Privacy
Introduction
Amplify 11, Inc., doing business as Maxed Marketing (“Maxed,” “Company,” “we,” “us,” or “our”), operates the Maxed AI Visibility platform and related websites (collectively, the “Service” or “Platform”). This Privacy Policy explains how we collect, use, disclose, and protect information in connection with the Service, including the marketing website(s) at which prospective customers first encounter us (the “Public Site”) and the authenticated application (the “App”).
1. Scope of This Policy
This Policy applies to: (a) visitors to the Public Site; (b) individuals whose information we research and use to create a pre-populated preview account before any customer relationship exists (“Prospects”); (c) registered users of the App and the individuals on whose behalf they act (“Customers” or “you”); and (d) individuals associated with businesses that are not our customers but that we independently research as part of our AI-visibility monitoring, as described in Section 4.3. It does not apply to information we process solely as a service provider/processor on behalf of a business customer under a separate Data Processing Agreement; that processing is governed by the applicable agreement between Maxed and that customer.
2. Information We Collect
We collect the following categories of personal information, as defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”). Consistent with our practice of building for the product we intend to operate rather than only the product that has existed for the past twelve months, the table below reflects both current collection and collection expected at commercial launch.
| Category | Examples | Collected | Business Purpose(s) | Whether Sold / Shared |
|---|---|---|---|---|
| A. Identifiers | Name, email, postal address, account name, IP address | Yes | Providing the Service; account administration; communications; security | Not sold. Shared for cross-context behavioral advertising via Public Site pixels only. |
| B. Customer Records (Cal. Civ. Code § 1798.80(e)) | Billing address; last four digits of payment card (via Stripe dashboard) | Yes | Billing and payment processing; fraud prevention | Not sold or shared. |
| C. Protected Classifications | Race, religion, sexual orientation, gender identity, age, etc. | No | N/A | N/A |
| D. Commercial Information | Products/services purchased or considered; subscription and usage history | Yes | Providing and improving the Service; account management; benchmarking (in de-identified, aggregated form) | Not sold or shared. |
| E. Biometric Information | Fingerprints, voiceprints, facial or retina scans | No | N/A | N/A |
| F. Internet or Network Activity | Browsing and search history on our sites; interaction with the Service, features used, log data | Yes | Operating and securing the Service; analytics; troubleshooting | Not sold. Shared for cross-context behavioral advertising via Public Site pixels only. |
| G. Geolocation Data | Approximate location derived from IP address | Yes | Security, fraud prevention, and localization | Not sold. Shared for cross-context behavioral advertising via Public Site pixels only. |
| H. Audio, Electronic, Visual Information | Recordings and transcripts of sales and onboarding calls conducted through meeting/conferencing software | Yes | Customer support, quality assurance, and service delivery | Not sold or shared. |
| I. Professional or Employment-Related Information | N/A – we do not collect information about individuals as our own employees, applicants, or contractors through the Service | No | N/A | N/A |
| J. Education Information | Records protected under FERPA | No | N/A | N/A |
| K. Inferences | Account-level anomaly and abuse-pattern indicators used for security monitoring | Yes | Security and integrity of the Service (detecting and preventing fraudulent or unauthorized activity) | Not sold or shared. |
2.1 Sources of Information
• Directly from you: when you create an account, fill out the contact form, contact support, or use the Service.
• Automatically: through cookies, log files, and similar technologies when you visit the Public Site or use the App (see Section 3).
• From our payment processor, Stripe, Inc., which provides us with billing address and the last four digits of a payment card through the Stripe dashboard. We never receive or store full payment card numbers.
• From publicly available sources, before any relationship exists, when we research a prospective customer’s business to build a pre-populated preview account (see Section 2.3).
• From meeting and conferencing software used to conduct sales and onboarding calls, which may record and transcribe those calls.
2.2 Company Information About Your Role
Our contact form and account records collect a company name, website, a description of what the business sells, and the role of the individual submitting the form. We treat this as Identifiers and Commercial Information (Categories A and D above) tied to the individual who submits it, rather than as “Professional or Employment-Related Information” (Category I), because Category I is intended to capture information about individuals in their capacity as our own personnel or job applicants, which we do not collect through the Service.
