Privacy Policy

Last updated: September 22, 2026

Introduction

GoFunnel ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, web application, Chrome extension, tracking scripts, and related services (collectively, the "Services").

Our Role

GoFunnel acts in two capacities depending on the data involved:

  • Controller for account data of our direct customers (e.g., the people who sign up for and administer a GoFunnel workspace).
  • Processorfor end-user data that our customers route through GoFunnel (e.g., leads, form submissions, call recordings, and payments belonging to our customers' businesses). Our customers are the controllers of that data, and our processing is governed by our Data Processing Agreement (available on request at support@gofunnel.ai).

Information We Collect

Account Information

When you create an account, we collect:

  • Email address
  • Name (if provided)
  • Authentication credentials (securely hashed by our auth provider)
  • Billing information (processed by Stripe; we do not store full card numbers)

Lead and Form Data

When our customers configure forms, tracking, or integrations, we collect and store data about the leads, customers, and prospects who interact with their funnels. This may include names, email addresses, phone numbers, IP addresses, user agents, page-view history, UTM parameters, custom form fields, and any other information our customers choose to capture.

Payment and Order Data

Through integrations with Shopify, Stripe, ThriveCart, ClickFunnels, Whop, Fanbasis, and similar checkout platforms, we receive transaction records (e.g., order amount, currency, product, customer name, email, and phone number, transaction ID) on behalf of the merchant whose store is connected, and use them solely to provide that merchant's sales attribution and analytics. We do not store full payment card numbers; that information stays with the payment processor. Store owners can request deletion of this data at any time (Shopify merchants: uninstalling the app or a GDPR redaction request triggers this automatically).

Call Recordings and Transcripts

If our customers connect Zoom or Fathom, we ingest sales-call recordings, transcripts, and call metadata (participants, duration, timestamps) to power our Call Intelligence features. Our customers are responsible for obtaining any consent required under applicable wiretap and recording laws (including two-party-consent jurisdictions such as California, Florida, Illinois, Massachusetts, Pennsylvania, and Washington).

Tracking and Attribution Data

When a website operator installs our tracking script, we set a first-party identifier (the "gf_sid" cookie) and collect page views, click events, form interactions, video engagement, referrer URLs, UTM parameters, IP address, and device/browser information. This data is associated with our customer's workspace and used to attribute leads and conversions across their funnel.

Connected Service Data

When you connect a third-party service (such as a CRM, calendar, advertising platform, or analytics tool), we store OAuth tokens or API keys securely and access only the data necessary to deliver the features you have enabled.

Usage Data

We automatically collect information about how you use the Services, including browser type, device identifiers, IP address, access times, and pages viewed. We may use session-replay tooling (Microsoft Clarity) on our own marketing and product pages to record interactions for usability analysis. Inside the logged-in application we use Google Analytics to understand which features are used and for how long. It receives pseudonymous account and workspace IDs, your role and workspace settings (such as industry vertical), the page path with record IDs removed, and feature-usage events such as data exports — never your name, email address, or any data about your leads — and it is not loaded for visitors in the EEA, the UK, Switzerland, or Quebec, or for browsers that send a Global Privacy Control signal.

AI and Automated Processing

GoFunnel uses artificial intelligence to analyze call recordings, transcripts, form submissions, and lead data. This processing may include:

  • Generating call summaries, scoring, and coaching insights
  • Classifying leads, calls, and events
  • Mapping fields between integrated systems
  • Suggesting integration configurations

To perform this processing we use third-party large-language-model providers, currently OpenAI, Anthropic, and Google (Gemini). Content sent to these providers is processed under their respective enterprise/API terms, which prohibit using customer content to train their foundation models. We do not sell this content, and we do not use it for advertising.

Google Workspace API Data — Limited Use

GoFunnel's Google Meet integration reads two read-only Google Workspace scopes, and only for meetings organised by your own team:

  • meetings.space.readonly— after a meeting ends we read that conference record and its participant list.
  • calendar.events.owned.readonly— we read the matching event on the organiser's own calendar to obtain invitee email addresses, because Google Meet reports participant display names but no addresses.

This is used for one purpose: deciding whether a booked sales call actually took place and who attended, so the call is marked completed or no-show in your call log. We do not read meeting media, recordings or transcripts through these scopes.

GoFunnel's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Google Workspace API data is never sent to any artificial-intelligence or machine-learning provider. This is enforced in code, not by policy alone: our AI assistant cannot query Google Meet attendance data, and any such data is stripped from results before they reach a language model. It is never used to develop, improve or train generalised or foundation models, and it is never sold or transferred for advertising.

