Privacy Policy
Effective date: April 9, 2026
1. Introduction
McCarthy AI Automations (“Company,” “we,” “our,” or “us”) respects your privacy. This Privacy Policy explains what personal information we collect, how we use it, and your rights regarding that information. It applies to our website, client portal, and any services we provide.
2. Information We Collect
We collect the following categories of personal information:
- Contact information — name, email address, phone number, and company name submitted through our consultation form or direct communications.
- Account information — email address, authentication credentials, and session data when you access our client portal.
- Project and billing data — project status, milestones, support requests, and payment records associated with your engagement.
- Usage data — pages visited, actions taken in the portal, and general analytics to help us improve our services.
- Communications — content of support requests, messages, and emails you send us.
3. How We Use Your Information
We use the information we collect to:
- Respond to consultation inquiries and onboard new clients
- Deliver, manage, and support your automation projects
- Send transactional emails (confirmations, invoices, project updates)
- Send follow-up communications related to your inquiry (you may opt out at any time)
- Process payments and maintain billing records
- Improve our website and services through aggregate analytics
- Comply with legal obligations
We use AI tools to help classify and prioritize inbound consultation requests. This classification is used internally to route and respond more effectively; it is not used to make automated decisions that legally or significantly affect you.
4. Sub-Processors and Third-Party Services
We share data with the following third-party service providers (“sub-processors”) as necessary to operate our business. Each is bound by their own privacy and security commitments.
| Provider | Purpose | Data shared |
|---|---|---|
| Clerk | Authentication & session management | Email, user ID |
| Supabase | Database (projects, billing, support) | All project and contact data |
| Resend | Transactional email delivery | Name, email, message content |
| Stripe | Payment processing | Name, email, billing details |
| OpenAI | AI lead classification & assistant | Consultation message content |
| Vercel | Website hosting & infrastructure | Request logs, IP addresses |
| Zapier | Internal workflow automation | Lead contact details (internal use only) |
We do not sell your personal information to any third party.
5. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this policy, maintain an active client relationship, or comply with legal obligations. Consultation inquiries that do not result in an engagement are typically retained for up to 24 months. You may request deletion at any time (see Section 7).
6. Cookies and Tracking
Our website may use functional cookies required for authentication (Clerk) and basic analytics. We do not use advertising cookies or cross-site tracking. You can manage cookies through your browser settings.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access — request a copy of the personal data we hold about you.
- Correction — request that we correct inaccurate or incomplete information.
- Deletion — request that we delete your personal data, subject to legal obligations.
- Opt-out of marketing — unsubscribe from follow-up emails at any time via the unsubscribe link in any email we send.
- Data portability — request your data in a machine-readable format where applicable.
California residents (CCPA): You have the right to know what personal information we collect, to delete it, to opt out of its sale (we do not sell it), and to non-discrimination for exercising your rights.
EEA/UK residents (GDPR): Our lawful basis for processing is generally contract performance (for active clients) and legitimate interest (for consultation inquiry follow-up). You may object to processing based on legitimate interest at any time.
To exercise any of these rights, contact us at mccarthyaiautomations@gmail.com. We will respond within 30 days.
8. Security
We use industry-standard measures to protect your data, including encryption in transit (TLS), encrypted storage, access controls, and authentication best practices. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
9. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or a notice on this page. The effective date at the top of this page reflects the most recent revision.
10. Contact
Questions or requests regarding this Privacy Policy can be sent to mccarthyaiautomations@gmail.com.