC and includes our physical postal address in the footer, in compliance with the US CAN-SPAM Act.
1. Data Roles & Responsibilities
Customer Data (B2B): Regarding our business relationship with you (the Customer), we act as a Data Controller.
End-User Data (The "Service Data"): Regarding the information you upload or that is generated via SMS, Voice, and DMs with your clients, we act as a Data Processor. You (the Customer) remain the Data Controller of your End-Users' information.
2. Information We Collect
A. From Our Customers (You)
Account Information: Name, business email, billing address, and payment details (processed via Stripe/third-party).
Technical Data: IP address, browser type, and usage logs on the Inflowence platform (via Vercel and Upstash).
B. From End-Users (Processed on your behalf)
Communication Content: Transcripts of Voice Agent calls, SMS message history, and social media Direct Messages (WhatsApp, Instagram, Facebook).
Contact Metadata: Phone numbers, social media handles, and timestamps of interactions.
Voice Data: Temporary audio recordings used for AI transcription and intent analysis.
3. The Technical Data Journey
To provide our services, data flows through a specific architecture designed for speed and reliability.
Interaction Trigger: An End-User sends a DM or calls your AI phone receptionist.
Processing Layer (GoHighLevel): The message is received by GoHighLevel, which handles CRM, voice, SMS, and social messaging (using Twilio and Mailgun as its own subprocessors). Intent analysis and AI responses run on GoHighLevel's Voice AI platform and the AI-model providers it engages. Separately, Inflowence uses OpenAI to prepare knowledge-base content (content extraction and embeddings) from your business's public materials.
Storage Layer (Supabase): The interaction history, lead status, and AI-generated logs are stored in our Supabase database to be displayed in your Inflowence dashboard.
State Management (Upstash): Temporary session data (like an active AI phone call state) is managed via Upstash for real-time performance.
4. How We Use Information
We do not sell End-User data. We use the information solely to:
- Facilitate multi-channel communications.
- Provide analytics and reporting on your communication performance.
- Improve the Services using operational metrics — call volumes, response latencies, error rates, feature usage. Not the content of what your callers said.
- Prevent fraud and ensure compliance with our Acceptable Use Policy.
How we use call content. The substance of a call — the audio, the transcript, what was actually said — is used to answer that call and to deliver the Service to the business you called. To improve our voice-AI prompts and conversation flows, we also review de-identified transcripts — processed so they cannot reasonably be linked to you, the business, or any individual. Even then, we do not train or fine-tune any AI model, and we never use call audio as training data. This de-identified improvement use applies by default; a business may opt out at any time on thirty days' notice.
5. Data Retention
Account Data: Retained as long as your account is active.
End-User Communication Data: Retained for the duration of your subscription unless you request deletion.
Voice Recordings: Unless otherwise configured by the Customer, raw audio files are typically deleted after transcription is finalized, though transcripts remain in the database.
6. Third-Party Disclosures (Subprocessors)
We do not sell or rent the personal information you give us to open an account, the content of your communications, or your mobile opt-in data. Consistent with the Mobile Information & SMS Consent section above, we never share your mobile opt-in data, the content of your messages, or your account information with third parties or affiliates for their own marketing or promotional purposes. We do share information with the subcontractors below, strictly to operate and maintain the platform on our behalf:
Infrastructure & hosting: Vercel (application hosting), Supabase (database and file storage), Upstash (Redis state/caching).
Communications & messaging: GoHighLevel (CRM, voice, SMS, and social DMs, using Twilio and Mailgun as its own subprocessors), AgentMail (programmatic inbox addresses used during account setup), Meta Platforms (WhatsApp / Instagram / Facebook messaging). Internal notifications: Resend delivers operational email to our own team only; it is not used for customer-facing or marketing email.
AI processing: GoHighLevel's Voice AI platform and the AI-model providers it engages (voice transcription and intent analysis of call, SMS, and message content); OpenAI (knowledge-base preparation — content extraction and embeddings).
Analytics & advertising technologies (loaded for United States and Canada visitors only; never loaded for visitors in the opt-in-consent regions — the EU/EEA, the United Kingdom, Switzerland, the UK Crown Dependencies (Guernsey, Jersey, and the Isle of Man) and Gibraltar, and Brazil, China, South Korea, and South Africa — see "Cookies & Tracking Technologies" below): Google (Analytics and Ads), Meta (Pixel), Microsoft (Clarity), and PostHog.
Separately, for visitors located in the United States and Canada only, our website loads the third-party analytics and advertising technologies listed above. The information those technologies collect about your device and browsing may qualify as a "sale" or "sharing" for cross-context behavioral advertising under the CCPA/CPRA and similar state laws. This is separate from the mobile and account data described above, and you can opt out of it at any time — see "Right to Opt Out of Sale / Sharing / Targeted Advertising" and "Cookies & Tracking Technologies" below.
This is a summary of the main categories. The complete and current list of subprocessors, including their roles and data locations, is maintained on our Subprocessors List, which controls if it differs from this summary.
