Legal

The rules, written to be read. Each policy starts with a plain-English summary — the full text follows.

Privacy Policy

EFFECTIVE SEPTEMBER 12, 2026 · THEONLINESAASCOMPANY LLC

The short version

Your documents are encrypted, used only to deliver your fax, and deleted right after delivery — a fax that didn’t go through keeps its documents for 7 days so you can try again.We never sell your personal information or share it for advertising — and we honor Global Privacy Control signals.You can see, correct, export, or delete everything we hold about you — some of it from Settings, all of it by emailing us — including your California and other state-law rights.Sending health records? A HIPAA Business Associate Agreement is available for healthcare organizations.

01Who we are and what this covers

This policy covers faxly.com and the Faxly service, operated by THEONLINESAASCOMPANY LLC (doing business as Faxly), 1309 Coffeen Avenue, STE 1200, Sheridan, WY 82801, United States. It explains what we collect, why, who we share it with, and the rights you have — including rights under California law and other US state privacy laws. Data protection questions go to support@faxly.com.

02What we collect

Identifiers you give us: email address, and optionally your name and mobile number. Commercial information: your plan, payments, and refunds — card payments are processed by Stripe, and we never store your full card number. Fax records: recipient and sender numbers, timestamps, page counts, and delivery outcomes. Document content: the files you send and receive, held transiently as described below. Internet activity: IP address, browser and device type, and pages used. Support communications: emails you send us.

03Where it comes from

Directly from you, from your device when you use the service, from Stripe (payment confirmations), and from telecommunications carriers (delivery confirmations). We do not buy personal information from data brokers.

04How we use it

To deliver and confirm your faxes, run your account and billing, send service emails such as receipts and renewal reminders, answer support requests, prevent fraud and abuse, and comply with law. Marketing email is opt-in only, and every message has a working unsubscribe link. We do not use your information for targeted advertising, and we do not train AI models on your documents.

05Your documents

Documents are encrypted with TLS in transit and AES-256 at rest. They exist on our systems only as long as delivery requires: the files of a delivered fax are deleted right after the receiving machine confirms it; the files of a fax that did not go through are kept for 7 days so you can try again, then deleted; uploads you never send are deleted after 7 days; faxes you receive stay in your account until you delete them or close your account. Delivery receipts contain metadata (numbers, timestamps, page counts), not document content. Staff can never open your documents except with your explicit permission during a support case.

06Health information

Many customers fax medical records. Faxly acts as a transmission conduit for documents you choose to send; we do not use or disclose their contents. Healthcare providers and other covered entities that require one can request a HIPAA Business Associate Agreement at support@faxly.com before sending protected health information.

07Who we share with

Service providers under contract: Stripe for payments, telecommunications carriers to transmit faxes, our cloud infrastructure provider for hosting, and our email provider for service messages — each limited to what their role requires. Legal requests: we disclose only what a valid subpoena, court order, or law requires, and we notify you unless legally prohibited. Business transfers: if Faxly is acquired, your information remains subject to commitments at least as protective as these. WE DO NOT SELL PERSONAL INFORMATION, AND WE DO NOT SHARE IT FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING.

08Cookies and tracking

We use a small set of essential cookies and no advertising cookies, no analytics trackers and no cross-site tracking, as described in our Cookie Policy. We do not sell or share personal information, so there is nothing to opt out of; where state law treats browser opt-out signals as binding, we honor Global Privacy Control (GPC) signals as opt-out requests. Legacy 'Do Not Track' browser signals have no settled standard, so we do not respond to them — GPC is the signal we act on.

09Your rights — everyone

Whatever state you live in, you can update your email address, payment method and plan from Settings, and you can access, correct, export, or delete everything else we hold about you — or close your account — at any time by emailing support@faxly.com from your account address. We verify requests against your account email, respond within 45 days, and never discriminate — no worse service or prices — for exercising rights. An authorized agent may submit requests on your behalf with written permission.

10California residents (CCPA/CPRA)

California residents have the rights to know the categories and specific pieces of personal information we collect (listed in section 02), to delete, to correct, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we use it only to provide the service you request), and to non-discrimination. Requests: support@faxly.com. We do not knowingly sell or share the personal information of anyone, including consumers under 16. California's Shine the Light law: we do not disclose personal information to third parties for their direct marketing.

