Privacy Policy

Last updated: June 1, 2026

Introduction

GoFunnel ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, web application, Chrome extension, tracking scripts, and related services (collectively, the "Services").

Our Role

GoFunnel acts in two capacities depending on the data involved:

  • Controller for account data of our direct customers (e.g., the people who sign up for and administer a GoFunnel workspace).
  • Processor for end-user data that our customers route through GoFunnel (e.g., leads, form submissions, call recordings, and payments belonging to our customers' businesses). Our customers are the controllers of that data, and our processing is governed by our Data Processing Agreement (available on request at support@gofunnel.ai).

Information We Collect

Account Information

When you create an account, we collect:

  • Email address
  • Name (if provided)
  • Authentication credentials (securely hashed by our auth provider)
  • Billing information (processed by Stripe; we do not store full card numbers)

Lead and Form Data

When our customers configure forms, tracking, or integrations, we collect and store data about the leads, customers, and prospects who interact with their funnels. This may include names, email addresses, phone numbers, IP addresses, user agents, page-view history, UTM parameters, custom form fields, and any other information our customers choose to capture.

Payment and Order Data

Through integrations with Stripe, ThriveCart, ClickFunnels, Whop, Fanbasis, and similar checkout platforms, we receive transaction records (e.g., order amount, currency, product, customer email, transaction ID). We do not store full payment card numbers; that information stays with the payment processor.

Call Recordings and Transcripts

If our customers connect Zoom or Fathom, we ingest sales-call recordings, transcripts, and call metadata (participants, duration, timestamps) to power our Call Intelligence features. Our customers are responsible for obtaining any consent required under applicable wiretap and recording laws (including two-party-consent jurisdictions such as California, Florida, Illinois, Massachusetts, Pennsylvania, and Washington).

Tracking and Attribution Data

When a website operator installs our tracking script, we set a first-party identifier (the "gf_sid" cookie) and collect page views, click events, form interactions, video engagement, referrer URLs, UTM parameters, IP address, and device/browser information. This data is associated with our customer's workspace and used to attribute leads and conversions across their funnel.

Connected Service Data

When you connect a third-party service (such as a CRM, calendar, advertising platform, or analytics tool), we store OAuth tokens or API keys securely and access only the data necessary to deliver the features you have enabled.

Usage Data

We automatically collect information about how you use the Services, including browser type, device identifiers, IP address, access times, and pages viewed. We may use session-replay tooling (Microsoft Clarity) on our own marketing and product pages to record interactions for usability analysis.

AI and Automated Processing

GoFunnel uses artificial intelligence to analyze call recordings, transcripts, form submissions, and lead data. This processing may include:

  • Generating call summaries, scoring, and coaching insights
  • Classifying leads, calls, and events
  • Mapping fields between integrated systems
  • Suggesting integration configurations

To perform this processing we use third-party large-language-model providers, currently OpenAI, Anthropic, and Google (Gemini). Content sent to these providers is processed under their respective enterprise/API terms, which prohibit using customer content to train their foundation models. We do not sell this content, and we do not use it for advertising.

Chrome Extension

Our Chrome extension ("GoFunnel Forms") collects and uses data as follows:

Data Collected

  • Authentication tokens (stored locally to maintain your session)
  • Form responses you submit through the extension
  • Page context on *.gofunnel.ai pages where the extension's content script runs to detect form elements

Data Usage

  • Authentication data is used solely to verify your identity
  • Form responses are transmitted to GoFunnel servers
  • No data is used for advertising
  • No data is sold to third parties

Permissions

  • storage: Stores authentication session locally
  • identity: Enables Google sign-in
  • Host permissions (*.gofunnel.ai, *.supabase.co): Communicates with GoFunnel servers and runs a content script on GoFunnel pages to detect and assist with form interactions

How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Services
  • Authenticate accounts and maintain security
  • Process form submissions, payments, and webhook events
  • Sync data with connected third-party services
  • Send hashed identifiers (such as email or phone) to advertising platforms (e.g., Meta Conversions API, Google Ads) for conversion measurement, where our customer has configured this
  • Generate analytics, dashboards, and AI-powered insights
  • Respond to support requests and service communications
  • Comply with legal obligations and enforce our Terms of Service