Data & Infrastructure
To provide transparency about our data processing relationships:
-
Subprocessors List - View the complete list of third-party service providers, including GoHighLevel, Vercel, Supabase, Upstash, OpenAI, and others, along with their roles and data locations.
-
Data Processing Addendum (DPA) - For business customers, review our data processing agreement which outlines our obligations as a data processor, security measures, and your rights under applicable US data protection laws.
7. Geographic Scope and Privacy Rights
7.1 Geographic Scope and GDPR Applicability
Service availability. Our Services are offered to businesses located in the United States and Canada. If you are located elsewhere, please do not use the Services or submit personal data through them.
Why GDPR still applies to our processing. Inflowence LLC is a Limited Liability Company (LLC) organized under the laws of the State of Wyoming, USA whose place of management is in Germany. Under Article 3(1) of Regulation (EU) 2016/679 ("GDPR"), processing of personal data carried out in the context of the activities of an establishment of a controller in the European Union is subject to the GDPR regardless of whether the processing itself takes place in the Union. Because the company's place of management - and thus an establishment of the controller - is in Germany, the GDPR applies to our processing of personal data, even though the Services themselves are offered only in the United States and Canada. This Privacy Policy is structured to satisfy both US state-privacy-law disclosures and the GDPR's controller-information and data-subject-rights requirements.
Controller identity (GDPR Art. 13(1)(a)). The data controller is Inflowence LLC, c/o Postflex PFX-828-651, Emsdettener Straße 10, 48268 Greven, Germany. Contact: privacy@inflowence.ai / (515) 461-7950. We do not designate an EU Representative under Art. 27, because that obligation applies only to controllers not established in the Union (Art. 3(2)); as our place of management is in Germany we are established in the Union and subject to the GDPR under Art. 3(1), so Art. 27 does not apply.
Lawful bases for processing (GDPR Art. 6). We rely on the following:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the Services to Customers and, in the Customer's role as controller, to facilitate Customer communications with End-Users.
- Legitimate interests (Art. 6(1)(f)): Platform security, fraud and abuse prevention, aggregated service improvement, and responding to support requests. Our interests are balanced against your rights and freedoms; you may object at any time (see rights below).
- Consent (Art. 6(1)(a)): Marketing communications and SMS messages, where required by law. Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
- Legal obligation (Art. 6(1)(c)): Tax, accounting, and telecommunications-compliance recordkeeping under applicable US and German law.
International transfers (GDPR Chapter V). The Services run on US-based infrastructure (Vercel, Supabase, Upstash, GoHighLevel, OpenAI, Resend, and others listed in our Subprocessors List). Personal data processed in the context of the German establishment is transferred from the EU to the United States in the ordinary course of providing the Services. We rely on the European Commission's 2021 Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, where the receiving organization is certified, the EU-US Data Privacy Framework (Commission Decision (EU) 2023/1795) as the transfer mechanism. You may request a copy of the SCCs applicable to a specific subprocessor by emailing privacy@inflowence.ai.
Data-subject rights under the GDPR (Arts. 15–22). To the extent the GDPR applies to our processing of your personal data, you have the right to access your personal data, request rectification of inaccurate data, request erasure, request restriction of processing, receive your data in a portable machine-readable format, object to processing based on legitimate interests (including a general right to object to direct marketing), and withdraw consent where processing is based on consent. To exercise these rights, email privacy@inflowence.ai. We will respond within one month, extendable by up to two further months for complex requests (Art. 12(3)).
Right to lodge a complaint (GDPR Art. 77). You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence or place of work. Our competent supervisory authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) — competent because the company's place of management is in Bavaria — Promenade 18, 91522 Ansbach, Germany - https://www.lda.bayern.de/.
Automated decision-making. We do not subject data subjects to decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of GDPR Art. 22.
Data Protection Officer. We have assessed our activities under GDPR Art. 37 and determined that a DPO is not mandatorily required because our core activities do not consist of large-scale, systematic monitoring of data subjects nor of large-scale processing of Article 9 special-category data. Where communication content processed on a Customer's behalf may contain special-category data within the meaning of Art. 9 (for example, health-related statements a caller makes to a Customer in a regulated sector), the Customer is the controller and bears responsibility for any Art. 9 condition; we act solely as processor under our Data Processing Addendum and do not use such content to uniquely identify individuals or to infer sensitive characteristics. Privacy inquiries may be directed to privacy@inflowence.ai.
7.2 US State Privacy Rights
We comply with applicable US state privacy laws. These currently include the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the comprehensive privacy laws of Virginia, Colorado, Utah, Connecticut, Texas, Oregon, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, each as it becomes effective and applicable to us. Your specific rights depend on your state of residence, and not every right described below is available in every state.
Right to Know / Access. You may request a copy of the personal data we have collected about you, the categories of data, the sources, and the purposes of processing.
Right to Delete. You may request deletion of your account data, subject to exceptions required or permitted by law (e.g., billing records, fraud prevention).
Right to Correct. You may request correction of inaccurate personal data.
Right to Portability. You may request a copy of your personal data in a portable, machine-readable format.
