Privacy Policy
Effective Date: July 5, 2026 · Last Updated: September 25, 2026
Jump to section
Who We Are & Our Role
This policy is from MJR Collective LLC, doing business as MJR Collective AI, of Springfield, Virginia, United States ("MJR", "we," "us," or "our"). We sell a modular growth system to local businesses:
- The Hub — a hosted business website, CRM dashboard, and lead tracking
- A 24/7 AI phone receptionist that answers calls and takes booking requests
- Meta (Facebook & Instagram) advertising, run in the client's own ad account
- SEO and Google Business Profile management
- The Outbound Engine — business-to-business cold email campaigns
- A free website and visibility audit, and an AI chat assistant on websites we host
We wear two hats
When we decide how data is used (we are the "controller"). This covers you if you visit mjrcollectiveai.com, fill in one of our forms, call or message us, receive an email from our own outreach, or hold an account with us. This policy governs that data.
When we act for a client (we are a "processor" or "service provider"). When a business that uses our services has us answer its phone, host its website, run its website chat, run its outreach, or store its leads, the personal information of that business's customers and contacts belongs to that business. We process it only on the business's instructions, under the data-processing terms in our Terms of Service. If you called, messaged, or booked with one of our clients, that business's own privacy policy applies, and requests about that data should go to the business. If you send one to us, we will pass it to the business and help it respond.
What We Collect & What We Don't
What We Collect
- Contact details you give us: name, business name, city or state, email, and phone (audit, booking, get-started, and review forms)
- The version and date of the consent wording you agreed to on a form
- Public business information: website address, listings, ratings and review counts (for audits and prospecting — see Section 3)
- Client account data: login email, hashed password, role, plan, settings, and access tokens for accounts you connect (for example Google Business Profile or a Facebook Page)
- Billing records: plan, invoices, and payment status (card details stay with Stripe)
- Calls answered by the AI receptionist: caller number, name if given, reason for calling, booking preferences, the recording, a transcript, and an AI summary
- Website chat conversations on sites we host
- Messages and comments sent to our Facebook Page or Instagram account
- Emails you send us, including replies to our outreach
- Visit logs on client websites we host: an anonymous session ID, the page viewed, and the time
- Security logs: login email, IP address, success or failure, and time
- Meta pixel events on four marketing pages — only after you allow it (Section 8)
What We Do NOT Collect
- Social Security numbers or government ID numbers
- Bank account numbers or full card numbers (Stripe handles cards)
- Precise GPS location from your device
- Voiceprints — we never use call audio to identify who someone is
- Your social media passwords or your personal contact lists
- Personal information we know belongs to a child under 18
- Consumer lists bought from data brokers
Where it comes from: directly from you; from your use of our sites and phone lines; from public sources (Section 3); from Meta when you message our Page or Instagram account; from Google when a client connects its Business Profile; and, when we act for a client, from that client and its customers.
Business Prospecting & Outreach
We find customers partly by contacting businesses directly. That means we hold contact details for businesses that are not our customers and never asked to hear from us. Here is how that works.
What we collect
Business name, category, address or city, public phone number, website, the business email addresses it publishes, names and titles of owners or staff where the business itself publishes them, ratings and review counts, and notes about the business's online presence (for example, whether it has a website, or whether its site works on a phone).
Where it comes from
Public sources only: Google Places and Google Maps listings, Yelp, OpenStreetMap, job boards (Adzuna), the business's own website, and public web search. We do not buy consumer lists and we do not collect from private profiles.
Why we use it
To send business-to-business email about our services — and, for clients who use our Outbound Engine, about that client's services — and to prepare free audits. We use AI to summarize the public information into short notes about each business (Section 4). Every email we send identifies who it is from, includes a mailing address, and carries a working unsubscribe link.
How long we keep it
A prospect record we never contact is deleted automatically 365 days after it was collected. Once we have emailed a business, we keep what we sent and any reply while the conversation or campaign is active, and afterwards only as long as we need it to honor opt-outs or answer questions about it. You can ask us to delete it at any time from our Data deletion page.
