PRIVACY

Privacy Policy

Last Updated: June 6, 2026

Section 1 — Introduction

This Privacy Policy describes how AXYION LLC, an Oklahoma limited liability company ("Axyion," "we," "us," or "our"), collects, uses, and shares information when you visit axyion.agency, use our client portal at app.axyion.agency, or engage our services. Axyion is a web design, AI automation, and digital marketing agency based in Broken Arrow and Tulsa, Oklahoma, USA. Our services are intended for businesses and the people who operate them; they are not directed to children. By using our website, portal, or services, you agree to the practices described in this policy.

Section 2 — Our Role (Controller vs. Service Provider)

For personal information about our clients and prospective clients (name, business contact details, billing information, portal activity), Axyion acts as a data controller. For data we process on behalf of clients — including website-visitor analytics collected on client websites, and advertising and email data accessed through connected accounts — Axyion acts as a service provider/processor; our client is the controller and we process that data only to provide our services under our agreement with the client. Visitors to client websites should consult that client's own privacy policy.

Section 3 — Information We Collect

We collect the following categories of information:

  • Information you provide directly: your name, email address, phone number, business name, and project details when you submit a contact form, get-started form, or otherwise communicate with us. Our contact and get-started forms are submitted directly to our own client portal at app.axyion.agency, where the information is stored in our database (see the providers listed in Section 13).
  • Electronic signature data: when you sign a Statement of Work or other document in the portal, we record your typed name, the date and time of signing, your account identifier, and your IP address at the time of signing for legal verification.
  • Uploaded files: project-related files you upload to the portal.
  • Portal messages: messages you send through the portal's support channel to Axyion, and messages exchanged through the portal's internal team-chat channel among your own invited team members.
  • Billing information: billing details and payment method information processed through our third-party payment processor. We do not collect or store full payment card numbers.
  • Website analytics: on axyion.agency and on client websites we manage, we automatically collect the page path visited, the referrer (the referring URL), device type, browser type, operating system, and an approximate country of origin derived from IP address. The full IP address is not stored. This data is collected through our own cookieless beacon and through a cookieless third-party analytics service.
  • OAuth tokens and connected-account data: when you connect a third-party account (Gmail, Microsoft Outlook, Google Ads, Meta/Facebook Ads, or TikTok Ads) via OAuth, we store an encrypted access token and access the data described in Sections 8 through 10.
  • Gmail and Microsoft Outlook email data: where you connect a Gmail or Microsoft Outlook account, we access email content and related data through Google's or Microsoft's APIs solely to provide the email features you enable.
  • Advertising-account data: campaign performance, ad status, audience settings, and budget data for ad accounts you connect, as described in Section 10.
  • Team-member data: the names, email addresses, and assigned roles of team members an Account Owner invites to the portal.
  • Referral-program data: information needed to administer our referral program, including the identities of referring and referred clients and the resulting discounts.

Under U.S. state privacy laws, the information above falls into the following categories: identifiers (such as name, email, phone, IP address, and account identifiers); commercial information (such as services purchased and billing records); internet or other electronic network activity information (such as analytics, page path, referrer, device, browser, and operating system); and approximate geolocation information (country-level only, derived from IP address).

Section 4 — How We Use Your Information

We use the information we collect to: respond to your inquiries and provide requested services; deliver web design, development, automation, and digital marketing services; grant and manage access to the client portal and team-member permissions; process payments and manage billing and subscriptions; generate and store electronically signed legal documents including Statements of Work; operate the email and advertising integrations you choose to enable; provide support and operate portal messaging; administer our referral program; provide clients with analytics reporting on their website performance; improve our website and service offerings; protect the security and integrity of our services; and comply with applicable legal obligations.

Section 5 — Electronic Signatures and Legal Documents

When you sign a Statement of Work or other document through our client portal, we record your typed name as an electronic signature, the date and time of signing, your account identifier, and your IP address at the time of signing. This information is retained as part of the legally executed document record for the period described in our retention schedule in Section 14.

Electronic signatures collected through our portal are legally binding under the Electronic Signatures in Global and National Commerce Act (ESIGN Act, 15 U.S.C. § 7001 et seq.) and the Uniform Electronic Transactions Act (UETA). Signed documents are stored securely and are available to both parties upon request.

Section 6 — Website Analytics

Our website analytics rely on two cookieless systems. The first is a custom beacon we operate, which sends the page path, the referrer (referring URL), device type, browser type, and operating system to our infrastructure. The second is a third-party, cookieless analytics service that collects aggregate page-view and visitor data. Neither system uses advertising cookies or performs cross-site tracking, and we derive only an approximate, country-level location from IP address without storing the full IP address.

