Amass Clientele - Privacy Policy

Amass Clientele, LLC ("Amass Clientele," "we," "us," or "our") provides an AI-operated marketing platform and managed marketing services. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit amassclientele.com and its subdomains (the "Site"), use the ACAI platform and client portal (the "Platform"), or interact with communications and campaigns operated through our services (collectively, the "Services").


This Policy addresses three groups:

  • Visitors — people who browse the Site or interact with our own marketing.
  • Clients — businesses (and their authorized users) that subscribe to the Services.
  • End Users — individuals, such as our Clients' customers and leads, who interact with campaigns, phone lines, texts, chats, forms, or booking flows that we operate on a Client's behalf.


Our role for End User data. When we process End Users' information as part of operating campaigns and systems for a Client, we act as a service provider/processor on that Client's behalf. The Client is responsible for its own privacy notices and legal bases. If you are an End User seeking to exercise privacy rights over data we hold for a Client, we will route your request to that Client and assist them in responding.


1. Information We Collect

From Clients directly: name, email, phone, business name and address, billing information (processed by our payment processors — we do not store full card numbers), account credentials, business profile details (services, service areas, pricing, offers, brand assets, scheduling rules), integration credentials and tokens, and communications with us including support requests and survey responses.

From End Users through Client campaigns: contact details and inquiry content submitted through forms, chats, texts, emails, and calls; call recordings and transcriptions where recording is used (with disclosure as required by law); appointment and booking details; lead status and outcome data; and communication metadata (numbers, timestamps, duration, delivery status).

From connected third-party services (at a Client's direction): CRM records, calendar availability and event metadata, ad-account performance data, analytics data, business-profile and review data, and messaging delivery data.

Automatically: IP address, device and browser information, pages viewed, links clicked, referring URLs, session identifiers, and usage patterns, collected via cookies, pixels, SDKs, and similar technologies. See Section 5.

From other sources: public business information, data providers and lead-enrichment services, ad platforms, and social networks, which we may combine with information we hold.


2. How We Use Information

We use information to: provide, operate, secure, and support the Services; generate analyses and marketing growth plans; run campaigns, communications, scheduling, and follow-up on Clients' behalf; process payments and manage accounts; personalize content; monitor performance and produce reporting; develop and improve our services, systems, and models, including in de-identified and aggregated form; communicate service notices and, with any legally required consent, marketing; enforce agreements and prevent fraud and abuse; and comply with law.

AI processing. The Services use artificial-intelligence systems, operating under human oversight, to analyze inputs, generate plans and content, converse by chat or voice where deployed, and optimize campaigns. Automated systems that interact with people are identified as automated where required by law. Recorded calls are disclosed at the start of the interaction where required.

De-identified data. We may de-identify or aggregate information so it no longer reasonably identifies a person or business, use it for any lawful purpose including benchmarks and model improvement, and maintain it in de-identified form without attempting re-identification.


3. How We Share Information

We do not sell personal information for money. We share information only:

  • With service providers and technology partners that host, power, or help fulfill the Services — including cloud infrastructure, the marketing-automation and AI platforms underlying ACAI, telephony and messaging carriers, payment processors, analytics providers, and creative and fulfillment vendors — under contracts limiting their use of the information to providing services to us.
  • With third-party platforms at a Client's direction — for example ad networks, CRMs, calendars, and review platforms a Client connects — governed by those platforms' terms and policies.
  • Between a Client and its End Users — information an End User submits through a Client's campaign is shared with that Client; it belongs to the Client's relationship with its customer.
  • For legal reasons — to comply with law, subpoena, or legal process; to enforce our agreements; or to protect the rights, safety, or property of any person or of the Services.
  • In a business transfer — in connection with a merger, acquisition, financing, or sale of assets, with notice as required by law.
  • With your consent.

Advertising cookies. If we use advertising pixels or similar technologies on the Site, that activity may constitute "sharing" for cross-context behavioral advertising under California law. You can opt out as described in Sections 5 and 8.

Text-messaging consent data. No mobile information, text-messaging originator opt-in data, or SMS consent will be shared with, sold, rented, or disclosed to third parties or affiliates for their own marketing or promotional purposes. We share this information only with service providers that operate our messaging programs and systems.


