Privacy Policy

GoldenFlow AI, Reviews, and Local SEO
Effective date: August 16, 2026
Last updated: August 16, 2026
Version 2.3 (supersedes the policy dated April 16, 2026)

This notice sets out what information we handle, the purposes for which we handle it, the parties with whom it is shared, and the rights available to you. It governs our websites, our services, and our review cards.

1. Who we are and what this policy covers

GoldenFlow AI is the trade name of GoldenFlow AI, Reviews, and Local SEO LLC, an Illinois limited liability company based in Chicago, Illinois ("GoldenFlow AI," "we," "us," or "our").

We provide review management, reputation services, local search visibility services, physical review cards, and related back office systems to small and local businesses, primarily in the Chicago metropolitan area.

This Privacy Notice describes how and why we access, collect, store, use, and share ("process") personal information. It applies when you:

- Visit goldenflowai.com, or any other website, landing page, form, or short link we operate, including go.goldenflowai.com and card.goldenflowai.com

- Use our services, including review request programs, review response services, local search visibility services, dashboards and reports, and physical review cards

- Tap or scan a GoldenFlow review card

- Interact with us through sales outreach, support, or a connected business account

This policy does not apply to the privacy practices of our client businesses, of Google, or of any other third party site or platform you may reach through a link, a card tap, or a QR scan.

The two roles we play

Our obligations with respect to any given item of information depend on which of the following two roles applies.

Role 1, we decide (Sections 3 through 12). When you visit our website, contact us, ask about our services, tap a card, or become our client, we decide why and how the information is used. In privacy law terms we are the controller or business.

Role 2, a client decides (Section 13). When a business hires us, we handle information about that business's own customers so we can send review requests, run a customer care channel, and produce reports. The client business decides why and how that information is used, and we act on their behalf. In privacy law terms we are the processor or service provider.

If you are a customer of a business that works with us and you want your information corrected or deleted, contact us at the address in Section 22 and we will help, but the business you dealt with controls that decision and we will pass your request to them.

2. Summary of key points

This summary is for convenience only. The full sections below control.

- What we process depends on how you interact with us: as a website visitor, a prospective client business, a paying client, a customer of one of our clients, or someone who tapped a review card.

- We do collect personal information. Our websites and services are not passive. We collect information you provide to us, information your browser transmits to us, information from business accounts you connect, and information our clients upload to us.

- We use artificial intelligence. Some features, most visibly the drafting of suggested review replies, use third party language models. See Section 8.

- We obtain information from third party data sources, including business data providers, contact enrichment services, and public records aggregators, for business to business outreach. See Section 3.5.

- Do we process sensitive personal information? No. We do not collect government identifiers, financial account numbers, precise geolocation, biometric data, health data, or any other category defined as sensitive under state privacy law.

- Do we collect information from third parties? Yes. From public sources such as Google Business Profiles and public review pages, and from business accounts you authorize us to connect to.

- We do not sell personal information and we do not share it for cross context behavioral advertising.

- Mobile numbers and text message consent records are never shared for marketing purposes.

- We do not provide your information, or your customers' information, to any third party for the purpose of training artificial intelligence models, and the providers we use operate under terms that exclude training on submitted content.

- You can ask what we have, ask us to fix it, and ask us to delete it. See Section 16.

3. Information we collect

3.1 Information you give us directly

- Contact and identity information: name, business name, job title, email address, phone number, mailing or business address.

- Account and authentication data: usernames, access tokens, and similar credentials for accounts you connect. Passwords you hold are never requested or stored by us.

- Inquiry content: anything you type into a form, send us by email or text, tell us on a call, or say to us in person.

- Booking information: requested times, service interests, and notes when you schedule a call or a visit.

- Agreement and billing information: signed agreements, billing address, tax status, and the last four digits and expiration of a payment card.

- Business context you choose to share: approximate revenue, customer volume, vertical, staffing, tools you use, and goals. We use this to size and price a recommendation.

