Skip to main content

Privacy Policy

Effective Date: July 5, 2026  ·  Last Updated: September 25, 2026

The short version: MJR Collective AI builds websites, Google and Meta marketing, outbound email campaigns, and a 24/7 AI phone receptionist for local businesses. We collect what we need to run those services, and we also collect public business contact details so we can email businesses that might want them — Section 3 explains exactly how that works and how to opt out. We do not sell personal information. The Meta pixel runs on four marketing pages only after you press “Allow”, and we treat a Global Privacy Control signal as “No”. To see, correct, or delete what we hold about you, email support@mjrcollectiveai.com.

Jump to section

Who We Are & Our Role

This policy is from MJR Collective LLC, doing business as MJR Collective AI, of Springfield, Virginia, United States ("MJR", "we," "us," or "our"). We sell a modular growth system to local businesses:

We wear two hats

When we decide how data is used (we are the "controller"). This covers you if you visit mjrcollectiveai.com, fill in one of our forms, call or message us, receive an email from our own outreach, or hold an account with us. This policy governs that data.

When we act for a client (we are a "processor" or "service provider"). When a business that uses our services has us answer its phone, host its website, run its website chat, run its outreach, or store its leads, the personal information of that business's customers and contacts belongs to that business. We process it only on the business's instructions, under the data-processing terms in our Terms of Service. If you called, messaged, or booked with one of our clients, that business's own privacy policy applies, and requests about that data should go to the business. If you send one to us, we will pass it to the business and help it respond.

What We Collect & What We Don't

What We Collect

  • Contact details you give us: name, business name, city or state, email, and phone (audit, booking, get-started, and review forms)
  • The version and date of the consent wording you agreed to on a form
  • Public business information: website address, listings, ratings and review counts (for audits and prospecting — see Section 3)
  • Client account data: login email, hashed password, role, plan, settings, and access tokens for accounts you connect (for example Google Business Profile or a Facebook Page)
  • Billing records: plan, invoices, and payment status (card details stay with Stripe)
  • Calls answered by the AI receptionist: caller number, name if given, reason for calling, booking preferences, the recording, a transcript, and an AI summary
  • Website chat conversations on sites we host
  • Messages and comments sent to our Facebook Page or Instagram account
  • Emails you send us, including replies to our outreach
  • Visit logs on client websites we host: an anonymous session ID, the page viewed, and the time
  • Security logs: login email, IP address, success or failure, and time
  • Meta pixel events on four marketing pages — only after you allow it (Section 8)

What We Do NOT Collect

  • Social Security numbers or government ID numbers
  • Bank account numbers or full card numbers (Stripe handles cards)
  • Precise GPS location from your device
  • Voiceprints — we never use call audio to identify who someone is
  • Your social media passwords or your personal contact lists
  • Personal information we know belongs to a child under 18
  • Consumer lists bought from data brokers

Where it comes from: directly from you; from your use of our sites and phone lines; from public sources (Section 3); from Meta when you message our Page or Instagram account; from Google when a client connects its Business Profile; and, when we act for a client, from that client and its customers.

Business Prospecting & Outreach

We find customers partly by contacting businesses directly. That means we hold contact details for businesses that are not our customers and never asked to hear from us. Here is how that works.

What we collect

Business name, category, address or city, public phone number, website, the business email addresses it publishes, names and titles of owners or staff where the business itself publishes them, ratings and review counts, and notes about the business's online presence (for example, whether it has a website, or whether its site works on a phone).

Where it comes from

Public sources only: Google Places and Google Maps listings, Yelp, OpenStreetMap, job boards (Adzuna), the business's own website, and public web search. We do not buy consumer lists and we do not collect from private profiles.

Why we use it

To send business-to-business email about our services — and, for clients who use our Outbound Engine, about that client's services — and to prepare free audits. We use AI to summarize the public information into short notes about each business (Section 4). Every email we send identifies who it is from, includes a mailing address, and carries a working unsubscribe link.

How long we keep it

A prospect record we never contact is deleted automatically 365 days after it was collected. Once we have emailed a business, we keep what we sent and any reply while the conversation or campaign is active, and afterwards only as long as we need it to honor opt-outs or answer questions about it. You can ask us to delete it at any time from our Data deletion page.

How to opt out

Our do-not-contact list. When you opt out, we add your email address to an internal do-not-contact list. It holds the address and the reason, and it is used only to make sure our outreach system never emails you again — even if your address turns up later in a public source. An opt-out from any campaign we run, ours or a client's, stops all email from our outreach system to that address.

