Cirqley LLC ("Cirqley," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit cirqley.com (the "Website"), use the Cirqley billing portal (the "Billing Portal"), communicate with us, or engage our digital marketing services (the "Services"). It also describes the choices and rights you have regarding your information.
This Privacy Policy applies to information we handle as a business, acting as a controller or business under applicable privacy law, about visitors to the Website, prospective clients, our clients, and our clients' authorized representatives.
This Privacy Policy does not apply to information we process on behalf of a client while performing the Services, where we act as a service provider or processor. That situation is addressed in Section 12.
By using the Website, the Billing Portal, or the Services, you acknowledge that you have read and understood this Privacy Policy.
When you visit the Website or the Billing Portal, we and our providers automatically collect:
We may receive information about you from:
The following table describes the statutory categories of personal information we have collected in the preceding twelve months and the categories of parties to whom we disclose each category for a business purpose.
| Category | What we collect | Disclosed to |
|---|---|---|
| Identifiers | Name, email address, phone number, mailing address, IP address, device identifiers, cookie identifiers | Service providers, advertising and analytics partners |
| Customer records and commercial information | Billing contact details, transaction and invoice records, payment method type and last four digits, service and engagement history | Service providers, payment processor, professional advisors, collection agencies where applicable |
| Internet or network activity | Pages viewed, clicks, referring URLs, session data, Billing Portal access and activity logs | Service providers, advertising and analytics partners |
| Geolocation data | Approximate city and region derived from IP address. Not precise location | Service providers, analytics partners |
| Professional or employment information | Company or firm name, job title, practice area, and recruiting information you submit | Service providers |
| Audio, electronic, or visual information | Emails, text messages, chat transcripts, uploaded documents and images | Service providers |
| Inferences | Engagement and interest inferences used to measure marketing performance | Advertising and analytics partners |
| Sensitive personal information | Bank account and routing details, where you choose to pay by bank debit. See Section 2.5 and Section 6.2 | Payment processor only |
We do not seek out sensitive personal information as that term is defined under California law, and we do not collect government identification numbers, precise geolocation, racial or ethnic origin, religious beliefs, health information, or biometric data.
One exception applies. If you choose to pay by bank debit, the bank account and routing numbers you enter constitute financial account information. That information is transmitted directly to our payment processor and is not stored on Cirqley systems. We retain only a token reference and the last four digits. We do not use this information for any purpose other than processing the payments you have authorized, and we do not use or disclose it for the purpose of inferring characteristics about you.
If you voluntarily provide other sensitive information to us, we will handle it in accordance with this Privacy Policy and will not use it for advertising.
We use the information we collect for the following business purposes:
We do not sell your personal information in exchange for money. However, because we use advertising cookies and pixels as described in Section 5, some uses of your information may qualify as a sale or as sharing under California law for cross context behavioral advertising purposes. See Section 10.2 for your opt out rights.
We disclose your information only in the circumstances described in this Section 4.
Card, digital wallet, and bank payments are processed by Braintree, a service of PayPal, Inc. Information you submit at the payment step is collected and processed by Braintree and PayPal under their own terms and privacy policies, and PayPal handles that information as an independent controller for its own compliance, risk, and fraud prevention purposes. See Section 6.
If a charge is disputed, reversed, or returned, we may disclose the executed Statement of Work, invoices, receipts, correspondence, service delivery records, campaign reporting, and platform activity records to your bank, your card issuer, the applicable card network, Braintree, PayPal, any acquiring bank, and any mediator or arbitrator, in each case as reasonably necessary to respond to the dispute. This disclosure is described in our Terms of Service.
As described in Section 5, third party cookies and pixels on the Website allow advertising partners to collect information about your visit and to serve advertisements to you on other sites. Under California law this constitutes sharing of personal information for cross context behavioral advertising.
If an account becomes past due and is not resolved, we may disclose your billing and account information to a third party collection agency, and we may report the delinquency to a consumer or commercial credit reporting agency to the extent permitted by applicable law. We will not report a delinquency that is the subject of a pending dispute properly raised under our Terms of Service until that dispute is resolved.
We share information with our accountants, auditors, attorneys, and insurers, under obligations of confidentiality.
We may disclose information in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to reasonable confidentiality protections.
We may disclose information when we believe disclosure is required by law, court order, subpoena, or governmental request; to enforce our Terms; to protect the rights, property, or safety of Cirqley, our clients, our users, or the public; or to investigate fraud or a security incident.
We will otherwise disclose information where you ask us to or agree that we may.
We do not sell personal information for monetary consideration. We do not disclose mobile phone numbers or text message consent records to third parties or affiliates for their marketing or promotional purposes. See Section 8. We do not disclose information we process on behalf of a client except as that client instructs. See Section 12.
We and our providers use cookies, web beacons, pixels, tags, local storage, and similar technologies, referred to collectively as Cookies, to operate and improve the Website, measure performance, and deliver advertising. Cookies are deployed in part through Google Tag Manager.
Most web browsers let you control Cookies through browser settings. You can also:
Disabling Cookies may impair some features of the Website.
Our Website does not currently respond to browser Do Not Track signals, because there is no common industry standard for interpreting them. We do honor the Global Privacy Control signal as a valid request to opt out of the sale or sharing of personal information for cross context behavioral advertising, for users in states whose laws require us to recognize it.