- Customer contact information uploaded or transmitted by clients. See Section 13, which governs it.

3.2 Payment data

Payments are processed by Stripe. GoldenFlow AI, Reviews, and Local SEO does not store full payment card numbers. Card details go directly to Stripe. Stripe's privacy policy is at stripe.com/privacy.

3.3 Information we collect about prospective client businesses

We conduct business to business outreach. Before contacting a business we review publicly available information about it, including business name, address, phone number, website, category, published Google Business Profile details, public review count, public star rating, and the date of the most recent public review. We may also review publicly posted business social media accounts.

This information concerns a business and is drawn entirely from public sources. We record it in our own prospect log so our outreach is relevant rather than generic, and so we do not contact the same business repeatedly. If you are a business owner and want us to stop contacting you and remove your business from our prospect log, tell us at the address in Section 22 and we will do both.

3.4 Information collected automatically on our websites

- IP address and the approximate city or region derived from it

- Browser type and version, device type, and operating system

- Pages viewed, time on page, referring source, and campaign parameters such as UTM tags

- Dates and times of visits

3.5 Information we obtain from third party data sources

In addition to public sources, we may obtain business contact and firmographic information from third party data providers, contact enrichment services, list vendors, business directories, and public records aggregators. Information obtained this way typically includes business name, address, phone number, website, industry classification, size indicators, and the name, title, and business email address of an owner or decision maker.

How we use it: to build and clean prospect lists, to verify that a business is still operating, to correct outdated records, and to avoid contacting the same business twice.

Limits on the use of this information:

- We do not use a phone number obtained from a third party data source to send text messages. Text messages go only to numbers where consent has been given directly to us or to the client business sending the message.

- We do not use it to build profiles about individuals as consumers.

- We do not resell it, redistribute it, or contribute it to any data marketplace.

- We do not merge it with card tap data, customer data uploaded by a client, or any other individual level record.

If you are a business owner and want your information removed from our prospect log and suppressed from future acquisition, email [email protected] with "Do Not Contact" in the subject. We will remove it and add you to a permanent suppression list so it does not return the next time we refresh a list.

3.6 Correspondence and calls

We keep business correspondence, including email and text threads. We do not record phone calls unless we tell you at the start of the call and you agree.

4. How we use information

Respond and quote - Answering inquiries, scheduling calls, preparing a recommendation and price

Deliver and maintain services - Configuring your review request program, connecting your business profile, programming and tracking your cards, building your dashboard, sending your reports

Manage accounts - Creating, maintaining, and closing client accounts

Billing - Starting a trial, processing subscription and one time charges, invoicing, collections, refunds

Service communications - Onboarding steps, trial checkpoints, results summaries, renewal and billing notices, support

Marketing communications - Newsletters and offers, only where you asked for them or where permitted for business contacts, with an unsubscribe link in every message

Improve our services - Understanding which offers, verticals, and messages work, generally in aggregate

Security and fraud prevention - Detecting bot traffic, abuse, and unauthorized access

Legal and safety - Tax and accounting records, responding to legal process, enforcing our agreements

5. Review cards: taps, scans, and tracking

This section describes our physical review card product. It applies to any individual who taps or scans a card, and to the client businesses that deploy them.

5.1 What a card does

A GoldenFlow review card is a physical card containing an NFC tag and a printed QR code. Tapping or scanning it opens a short link we operate at card.goldenflowai.com or go.goldenflowai.com. That link records the tap and immediately redirects the phone to the business's own public Google review page.

The redirect is instant and the destination is Google. Once the redirect completes, what happens next is governed by Google's privacy policy, not ours.

5.2 What we record on a tap or scan

At the moment of a tap or scan we record:

- The card code and the client business code

- The date and time

- A one way cryptographic hash of the IP address, combined with a secret salt value. The raw IP address is not written to our tap records. The hash exists only so we can recognize that two taps came from the same device within a short window. We keep no lookup table linking a hash back to an address and we make no attempt to reverse one

- The browser user agent string, truncated

- The two letter country code supplied by our network provider

- Whether the request appears to come from an automated crawler rather than a person

Our network and content delivery provider may briefly process and log the originating IP address as part of routing and securing the request, under its own privacy terms. That is separate from the tap records we retain.

