Privacy Policy
How Testamplify LLC handles personal information when people use Concierge, visit our websites, connect an integration, or interact with a customer’s Concierge Agent.
Last updated: August 19, 2026
1. Who we are and when this policy applies
Concierge is built by PracticaLabs and owned and operated by Testamplify LLC (“Concierge,” “we,” “us,” or “our”). Questions can be sent to support@poweredbyconcierge.com.
This policy applies to poweredbyconcierge.com, Concierge accounts, the Concierge Agent and inbox, Concierge Pages, mobile experiences, Growth and Insights features, integrations, support, and other services that link to this policy.
For account administration, billing, our public websites, product analytics, and direct support, Testamplify LLC generally determines why and how information is processed. When a Concierge customer uses the service to interact with its own website visitors, that customer determines the purpose of the interaction and Testamplify LLC processes visitor information on the customer's behalf. Visitors should also review the privacy notice of the business whose site they are visiting.
2. Information we collect
Account, team, and billing information
- Name, email address, phone number, profile image, account role, team memberships, and authentication records.
- Subscription, plan, invoice, transaction, and payment-status information. Payment card details are processed by our payment provider and are not stored as full card numbers by Concierge.
- Support requests, administrative records, and communications with us.
Visitor, conversation, and customer-growth information
- Chat messages, internal notes, assignments, replies, tickets, call requests, contact names, email addresses, and phone numbers.
- Conversation source, page URL, landing page, referrer, timestamps, visitor country, IP address, device, browser, operating system, and user agent.
- Page views, clicks, scrolling, navigation paths, and limited live interaction signals such as a typing preview when that feature is enabled.
- Customer relationship lifecycle, ownership, consent indicators, tags, source, outcome, conversion value, currency, and internal follow-up notes entered by an authorized customer user.
Website, content, and agent information
- Public website pages, visible text, links, metadata, structured data, business information, screenshots or uploaded files, and crawler findings used to build and evaluate a site's Concierge experience.
- Agent instructions, knowledge sources, routing rules, voice settings, page content, domains, and customer configuration.
- Voice transcripts or audio-derived content, usage minutes, and operational cost metadata when voice is enabled.
Integration and device information
- Provider account identifiers, selected resources, requested scopes, connection status, encrypted OAuth access and refresh tokens, webhook configuration, and synchronization records.
- Google Search Console metrics, Google Business Profile information, and Google Ads account or campaign metrics when a customer expressly connects those services.
- Mobile push-notification token, platform, device label, and app version when notifications are enabled.
Public-site and security information
- Host, path, referrer, campaign parameters, session identifier, cookie preferences, and basic product or marketing events after any required consent.
- When a person requests a public Concierge website preview: the submitted website URL and work email, optional name, scan status and results, referral or campaign source, account-conversion match, and the version and timestamp of any optional outreach consent.
- IP address, user agent, request identifiers, authentication events, security logs, and abuse-prevention signals. Public-preview rate limiting stores a one-way requester hash rather than displaying a raw IP address to Platform Admin.
3. Sources of information
We receive information directly from account users and visitors; automatically from browsers, devices, and the installed Concierge Agent; from public website pages a customer authorizes us to scan; from connected providers; from customer team members; and from service providers that help us operate Concierge.
4. How we use information
- Provide, personalize, maintain, and secure Concierge.
- Generate and deliver AI-assisted responses, voice responses, recommendations, website findings, and agent previews. The initial public website preview is produced from deterministic crawler evidence and does not require generative AI.
- Secure a requested public preview, show its results, match the submitted email to a later Concierge account, and contact the person about the preview or setup only when the optional outreach choice was selected.
- Route conversations, notifications, calls, tickets, and customer follow-up to the destinations configured by the customer.
- Synchronize information with customer-authorized Google, CRM, productivity, communication, and marketplace providers.
- Administer accounts, subscriptions, payments, limits, invoices, trials, and customer support.
- Detect fraud, abuse, security incidents, prohibited content, and violations of our policies.
- Measure reliability and, where permitted, understand product and public-site usage.
- Comply with law, protect rights and safety, and establish or defend legal claims.
Where a legal basis is required, we rely on performance of a contract, consent, compliance with legal obligations, and legitimate interests such as operating, securing, and improving the service. A Concierge customer may rely on a different lawful basis for its visitor interactions and is responsible for communicating that basis to its visitors.