AI Features

AI phone receptionist. Our own line and our clients' lines can be answered by an AI voice assistant. It tells callers at the start of the call that it is an AI assistant and that the call may be recorded, and it answers honestly if asked. Calls are recorded, transcribed, and summarized so the business can follow up. If you would rather not be recorded, you can hang up and email instead, or ask the assistant to take a short message.
Website chat. An AI assistant answers questions on our site and on client sites we host. We store the conversation so the business can follow up; the conversation text is erased after 180 days.
AI-drafted email. We use AI to help draft replies to emails we receive and to write outreach messages. Drafts are produced and reviewed under our written policies before they are sent — no invented facts, no guarantees, no pricing promises.
AI summaries of public business data. Our free audits and prospect notes are AI-written summaries of public information about a business. They can be wrong; tell us and we will fix them.

We do not use AI to make decisions about individuals that have legal or similarly significant effects. We do not train our own AI models on your data. Our AI providers (Section 6) process text and audio for us under their business terms.

Calls & Texts

Your consent. Our forms ask for your permission before we call or text you. By submitting a form that shows this notice, you agree that MJR Collective AI may call or text you at the number you provide about your request, including with automated technology and AI-generated or prerecorded voice. Consent is not a condition of purchase. We store which version of that wording you saw and when. You can withdraw it at any time by telling us on a call, replying STOP to a text, or emailing support@mjrcollectiveai.com.

Call recording. Calls answered by our AI receptionist, and calls we place, may be recorded and transcribed where the law allows. We announce it at the start of the call.

Text messages. We do not run a text-message program today, so we are not sending you texts. If we start one, every program will identify us, honor STOP (to opt out) and HELP (for help) replies, follow carrier rules and the Telephone Consumer Protection Act, and say that message and data rates may apply and message frequency varies.

Business calls. We may call a business at its published business phone number about our services. Those calls are placed by a person, not an automated dialer or a recording. Ask us to stop and we will add the number to our do-not-contact list.

We never sell or share phone numbers or text consent with anyone for their own marketing.

Service Providers We Use

These companies process personal information for us so we can run the services. Each one gets only what it needs for its job. This is also our list of subprocessors for client data.

Hosting
Vercel
Hosts our websites, client websites, and our API. Keeps request logs (such as IP address and browser type) for security and reliability.
vercel.com/legal/privacy-policy →
File storage
Vercel Blob
Stores files and images used on client websites and in ad campaigns.
vercel.com/legal/privacy-policy →
Database
Supabase (PostgreSQL)
Our main database: accounts, leads, appointments, call records, prospect records, and billing status. Hosted in the United States.
supabase.com/privacy →
Payments
Stripe
Runs checkout, subscriptions, and invoices. Stripe collects and stores card details; we never see full card numbers.
stripe.com/privacy →
Telephony
SignalWire
Provides our phone numbers and routes calls to the AI receptionist. Handles caller numbers and call metadata.
signalwire.com/legal →
Email delivery
Resend
Delivers email we send, including outreach and system notifications.
resend.com/legal/privacy-policy →
Email & mailbox
Google Workspace (Gmail)
Our business mailbox. Sends audit results, lead alerts, and confirmations, and receives the emails you send us.
policies.google.com/privacy →
Voice AI
ElevenLabs
Runs the AI receptionist's voice conversations. Processes call audio and produces transcripts; its copy of call records is deleted on request (see our Data deletion page).
elevenlabs.io/privacy →
AI text
Groq
Generates AI text: audits, summaries, chat replies, and email drafts. Receives text only — never payment details or passwords.
groq.com/privacy-policy →
Business data
Google Places & Google Business Profile
Public business listing data for audits and prospecting. For clients who connect it, managing their own Business Profile through Google's API.
policies.google.com/privacy →
Business data
Yelp
Public business listing data for audits and prospecting.
terms.yelp.com/privacy →
Business data
OpenStreetMap
Public map data about businesses (name, category, location, website).
osmfoundation.org privacy →
Business data
Adzuna
Public job-board listings, which tell us which local businesses are hiring — for example, for front-desk staff.
adzuna.com →
Ads & social
Meta Platforms
The Meta pixel (only with your consent), client ad campaigns run in the client's own ad account, and messages or comments sent to our Facebook Page or Instagram account.
facebook.com/privacy/policy →
Fonts
Google Fonts
Our pages load their typefaces from Google's servers, so your browser sends your IP address and browser details to Google when a page loads.
policies.google.com/privacy →

When we add or replace a provider that handles client data, we update this list, and for a material change we email active clients first (see our Terms of Service).