2.3 Pre-Populated Preview Accounts
Before any relationship exists between Maxed and a prospective customer, we research that business using publicly available information and build a working preview account populated with the results, which we then send to that individual by way of an invitation link. For incorporated businesses, the information we use is generally business information about the entity rather than personal information about an individual. Where the prospective customer is a sole proprietor or the research otherwise identifies a specific individual, we treat the information as personal information and provide notice of this practice at or before the point the individual first accesses the preview account, together with an accessible copy of this Policy and a means to object or request deletion before proceeding further.
2.4 Information From Platforms You Connect
The Service allows you to connect third-party marketing and business platforms to your account, including Google Analytics 4, Google Search Console, Google Business Profile, and additional platforms we add over time. When you connect a platform, we receive data from that platform through its application programming interface using only the access you authorize.
We process that data on your behalf to deliver the features you connected it to. We do not use it for advertising, and we do not sell or share it. You may disconnect any platform at any time from your account settings, and you may revoke our access directly through that platform.
A current list of the platforms available for connection, and of the subprocessors that support them, is maintained at https://maxedmarketing.ai/subprocessors.
2.5 Google API Services Limited Use
Maxed AI Visibility’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained through Google APIs, including Google Analytics 4, Google Search Console, and Google Business Profile, is used only to provide and improve the features you connected it to; is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you; is not used for advertising purposes; and is not read by humans except where you give affirmative consent, where it is necessary for security purposes such as investigating abuse, where required by applicable law, or where the data has been aggregated and de-identified.
You may revoke our access to your Google data at any time through your account settings or through the permissions page of your Google account.
3. Cookies and Similar Technologies
3.1 Public Site
The Public Site uses cookies and similar technologies, including advertising and analytics pixels, for functionality, analytics, and advertising purposes, and presents a cookie consent banner compliant with the EU General Data Protection Regulation (“GDPR”) and the ePrivacy Directive as implemented in applicable EU/EEA and UK member states.
3.2 The App
Once you are logged in, the App uses cookies and similar local storage for session authentication, security (e.g., CSRF protection), load balancing, and remembering your in-app preferences (e.g., display settings). We treat these as strictly necessary to provide the Service you have requested, and accordingly they do not require separate cookie-banner consent under Article 5(3) of the ePrivacy Directive.
We also record how signed-in users interact with the App, such as which pages are viewed, which reports are run, and which features are used, and we attribute that activity to the user account it came from. We use this for support, for security and abuse detection, and to improve the Service. We do not use it for advertising, and we do not sell or share it. Our legal basis is our legitimate interests as described in Section 4.4. You can turn this off at any time using the usage-tracking setting in your account, and turning it off does not affect your ability to use the Service.
3.3 Advertising and Analytics Pixels
Pixels placed on the Public Site may make Identifiers, Internet/Network Activity, and Geolocation Data available to advertising and analytics partners for cross-context behavioral advertising. Under the CCPA, this is “sharing” even though we receive no payment and do not consider it a “sale.” We provide a “Do Not Sell or Share My Personal Information” link, honor the Global Privacy Control and other recognized opt-out preference signals, and display confirmation when an opt-out has been honored, as described in Section 7.
4. How We Use Information
• Providing, maintaining, and improving the Service, including the Maxed AI Visibility platform, account features, and customer support;
• Processing payments through Stripe and managing billing;
• Communicating with you about your account, the Service, and updates to our policies;
• Security, fraud prevention, and abuse detection, including monitoring accounts for unusual usage patterns (see Section 4.1);
• Producing aggregated, de-identified industry insights and benchmarks (see Section 4.2);
• Independently researching and publishing AI-search visibility analysis regarding businesses that are not our customers, using publicly available information (see Section 4.3);
• Complying with legal obligations and enforcing our agreements.
4.1 Security Monitoring and Account Anomaly Detection
We monitor accounts for unusual usage patterns as a security and abuse control. This involves forming a judgment about a specific account’s behavior and is an “inference” for CCPA purposes, undertaken for the enumerated business purpose of security and integrity. It is not used to make, and does not contribute to, any decision concerning employment, lending or financial services, housing, education, or healthcare, and accordingly we do not treat it as “automated decision-making technology” for a “significant decision” under the CCPA regulations effective January 1, 2026. We will revisit this conclusion as further CPPA guidance on automated decision-making technology develops, and before using this monitoring as the basis for any decision to suspend or terminate an account.