5. Artificial intelligence and human review
Concierge uses AI providers to help generate answers, summarize or classify conversations, analyze authorized website content, and support voice or workflow features. AI output may be inaccurate or incomplete and should not replace professional judgment. Authorized customer personnel may review, join, or continue a conversation. Read our AI Disclosure for limitations and human-escalation information.
We provide customer content to AI providers only as needed to operate enabled features and subject to our provider arrangements. We do not use visitor conversations to create a public advertising profile. Customers should not submit content they are not authorized to process.
6. Google user data
When an authorized user connects Google, Concierge requests only the scopes shown during Google authorization and uses Google data to provide the selected integration. Search Console supports read-only search insights; Business Profile supports selected location and presence features; Google Ads supports read-only advertiser and campaign insights unless a future feature separately requests write access.
OAuth tokens are stored in encrypted form, access is limited to the connected account and authorized Concierge services, and Google user data is not sold, used for cross-context behavioral advertising, or used to train a general-purpose AI model. A user can disconnect the provider in Concierge or revoke access through their Google Account. A verified deletion request may be submitted through Privacy Choices. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
7. When we disclose information
- To the Concierge customer and its authorized teammates, assignees, agencies, and connected destinations.
- To infrastructure, hosting, database, email, payment, AI, voice, geolocation, analytics, security, support, and integration providers acting for us.
- To a provider the customer expressly connects, such as Google, Slack, Taskologic, a CRM, Airtable, or a webhook destination.
- To professional advisers, authorities, or other parties when reasonably necessary to comply with law or protect rights, safety, and service integrity.
- In a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and notice obligations.
Our current provider list is available on the Subprocessors page.
8. Cookies and analytics
Necessary browser storage supports security, authentication, preferences, and core operation. Optional analytics is used only after the applicable consent choice. You can reject optional analytics or change your choice at any time. See the Cookie Notice.
9. Retention and deletion
We retain information according to its purpose, account status, customer instructions, legal requirements, security needs, and backup lifecycle. We do not keep every category for the same period. Our Data Retention Notice describes the current category-level schedule.
Customers may remove records through available product controls. Individuals can use Privacy Choices or the Data Deletion instructions. Limited billing, tax, fraud, security, dispute, audit, backup, and legal-hold information may be retained when necessary.
10. International data transfers
Concierge and its providers may process information in the United States and other countries where they operate. Where required, we use contractual protections or another recognized transfer mechanism. Business customers that require contractual transfer terms may review our Data Processing Addendum.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, encrypted transport, protected secrets, provider-token encryption, request validation, security logging, and rate limiting. No service can guarantee absolute security. Read our Security overview or report a potential vulnerability through Security Reporting.
12. Health information and high-risk data
The standard Concierge service is designed for administrative website information and routing—not diagnosis, treatment, emergency response, or clinical decision-making. Unless a separate written agreement expressly states otherwise, the standard service is not offered as a HIPAA-compliant service and Testamplify LLC does not enter into a Business Associate Agreement by default.
Customers should minimize sensitive information and route medical, legal, financial, child-safety, emergency, and other high-risk matters to qualified people and approved private channels. Visitors should not provide sensitive health information through Concierge unless the relevant business has clearly instructed them to do so through an approved process.
13. Your privacy choices and rights
Depending on location and context, a person may have rights to access, know about, correct, delete, restrict, object to, or receive a portable copy of personal information, or to withdraw consent. Where applicable, a person may also opt out of sale or sharing and appeal a decision. Concierge does not currently sell personal information for money or share it for cross-context behavioral advertising.
Submit a verified request at Privacy Choices. We may need to verify identity, authority, account ownership, or the records involved. We will not discriminate against a person for exercising an applicable privacy right.
14. Children
Concierge accounts are not intended for children under 18. Our public services are not directed to children under 13, and we do not knowingly collect their personal information through our own public website. Customers serving families or children must configure their use appropriately, avoid unnecessary child-specific information, and obtain any legally required authorization. Contact us if you believe a child's information was submitted improperly.
15. Changes and contact
We may update this policy as the product, providers, and law change. The “Last updated” date identifies the current version. We will provide additional notice when a material change requires it.
Testamplify LLC
support@poweredbyconcierge.com