Privacy Policy
Fixr AI LLC · Effective July 31, 2026
Fixr AI LLC Effective Date: July 31, 2026 Last Updated: July 31, 2026
1. Introduction
Fixr AI LLC ("Fixr AI," "we," "us," or "our") is a Delaware limited liability company that provides marketing, advertising, lead generation, automation, and customer relationship management services to businesses, primarily in the aesthetics, med spa, men's health, and broader healthcare and wellness industries.
This Privacy Policy explains how we collect, use, disclose, and protect personal information when you:
- Visit getfixr.ai or any subdomain, landing page, or funnel page we operate (collectively, the "Site");
- Interact with our advertisements on Meta (Facebook and Instagram), Google, TikTok, YouTube, LinkedIn, or other platforms;
- Submit a form, book a call, start a chat, or otherwise contact us;
- Receive or respond to our email, SMS, or direct-message outreach;
- Engage Fixr AI as a client and use the systems, dashboards, or automations we deploy (the "Services").
By using the Site or Services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Site or Services.
Please read Section 4 carefully. It explains the distinction between data we control and data we process on behalf of our business clients.
2. Scope of This Policy
This Privacy Policy applies to personal information we collect in our capacity as a business (data controller) — that is, information about prospective clients, clients, website visitors, applicants, vendors, and other individuals who interact with Fixr AI directly.
This Privacy Policy does not govern:
- The privacy practices of our clients. When a med spa, clinic, or other business engages Fixr AI, and we collect or process consumer information on that business's behalf, that business is the controller of the information and its own privacy policy governs. Fixr AI acts as a service provider / processor in that context (see Section 4).
- The privacy practices of third-party websites, platforms, or services we link to or integrate with, including Meta, Google, TikTok, GoHighLevel, Stripe, Twilio, or payment processors. Each maintains its own privacy policy.
3. Information We Collect
3.1 Information You Provide Directly
- Identity and contact information: name, business name, email address, telephone number, mailing address, job title.
- Business information: industry, service offerings, number of locations, monthly revenue range, current advertising spend, CRM in use, marketing goals, and similar qualifying information submitted through forms, applications, questionnaires, or discovery calls.
- Communications: the content of emails, SMS messages, chat conversations, direct messages, voicemails, call recordings and transcripts, support tickets, and any other correspondence you send us.
- Account and billing information: login credentials for accounts you create with us, billing contact details, and payment method information. Full payment card numbers are collected and stored by our payment processors, not by Fixr AI.
- Content you submit: creative assets, brand materials, customer lists, offer details, testimonials, and other materials you provide for use in campaigns.
3.2 Information Collected Automatically
When you visit the Site or interact with our ads and funnels, we and our service providers automatically collect:
- Device and browser data: IP address, browser type and version, operating system, device type, screen resolution, language settings.
- Usage data: pages viewed, time on page, scroll depth, referring and exit URLs, click paths, video watch time, form field interactions, and timestamps.
- Advertising identifiers and click IDs: including Meta's fbclid and _fbp/_fbc cookies, Google's gclid and wbraid/gbraid parameters, and TikTok's ttclid. These allow us to attribute a visit or lead to the specific ad, campaign, ad set, and creative that produced it.
- UTM and campaign parameters: utm_source, utm_medium, utm_campaign, utm_content, utm_term.
- Approximate location: derived from IP address (typically city or region level).
3.3 Information From Third Parties
- Advertising platforms: aggregate and event-level performance data from Meta, Google, TikTok, and similar platforms.
- Data enrichment and prospecting providers: business contact information, firmographic data, and professional profile data obtained from lawful commercial sources (for example, Apollo.io) used for business-to-business outreach.
- Publicly available sources: business listings, company websites, public social media profiles, and public review platforms.
- Payment processors and merchant partners: transaction confirmations, settlement data, chargeback notices, and lifetime-value metrics used for attribution and reporting.
- Referral partners: contact details of individuals referred to us with the referrer's representation that appropriate consent exists.
3.4 Information We Do Not Intentionally Collect
Fixr AI operates as a marketing and advertising services provider. Our Services are not designed to collect, receive, store, or process Protected Health Information ("PHI") as defined by the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), nor to create a business associate relationship.
Clients and their end users should not submit clinical records, diagnoses, treatment histories, medical images, insurance information, or other PHI to Fixr AI or through the forms, chat interfaces, or CRM configurations we deploy. Lead capture is limited to contact details and general expressions of interest.