5.3 What we do not record, and do not know

- We do not record any name, phone number, email address, or account. A card tap is anonymous to us.

- We do not use tap data to identify, profile, track, retarget, or advertise to the person who tapped.

- We do not know which taps became reviews. Google does not disclose that information, and we make no claim to the contrary. Tap counts and review counts are reported side by side and are never presented as cause and effect.

- We do not place a cookie, install anything, or ask for any permission on the phone that tapped.

5.4 Why we record it

Tap data is retained for two purposes only: to provide the business that purchased the cards with an accurate count of how often each card is used, and to maintain the integrity of those counts.

Accuracy requires two filters. The IP hash allows us to collapse repeat taps from the same device within a short window, so that repeated taps by a single customer are not recorded as separate uses. The user agent check allows us to identify link preview crawlers and other automated traffic so that it is excluded from reported totals. These two filters are the only uses of the hashed address and the user agent string.

5.5 What the business sees

The business that owns the cards receives tap counts by card and in total, by day, week, month, and year, plus an automated monthly summary email. They see counts, not people. No business receives an IP address, a hashed address, a device identifier, or anything that could identify an individual who tapped a card.

5.6 Cards after a client leaves

Cards remain in circulation after an engagement ends. A card still in circulation will continue to redirect to the business's review page, so that a customer who taps it is not directed to an error page. We cease reporting on the card and mark the account inactive. A business may request that we retire a card code at any time.

5.7 Retention of tap records

Tap records contain no name and no raw IP address. We retain them as a running history while the client is active so year over year comparisons are possible, and thereafter in aggregate form. Because these records are not linked to an identified person, they are not subject to individual access or deletion requests, though we will describe them to any client on request.

6. Text messages and phone calls

This section applies to any individual who receives text messages from GoldenFlow AI, or from a messaging program we operate on behalf of a client business.

6.1 Texts we send you as a prospective or current client

If you give us your mobile number and agree to receive texts from GoldenFlow AI, we may text you about your inquiry, your trial, your account, and your service. Message frequency varies. Message and data rates may apply. Reply STOP to any message to opt out. Reply HELP for help, or email [email protected]. Carriers are not liable for delayed or undelivered messages.

Consent to receive text messages is never a condition of purchasing any product or service from us.

6.2 Texts sent to your customers on behalf of a business

Where we operate a review request program for a client business, messages are sent in that business's name, to that business's own customers, based on consent that business obtained. Every message identifies the business and includes opt out instructions. An opt out is honored immediately and permanently across every program we run for that business.

6.3 Mobile information sharing

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

We may disclose mobile numbers and related opt in records to subcontractors and service providers strictly to operate the messaging program itself, such as our messaging platform and its telecommunications carriers, under confidentiality obligations. We do not sell, rent, or trade mobile numbers or consent records, and we do not disclose them to lead generators, data brokers, or affiliates for marketing.

6.4 Commercial email

The CAN-SPAM Act applies to commercial email, including email sent business to business. In every commercial email we send:

- The sender is identified as GoldenFlow AI and the from, reply to, and routing information is accurate

- The subject line accurately reflects the content

- Our valid physical postal address appears in the message: GoldenFlow AI, Reviews, and Local SEO LLC, 1201 N La Salle Dr Apt 1307, Chicago, IL 60610

- A working unsubscribe mechanism is included, and we honor an opt out within 10 business days and permanently thereafter

Transactional and service messages about an existing account, such as billing notices and trial reminders, are not marketing and are sent regardless of marketing preferences.

6.5 Calls

We place business to business calls. If you ask us not to call again, we record that request and honor it.