How to opt out
- Use the unsubscribe link in any email we send. It takes effect as soon as you confirm on the page it opens.
- Reply "remove me" to any of our emails.
- Email support@mjrcollectiveai.com and tell us the address to remove.
Our do-not-contact list. When you opt out, we add your email address to an internal do-not-contact list. It holds the address and the reason, and it is used only to make sure our outreach system never emails you again — even if your address turns up later in a public source. An opt-out from any campaign we run, ours or a client's, stops all email from our outreach system to that address.
AI Features
We do not use AI to make decisions about individuals that have legal or similarly significant effects. We do not train our own AI models on your data. Our AI providers (Section 6) process text and audio for us under their business terms.
Calls & Texts
Your consent. Our forms ask for your permission before we call or text you. By submitting a form that shows this notice, you agree that MJR Collective AI may call or text you at the number you provide about your request, including with automated technology and AI-generated or prerecorded voice. Consent is not a condition of purchase. We store which version of that wording you saw and when. You can withdraw it at any time by telling us on a call, replying STOP to a text, or emailing support@mjrcollectiveai.com.
Call recording. Calls answered by our AI receptionist, and calls we place, may be recorded and transcribed where the law allows. We announce it at the start of the call.
Text messages. We do not run a text-message program today, so we are not sending you texts. If we start one, every program will identify us, honor STOP (to opt out) and HELP (for help) replies, follow carrier rules and the Telephone Consumer Protection Act, and say that message and data rates may apply and message frequency varies.
Business calls. We may call a business at its published business phone number about our services. Those calls are placed by a person, not an automated dialer or a recording. Ask us to stop and we will add the number to our do-not-contact list.
We never sell or share phone numbers or text consent with anyone for their own marketing.
Service Providers We Use
These companies process personal information for us so we can run the services. Each one gets only what it needs for its job. This is also our list of subprocessors for client data.
When we add or replace a provider that handles client data, we update this list, and for a material change we email active clients first (see our Terms of Service).
How We Use Your Data
How Long We Keep Data
We keep data only as long as we need it. These are the windows our systems apply:
| Data | How long |
|---|---|
| Call transcripts | 180 days, then the transcript text is erased. The call's date, length, and short summary stay with the client's account for its call history and billing. |
| Website chat transcripts | 180 days, then the conversation text is erased. |
| Site-visit logs on client websites | 180 days, then deleted. |
| Login and security logs | 90 days, then deleted. |
| Prospect records we never contact | 365 days, then deleted. |
| Customer account data | For the life of the account, plus 90 days after it closes (so you can come back or ask for an export), then deleted. |
| Backups | Rolling backups are kept for 14 days, so deleted data is gone from backups within 14 days. |
| Billing records and signed agreements | As long as tax and contract law require — typically 7 years for financial records. |
| Consent records (form consent, IP, user agent, page) | 4 years (TCPA evidence). |
| Do-not-contact list | Kept for as long as we run outreach, so we never contact you again (Section 3). |
Recordings and transcripts held by ElevenLabs follow the retention settings on our ElevenLabs account and are deleted there on request. To ask us to delete your data sooner, see our Data deletion page.
Security
These are the measures we actually have in place:
No system is perfectly secure. If you find a security problem, please report it to support@mjrcollectiveai.com.
Your Privacy Rights
Wherever you live, you can ask us to:
How to ask: email support@mjrcollectiveai.com with the subject "Privacy Request", or call (571) 356-3125. We confirm we received it within 10 business days and answer within 45 days. If we need more time (up to another 45 days), we will tell you why before the first 45 days are up. We verify requests by matching the details you give us to what we hold, and we only ask for what we need to do that. You can use an authorized agent; we will ask for your signed permission and may confirm directly with you.
If your request is about data we hold for one of our clients (Section 1), we will send it to that business and help it respond.
California Residents (CCPA / CPRA)
We honor the rights below for California residents whether or not the California Consumer Privacy Act technically applies to a business of our size.
Categories we collected in the last 12 months
- Identifiers — name, email, phone, IP address, account login. Sources: you, our websites and phone lines, public sources.