How We Use Your Data

Requests you make — send your free audit, book your call, set up your trial, and answer your questions.
Running client services — host websites, answer and log calls, store leads and appointments, run ads, SEO, and outreach, when a client turns those modules on.
Prospecting — find and email businesses that might want our services (Section 3).
Notifications — lead alerts, appointment confirmations, account and billing email.
Billing — process subscriptions through Stripe and keep the records the law requires.
Security — detect and block abuse, brute-force logins, and spam.
Measuring our ads — the Meta pixel, only if you allow it (Section 8).
Improving the service — look at usage in aggregate to fix problems and improve features.
Legal — comply with the law, enforce our terms, and respond to lawful requests.

Cookies, the Meta Pixel & Your Choices

Login token — when you sign in to the client dashboard, a signed session token is stored in your browser's localStorage to keep you signed in. It is not an advertising cookie.

Accessibility preferences — if you use the accessibility toolbar, your settings (text size, contrast, and so on) are saved in localStorage under mjr_a11y.

Meta pixel — only after you allow it. Four marketing pages can load Meta's advertising pixel: the home page, /audit, /book, and /reviews. It tells us which of our ads brought someone to the site. Nothing is requested from Meta until you press “Allow” on the consent bar; press “No thanks” and the pixel never loads. No other page carries a pixel, and the client dashboard never does.

Once allowed, the pixel sets two first-party cookies on mjrcollectiveai.com: _fbp (a random browser identifier Meta uses to connect a visit to an ad; expires after about 90 days) and _fbc (set only when you arrive from a Meta ad link; stores that ad's click ID; about 90 days). What the pixel sends to Meta — page views and form submissions on those four pages — is governed by Meta's privacy policy.

Your answer is stored in your browser's localStorage under mjr_consent as granted or denied. It never leaves your browser.

Global Privacy Control. If your browser sends a Global Privacy Control (GPC) signal, we treat it as “No”: the pixel does not load on any page, even if you allowed it before, and we do not ask. We treat GPC as a valid request to opt out of the sale or sharing of personal information and of targeted advertising.

Beyond that, we do not use advertising cookies, Google Analytics, or third-party behavioral analytics. Our pages do load fonts from Google Fonts (Section 6).

When & With Whom We Share Data

We do not sell personal information, and we do not rent or trade it. We share it only in these situations:

Service providers: the companies listed in Section 6, only so they can do their job for us.

Our clients: when we act for a business, the leads, calls, chats, and bookings we handle for it go to that business.

Meta, if you allow the pixel: under California law, letting an ad platform's pixel collect browsing activity for advertising can count as "sharing" for cross-context behavioral advertising, even though no money changes hands. It only happens after you press “Allow”, never under Global Privacy Control, and you can turn it off with Cookie settings.

Legal requirements: when required by law, court order, or government authority, or to protect the rights, property, or safety of MJR, our clients, or the public.

Business transfers: if MJR is acquired or merges with another company, data may transfer as part of that deal. We will email you before your data becomes subject to a different privacy policy.

With your consent: for any other purpose you agree to.

How Long We Keep Data

We keep data only as long as we need it. These are the windows our systems apply:

DataHow long
Call transcripts180 days, then the transcript text is erased. The call's date, length, and short summary stay with the client's account for its call history and billing.
Website chat transcripts180 days, then the conversation text is erased.
Site-visit logs on client websites180 days, then deleted.
Login and security logs90 days, then deleted.
Prospect records we never contact365 days, then deleted.
Customer account dataFor the life of the account, plus 90 days after it closes (so you can come back or ask for an export), then deleted.
BackupsRolling backups are kept for 14 days, so deleted data is gone from backups within 14 days.
Billing records and signed agreementsAs long as tax and contract law require — typically 7 years for financial records.
Consent records (form consent, IP, user agent, page)4 years (TCPA evidence).
Do-not-contact listKept for as long as we run outreach, so we never contact you again (Section 3).

Recordings and transcripts held by ElevenLabs follow the retention settings on our ElevenLabs account and are deleted there on request. To ask us to delete your data sooner, see our Data deletion page.

Security

These are the measures we actually have in place:

Encrypted in transit
Our sites and API are served over HTTPS/TLS only, with HSTS.
Hashed passwords
Passwords are stored as bcrypt hashes, never in plain text.
Role-based access
Client accounts see only their own business's data; admin tools require an admin role.
Rate limiting
Our API limits request rates, and accounts lock temporarily after repeated failed logins.
Least-privilege database roles
Background jobs connect with a restricted database role rather than full owner access.
Regular backups
The database is backed up on a schedule, and backups roll off after 14 days.