7. Access to your business accounts and platforms

To deliver our services we may ask you to authorize access to accounts you control, such as your Google Business Profile, your review platforms, your customer records, your scheduling or job management system, or your website.

Our commitments:

- Access is limited to what is necessary to deliver the services in your agreement.

- We use it only for you, on your account, for your stated purposes.

- We do not use it to build products for other clients, and we do not sell it.

- You may revoke our access at any time from the platform itself. Doing so may stop parts of the service from working.

- When our engagement ends, we disconnect our access.

7.1 Google user data, limited use

This section applies where we access Google user data through a Google API under an authorization you grant us. Publicly available business and review information that we look up without accessing your account is covered by Section 3.3 instead.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Information obtained from Google APIs is used only to provide or improve the features you engaged us to deliver, is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition, is not used or transferred for advertising purposes, and is not read by any human except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymized for internal operations.

8. Our use of artificial intelligence

We use artificial intelligence in delivering our services. This section describes where it is used, how it is used, and the limits that apply to it.

Specifically, we use third party large language model providers to draft text. The most common use is a suggested reply to a customer review, generated from the review text and the tone notes a business gives us. We may also use these tools to draft post copy, summarize activity for a report, or classify an inbound message as a question, a complaint, or an opt out request.

Scope and limits:

- Drafts are generated for your account and your business only.

- We use business or enterprise tier arrangements whose published terms exclude training on submitted content. We do not consent to training on customer content and we will not knowingly use a provider that requires it. We do not control a provider's internal operations and we do not warrant them beyond the terms that provider publishes.

- A draft reply to a negative review is never posted publicly without the business owner seeing and approving it first.

- No automated feature makes a decision that produces a legal or similarly significant effect about any individual. These features draft text. They do not score, rank, or profile people.

- A client may ask us to disable drafting features on their account and have every response written manually.

9. Cookies and tracking technologies

We use cookies and similar technologies to:

- Essential: keep the site and the admin dashboard working and secure

- Analytics: understand how visitors use the site, for example through Google Analytics

- Attribution: identify which page or campaign a visitor came from, through parameters such as UTM tags

You can block or delete cookies in your browser settings. Blocking analytics cookies will not affect your ability to use the site or our services. Full detail is in our Cookie Policy.

Do Not Track. Browsers send Do Not Track signals inconsistently and there is no standardized industry approach, so we do not respond to them. We do honor recognized opt out preference signals such as Global Privacy Control where required by applicable state law.

10. How we share information

We share personal information only in these circumstances.

10.1 Service providers

We use vendors to run the business. Each is bound by contract to protect the information, to use it only as we direct, and not to sell it.

The list below is current as of the effective date and is representative rather than exhaustive. We add, replace, and retire vendors from time to time, and this policy is not revised for every such change. The categories and purposes stated below are binding commitments; the named providers are disclosed for transparency.

Payments, including subscriptions, trials, one time charges, and tax calculation: Stripe.
Client platform and messaging, including contact records, review requests, text and email delivery, and pipelines: GoHighLevel and its telecommunications carriers.
Data storage, including tap logs, review records, and reporting data: Supabase.
Network and short links, including redirects, bot filtering, security, and site delivery: Cloudflare.
Reporting and dashboards, for client facing reports: Google Looker Studio.
Business profile and review data, including profile management and public review data: Google.
Email delivery, for transactional and report emails: Resend, Google Workspace or Microsoft 365.
Language processing, for drafting suggested review replies: business tier providers under no training terms.
Accounting, including bookkeeping, invoicing, and tax filings: QuickBooks Online and our accountant.
File storage and productivity, including documents, logs, and client files: Microsoft 365 and OneDrive.

We maintain a current list of service providers and will provide it on request.

10.2 Client businesses

Where a business hires us, we make that business's own information available to it, which is the point of the service.

10.3 Case studies and marketing use

We may use business level information to create case studies, testimonials, and marketing materials about our services. This may include the client business name, logo, publicly available reviews, testimonials you provide, and high level performance results such as an increase in review volume or profile actions.