Right to Opt Out of Sale / Sharing / Targeted Advertising. For US/Canada visitors we use the cookie-based analytics and advertising technologies listed in Section 6 (Google Analytics & Ads, the Meta Pixel, Microsoft Clarity, and PostHog), which may constitute a "sale" or "sharing" for cross-context behavioral advertising under some state laws. You may opt out at any time using the "Do Not Sell or Share My Personal Information" control in our website footer, and we honor opt-out preference signals, including Global Privacy Control (GPC) — when GPC is detected we automatically set those technologies to a denied state. Visitors in the opt-in-consent regions (the EU/EEA, the United Kingdom, Switzerland, the UK Crown Dependencies and Gibraltar, and Brazil, China, South Korea, and South Africa) are served none of these analytics or advertising technologies. See "Cookies & Tracking Technologies" below.
Right to Limit Use of Sensitive Personal Information (CCPA/CPRA). The only category of Sensitive Personal Information we handle for our own account is account log-in credentials (a username together with a password or security-question answer that permits access to an account), which we use solely to authenticate and secure accounts. We do not use or disclose Sensitive PI to infer characteristics about you or to build a profile — a use for which the CCPA does not require a "Limit the Use of My Sensitive Personal Information" link. Even so, you may ask us to limit our use of any Sensitive PI by contacting us below. Voice and message content is processed on our Customers' behalf as a processor; the Customer is the controller of that content.
Right to Appeal (available in most states that grant a comprehensive privacy right, including Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Jersey, and Minnesota). If we decline to act on a verified rights request, you have the right to appeal that decision. To appeal, email our Privacy Officer (address below) with the subject "Privacy Rights Appeal" within 60 days of our decision. We will respond to your appeal in writing within the period your state's law requires (45 or 60 days depending on the state) and, where the law requires it, explain the reasons for our decision. If the appeal is denied, you may contact your state Attorney General.
Right to Opt Out of Profiling (CPA, CTDPA, OCPA). We do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects. No opt-out mechanism is required. If our practices change, we will update this section.
Non-Discrimination. We will not discriminate against you for exercising any of these rights (no denial of Service, different prices, reduced quality, etc.).
Minors. Our Services and website are directed to businesses and their operators, not to children. We do not knowingly collect personal information from anyone under 16, and we do not knowingly sell or share the personal information of consumers under 16. If you believe we have collected data from a minor, contact us and we will delete it.
How to exercise rights. Submit a verifiable request to privacy@inflowence.ai. We will respond within the timeframe required by applicable law (generally 45 days, extendable by 45 days).
Authorized agents. You may designate an authorized agent to make a request on your behalf. We may require written authorization and verification of identity.
End-User data. Where we act as a service provider / processor, Customers (the businesses that use our Services) are the controller of their End-Users' data and are responsible for providing End-User opt-out mechanisms (e.g., "Reply STOP to opt out of text messages"). We will assist Customers in fulfilling verified End-User requests.
Shine the Light (California Civil Code § 1798.83). California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes, so no such disclosures exist to report.
7.3 Cookies & Tracking Technologies
We apply tracking technologies on a geographic basis:
- All visitors: we collect anonymous Core Web Vitals performance metrics (page-load and responsiveness timings), along with your device type and a coarse country derived from your IP address, via a first-party measurement that sets no cookies and stores no persistent identifier. We do not store your IP address — only the derived two-letter country code — so this measurement does not identify you.
- Opt-in-consent regions — the EU/EEA, the United Kingdom, Switzerland, the UK Crown Dependencies (Guernsey, Jersey, and the Isle of Man) and Gibraltar, and Brazil, China, South Korea, and South Africa: no analytics or advertising technologies are loaded — no Google, Meta, Microsoft, or PostHog. Apart from the anonymous performance metrics above, no non-essential cookies or device storage are used, so no consent banner is presented.
- United States and Canada visitors: we additionally load Google Analytics and Google Ads, the Meta Pixel, Microsoft Clarity, and PostHog (product analytics). For the Google tags we operate Google Consent Mode v2, defaulting to granted under the US opt-out model. PostHog runs anonymized — a randomly generated identifier in local storage; we do not send your name or email to it.
Your choices (US/Canada). You can opt out of the analytics and advertising technologies at any time using the "Do Not Sell or Share My Personal Information" link in our footer. We also honor the Global Privacy Control (GPC) browser signal: when GPC is present we automatically set the Google, Meta, and PostHog technologies to a denied / opted-out state and display a confirmation that your opt-out has been honored.
8. Security
We implement enterprise-grade security via our infrastructure providers (Vercel, Supabase, and Upstash), including:
Encryption at Rest: All database entries are encrypted.
Encryption in Transit: Data is transmitted over encrypted HTTPS connections using TLS 1.2 or higher.
Access Control: Strict internal policies regarding who can access Customer databases for support purposes.
9. Contact Us
For any privacy-related inquiries or to exercise your data rights, please contact:
Privacy Officer Email: privacy@inflowence.ai
By using Inflowence, you acknowledge that you have read, understood, and agree to this Privacy Policy.