4.2 Aggregated Benchmarks and Industry Insights
Consistent with Section 3.7 of our Terms of Service, we may combine and anonymize customer data with data from other customers and public sources to produce industry-level insights and benchmarks, which we may publish. Aggregated and de-identified information of this kind is not linked or reasonably linkable to you and is not “personal information” under the CCPA. We maintain technical and contractual safeguards designed to prevent re-identification and do not attempt to re-identify such information.
4.3 Research on Non-Customer Businesses
Consistent with Section 3.8 of our Terms of Service, we independently track AI-search visibility for businesses that are not our customers, using publicly available data, and may publish analyses derived from that research. Where this research identifies a specific individual (for example, a sole proprietor or a named executive), that individual has the same rights described in Section 10 of this Policy with respect to that information, even though they are not a registered user of the Service. Requests from such individuals may be directed to the contact information in Section 14.
4.4 Legal Bases for Processing (EEA, UK, and Switzerland)
Where the GDPR or UK GDPR applies, we rely on the following legal bases for the processing described above:
• Performance of a contract: creating and administering your account, delivering the Service, processing payments through Stripe, and providing support.
• Legitimate interests: securing the Service and detecting abuse; improving and developing the Service; producing aggregated and de-identified benchmarks; researching AI-search visibility for businesses that are not customers; researching a prospective customer’s business using publicly available information to create a preview account as described in Section 2.3; and contacting business representatives about products relevant to their work. Where we rely on legitimate interests we have considered the impact on the individual, and you may object at any time as described in Section 10.2.
• Consent: advertising and analytics cookies on the Public Site, and marketing communications where consent is required. You may withdraw consent at any time without affecting processing carried out before withdrawal.
• Compliance with legal obligations: tax and accounting records, and responding to lawful requests from public authorities.
5. How We Disclose Information
We disclose personal information to the following categories of recipients for the business purposes described above:
• Service providers and processors who perform functions on our behalf, including payment processing, cloud hosting and infrastructure, AI model providers who generate the answers, summaries and drafts produced by Maxed features that use AI, and meeting and video-conferencing software used for sales and onboarding calls. Each is bound by a written contract restricting their use of personal information to the purposes we specify. The current list of these companies is maintained at https://maxedmarketing.ai/subprocessors;
• Advertising and analytics partners who receive information via Public Site pixels, which constitutes “sharing” for cross-context behavioral advertising as described in Section 3.3 and Section 7;
• Third-party AI platforms that you choose to connect to your account, as described in Section 6 below;
• Professional advisors, and successors in the event of a merger, acquisition, financing, or sale of assets;
• Law enforcement, regulators, or other third parties where required by law, to protect our rights, or to protect the safety of any person.
6. The MCP Connector: Using Your Data With Third-Party AI Platforms
The Service includes a feature that allows you to connect your Maxed account to third-party large language model applications (for example, ChatGPT or Claude) using the Model Context Protocol (“MCP”) or similar mechanisms (the “Connector”), so that you can query your own data using the AI platform of your choice.
• Connecting is your action. You decide whether to enable the Connector, which third-party platform to connect, and what scope of access to grant. We are not a party to your relationship with that third-party platform, and your use of it is governed by that platform’s own terms and privacy policy, which we encourage you to review before connecting.
• Data flows to the platform you choose. Once you query your data through a connected third-party AI platform, the relevant data is transmitted to and processed by that platform in accordance with its own practices, outside our systems and outside our control. That platform, not Maxed, determines how it stores, retains, uses, or further processes the data you send it, including whether it is used to train models, subject to applicable settings you control on that platform.
• We cannot recall data once transmitted. Because the third-party platform operates independently of Maxed, we cannot delete, restrict, or otherwise control data after it has been sent through the Connector to that platform. You should exercise the same care in directing your data to a third-party AI platform that you would in sending it to any other external application.
• Revocation and credentials. You may disconnect the Connector or revoke its access at any time from your account settings; doing so stops future transmissions but does not affect data already sent. You are responsible for safeguarding any API keys, tokens, or credentials used to establish the connection.
This Section describes data you send to an AI platform you connected yourself. It is separate from the Maxed features that use an AI model to answer you, such as Ask Max, Report Builder, AI Visibility topic setup, and the audience name generator. Those features run on our own accounts with the AI model providers identified at https://maxedmarketing.ai/subprocessors, not on your connection, and the disclosures in Section 5 apply to them. Some of those features can also be reached through the Connector; when they are, the processing still happens on our accounts and is covered by Section 5 rather than by this Section.