We never use an individual customer's name, contact information, or personal details in marketing materials. If you prefer that your business not appear in our marketing, email [email protected] and we will honor it, before or after publication.

10.4 Testimonials, reviews, and results claims

The Federal Trade Commission's Rule on the Use of Consumer Reviews and Testimonials prohibits fake and misleading reviews and testimonials.

We comply with that rule and treat it as the minimum standard applicable to a provider of review services.

- Every testimonial we publish comes from a real, identifiable client who actually used our services. We do not write, invent, buy, trade, or commission testimonials, and we do not publish a testimonial the named client has not approved.

- We do not create, buy, sell, or exchange reviews, ratings, followers, or engagement for ourselves or for any client, on any platform.

- We do not suppress, hide, reorder, or selectively publish reviews of our own business to make our rating look better than it is.

- We do not have employees, family members, or contractors post reviews of GoldenFlow AI without clearly disclosing that connection.

- Results shown in case studies are the actual results of the named client for the period stated. Results vary by business, and a result achieved by one client is not a prediction or a promise for another.

- We disclose any material connection between us and anyone endorsing us, including payment, free service, or a business relationship.

If you believe a testimonial or result we have published is inaccurate, tell us and we will correct or remove it.

10.5 Legal and protective disclosures

We may disclose information where we reasonably believe it is required by law, subpoena, court order, regulatory demand, or other legal process, or where necessary to establish or defend legal claims, to enforce our agreements, or to protect the rights, property, or safety of GoldenFlow AI, our clients, or the public.

10.6 Business transfers

If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. The recipient will remain bound by this policy for the information transferred, or you will be notified and given a choice as required by law.

10.7 With your direction

We will share information at your request or with your written consent.

10.8 What we never do

We do not sell personal information, and we do not share personal information for cross context behavioral advertising, as those terms are defined under United States state privacy laws. We have not done so in the preceding twelve months. We do not sell or trade personal information to data brokers, lead generators, or third party marketers. Mobile phone numbers and text message consent records are never shared for marketing purposes under any circumstance.

We do not knowingly sell or share the personal information of anyone under sixteen.

11. Third party platform disclaimer

Our services connect to platforms we do not control, including Google, Facebook, Yelp, and other review and social networks.

Those platforms operate independently and may remove, filter, delay, reorder, or modify reviews at their sole discretion. GoldenFlow AI, Reviews, and Local SEO cannot guarantee that any review will appear, remain visible, or remain permanent on a third party platform. We cannot guarantee any specific review count, star rating, search ranking, or map position, all of which are determined by the platform.

Those platforms may also change their policies, pricing, or availability at any time, which may affect what we are able to deliver. We will tell you if a change materially affects your service.

12. How long we keep information

- Inquiries that do not become clients - Typically up to 24 months from last contact, then deleted or anonymized, unless needed for an active dispute.

- Prospect log entries about businesses - Until you ask us to remove the business, or until the record is stale.

- Client records, agreements, and project files - At least 4 years after the engagement ends, for tax, accounting, and legal purposes

- Billing and tax records - As required by federal and Illinois law, generally 7 years

- Text message consent and opt out records - For the life of the program and at least 4 years after, because we must be able to prove consent and must keep honoring an opt out.

- Card tap records - Running history while the client is active, then aggregate. No name, no raw IP address.

- Customer contact data and files uploaded by a client - Retained for the life of the account, not automatically deleted. Returned or deleted on the client's request. See Section 13.1

- Marketing contact information - Until you opt out or ask for deletion.

- Website analytics - Aggregated and anonymized, retained indefinitely.

Backups. Information may persist in encrypted backups and archives for a limited period after deletion from active systems, typically up to 90 days, after which it is overwritten on the normal backup cycle. Deleted information is not restored to active use.

