Skip to content
Legal

Privacy Policy

Last updated: September 29, 2026

1. Introduction

Express Consent, LLC (“ExpressConsent,” “we,” “us,” or “our”) operates the ExpressConsent platform, including the website at expressconsent.com and all related services (collectively, the “Service”). This Privacy Policy explains what personal information we collect, how we use it, and who we share it with. It covers three groups of people:

  • Consumers: people who use a website where one of our customers has installed ExpressConsent. For this information, we act as a service provider to our customer (Section 2).
  • Website visitors and prospective customers: people who visit expressconsent.com, contact us, or call us (Section 3).
  • Customer account users: people who use our dashboard, API, or share pages on behalf of a business (Section 3).

If you arrived here from a notice on another company’s website: that company uses ExpressConsent to keep a record of the page you saw and the information you submitted. Section 2 explains what that record contains and how to make requests about it.

2. Consumers: Records We Keep for Our Customers

What a record contains

Our customers are businesses that install our software on their websites. When you take an action the business has chosen, usually submitting a form, our software creates a Certified Digital Record (“CDR”) of that moment. A CDR can include:

  • The page as it appeared to you, including its text, images, and any consent language shown
  • The information you entered on the page, such as your name, phone number, email address, or postal address, unless the business has chosen to mask a field
  • Which boxes were checked, which button you used to submit, and your interactions with the page leading up to that moment
  • The date and time, the page address, your IP address, and your browser and device information
  • Your approximate location (city, region, and country), which we look up from your IP address in a database we host ourselves, without sending your IP address to anyone else
  • A session identifier that links records from the same visit when a form spans several pages
  • Copies of documents the page links to, such as terms and conditions, if the business has asked us to archive them
  • Reference information the business chooses to attach, such as its own lead ID
  • If the business turns it on, a bot-detection result from our provider Anura, which loads a script in your browser that analyzes browser and device signals to assess whether the visitor is a real person

Storage on your device

Our software does not set cookies. It stores a random session identifier in your browser’s session storage, which is cleared when you close the tab. If a record cannot be uploaded right away, our software keeps an encrypted copy in your browser’s storage, uploads it the next time you load a page on that website, and then deletes it.

How we use it

We process CDRs on behalf of the business whose website you used, and we follow its instructions. We use CDRs only to create, store, verify, and deliver records to that business and to the businesses it shares them with; to keep the Service secure and working; and to maintain and improve the Service, for example by testing that records are reproduced accurately. We do not sell this information, use it to market to you, or use it to build a profile about you.

Who receives it

  • The business whose website you used.
  • Businesses it shares the record with, such as companies that receive your information in order to contact you. Those businesses are responsible for their own use of it.
  • Our service providers, listed in Section 4.
  • Courts, parties to legal proceedings, regulators, or law enforcement, when required by law, subpoena, or court order. Because CDRs serve as evidence, we may provide a sworn declaration confirming that a CDR is authentic and unchanged.

How long we keep it

We keep each CDR for five (5) years from the date it is created, which covers the period in which consent-related legal claims can generally be brought. During that period, the record is stored so that it cannot be changed or deleted by anyone, including us. That is what makes it reliable as evidence. After five years, CDRs are deleted. We separately keep a digital fingerprint of each record, which contains no personal information, so that its authenticity can be checked.

Your requests

The business whose website you used decides what information is collected and how it is used, so please send requests to access, correct, or delete your information to that business. If you contact us, we will direct your request to the business or help it respond. Because CDRs are kept to establish and defend legal claims, they cannot be changed or deleted during the five-year retention period, which privacy laws permit.

If you want to stop receiving calls, texts, or emails, tell the business that is contacting you. ExpressConsent does not call, text, or email consumers on our customers’ behalf.

