Legal
Privacy Policy
Version 2026-09-17 · Effective September 17, 2026 · Replaces the January 2025 version
The Livewell Media LLC, 27131 Calle Arroyo, Suite 1722, San Juan Capistrano, CA 92675
What we collect, why, who sees it, how long we keep it, how we protect it, and what you can ask us to do about it. Written to California's disclosure rules and honored for everyone.
1. Who we are and what this covers
The Livewell Media LLC ("TLWM", "we") is a California limited liability company at 27131 Calle Arroyo, Suite 1722, San Juan Capistrano, CA 92675. This policy covers thelivewellmedia.com (the "Site") and the client application at app.thelivewellmedia.com (the "Client Portal").
It describes what personal information we collect, where it comes from, why we use it, who we share it with, how long we keep it, how we protect it, and the rights you have over it. If you are a client, the Terms and Conditions of Service also apply, and Section 14 of those Terms governs how we handle the data you give us about your own customers.
2. Information we collect and where it comes from
You give it to us directly:
• Qualifier and contact forms — name, email address, phone number, company, website, industry, what you sell and to whom, whether you are the decision maker, current and target revenue, leads per month, close rate, lead channels, budget, ad spend, timeline, who handles follow-up, links to your content, and any compliance notes you add.
• Booking a call — name, email address and the time you choose, collected through Calendly's scheduling widget on our Apply page.
• Email, phone and messages — whatever you include when you write or call us.
• Client Portal account — name, email address, company, role, and your sign-in details.
• Orders — the services you select, the terms version you accept, and the acceptance record: who accepted, the date and time, the network (IP) address and browser used. This record is the electronic signature on your order.
Collected automatically when you use the Site:
• Usage and device data — pages viewed, links clicked, referring page, approximate location derived from your network address, browser and device type, and the date and time of your visit. We collect this through Google Analytics 4, which does not log or store full IP addresses, and through our hosting platform's first-party analytics, which records that a form was submitted and the industry, budget and timeline selected — not your name or contact details.
• Cookies and similar technologies — see Section 5.
Data our clients give us about their customers:
• When a client connects a system to the Client Portal or hands us data to perform a service — contacts, leads, bookings, campaign and engagement records from tools such as a CRM, an email platform, a scheduling tool or an advertising account — we process that information only to perform the ordered services and on the client's instructions. We are a service provider for that data, not its owner. Requests about it go to the client; we will point you to them.
We do not collect Social Security numbers, government identifiers, financial account numbers or payment card numbers through the Site or the Client Portal. Invoices are paid through payment links and codes handled by the payment provider, or by bank transfer; card numbers never pass through our systems.
3. How we use it
• To answer your inquiry, qualify whether we are a fit, and schedule and hold calls.
• To provide the services a client orders, run the Client Portal, and keep the records the Terms require — including the acceptance record on every order.
• To invoice, collect payment, and keep our books.
• To send you information about our services. You can opt out at any time (Section 9).
• To understand how the Site is used and improve it.
• To protect the Site, the Client Portal and our clients' data, and to detect misuse.
• To comply with law, respond to lawful requests, and enforce our Terms.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act. We do not use sensitive personal information to infer characteristics about you, and we do not make automated decisions about you that produce legal or similarly significant effects.
4. Who we share it with
We share personal information only with the providers below, and only for the purpose stated. Each is bound by a contract or its published terms to use the information solely to provide its service to us.
• Hosting and application platform — Base44 (a Wix company) hosts the Site and the Client Portal and processes all form submissions, order records and client data on our behalf. Base44's own subprocessors include MongoDB, Google Cloud Platform, Render, SendGrid, Datadog, Wix.com Ltd. and, for AI features, OpenAI and Anthropic; the current list is published on Base44's security page.
• Email delivery — form submissions and order notifications are delivered to our mailbox by SendGrid through the hosting platform.
• Business email and documents — Google Workspace, where our mailboxes and working files live.
• Scheduling — Calendly, when you book a call. Calendly's privacy policy governs what it collects on its widget.
• Analytics — Google Analytics 4. Google's privacy policy governs its processing. We have not enabled Google's advertising features or signals on this property.
• Embedded video — Vimeo and YouTube players on the Site may set their own cookies when a video loads; their policies govern that.
• Client systems — when performing services, we send data to the tools a client has asked us to use for them (for example their email platform, CRM, scheduling tool, video channel or advertising account). That data belongs to the client, and the client's instructions govern it.
• Professional advisers, and authorities where the law requires.
• A successor, if TLWM is sold or merged, under the same commitments made here.
We do not share personal information with third parties for their own direct marketing, and we have not done so in the past calendar year.
5. Cookies, analytics, and the signals we honor
The Site uses a small number of cookies and similar technologies: those needed for the Site and the Client Portal to work (including keeping you signed in), Google Analytics 4 cookies that tell us which pages are used, and cookies set by embedded Vimeo or YouTube players when a video loads. We do not run advertising cookies or retargeting pixels on the Site.
Global Privacy Control and Do Not Track: if your browser sends a Global Privacy Control (GPC) signal, or a Do Not Track signal, the Site turns analytics off for your visit automatically. You do not need to ask. You can also block or delete cookies in your browser settings; the Site will still work, though a few things — like staying signed in to the Client Portal — may not.