Where you ask us to delete information, we will do so unless we are required or permitted to keep it, in which case we will tell you why and delete the rest.

The periods above describe the criteria we apply and the outcomes we work toward. They are not a guarantee about any individual record, and a period may be extended where required by law, needed to resolve a dispute, or necessary to enforce an agreement.

13. Information we handle on behalf of a client business

When a business engages us, we handle information about that business's own customers so we can deliver the service. This typically includes customer first and last name, mobile number, email address, service or visit date, message history, survey responses, and public review content and star rating.

Our commitments in this role:

- We process this information only on the client's documented instructions and only to deliver the agreed services.

- We do not use it for our own marketing.

- We do not sell it, and we do not disclose it except to the service providers listed in Section 10.1 or as required by law.

- We do not use it to train third party artificial intelligence models.

- Opt outs are honored immediately and permanently.

- On termination we return or delete it at the client's direction, subject to Section 13.1 and to legal retention requirements.

13.1 Uploads and files are retained, not automatically deleted

Files, contact lists, and records a client uploads to us are retained for the life of the account and are not deleted automatically. They are not purged on a schedule, they are not removed when a contact is marked inactive, and removing a contact from an active list does not erase the underlying upload.

We retain them because they constitute the record of what was sent, to whom, and on whose instruction. That record enables us to reconstruct an account, to respond to a billing or performance dispute, and to demonstrate the consent basis for a message in the event it is challenged.

This retention practice is subject to two qualifications:

1. It does not mean we refuse deletion requests. A client may direct us to delete their uploads at any time, and we will do so, subject to the limits described below. Deletion occurs on request rather than automatically.

2. It does not mean a suppression record disappears. If an individual opts out, we delete or restrict their contact information but permanently retain a minimal suppression record, typically a hashed identifier and the opt out date, so that person is never messaged again. Deleting the suppression record would defeat the opt out, so it is retained even where the rest is removed.

Where a deletion request conflicts with a legal retention obligation, an active dispute, or the need to preserve consent and opt out proof, we retain only what is necessary for that purpose, delete the rest, and tell the requester what was kept and why.

13.2 Client responsibility for customer data

Clients using our services may upload or transmit customer contact information so we can send review invitations and related communications on their behalf.

Clients represent and warrant that they have obtained all permissions, consents, and legal authority required by applicable law, including the Telephone Consumer Protection Act and applicable state law, to contact those individuals by text message, email, or other electronic means, and that no individual on any list provided has revoked consent or asked not to be contacted.

During onboarding, and each time contact information is provided, clients are required to confirm that appropriate consent was obtained and to describe how it was obtained.

GoldenFlow AI does not independently verify how customer contact information was obtained and relies on the client's representations that it was collected lawfully. A client who provides contact information without valid consent is responsible for the consequences, as set out in our client service agreement.

13.3 Review requests and Google policy

We follow Google's review policies without exception:

- Where we operate a customer care channel or service recovery path, it runs in parallel with the public review request and never determines who is asked for a public review.

- We never offer or permit an incentive of any kind in exchange for leaving a review.

- We never write, script, or dictate the content of a customer's review.

A review request stops only upon an opt out, a review already left, a client instruction to exclude a specific individual for a reason unrelated to predicted sentiment, or a technical failure. None of these constitutes a sentiment screen, and we do not implement sentiment screening at a client's request.

14. Legal bases for processing

We process personal information where we have a valid legal basis, including:

- Performance of a contract, to deliver services you engaged us for

- Legitimate business interests, such as business to business outreach, service improvement, security, and fraud prevention, where not overridden by your rights

- Legal compliance, where processing is required by law

- Consent, where you have given it, such as for marketing text messages, which you may withdraw at any time

15. Security

We take reasonable technical and organizational measures appropriate to the size of our business and the sensitivity of the information, including:

- Encryption of data in transit, and encryption at rest through our platform providers

- No data store, database, storage bucket, or file location we control is configured for public access. Databases run with row level security enabled and no public read policies. File storage is private by default. Nothing is reachable by anonymous request or by guessing a URL