No system is perfectly secure. If you find a security problem, please report it to support@mjrcollectiveai.com.

Your Privacy Rights

Wherever you live, you can ask us to:

Know & access
Tell you what we hold about you and give you a copy.
Correct
Fix information that is wrong or incomplete.
Delete
Delete your personal information (see Data deletion).
Portability
Give you your data in a common, machine-readable format.
Opt out
Stop outreach email, turn off the pixel, and opt out of any sale, sharing, or targeted advertising.
No discrimination
We will not treat you differently for using any of these rights.

How to ask: email support@mjrcollectiveai.com with the subject "Privacy Request", or call (571) 356-3125. We confirm we received it within 10 business days and answer within 45 days. If we need more time (up to another 45 days), we will tell you why before the first 45 days are up. We verify requests by matching the details you give us to what we hold, and we only ask for what we need to do that. You can use an authorized agent; we will ask for your signed permission and may confirm directly with you.

If your request is about data we hold for one of our clients (Section 1), we will send it to that business and help it respond.

California Residents (CCPA / CPRA)

We honor the rights below for California residents whether or not the California Consumer Privacy Act technically applies to a business of our size.

Categories we collected in the last 12 months

We use each category for the purposes in Section 7, disclose it to the service providers in Section 6 for business purposes, and keep it for the periods in Section 10.

Sale and sharing

We do not sell personal information. The only "sharing" for cross-context behavioral advertising is the Meta pixel (identifiers and internet activity), and only after you allow it. We do not knowingly sell or share the personal information of anyone under 16.

Your rights

How to exercise them: email support@mjrcollectiveai.com with the subject "Privacy Request" or call (571) 356-3125. We respond within 45 days, as described in Section 12.

Virginia Residents (VCDPA)

We are a Virginia company, and we honor the Virginia Consumer Data Protection Act rights for Virginia residents whether or not the Act technically applies to a business of our size.

Categories we process: the categories listed in Section 13, for the purposes in Section 7, shared with the categories of third parties in Section 6. We do not process sensitive data as defined by Virginia law except account login credentials, and we do not sell personal data.

Your rights: to confirm whether we process your personal data and to access it; to correct it; to delete it; to get a portable copy; and to opt out of targeted advertising (the Meta pixel), the sale of personal data, and profiling that produces legal or similarly significant effects (we do not do that kind of profiling).

How to exercise them: email support@mjrcollectiveai.com with the subject "Privacy Request". We respond within 45 days, and may extend once by another 45 days when reasonably necessary, telling you why.

Appeals: if we decline to act on your request, you can appeal by replying to our decision or emailing support@mjrcollectiveai.com with the subject "Privacy Appeal". We will answer in writing within 60 days of receiving your appeal, explaining what we did and why. If we deny your appeal, you can contact the Virginia Attorney General at oag.state.va.us — File a Complaint.

Children's Privacy

Our services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from children. If we learn we have, we delete it. If you think we hold a child's data, email support@mjrcollectiveai.com.

Data Breach Notification

If we confirm a breach that affects your personal information, we will notify you without unreasonable delay and within the time the law requires. We aim to notify affected clients within 72 hours of confirming it. The notice will say what happened, what data was involved, what we are doing about it, and what you can do. Where required, we also notify regulators.

Retired Legal-Industry Services

We previously offered tools for legal-industry clients: AI intake, demand letter drafting, and AI medical record summaries. These tools are retired and disabled. Their historical records have been deleted, or are retained only where the law requires us to keep them, and are not used for anything else. Former legal-industry clients with questions can email support@mjrcollectiveai.com.

Visitors Outside the United States

Our services are for businesses in the United States. They are not directed to people in the European Economic Area, the United Kingdom, or Switzerland, and we do not market to them. Our systems and providers are in the United States, so if you contact us from another country, your information is processed in the United States under this policy.

Updates to This Policy

We update this policy when our services or the law change. The "Last Updated" date at the top always shows the current version. For material changes, we email active clients at least 14 days before the change takes effect.

Contact Us

Questions or requests about this policy or your data:

MJR Collective LLC, doing business as MJR Collective AI

Email: support@mjrcollectiveai.com

Phone: (571) 356-3125

Mail: MJR Collective LLC, Springfield, VA 22150

Website: mjrcollectiveai.com

Use the subject line "Privacy Request" for privacy requests.