If Fixr AI inadvertently receives PHI, we will notify the submitting party, will not use the information for any purpose, and will delete or securely return it. If a client requires PHI-handling capabilities, a separate written Business Associate Agreement must be executed before any such data is transmitted; absent that agreement, no PHI may be shared with us.
We also do not knowingly collect information from individuals under 18 years of age, and we do not intentionally collect government-issued identification numbers, biometric identifiers, precise geolocation, or financial account credentials.
4. Our Two Roles: Controller and Service Provider
Understanding which role we occupy determines whose privacy policy applies and where you direct requests.
Fixr AI as Controller. When you visit getfixr.ai, respond to a Fixr AI advertisement, request information about our agency services, become a Fixr AI client, or apply for a role with us, Fixr AI determines the purposes and means of processing your information. This Privacy Policy governs, and you may exercise your rights directly with us (Section 10).
Fixr AI as Service Provider / Processor. When Fixr AI runs advertising campaigns, deploys chat and voice AI agents, configures CRM pipelines, sends SMS and email sequences, or builds reporting for a client business, the consumer information flowing through those systems belongs to and is controlled by that client business. We process it only on the client's documented instructions and only to deliver the contracted Services. In that context:
- The client's own privacy policy and consent disclosures govern the consumer relationship.
- The client is responsible for obtaining all legally required consents, including express written consent for SMS and automated calling.
- Consumers should direct access, deletion, and opt-out requests to the client business. If a consumer contacts us directly, we will forward the request to the applicable client and assist in fulfilling it.
- We do not sell, share, retain, or use client consumer data for any purpose other than performing the Services, and we do not combine it with data from other sources except as permitted by applicable law.
5. How We Use Information
We use personal information for the following purposes:
Delivering and operating the Services — providing the marketing, advertising, automation, CRM, and reporting services you or your business have engaged us to perform; configuring and maintaining integrations; responding to leads and inquiries through automated and human channels.
Communicating with you — responding to inquiries, scheduling and confirming appointments, sending appointment reminders and follow-ups, delivering service updates, providing support, and sending invoices and billing notices.
Marketing and advertising our own business — sending promotional email and SMS to individuals who have opted in, conducting business-to-business outreach, building and serving custom and lookalike audiences on advertising platforms, and retargeting visitors who have interacted with our Site or ads.
Measurement, attribution, and optimization — determining which campaigns, creatives, and channels generate leads and revenue; calculating cost per lead, cost per acquisition, show rate, close rate, and lifetime value; and transmitting conversion events back to advertising platforms through server-side APIs (see Section 6).
Improving our Services — analyzing usage patterns, testing offers and creative, developing new service lines, and training our team.
Security and fraud prevention — monitoring for unauthorized access, abuse, bot traffic, click fraud, and violations of our Terms of Service.
Legal and compliance — complying with applicable laws, responding to lawful requests from public authorities, enforcing our agreements, and establishing or defending legal claims.
Legal Bases (for individuals in the EEA, UK, and Switzerland)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (delivering Services, billing); legitimate interests (business-to-business outreach, security, measurement, service improvement, provided such interests are not overridden by your rights); consent (non-essential cookies, marketing communications where consent is required, which you may withdraw at any time); and legal obligation (tax, accounting, and regulatory recordkeeping).
6. Advertising Platforms, Pixels, and Conversions APIs
Because advertising is central to what we do, this section describes those practices in detail.
6.1 Tracking Technologies on Our Site
We deploy the Meta Pixel, Google Ads and Google Analytics tags, the TikTok Pixel, and similar tags on the Site and on landing pages we operate. These technologies use cookies, pixels, local storage, and similar identifiers to record page views, form submissions, button clicks, video views, scheduled calls, and purchases.
6.2 Server-Side Conversion Tracking
In addition to browser-based pixels, we transmit conversion events server-to-server using the Meta Conversions API, Google Enhanced Conversions / Google Ads API, and TikTok Events API. These transmissions may include:
- Event details (event name, timestamp, event ID, value, currency, and the source URL);
- Click identifiers and browser cookie values (fbc, fbp, gclid, ttclid);
- IP address and user agent;
- Hashed customer information, including email address, phone number, first and last name, city, state, ZIP code, and country. Where technically supported, this information is hashed using SHA-256 before transmission so that the platform receives an irreversible cryptographic representation rather than the underlying value. The platform matches the hash against its own records to attribute the conversion and then discards non-matching data in accordance with its terms.
We use event deduplication (matching browser and server events by event ID) so a single conversion is not double-counted.