- Customer records — billing contact details and payment status. Source: you and Stripe.
- Commercial information — plans purchased and billing history. Source: you.
- Internet or network activity — security logs, visit logs on client sites, and pixel events if you allow them. Source: your browser.
- Audio and electronic information — call recordings, transcripts, and chat conversations. Source: you.
- Professional information — business name, role, and business contact details, including for prospects. Source: you and public sources.
- Inferences — AI-written notes about a business's online presence. Source: public information.
- Sensitive personal information — only account login credentials (email and password), used solely to sign you in. We do not use sensitive information to infer characteristics about you.
We use each category for the purposes in Section 7, disclose it to the service providers in Section 6 for business purposes, and keep it for the periods in Section 10.
Sale and sharing
We do not sell personal information. The only "sharing" for cross-context behavioral advertising is the Meta pixel (identifiers and internet activity), and only after you allow it. We do not knowingly sell or share the personal information of anyone under 16.
Your rights
- Right to know and access the categories and specific pieces of personal information we hold, where it came from, why we use it, and who we disclose it to.
- Right to delete personal information we collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing — use Cookie settings, turn on Global Privacy Control, or email us.
- Right to limit use of sensitive personal information — we already use it only to sign you in.
- Right to non-discrimination — we will not deny service, charge a different price, or give a different quality of service because you used a right.
How to exercise them: email support@mjrcollectiveai.com with the subject "Privacy Request" or call (571) 356-3125. We respond within 45 days, as described in Section 12.
Virginia Residents (VCDPA)
We are a Virginia company, and we honor the Virginia Consumer Data Protection Act rights for Virginia residents whether or not the Act technically applies to a business of our size.
Categories we process: the categories listed in Section 13, for the purposes in Section 7, shared with the categories of third parties in Section 6. We do not process sensitive data as defined by Virginia law except account login credentials, and we do not sell personal data.
Your rights: to confirm whether we process your personal data and to access it; to correct it; to delete it; to get a portable copy; and to opt out of targeted advertising (the Meta pixel), the sale of personal data, and profiling that produces legal or similarly significant effects (we do not do that kind of profiling).
How to exercise them: email support@mjrcollectiveai.com with the subject "Privacy Request". We respond within 45 days, and may extend once by another 45 days when reasonably necessary, telling you why.
Appeals: if we decline to act on your request, you can appeal by replying to our decision or emailing support@mjrcollectiveai.com with the subject "Privacy Appeal". We will answer in writing within 60 days of receiving your appeal, explaining what we did and why. If we deny your appeal, you can contact the Virginia Attorney General at oag.state.va.us — File a Complaint.
Children's Privacy
Our services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from children. If we learn we have, we delete it. If you think we hold a child's data, email support@mjrcollectiveai.com.
Data Breach Notification
If we confirm a breach that affects your personal information, we will notify you without unreasonable delay and within the time the law requires. We aim to notify affected clients within 72 hours of confirming it. The notice will say what happened, what data was involved, what we are doing about it, and what you can do. Where required, we also notify regulators.
Retired Legal-Industry Services
We previously offered tools for legal-industry clients: AI intake, demand letter drafting, and AI medical record summaries. These tools are retired and disabled. Their historical records have been deleted, or are retained only where the law requires us to keep them, and are not used for anything else. Former legal-industry clients with questions can email support@mjrcollectiveai.com.
Visitors Outside the United States
Our services are for businesses in the United States. They are not directed to people in the European Economic Area, the United Kingdom, or Switzerland, and we do not market to them. Our systems and providers are in the United States, so if you contact us from another country, your information is processed in the United States under this policy.
Updates to This Policy
We update this policy when our services or the law change. The "Last Updated" date at the top always shows the current version. For material changes, we email active clients at least 14 days before the change takes effect.
Contact Us
Questions or requests about this policy or your data:
MJR Collective LLC, doing business as MJR Collective AI
Email: support@mjrcollectiveai.com
Phone: (571) 356-3125
Mail: MJR Collective LLC, Springfield, VA 22150
Website: mjrcollectiveai.com
Use the subject line "Privacy Request" for privacy requests.