For client websites we manage, our custom beacon may be deployed to provide clients with performance reporting on their own website traffic. In that case Axyion acts as a service provider to the client, who is the controller of that visitor data. In all cases, only aggregate and device-level data is collected, and we do not build individual user profiles from analytics data.

Section 7 — Portal Messaging and Team Chat

The portal includes a support channel for communicating with Axyion and an internal team-chat channel for communication among your own invited team members. You acknowledge and agree that Axyion personnel and systems may access, monitor, and review messages sent through both channels for purposes of providing support, ensuring security, investigating abuse or violations of our Terms, and complying with law. Do not use portal messaging to share information you do not wish Axyion to be able to access. Support messages are automatically deleted 24 hours after they are sent; internal team-chat messages are automatically deleted 7 days after they are sent.

Section 8 — Google User Data and Limited Use

When you connect a Gmail account to the Axyion portal, you authorize us to access certain Google user data through Google's APIs, including the ability to read, compose, send, and display email messages associated with your connected account, solely to provide the email features you enable within the portal.

Axyion's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements (https://developers.google.com/terms/api-services-user-data-policy).

Specifically:

  • We access Google user data only to operate the email features you choose to use.
  • We do NOT use Google user data, including the content of your emails, to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
  • We do NOT allow humans to read your email data, except (a) with your affirmative consent, (b) as necessary for security, (c) to comply with applicable law, or (d) where aggregated and anonymized.
  • We do NOT sell Google user data and do not transfer it to third parties except as necessary to provide the features you enable, to comply with law, or in a merger or acquisition.
  • We do NOT store the content of your emails on our servers; email content is accessed live through Google's APIs at the time you view it.
  • OAuth access tokens are stored using AES-256 encryption and are permanently deleted immediately upon disconnection or account termination.

Section 9 — Microsoft Outlook Email Data

When you connect a Microsoft Outlook account to the Axyion portal, you authorize us to access your Outlook mail through the Microsoft Graph API (Mail.Read, Mail.Send, and Mail.ReadWrite) solely to provide the email features you enable within the portal. As with Gmail, we do not store the content of your emails on our servers; email content is accessed live through Microsoft's APIs at the time you view it and is not used to train artificial-intelligence or machine-learning models. OAuth access tokens are stored using AES-256 encryption and are permanently deleted immediately upon disconnection or account termination. Our use of Microsoft data complies with the Microsoft APIs Terms of Use and the Microsoft Privacy Statement.

Section 10 — Advertising Platform Data

Separately from the email integrations described in Sections 8 and 9, Axyion integrates with advertising APIs provided by Google (Google Ads), Meta (Facebook and Instagram Ads), and TikTok (TikTok Ads) to manage ad campaigns on behalf of clients who have explicitly authorized this access. Through these advertising integrations we access only campaign performance data, ad creative status, audience targeting settings, and budget information, and only for the client who authorized the connection, solely for the purpose of campaign management and reporting.

For these advertising platforms only, we do not access personal messages, organic posts, contact lists, or any data outside the scope of advertising management. (This limitation does not apply to the separate email integrations described in Sections 8 and 9, which by design access the email data you authorize.) We do not sell advertising platform data, and we do not use it for any purpose other than providing services to the client who authorized the connection. Access tokens provided by these platforms are stored using AES-256 encryption and are deleted immediately upon disconnection or termination of the service relationship.

Section 11 — Requesting Deletion of Data Obtained Through Meta

If you connected a Meta (Facebook/Instagram) advertising account and wish to request deletion of data we obtained through Meta, email hello@axyion.agency with the subject "Meta Data Deletion Request." We will delete the associated Meta Platform Data and confirm within 30 days. Disconnecting your Meta ad account in the portal also immediately revokes our access and deletes the stored credentials.

Section 12 — TikTok Platform Compliance

For the TikTok Ads integration, we comply with the TikTok Developer Terms of Service and the TikTok Marketing API policies. We access only advertising campaign, ad, audience-setting, and budget data for the client who authorized the connection. TikTok access tokens are stored using AES-256 encryption and are deleted immediately upon disconnection or termination of the service relationship.