Card and digital wallet payments are collected, tokenized, transmitted, and stored by Braintree, a service of PayPal, Inc., under Braintree's and PayPal's own terms and privacy policies. We do not collect, process, or store full payment card numbers or card verification values on our own systems. We retain a token reference, the payment method type, the card brand, the last four digits, and the expiration date, for account administration, invoicing, and payment dispute response.
Where you have authorized recurring charges, we and Braintree may use card network account update services to receive and apply updated card credentials automatically when your card is reissued or replaced, so that authorized charges continue without interruption.
If you choose to pay by bank debit, the account and routing numbers you enter are transmitted directly to Braintree for tokenization and verification. We do not store the full account or routing number. We retain a token reference and the last four digits.
Before a bank account can be debited, Braintree must verify it. Verification may involve checking the account details against banking and consumer report data, or depositing two small amounts into the account for you to confirm. You should be aware that this verification may involve a consumer report obtained by Braintree or its verification provider about the account. If a verification is declined on the basis of consumer report data, we will provide you with the notice and the provider contact details required so that you can obtain a copy of that report and dispute its accuracy with the provider.
We also retain a record of the bank debit authorization you accept at the payment step, including its text, the date, and the account identifiers shown in it, because we are required to be able to produce that authorization on request.
We retain records of your Billing Portal activity, including login times, the IP address used, changes to a payment method, and each acceptance of our Terms of Service or of a payment authorization, together with the date, time, and version accepted. These records exist to administer your account, to secure the Billing Portal, and to evidence the authorizations you have given. You are responsible for safeguarding your credentials and for managing who at your organization has access.
At the payment step we and Braintree may collect device and browser signals, such as device configuration, browser characteristics, and a device identifier, for the purpose of detecting and preventing payment fraud. This information is used for fraud prevention and security only. It is not used for advertising.
We may retain information longer where required by law, necessary to resolve a dispute, or appropriate to enforce our agreements.
Cirqley may send text messages to clients and authorized client contacts as part of our Cirqley Client Care program. This Section 8 supplements the text message terms in our Terms of Service.
We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Measures include encryption of data in transit using TLS, access controls, least privilege principles for personnel, multifactor authentication on administrative accounts where available, and vendor agreements that require reasonable security. Payment card and bank account data is handled by our payment processor rather than by us, which reduces the amount of sensitive payment data in our environment.
No method of electronic transmission or storage is completely secure. While we use commercially reasonable measures, we cannot guarantee absolute security. If a security incident affects your information, we will notify you and any applicable regulator as required by law.
You are responsible for maintaining the security of any credentials you use to access our systems, including the Billing Portal, and for promptly notifying us at info@cirqley.com of any suspected unauthorized access.
Regardless of where you live, you may:
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
To opt out of that sharing, you may use any of the following methods:
Cirqley is based in Washington State. The Washington My Health My Data Act regulates the collection and sharing of consumer health data. Cirqley does not collect, use, or share consumer health data as defined by that Act, and we do not sell consumer health data. We do not maintain a separate consumer health data privacy policy because we do not collect that category of information. If our practices ever change, we will publish the separate notice that the Act requires before collecting any such data.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, and other states with comprehensive privacy laws have similar rights, including the rights to access, correct, and delete personal information, to obtain a portable copy of it, and to opt out of targeted advertising and the sale of personal information. To exercise these rights, contact us at info@cirqley.com.
If we deny your request, you may appeal by replying to our response with the word Appeal. We will respond to an appeal within the period your state's law requires and will explain the reasons for our decision. If your appeal is denied, you may contact your state attorney general to submit a complaint.
Submit a privacy request by emailing info@cirqley.com or calling 206.866.1719. We will verify your identity before responding, typically by confirming information you have previously provided to us. We will acknowledge your request promptly and will respond within 45 days, with one additional 45 day extension where permitted and where we notify you of the extension. There is no charge for a request unless it is excessive or repetitive, in which case we will tell you before proceeding.
The Website and the Services are intended for business and professional users and are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, contact us at info@cirqley.com and we will promptly delete it.
When Cirqley performs Services for a client, for example managing a client's website, CRM, lead forms, advertising campaigns, or email lists, we may collect or access personal information about that client's own end users, such as names and email addresses submitted through the client's website contact form.
With respect to that information, Cirqley acts as a service provider, processor, or agent on behalf of our client, and not as an independent controller or business. The client is the party responsible to those end users under applicable law, and the client's own privacy policy governs the collection and use of that information.
With respect to information processed on behalf of a client, Cirqley:
End users of our clients who wish to exercise privacy rights over their information should contact the client, meaning the law firm or business whose website they submitted their information through, rather than Cirqley. We will forward any such request we receive to the relevant client.
The Website may contain links to third party websites, advertisements, or integrated third party tools, including our payment processor's payment interface. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before providing information to them.
The Website and the Services are intended for users in the United States. If you access the Website from outside the United States, you acknowledge that your information will be transferred to and processed in the United States, which may have data protection laws different from those of your jurisdiction. We do not currently offer the Services to individuals in the European Economic Area or the United Kingdom, and this Privacy Policy is not intended to serve as a notice under the General Data Protection Regulation.
We may update this Privacy Policy from time to time. The Last Updated date at the top of this page reflects the most recent version. Where a change is material, we will identify it and will provide notice by posting on the Website or by email where appropriate. Your continued use of the Website or the Services after the effective date of an updated Privacy Policy constitutes acceptance of the changes. We retain prior versions of this Privacy Policy and will provide a copy of a specific prior version on request.
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, contact:
Cirqley LLC