4. Google User Data

If a Client connects a Google account (for example, Google Calendar or Google Business Profile), we access only the data needed for the connected functionality — such as checking availability and creating, modifying, or deleting events for scheduling workflows — transmit it over encrypted connections, do not use it for advertising, and do not sell it. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Clients may disconnect Google integrations at any time from their account settings.


5. Cookies and Tracking

We use essential cookies (required for the Site and Platform to function), analytics cookies (to understand usage and improve the Services), preference cookies, and — where deployed — advertising cookies and pixels (to measure and improve our own marketing). You can manage cookies in your browser settings; disabling some cookies may affect functionality. Where a cookie-consent or "Your Privacy Choices" control is presented on the Site, you can use it to opt out of non-essential cookies and of any "sharing" for advertising. We honor Global Privacy Control (GPC) signals as an opt-out of sale/sharing where required by law.


6. Data Security

We use commercially reasonable safeguards, including encryption in transit (TLS 1.2+) and at rest (AES-256) for sensitive data, least-privilege access controls, credential and secret management, monitoring, and an incident-response process with breach notification as required by law. No system is perfectly secure; please protect your credentials and notify us of suspected unauthorized access.


7. Retention

We retain: Client account records for the duration of the relationship and a reasonable period after for legal, tax, and record-keeping purposes; End User campaign data (including recordings and transcripts) per the Client's settings and instructions and applicable law; and analytics data for standard tool retention periods. Upon account termination, Client business data is exportable for 30 days and then deleted in the ordinary course, subject to law and backup cycles. We may retain de-identified data indefinitely.


8. Your Privacy Rights

Depending on your residence, you may have rights to: know or access the personal information we hold about you; obtain a copy in a portable format; correct inaccurate information; delete personal information; opt out of sale or sharing of personal information; limit use of sensitive personal information; and not be discriminated against for exercising rights.

California (CCPA/CPRA). In the last 12 months we have collected the categories described in Section 1 (identifiers; commercial information; internet activity; audio recordings where calls are recorded; professional information; and inferences used for service delivery), from the sources and for the purposes described above, and disclosed them for business purposes to the categories of recipients in Section 3. We do not sell personal information for money and do not knowingly sell or share the personal information of anyone under 16; if we "share" information for cross-context behavioral advertising via cookies, you may opt out via the Site's privacy controls or GPC. To exercise rights, email info@amassclientele.com with "Privacy Request" in the subject; we will verify your identity and respond within the time required by law. You may use an authorized agent as permitted by law.

End Users: if your data relates to a campaign we ran for one of our Clients, we will forward your request to that Client and support their response, as their service provider.

Other jurisdictions. Residents of other U.S. states with comprehensive privacy laws, and of the EEA/UK or Canada where those laws apply, may exercise the rights those laws provide by contacting us; where GDPR applies, our legal bases are contract performance, legitimate interests, consent, and legal compliance, and you may lodge a complaint with your supervisory authority.


9. Communications Choices

You may opt out of our marketing emails via the unsubscribe link in any message, and of our texts by replying STOP (HELP for help). Transactional and account messages continue as needed to serve you. Note that opting out of our marketing does not affect campaigns we run for Clients you do business with — direct those choices to the business that contacted you, or reply STOP to its messages.


10. Children

The Services are for business use and are not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 for sale/share purposes). If you believe a child has provided us information, contact us and we will delete it.


11. International Transfers

We are based in the United States and process information in the U.S. and in other countries where our service providers operate. Where required, we use appropriate safeguards for cross-border transfers. By using the Services you understand your information may be processed in jurisdictions with different data-protection laws than your own.


12. Third-Party Sites

The Site and Services may link to third-party websites and services we do not control. Their privacy practices are their own; review their policies.


13. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new "Last Updated" date and, for material changes, notify active Clients by email or in-Platform notice. Continued use after the effective date constitutes acceptance.


14. Contact

Amass Clientele, LLC · info@amassclientele.com · amassclientele.com · 427 Mendocino Avenue STE 100, Santa Rosa, CA 95401