Section 13 — Third-Party Service Providers and Subprocessors

To deliver our website and services, we share data with the following categories of third-party service providers, each of which processes data only to perform its specific function:

  • Payment and billing processing — third-party payment processor — USA
  • Database and encrypted file storage — third-party cloud infrastructure provider — USA
  • Authentication and account management — third-party authentication provider — USA
  • Website hosting, content delivery, and cookieless website analytics — third-party hosting and infrastructure provider — USA
  • Transactional email delivery — third-party email-delivery provider — USA
  • Email account integrations — the email providers you choose to connect, as described in Sections 8–9 — USA
  • Advertising account integrations — the advertising platforms you choose to connect, as described in Sections 10–12 — USA
  • Fulfillment partners — certain subcontracted services such as content and SEO production — location varies, including outside the U.S.

All providers are bound by confidentiality and process data only to perform their function. We do not sell your personal information, and we do not use it for our own advertising; we manage advertising campaigns only on behalf of clients who authorize it, using their own connected accounts.

Section 14 — Data Retention

This is our canonical data retention schedule. Where our Terms of Service reference data retention, they refer to this schedule:

  • Account and project records — duration of engagement plus up to 3 years
  • Support-channel messages — auto-deleted 24 hours after sending
  • Internal team-chat messages — auto-deleted 7 days after sending
  • Client-uploaded files — 30 days after account termination
  • Signed SOWs / executed agreements — at least 7 years after the engagement ends
  • Analytics data — rolling 90 days
  • OAuth tokens (email and ad accounts) — deleted immediately on disconnect/termination
  • Email content — not stored (accessed live via API)
  • Payment/billing data — held by our third-party payment processor per its policies

Certain data may be retained beyond the periods above where required by law, regulation, or ongoing legal proceedings. You may request deletion of non-legal-record data at any time by contacting hello@axyion.agency.

Section 15 — Cookies

Our main website at axyion.agency does not use advertising or behavioral tracking cookies. The website analytics described in Section 6 are cookieless: our custom beacon uses the browser's sendBeacon mechanism, and our third-party analytics service operates without cookies. Our client portal at app.axyion.agency uses functional authentication cookies provided by our third-party authentication provider to maintain your logged-in session; these are required for the portal to operate. No advertising cookies are used on any Axyion property.

Section 16 — Your Privacy Rights

Depending on your state, you may have rights to know/access, correct, delete, obtain a portable copy of, and opt out of the sale or targeted-advertising use of your personal information. We do not sell your personal information or use it for cross-context behavioral or targeted advertising. We will not discriminate against you for exercising these rights. To exercise a right, email hello@axyion.agency; we verify by matching information against our records and respond within 45 days (extendable 45 more where permitted). You may use an authorized agent.

Appeals: If we decline, email hello@axyion.agency with subject "Privacy Request Appeal." We respond within 45 days (60 for Texas residents); if denied you may contact your state Attorney General.

California (CCPA/CPRA): you may request the categories of personal information collected, sources, purposes, and categories disclosed, and may limit use of sensitive personal information.

Texas (TDPSA): the rights above apply; we do not sell sensitive personal data without consent.

Section 17 — International Users

Axyion is based in the United States and our providers are primarily in the United States. If you access our services from outside the U.S. (including the EEA, UK, or Switzerland), your information will be transferred to and processed in the United States. Where we process EEA/UK personal data on a client's behalf, we act as a processor and will enter a Data Processing Addendum on request. We honor access, correction, and deletion rights for all users regardless of location.

Section 18 — Security

We implement commercially reasonable technical and organizational measures to protect your personal information, including access controls, private file storage, and secure authentication. Data is encrypted in transit using TLS, and OAuth access tokens for connected accounts are encrypted at rest using AES-256. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

In the event of a data breach affecting your personal information, we will notify you and applicable authorities as required by law, including the Oklahoma Security Breach Notification Act.

Section 19 — Children's Privacy

Our services are business-to-business and are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, please contact us at hello@axyion.agency. Where a client's own website is directed to children, compliance with the Children's Online Privacy Protection Act (COPPA) and similar laws for that website is the client's responsibility.

Section 20 — Changes to This Policy

We may update this Privacy Policy from time to time. We will update the Last Updated date at the top of this page and, for material changes, will notify active clients by email. Continued use of our website or services after any changes constitutes acceptance of the updated policy.

Section 21 — Third-Party Platform Privacy Policies

Our integrations are subject to the privacy policies of the respective platforms. We encourage you to review the privacy policies of any platform whose services are connected to your Axyion account:

Section 22 — Contact

For privacy-related inquiries, contact AXYION LLC at hello@axyion.agency or (918) 416-8951.