6.3 Custom Audiences and Lookalike Audiences
We may upload hashed contact lists to advertising platforms to build custom audiences for retargeting, to build lookalike/similar audiences for prospecting, or to suppress existing customers from prospecting campaigns. We do this only where the underlying individuals have a relationship with the business whose account is running the ads, and only in compliance with each platform's data-use terms. We do not upload lists purchased from third parties or lists for which we lack an appropriate lawful basis.
6.4 Platform Terms and Your Choices Regarding Ads
Our use of these tools is subject to each platform's terms, including Meta's Business Tools Terms and Custom Audiences Terms, Google's Ads Data Processing Terms and Customer Match policies, and TikTok's Business Products Terms. To limit interest-based advertising, you can use:
- Meta: Ad Preferences and the "Off-Facebook Activity" / "Activity off Meta Technologies" controls in your account settings;
- Google: adssettings.google.com and the Google Analytics Opt-out Browser Add-on;
- TikTok: Ad Personalization settings within the app;
- Industry tools: the Digital Advertising Alliance (optout.aboutads.info), the Network Advertising Initiative (optout.networkadvertising.org), and the European Interactive Digital Advertising Alliance (youronlinechoices.eu);
- Browser controls: cookie blocking, tracking prevention, and Global Privacy Control (GPC) signals, which we honor as valid opt-out requests where required by law.
7. Cookies and Similar Technologies
We use the following categories:
Strictly necessary — required for the Site to function, including session management, load balancing, form security, and fraud prevention. These cannot be disabled through our cookie controls.
Performance and analytics — help us understand how visitors use the Site, which pages perform, and where visitors drop off.
Functional — remember your preferences, prefill form fields, and enable chat widgets and scheduling tools.
Advertising and targeting — set by us and by advertising partners to deliver relevant ads, measure campaign performance, and limit how often you see a given ad.
Most browsers allow you to refuse or delete cookies through their settings. Disabling cookies may impair Site functionality. Where required by law, we present a consent banner and do not set non-essential cookies until you consent.
8. SMS and Email Communications
8.1 SMS / Text Messaging
By providing your mobile telephone number and affirmatively opting in, you consent to receive text messages from Fixr AI, which may include appointment reminders, confirmations, follow-ups, account and service notifications, and promotional messages. Messages may be sent using automated technology.
- Consent is not a condition of purchase. You may receive our Services without agreeing to receive marketing texts.
- Message frequency varies. Message and data rates may apply.
- To stop: reply STOP to any message. You will receive one confirmation and no further messages, other than as required to confirm the opt-out.
- For help: reply HELP or contact us using the details in Section 15.
- Carriers are not liable for delayed or undelivered messages.
- Mobile opt-in data is not sold, rented, or shared with third parties for their own marketing purposes. Phone numbers collected for SMS consent are shared only with the messaging providers and telecommunications carriers strictly necessary to deliver the messages you requested.
Where we send SMS on behalf of a client, the client is responsible for obtaining express written consent from each recipient in compliance with the Telephone Consumer Protection Act ("TCPA"), applicable state analogs, and CTIA and carrier messaging guidelines, and for maintaining records of that consent.
8.2 Email
Marketing emails include an unsubscribe link in every message. You may also email us directly to opt out. Transactional and service-related emails — invoices, security notices, contract and account communications — are not marketing and may continue after you unsubscribe from marketing.
9. How We Share Information
We disclose personal information in the following circumstances. We do not sell personal information for money.
Service providers and subprocessors — vendors that perform functions on our behalf under contractual confidentiality and data protection obligations, including: CRM and marketing automation platforms (GoHighLevel), advertising platforms (Meta, Google, TikTok), email and SMS delivery providers, cloud hosting and storage providers, analytics providers, scheduling and calendar tools, payment processors and merchant service partners, AI and language model providers powering our chat and voice agents, project management and communication tools, and professional advisors including accountants and attorneys.
Our clients — where you are a lead or customer generated for a Fixr AI client, your information is delivered to that client, which is the intended recipient and the controller of that information.
Advertising platforms — as described in Section 6, including hashed identifiers for conversion measurement and audience building. Under certain state privacy laws, the transmission of identifiers to advertising platforms for cross-context behavioral advertising may be considered a "sale" or "sharing" of personal information even though no money changes hands. You may opt out as described in Sections 6.4 and 10.
Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business or assets, subject to the acquirer's commitment to honor this Policy for information transferred.
Legal and protective disclosures — when we believe in good faith that disclosure is required by law, subpoena, court order, or governmental request, or is necessary to protect the rights, property, or safety of Fixr AI, our clients, or others, or to investigate suspected fraud or violations of our Terms of Service.