Third parties on the Site (Google Analytics, Calendly, Vimeo, YouTube) may collect information about your online activities over time and across other websites when you use their services. We do not.
6. How long we keep it
• Qualifier and contact form submissions, and call bookings: up to 24 months from the last contact, then deleted, unless you become a client.
• Client Portal accounts and client data: for as long as the client has an active service, and for 90 days after the last service ends (Terms, Section 20.3). Within that window the client may ask us in writing to return or delete the personal data we hold for them (Terms, Section 14.3); copies in routine backups age out on the backup schedule and remain protected until they do. Deliverable files are organized and handed over at the end of the engagement.
• Order and acceptance records, invoices and payment records: as long as needed to evidence the agreement and meet tax and accounting requirements — at least four years after the last order, and longer where the law requires.
• Analytics data: Google Analytics 4 retains event data for up to 14 months; our hosting platform's analytics are retained under its published terms.
• Email: retained in our business mailboxes under our ordinary retention practice, and deleted on request where no legal or contractual reason requires keeping it.
7. How we protect it
The Site and the Client Portal run on the Base44 platform, which is independently audited under SOC 2 Type II and certified to ISO 27001, and offers a GDPR Data Processing Agreement on request. On that platform:
• Everything is encrypted in transit using TLS 1.2 or higher, and encrypted at rest using AES-256. Backups are encrypted to the same standard.
• Data is stored in the United States.
• Each client's data in the Client Portal is isolated by row-level security: a client's users can see only their own organization's records, enforced by the database, not just by the screen.
• Connections to a client's systems (CRM, email platform, scheduling, advertising and video accounts) use API keys or OAuth tokens the client authorizes, stored in the platform's encrypted secrets store and revocable by the client at any time. We never ask for, and do not store, a client's passwords.
• Administrative access is limited to named TLWM accounts on a least-privilege basis and protected by two-factor authentication. Access is removed when a person's role ends.
• The platform is monitored around the clock, undergoes third-party penetration testing, and operates a formal incident response plan.
We do not store payment card numbers, bank account numbers or government identifiers. If we ever became aware of unauthorized access to personal data in our possession, we would notify the affected client without undue delay and in any event within 72 hours (Terms, Section 14.2), and notify affected California residents as California Civil Code Section 1798.82 requires.
No method of transmission or storage is completely secure. We keep these measures current and proportionate to the data we hold, and we ask clients to do the same on their side of every connection.
8. Your California privacy rights
The California Consumer Privacy Act (as amended by the California Privacy Rights Act) applies to businesses above certain size thresholds. Whether or not those thresholds apply to TLWM in a given year, we honor the following rights for every California resident, and we extend them to residents of any other state:
• Right to know — what personal information we have collected about you, the sources, the purposes, and who we have shared it with, together with a copy of the specific pieces of information.
• Right to delete — subject to exceptions the law allows, such as records we must keep to evidence a contract or meet a legal obligation.
• Right to correct — inaccurate personal information.
• Right to opt out of sale or sharing — we do not sell or share personal information, and we honor GPC signals as an opt-out (Section 5).
• Right to limit use of sensitive personal information — we do not use it beyond what the services require.
• Right not to be discriminated against for exercising any of these rights.
How to make a request: email grow@thelivewellmedia.com with "Privacy request" in the subject, or call +1 (657) 549-2043. Tell us which right you are exercising. We will confirm receipt within 10 business days and respond within 45 days; if we need more time, we will tell you why and take up to 45 more. To protect your information we verify requests by matching them to the details we already hold (for example, replying from the email address on file) and may ask for one more identifying detail; we never ask for a government ID or a payment card number to verify a request. You may use an authorized agent; we will ask for your written permission and may confirm the request with you directly.
Requests about data our clients gave us about their customers go to the client, who controls that data; we will forward your request to them within 5 business days and help them fulfil it.
California's "Shine the Light" law (Civil Code Section 1798.83): we do not disclose personal information to third parties for their own direct marketing purposes.
9. Marketing email and text messages
If we send you marketing email, every message carries an unsubscribe link, and we honor opt-outs within 10 business days as the CAN-SPAM Act requires. Transactional messages — invoices, order confirmations, notices under the Terms — are not marketing and continue while you are a client.
We send text messages only to people who have agreed to receive them, and only about the matter they agreed to. Reply STOP to any text to stop, and HELP for help. Message and data rates may apply. We do not share mobile numbers or SMS consent with third parties for their own marketing.
10. Children
The Site and the Client Portal are for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from anyone under 16. If you believe a minor has given us personal information, email grow@thelivewellmedia.com and we will delete it.
11. Links to other sites
The Site links to third-party websites and embeds third-party players and widgets. We are not responsible for the privacy practices or content of those services. Read their policies before giving them any information.
12. Changes to this policy
When we change this policy we post the new version on this page with a new version number and effective date at the top. If a change materially reduces your rights or changes how we use personal information we already hold, we will email clients and anyone else whose email address we have before the change takes effect. Earlier versions are available on request.
13. Contact
Privacy requests, billing and administration: grow@thelivewellmedia.com · +1 (657) 549-2043
Everything else: info@thelivewellmedia.com
The Livewell Media LLC
27131 Calle Arroyo, Suite 1722
San Juan Capistrano, CA 92675