Data Sharing

We do not sell your personal information. We share data only in these circumstances:

  • Subprocessors: Vetted third parties that help operate the Services (see list below)
  • Connected services: Third-party platforms you or your workspace administrator explicitly connect (e.g., your CRM, calendar, advertising account)
  • Advertising platforms (server-side): Where configured, we send conversion events containing hashed identifiers to platforms such as Meta and Google so our customers can measure ad performance
  • Business transfers: In connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections
  • Legal requirements: When required by law, subpoena, or to protect our rights, users, or the public

Subprocessors

We engage the following categories of subprocessors to deliver the Services. An up-to-date list is available on request.

ProviderPurpose
SupabaseAuthentication and primary database
VercelApplication hosting and edge delivery
InngestBackground job and webhook processing
StripeSubscription billing and payment processing
ResendTransactional email delivery
Google (OAuth)Single sign-on
OpenAI, Anthropic, Google GeminiLarge-language-model processing for AI features
Microsoft ClaritySession replay and usability analytics on our own properties
Meta (Facebook), Google AdsServer-side conversion APIs (where enabled by customer)
Zoom, FathomCall recording, transcription, and metadata
Customer-connected platforms (e.g., GoHighLevel, Close, HubSpot, Typeform, Calendly, ClickFunnels, ThriveCart, Whop, Fanbasis, iClosed, Instantly, Hyros, Wix, ClickUp)Activated only when a customer explicitly connects the service

Data Security

We implement technical and organizational measures appropriate to the risk of processing, including encryption in transit (TLS) and at rest, role-based access controls, secret management via a dedicated secrets platform, audit logging, and least-privilege production access. No method of transmission or storage is 100% secure, but we work to maintain industry-standard safeguards.

Breach Notification

If we become aware of a personal-data breach affecting your information, we will notify affected customers without undue delay and, where required, within the timeframes mandated by applicable law (including GDPR's 72-hour window for notifying supervisory authorities). Customers acting as controllers are responsible for notifying their own end users where required.

Data Retention

We retain your information for as long as your account is active and as needed to provide the Services. Typical retention periods:

  • Account data: Until account deletion, then up to 30 days in backups
  • Lead, form, and event data: For the lifetime of the workspace, unless the workspace owner requests deletion
  • Call recordings and transcripts: For the lifetime of the workspace, subject to the source provider's retention policy
  • Billing records: Retained as required by tax and accounting law (typically 7 years)
  • Logs and security telemetry: Up to 90 days

You may request deletion of your account and associated data at any time by contacting support@gofunnel.ai.

Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Data portability (receive your data in a machine-readable format)
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a supervisory authority

If your data was provided to GoFunnel by one of our customers (for example, you submitted a form on their website), please direct rights requests to that customer in the first instance. We will assist them in fulfilling those requests.

California Residents (CCPA / CPRA)

If you are a California resident, you have the rights described above plus the right to know what categories of personal information we collect, the right to opt out of "sale" or "sharing" of personal information, and the right to limit use of sensitive personal information.

We do not sell personal information. Our server-side transmissions of hashed conversion events to advertising platforms (e.g., Meta, Google) may be considered "sharing" for cross-context behavioral advertising under California law. You can opt out by emailing support@gofunnel.ai with the subject "Do Not Sell or Share My Personal Information."

International Data Transfers

GoFunnel is operated from the United States, and our subprocessors may process data in the United States and other jurisdictions. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) to safeguard the transfer.

Children's Privacy

The Services are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us so we can delete it.

Cookies and Tracking

We and our customers use first-party cookies (including the "gf_sid" identifier) and similar technologies to operate the Services, remember preferences, and attribute leads and conversions. We do not use third-party advertising cookies on our own properties. Browser controls and opt-out mechanisms (including Global Privacy Control) are honored where technically feasible.

Third-Party Services

The Services integrate with many third-party platforms (see Subprocessors above and any services your workspace administrator connects). Those services have their own privacy policies governing their use of your data, and we encourage you to review them.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page, updating the "Last updated" date, and, where appropriate, sending an email or in-app notice.

Contact Us

If you have questions about this Privacy Policy or want to exercise any of your rights, contact us at: support@gofunnel.ai