- Database and API keys are held server side only and are never delivered to a browser

- Administrative dashboards require authentication, use signed session cookies, and rate limit failed login attempts

- Multi factor authentication on business accounts wherever available

- Credentials stored in a password manager, never in plain text documents or in code

- Server side handling of database keys, which are never exposed to a browser

- One way hashing of IP addresses in card tap logs, so raw addresses are not retained

- Access limited to authorized personnel with a demonstrated need to know, including any contractor engaged under a written confidentiality obligation

- Use of established third party platforms with their own security programs

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and any required authority in accordance with the Illinois Personal Information Protection Act and other applicable law.

16. Your privacy rights

Depending on where you live, you may have some or all of the following rights regarding personal information we hold as a controller:

- Know and access. Confirmation of whether we process your personal information, the categories involved, the sources, the purposes, the categories of recipients, and a copy.

- Correct. Correction of inaccurate personal information.

- Delete. Deletion, subject to legal retention obligations.

- Portability. A copy in a portable, machine readable format.

- Withdraw consent. At any time, where processing is based on consent.

- Opt out of sale, sharing, and targeted advertising. We do not engage in these activities, so there is nothing to opt out of, but the right is stated for completeness.

Opt out of marketing. Unsubscribe from any marketing email, reply STOP to any text, or tell us directly.

- Limit use of sensitive personal information. We do not collect sensitive personal information as defined by state privacy law.

- Non discrimination. We will not deny service, charge a different price, or provide a lesser quality of service because you exercised a privacy right.

16.1 How to exercise a right

Email [email protected] with the subject line "Privacy Request," call 312-344-3030, or write to us at the address in Section 22.

We will verify your identity before acting, typically by confirming information we already hold. We will respond within 45 days, and may extend once by another 45 days where reasonably necessary, in which case we will tell you before the first period ends.

16.2 Authorized agents

You may use an authorized agent. We will require written authorization from you and will verify your identity directly.

16.3 Appeals

Several state privacy laws require businesses to offer an appeal. We offer it to everyone, including residents of states whose law does not require it.

If we decline a request, you may appeal by replying to our decision with the subject line "Privacy Appeal" within 60 days. We will respond in writing within 45 days with our decision and our reasons. If we deny the appeal, you may contact your state Attorney General. Illinois residents may contact the Office of the Illinois Attorney General, Consumer Fraud Bureau.

16.4 California residents

Categories of personal information collected in the preceding twelve months: identifiers, customer records information, commercial information, internet or network activity, approximate geolocation, and inferences drawn to size and price an offer. Sources, purposes, and recipient categories appear in Sections 3, 4, and 10. We have not sold or shared personal information in the preceding twelve months and we do not do so now. We have no actual knowledge of selling or sharing the personal information of consumers under sixteen. Additional detail is in our California Privacy Rights notice.

16.5 Nevada residents

Nevada law allows residents to opt out of the sale of certain covered information. We do not sell covered information, but you may submit a request to the contact in Section 22.

17. Illinois specific matters

Illinois has not enacted a comprehensive consumer privacy statute of the kind in force in California, Virginia, Colorado, Texas, and other states. The rights described in Section 16 are offered to everyone as a matter of our policy, and separately are legal rights for residents of states that have enacted such laws. Illinois does have several targeted statutes that apply to us:

- We are an Illinois limited liability company and we comply with the Illinois Personal Information Protection Act, including its breach notification requirements.

- We do not collect, capture, purchase, receive, store, or disclose biometric identifiers or biometric information as defined in the Illinois Biometric Information Privacy Act. We do not use facial recognition, fingerprint scanning, or voiceprints.

- Where the Illinois Automatic Contract Renewal Act or a comparable automatic renewal law applies, we comply with it. Because our agreements are generally business to business, the application of any particular statute depends on the contract at issue. We apply the practices set out in Section 18 to every client regardless.