3. Website Visitors, Prospective Customers, and Account Users

Information you provide

  • Inquiries: your name, work email, company, phone number, and message when you request a demo or contact us, and the details you include when you ask about working with us. When you submit a form on our website, we keep a record of the page as you submitted it, using our own Service. We add sales inquiries to our customer relationship software (Salesforce), and we share the submission with our call and form tracking provider, CallRail, so we can tell which advertising led to it.
  • Meetings: your name, email, and any details you provide when you book a meeting through our scheduling page, which is provided by Google Calendar.
  • Account information: name, work email, company, sign-in and multi-factor authentication details, and billing contacts. When you accept terms inside the Service, we may keep a record of your acceptance using our own Service.
  • Communications: anything you send us when you contact us for support.

Information collected automatically

  • Usage and device data: on our marketing pages, Google Analytics collects the pages you visit, how you arrived (including advertising click identifiers), your browser, operating system, IP address, and approximate location. We use it with Google Ads to measure how our advertising performs. We do not use Google Analytics inside the dashboard.
  • Call tracking: the phone number shown on our website may be a tracking number provided by CallRail that forwards to our office. CallRail uses a cookie to show you the same number on return visits and to associate your call with how you found our website. When you call, CallRail records your phone number, the time and length of the call, and may record the call.
  • Service logs: sign-ins, actions taken in the dashboard, and API requests, which we use for security, support, and billing.

Cookies

Our marketing pages use cookies from Google Analytics and CallRail for the purposes described above. The dashboard uses browser storage to keep you signed in. You can block or delete cookies in your browser settings, and you can opt out of Google Analytics with Google’s opt-out browser add-on. Our website does not currently respond to “Do Not Track” browser signals.

How we use it

  • Provide, maintain, and improve the Service
  • Respond to inquiries and support requests, and follow up about our Service
  • Process transactions and send related information
  • Send technical notices, updates, security alerts, and administrative messages
  • Measure and improve our website and advertising
  • Detect, investigate, and prevent fraudulent or unauthorized activity
  • Comply with legal obligations

How long we keep it

We keep account information for as long as your account is active and for a reasonable period afterward for legal, tax, and security purposes. We keep inquiries, meeting details, and call records for as long as they are useful to our relationship with you or as the law requires.

Who we share it with

We do not sell your personal information. We share it only with our service providers (Section 4), with Google to measure our advertising, when required by law, regulation, or legal process, in connection with a merger, acquisition, or sale of assets, or with your consent.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of the personal information we hold about you as a visitor, prospective customer, or account user. To make a request, contact us using the information below. We will verify your identity and respond as the law requires, and we will not discriminate against you for exercising these rights. For CDRs, see “Your requests” in Section 2.

4. Service Providers

We use the following providers to operate the Service and our website. They may use personal information only to provide services to us.

  • Google Cloud and Firebase: hosting, storage, databases, sign-in, and email delivery for the Service, in the United States.
  • Cloudflare: delivers our software to websites and receives records uploaded from consumers’ browsers, holding them briefly before they are stored in Google Cloud.
  • Anura: bot detection, only for records where a customer turns it on.
  • Salesforce: customer relationship management for inquiries from our website.
  • CallRail: call and form tracking on our website.
  • Google Analytics, Google Ads, and Google Calendar: website analytics, advertising measurement, and meeting scheduling.

5. Security

We use administrative, technical, and physical safeguards to protect personal information. Data is encrypted in transit and at rest, and access is limited to people who need it. Each CDR is sealed with a cryptographic fingerprint when it is captured so that any later change can be detected. No method of transmission over the Internet or method of electronic storage is completely secure.

6. Children

Our website and Service are intended for businesses and are not directed to children under 13. Our customers may not use the Service to collect information from children under 13. If you believe a child’s information has been captured, please contact us.

7. United States Only

We are based in the United States, and we store and process information in the United States. The Service is intended for use with consumers located in the United States.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the “Last updated” date. If a change materially affects our customers, we will also notify them by email or in the dashboard.

9. Contact Us

If you have questions about this Privacy Policy or want to make a request, email support@expressconsent.com or contact us.

Express Consent, LLC
55 SE 2nd Ave.
Delray Beach, FL 33444