Chrome Extension

Our Chrome extension ("GoFunnel Forms") collects and uses data as follows:

Data Collected

  • Authentication tokens (stored locally to maintain your session)
  • Form responses you submit through the extension
  • Page context on *.gofunnel.aipages where the extension's content script runs to detect form elements

Data Usage

  • Authentication data is used solely to verify your identity
  • Form responses are transmitted to GoFunnel servers
  • No data is used for advertising
  • No data is sold to third parties

Permissions

  • storage: Stores authentication session locally
  • identity: Enables Google sign-in
  • Host permissions (*.gofunnel.ai, *.supabase.co): Communicates with GoFunnel servers and runs a content script on GoFunnel pages to detect and assist with form interactions

How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Services
  • Authenticate accounts and maintain security
  • Process form submissions, payments, and webhook events
  • Sync data with connected third-party services
  • Send hashed identifiers (such as email or phone) to advertising platforms (e.g., Meta Conversions API, Google Ads) for conversion measurement, where our customer has configured this
  • Generate analytics, dashboards, and AI-powered insights
  • Respond to support requests and service communications
  • Comply with legal obligations and enforce our Terms of Service

Data Sharing

We do not sell your personal information. We share data only in these circumstances:

  • Subprocessors: Vetted third parties that help operate the Services (see list below)
  • Connected services: Third-party platforms you or your workspace administrator explicitly connect (e.g., your CRM, calendar, advertising account)
  • Advertising platforms (server-side): Where configured, we send conversion events containing hashed identifiers to platforms such as Meta and Google so our customers can measure ad performance
  • Business transfers: In connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections
  • Legal requirements: When required by law, subpoena, or to protect our rights, users, or the public

Subprocessors

We engage the following categories of subprocessors to deliver the Services. An up-to-date list is available on request.

ProviderPurpose
SupabaseAuthentication and primary database
VercelApplication hosting and edge delivery
InngestBackground job and webhook processing
StripeSubscription billing and payment processing
ResendTransactional email delivery
Google (OAuth)Single sign-on
OpenAI, Anthropic, Google GeminiLarge-language-model processing for AI features
Google AnalyticsProduct-usage analytics inside the logged-in app (pseudonymous account and workspace IDs; Google signals, advertising features, and data sharing disabled)
Microsoft ClaritySession replay and usability analytics on our own properties
Meta (Facebook), Google AdsServer-side conversion APIs (where enabled by customer)
Zoom, FathomCall recording, transcription, and metadata
Customer-connected platforms (e.g., GoHighLevel, Close, HubSpot, Typeform, Calendly, ClickFunnels, ThriveCart, Whop, Fanbasis, iClosed, Instantly, Hyros, Wix, ClickUp)Activated only when a customer explicitly connects the service

Data Security

We implement technical and organizational measures appropriate to the risk of processing, including encryption in transit (TLS) and at rest, role-based access controls, secret management via a dedicated secrets platform, audit logging, and least-privilege production access. No method of transmission or storage is 100% secure, but we work to maintain industry-standard safeguards.

Breach Notification

If we become aware of a personal-data breach affecting your information, we will notify affected customers without undue delay and, where required, within the timeframes mandated by applicable law (including GDPR's 72-hour window for notifying supervisory authorities). Customers acting as controllers are responsible for notifying their own end users where required.

Data Retention

We retain your information for as long as your account is active and as needed to provide the Services. Typical retention periods:

  • Account data: Until account deletion, then up to 30 days in backups
  • Lead, form, and event data: For the lifetime of the workspace, unless the workspace owner requests deletion
  • Call recordings and transcripts:For the lifetime of the workspace, subject to the source provider's retention policy
  • Billing records: Retained as required by tax and accounting law (typically 7 years)
  • Logs and security telemetry: Up to 90 days
  • Product-usage analytics (Google Analytics): Up to 14 months

You may request deletion of your account and associated data at any time by contacting support@gofunnel.ai.

Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Data portability (receive your data in a machine-readable format)
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a supervisory authority

If your data was provided to GoFunnel by one of our customers (for example, you submitted a form on their website), please direct rights requests to that customer in the first instance. We will assist them in fulfilling those requests.

California Residents (CCPA / CPRA)

If you are a California resident, you have the rights described above plus the right to know what categories of personal information we collect, the right to opt out of "sale" or "sharing" of personal information, and the right to limit use of sensitive personal information.

We do not sell personal information.Our server-side transmissions of hashed conversion events to advertising platforms (e.g., Meta, Google) may be considered "sharing" for cross-context behavioral advertising under California law. You can opt out by emailing support@gofunnel.ai with the subject "Do Not Sell or Share My Personal Information."

International Data Transfers

GoFunnel is operated from the United States, and our subprocessors may process data in the United States and other jurisdictions. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) to safeguard the transfer.

Children's Privacy

The Services are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us so we can delete it.

Cookies and Tracking

We and our customers use first-party cookies (including the "gf_sid" identifier) and similar technologies to operate the Services, remember preferences, and attribute leads and conversions. We do not use third-party advertising cookies on our own properties. Inside the logged-in application, Google Analytics sets first-party analytics cookies ("_ga" and "_ga_<id>") to measure product usage; they are not used for advertising, and Google Analytics is not loaded when your browser sends a Global Privacy Control signal. Browser controls and opt-out mechanisms (including Global Privacy Control) are honored where technically feasible.

Third-Party Services

The Services integrate with many third-party platforms (see Subprocessors above and any services your workspace administrator connects). Those services have their own privacy policies governing their use of your data, and we encourage you to review them.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page, updating the "Last updated" date, and, where appropriate, sending an email or in-app notice.

Contact Us

If you have questions about this Privacy Policy or want to exercise any of your rights, contact us at: support@gofunnel.ai