18. Free trials, automatic renewal, and cancellation

Our recurring packages open with a free trial and require a payment method at trial start. A trial converts to a paid subscription automatically at the end of the trial period unless you cancel first. This disclosure is made here, again at checkout, and again in the advance reminders described below.

18.1 What we tell you before you enter a payment method

Before you provide payment information, in the checkout itself and not in a linked document, we disclose:

- That the trial converts to a paid subscription automatically

- The length of the trial and the exact calendar date it ends

- The exact amount that will be charged, and that it recurs monthly until cancelled

- How to cancel, including the email address and phone number

- That you may cancel at any time during the trial and will not be charged

18.2 Reminders before an automatic charge

We send advance reminders before every trial converts to a paid charge. No action is required on your part to receive them.

- A written reminder, by email, at least three days before the trial ends, stating the date of the first charge and the amount, and containing cancellation instructions and a direct way to reach us

- A results summary during the trial so you can judge the service before that decision arrives

- A receipt after every charge

We also send advance notice before any change to your price or billing frequency takes effect.

18.3 Cancellation

Cancelling is at least as easy as signing up. The following terms govern cancellation of any recurring package.

- You may cancel by email to [email protected], by phone or text to 312-344-3030, or by replying to any billing message

- Cancellation is effective upon notice to us. There is no retention call, no form to complete, no cancellation fee, and no requirement to state a reason

- We will confirm your cancellation in writing

- We will not use delay, repeated offers, or additional steps to obstruct a cancellation. A single request is sufficient

Cancelling during a trial means you are never charged. Cancelling a paid subscription stops the next charge and your service continues through the end of the period you already paid for

Full terms, including any refund terms, are in your service agreement and in our Terms and Conditions.

19. Information from minors

Our own processing. Our website and services are directed to businesses and are not intended for individuals under eighteen. We do not knowingly collect personal information from anyone under sixteen. If you believe a child has provided us information, contact us and we will delete it promptly.

Programs we run for a client. Where we send messages on behalf of a client business, that business is responsible for ensuring its customer list contains only individuals it may lawfully contact, which excludes minors where consent from a parent or guardian was not obtained. We do not screen client lists for age and have no way to do so. If we are told a minor's information is in a client program, we will remove it, stop messaging that individual, and notify the client.

20. Where we operate

We are based in the United States and our services are intended for businesses in the United States. Our primary data storage is located in the United States. Some service providers, including our network and content delivery provider, operate globally and may process a request at a location near the visitor before it reaches our systems. If you access our website from outside the United States, you are transferring information to the United States, where privacy laws may differ from those in your country.

21. Communications preferences at a glance

- To stop marketing email, click unsubscribe in any message, or email us.
- To stop text messages, reply STOP to any message.
- To stop phone calls, tell us on the call, or email us.
- To stop in person visits, email us and we will remove the business from our prospect log.
- To stop use of your business in our marketing, email us and we will remove it.
- To stop all contact, email [email protected] with "Do Not Contact" in the subject.

22. Updates to this notice and how to reach us

We may update this policy. When we make material changes we will update the "Last updated" date, post the revised policy on this page, and where the change materially affects information already collected, notify affected clients by email. Continued use of our website or services after the effective date constitutes acceptance. Prior versions are available on request.

GoldenFlow AI
GoldenFlow AI, Reviews, and Local SEO LLC
1201 N La Salle Dr Apt 1307
Chicago, IL 60610
United States

Email: [email protected]
Phone: 312-344-3030
Web: goldenflowai.com

To review, update, or delete your information, email [email protected]. For security we may verify your identity before acting on a request.

Response times. A formal privacy rights request under Section 16 is answered on the timeline in Section 16.1, which is 45 days with one permitted 45 day extension. General questions about this policy are answered within 30 days. Where the two could be read to conflict, Section 16.1 controls.

GoldenFlow AI, Reviews, and Local SEO LLC, Chicago, Illinois