With your direction or consent — for any other purpose you authorize.
10. Your Privacy Rights
10.1 Rights Available to All Users
Regardless of where you live, you may contact us to: request access to the personal information we hold about you; request correction of inaccurate information; request deletion; opt out of marketing email and SMS; or ask a question about this Policy.
10.2 United States — State Privacy Rights
Residents of California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights that may include:
- Right to know / access the categories and specific pieces of personal information collected, the sources, the business purposes, and the categories of third parties to whom it was disclosed;
- Right to delete personal information, subject to legal exceptions;
- Right to correct inaccurate personal information;
- Right to opt out of the sale or sharing of personal information and of targeted or cross-context behavioral advertising;
- Right to limit the use and disclosure of sensitive personal information (note: we do not use sensitive personal information for inferring characteristics);
- Right to data portability in a readily usable format;
- Right to non-discrimination for exercising any of these rights. We will not deny services, charge different prices, or provide a different level of quality because you exercised a privacy right.
To exercise these rights, email hello@getfixr.ai with "Privacy Request" in the subject line, or use the contact details in Section 15. We will verify your identity before fulfilling a request, typically by matching information you provide against our records; for deletion and access requests we may require additional verification. An authorized agent may submit a request on your behalf with written permission and verification of the agent's authority.
We respond within 45 days, extendable by an additional 45 days where reasonably necessary, and will notify you of any extension.
Opt-out preference signals. We honor the Global Privacy Control (GPC) as a valid opt-out of sale/sharing for the browser transmitting it.
Appeals. If we decline your request and your state provides an appeal right, you may appeal by replying to our response with the word "Appeal." We will respond within 45 days (or the period your state requires) with a written explanation.
10.3 EEA, United Kingdom, and Switzerland
If you are located in these regions, you additionally have the right to object to processing based on legitimate interests, the right to restrict processing, the right to withdraw consent at any time without affecting the lawfulness of prior processing, and the right to lodge a complaint with your local supervisory authority. Where we transfer personal information outside your region, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10.4 Canada
Residents of Canada have rights of access and correction under PIPEDA. Our commercial electronic messages comply with Canada's Anti-Spam Legislation (CASL), including identification of the sender and a functioning unsubscribe mechanism.
11. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer period is required or permitted by law. In general:
- Prospect and lead data: up to 36 months from the last interaction, unless deletion is requested sooner.
- Client account and campaign records: for the duration of the engagement plus 7 years, to satisfy tax, accounting, and contractual recordkeeping obligations.
- Billing and transaction records: 7 years.
- Marketing consent and opt-out records: retained indefinitely where necessary to honor suppression lists and demonstrate compliance with TCPA, CAN-SPAM, and similar laws. An opt-out record is retained precisely so we can continue honoring your opt-out.
- Website analytics and advertising identifiers: typically 13–26 months, per platform defaults.
- Call recordings and transcripts: up to 24 months.
Data processed on behalf of clients is retained per the applicable client agreement and returned or deleted within 30 days of a written request following termination, subject to backup rotation cycles.
12. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS), access controls and role-based permissions, multi-factor authentication on administrative accounts, vendor due diligence, and least-privilege access practices for team members and contractors.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you provide information at your own risk. If we become aware of a breach affecting your personal information, we will notify you and applicable regulators as required by law.
13. Children's Privacy
The Site and Services are directed to businesses and to adults 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected such information, we will delete it promptly. A parent or guardian who believes a minor has provided us information should contact us at hello@getfixr.ai.
14. Additional Disclosures
Third-party links. The Site may link to third-party websites and platforms. We are not responsible for their content or privacy practices, and we encourage you to review their policies.
Do Not Track. Browsers may transmit a "Do Not Track" signal. Because no common industry standard for responding to DNT has been adopted, we do not currently respond to DNT signals. We do honor Global Privacy Control signals as described in Section 10.2.
International transfers. Fixr AI is based in the United States. If you access the Site or Services from outside the United States, your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those of your jurisdiction.
Changes to this Policy. We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the most recent revision. Material changes will be announced through a notice on the Site or by email to registered clients at least 10 days before taking effect. Your continued use after the effective date constitutes acceptance.
15. Contact Us
Fixr AI LLC Attn: Privacy Email (privacy requests and general inquiries): hello@getfixr.ai Website: https://getfixr.ai
Mailing address: [INSERT FULL MAILING ADDRESS] Telephone: [INSERT BUSINESS PHONE]
*Fixr AI LLC is organized under the laws of the State of Delaware.*