For purposes of the CCPA, when you use the Connector to direct disclosure of your own account data to a third-party AI platform you select, that disclosure is made at your specific direction for your own purposes, consistent with Cal. Civ. Code § 1798.140’s exclusion of consumer-directed disclosures from the definition of “sale” or “share.” It is not something Maxed initiates, controls, or is paid for. For purposes of the GDPR, where you are (or act on behalf of) a controller, your decision to route your own data to another platform of your choosing is your own controller decision, made independently of Maxed’s role as your service provider or processor; Maxed’s processing obligations with respect to that data end at the point the Connector transmits it to the platform you selected.
7. Sale and Sharing of Personal Information; Your Opt-Out Rights
We do not sell personal information. We “share” Identifiers, Internet/Network Activity, and Geolocation Data collected via Public Site advertising and analytics pixels for cross-context behavioral advertising, as described in Section 3.3.
• Do Not Sell or Share My Personal Information: a link is provided in the footer of the Public Site and, where applicable, in the App, allowing you to opt out of sharing.
• Global Privacy Control: we recognize and honor the Global Privacy Control and other opt-out preference signals recognized under the CCPA regulations, and display confirmation that an opt-out request has been honored, as required effective January 1, 2026.
• We do not use dark patterns; our opt-out process requires no more steps than opting in.
8. Sensitive Personal Information
Based on our understanding that the geolocation data we collect is approximate (derived from IP address) rather than precise, and that we do not collect government identification numbers, account log-in credentials in combination with a password or security code, racial or ethnic origin, religious beliefs, health information, or other categories of Sensitive Personal Information as defined by the CCPA, we do not believe we collect Sensitive Personal Information requiring a “Limit the Use of My Sensitive Personal Information” right. Card numbers are processed exclusively by Stripe and are never transmitted to or stored by us.
9. Data Retention
We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Policy, including to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements, after which it is deleted or de-identified.
Specific periods: billing and tax records are retained for seven years from the end of the tax year to which they relate, after which our copy is deleted. Product usage data is retained for twenty-five months and then deleted automatically; we keep anonymous aggregate counts beyond that period, with no link to any individual. Personal information we process on behalf of a business customer is retained and deleted in accordance with the applicable Data Processing Agreement. Where a longer period is required by law or to resolve a dispute, we retain the information for that period only.
10. Your Privacy Rights
10.1 California Residents (CCPA)
• Right to Know / Access the specific pieces and categories of personal information we have collected;
• Right to Delete personal information we have collected, subject to certain exceptions;
• Right to Correct inaccurate personal information;
• Right to Opt Out of the sharing of personal information for cross-context behavioral advertising (see Section 7); we do not sell personal information;
• Right to Non-Discrimination for exercising any of these rights;
• Right to designate an Authorized Agent to make a request on your behalf, subject to verification.
To exercise these rights, contact us using the information in Section 14. We will verify your identity before responding and will respond within the time periods required by law. If we deny your request, you may appeal by contacting us at the same address.
10.2 EEA, UK, and Swiss Residents (GDPR / UK GDPR)
• Right of access, rectification, and erasure;
• Right to restrict or object to processing, including processing based on legitimate interests;
• Right to data portability;
• Right to withdraw consent at any time, where processing is based on consent;
• Right to lodge a complaint with your local data protection supervisory authority.
10.3 International Data Transfers
We are based in the United States and process personal information there. Where we transfer personal information from the EEA, the United Kingdom, or Switzerland to the United States or to another country that has not received an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and we carry out transfer risk assessments where required. Our Data Processing Addendum incorporates these clauses for business customers. You may request a copy of the relevant safeguards using the contact information in Section 14.
11. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, or disclosure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Children’s Privacy
The Service is directed to businesses and is not directed to, and we do not knowingly collect personal information from, individuals under the age of 16. If we learn we have done so, we will delete that information.
13. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a new “Last Updated” date and, where changes are material, provide additional notice as required by law.
14. Contact Us
Amplify 11, Inc. d/b/a Maxed Marketing
25400 US 19 North, Suite 137
Clearwater, FL 33763