What Max Level collects, why, who we share it with, and the choices you have. Written to be understood rather than to be technically survivable.
Max Level Marketing LLC, a Wyoming limited liability company trading as Max Level (“we”, “us”, “our”), is responsible for the personal information described in this policy. It applies to maxlevelmarketing.com, to the Max Level CRM platform, and to every service we provide. We are registered at 1408 E 13th St, Cheyenne, WY 82001 and operated from Houston, TX; that registered address is the one to use for written privacy requests and legal notices.
We handle personal information in two very different roles, and which one applies changes your rights and who you should contact.
We do not knowingly collect information from children under 16, we do not collect government identifiers or biometric data, and we ask clients not to place health information, full payment card numbers or other sensitive categories into the Services (see section 4 of the Terms).
| Purpose | What that means in practice |
|---|---|
| Providing the Services | Creating and running your account, configuring and operating your system, sending and receiving messages on your instruction, processing bookings and invoices. |
| Billing | Taking payment, issuing invoices, chasing failed payments, and keeping the financial records the law requires. |
| Support | Answering your questions, investigating faults, and telling you about problems affecting your account. |
| AI processing | Reading, drafting, summarising, classifying and transcribing communications, where your plan includes AI Features – see section 4. |
| Improving the Services | Understanding which features are used and where the Services fail, using aggregated or de-identified data wherever that is sufficient. |
| Security and abuse prevention | Detecting fraud, abuse, spam, and unauthorised access, and enforcing our Terms. |
| Marketing | Sending you information about our services, with an unsubscribe link in every message. See section 6 for your choices. |
| Legal obligations | Complying with tax, accounting, consumer protection, telecommunications and other legal requirements, and responding to lawful requests. |
Where a legal basis is required (for example under the UK or EU GDPR), we rely on: performance of a contract with you; our legitimate interests in running, securing and improving our business, where those are not overridden by your rights; compliance with a legal obligation; and consent, where we ask for it.
Parts of the Services use artificial intelligence to read messages and to compose and send replies without a human reading them first. If you are a customer of a business that uses Max Level, a reply you receive may have been written by an AI acting for that business.
To do that, message content, conversation history and the relevant contact record are sent to AI model providers acting as our sub-processors.
AI output can be wrong. If an AI-generated message about you was inaccurate, contact the business that sent it, or us at [email protected] and we will route it.
Where the Services record or transcribe calls, the business operating the account is responsible for providing the notice and obtaining the consent its jurisdiction requires. Several states require all parties to consent.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.
We share information only in these circumstances:
Companies that perform functions on our behalf, bound by contract to use the information only for that purpose. By category:
| Category | What they do |
|---|---|
| CRM and marketing platform | Hosts the Max Level CRM platform and your Client Account |
| Telephony and messaging carriers | Deliver SMS, MMS and voice calls |
| Email infrastructure | Delivers email and reports on deliverability |
| Payment processors | Take payment and handle card data |
| AI model providers | Process message content for AI Features (section 4) |
| Automation and integration infrastructure | Moves data between systems |
| Hosting, storage and analytics | Runs and measures the Services |
The specific providers change as our stack changes. For the current list, email [email protected] and we will provide it.
Every commercial email we send carries an unsubscribe link, and we honour opt-outs promptly. We will still send you transactional messages about your account, billing and security, which you cannot opt out of while you have an account.
Where you give us your mobile number and consent to texts, we may send you account, appointment and service messages, and marketing messages where you have agreed to them.
No mobile information will be sold or shared with third parties or affiliates for marketing or promotional purposes. Information sharing with the subcontractors listed in section 5 who support the delivery of our messages is permitted; all other sharing is excluded. Text-messaging originator opt-in data and consent are never shared with any third party.
We and our providers use cookies and similar technologies to keep the site working, remember your preferences, keep your session secure, and understand how the site is used.
Most browsers let you refuse or delete cookies; blocking strictly necessary cookies will break parts of the site. Some browsers send a Global Privacy Control signal, which we treat as a valid opt-out request where the law requires it. We do not currently respond to Do Not Track headers, as there is no common standard for them.
| What | How long |
|---|---|
| Client Account data | For the life of the account, then 30 days after termination for export, then deleted |
| Billing and tax records | As long as tax and accounting law requires, typically 7 years |
| Marketing contact records | Until you unsubscribe, then a minimal suppression record kept indefinitely so we do not contact you again |
| Support correspondence | Up to 3 years |
| Consent and opt-out records | Kept for as long as needed to evidence compliance |
| Backups | Overwritten on a rolling cycle, normally within 90 days |
Where we no longer need information but cannot yet delete it, we restrict it from further use.
Depending on where you live, you may have the right to:
These rights apply under state privacy laws including those of California, Texas, Virginia, Colorado, Connecticut, Utah and others, and under the UK and EU GDPR where applicable. Residents of the EEA and UK may also object to processing based on legitimate interests, and may lodge a complaint with their local supervisory authority.
Email [email protected] with the subject line “Privacy Request”. We will acknowledge within 10 business days and respond substantively within 45 days, extendable once by a further 45 days where the request is complex, and we will tell you if we need the extension. We will verify your identity before acting, using information we already hold. An authorised agent may act for you with written permission.
Read this if you received a message from a business running on Max Level and you want your information changed or deleted.
In that situation the business is the controller of your information and we are only its processor. We handle it on their instructions and we are not permitted to change or delete it on our own initiative.
We use administrative, technical and physical safeguards appropriate to the sensitivity of the information, including encryption in transit, access controls and least-privilege access, multi-factor authentication on administrative accounts, and vendor review of the providers we rely on.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your own credentials safe and for who you give access to. If we become aware of a breach affecting your personal information, we will notify you and any regulator as the law requires, without undue delay.
We operate in the United States and our providers may process information in the United States and elsewhere. If you are outside the United States, you understand your information will be transferred to and processed there, where privacy law may differ. Where required, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
The Services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email [email protected] and we will delete it.
Our site links to services we do not control. This policy does not apply to them, and we are not responsible for their practices.
We may update this policy. If a change is material we will give notice by email or in the Services before it takes effect. The “Effective” date at the top shows the current version.
See also our Terms & Conditions.