11Other state privacy laws

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Nevada, and other states with comprehensive privacy laws have equivalent rights of access, correction, deletion, portability, and opt-out of targeted advertising and sales (we do neither). If we refuse a request, you may appeal by replying to our decision; if the appeal fails, you may contact your state Attorney General.

12European Economic Area, United Kingdom and Switzerland (GDPR)

If you are in the EEA, the UK or Switzerland, THEONLINESAASCOMPANY LLC is the controller of your personal data. We process it to perform our contract with you (Art. 6(1)(b) GDPR — delivering your faxes, running your account and billing), to comply with legal obligations (Art. 6(1)(c) — tax and accounting records), and for our legitimate interests (Art. 6(1)(f) — keeping the service secure and preventing abuse); marketing email only with your consent (Art. 6(1)(a)), which you can withdraw at any time. Your data is processed in the United States, where we are established; where our service providers move data across borders we rely on the European Commission’s standard contractual clauses or an adequacy decision, and you can ask us for details. You have the rights to access, rectify, erase, restrict and port your data, to object to processing based on our legitimate interests, to withdraw consent, and to lodge a complaint with your local supervisory authority — in France, the CNIL; in Germany, the data protection authority of your federal state; in Italy, the Garante per la protezione dei dati personali. Providing your email address is required to use the service; everything else is optional. We do not make automated decisions with legal effect about you. Requests: support@faxly.com.

13Japan (APPI)

If you are in Japan, we handle your personal information under the Act on the Protection of Personal Information (APPI) as a business operator established outside Japan. We use it for the purposes in section 04 and entrust parts of the processing to the service providers in section 07, which are located in the United States and other countries whose data-protection rules you can ask us about; we take the security measures described in section 16 and require the same of them. We do not provide personal information to third parties without your consent except where the law allows. You may request disclosure, correction, suspension of use or deletion of your personal information at support@faxly.com, and we respond within the time the law provides. Complaints about our handling of personal information go to the same address; the Personal Information Protection Commission is the supervisory authority.

14Korea (PIPA)

If you are in Korea, we handle your personal information under the Personal Information Protection Act (PIPA) as a business operator established outside Korea. We collect only what section 02 lists, use it for the purposes in section 04, keep it for the periods in section 15 and then destroy it, and entrust parts of the processing to the service providers in section 07 — which means your personal information is transferred to and stored in the United States, where we are established, and processed by those providers in the United States and other countries; you can ask us for their details and object to the transfer, though we cannot provide the service without it. We take the security measures described in section 16. You may request access to, correction or deletion of your personal information, or the suspension of its processing, at support@faxly.com, and we respond within the time the law provides; the company’s representative is our privacy officer and can be reached at the same address. You may also contact the Personal Information Protection Commission, the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118) or the Personal Information Dispute Mediation Committee (1833-6972).

15Retention

Account data: kept while your account is active and deleted within 90 days after you close it. Fax records and delivery receipts: kept 7 years for tax and dispute purposes, unless you request earlier deletion where the law allows. Documents: deleted on the schedule in section 05. Sign-in codes expire after 10 minutes and sign-in sessions after 30 days. Support emails: 2 years. Backup copies expire on a rolling cycle of no more than 30 days.

16Security and breach notification

We protect personal information with encryption in transit and at rest, least-privilege access controls, and monitoring of our systems. Card details are handled by our payment processor and never stored by Faxly. If a breach affects your unencrypted personal information, we will notify you and the required regulators without unreasonable delay, consistent with state breach-notification laws.

17Children

Faxly is not directed at children under 16, and we do not knowingly collect personal information from children under 13, consistent with COPPA. If you believe a child has provided us personal information, email support@faxly.com and we will delete it.

18Where data lives, changes, and contact

Faxly is operated from the United States and your information is processed on US servers. If we make material changes to this policy, we will email you at least 14 days before they take effect. Contact: support@faxly.com, or THEONLINESAASCOMPANY LLC, 1309 Coffeen Avenue, STE 1200, Sheridan, WY 82801, United States.

Questions about this policy? Write to support@faxly.com — a human replies within two business days.