Iron Customer Reach VMAX Privacy Policy
Effective date: September 24, 2026
American Iron LLC ("American Iron," "we," "us," or "our") provides Iron Customer Reach VMAX (the "Service"), a business communications and customer-engagement platform. This Policy explains how information is handled when an organization uses the Service, when an administrator or other user accesses it, and when someone communicates with a business through a channel powered by it.
For privacy questions or requests, contact info@americanironus.com. American Iron is based in Tampa, Florida, USA.
1. Roles and scope
When an organization uploads or manages its customers' information in the Service, that organization decides why and how it uses the information. It is responsible for its notices, permissions, lawful basis, retention instructions, and responses to individual requests. American Iron generally handles that information to provide and secure the Service under the organization's instructions and applicable service terms.
American Iron separately handles business-account, support, security, and service-operation information for its own purposes as described here. If this Policy conflicts with a signed data-processing agreement or other written customer agreement, the signed agreement controls for the information it covers.
2. Information we handle
Depending on the features an organization enables, information may include:
- Account and business information: names, business email addresses, user roles, organization details, and support correspondence.
- Contact and customer records: names, company, email and phone numbers (including WhatsApp numbers), tags, preferences, communication permissions, opt-out and suppression records, and the source or history of a permission.
- Communications: message content, attachments, delivery and response events, campaign and template content, and related timestamps and channel identifiers.
- Voice information: call metadata and, only where the organization enables a feature that captures them, recordings, transcripts, summaries, or related analysis.
- AI feature inputs and results: prompts, selected contact or message context, generated text, and user feedback needed to provide an AI-enabled feature.
- Technical and usage information: device and browser details, IP address, session and event timestamps, error and diagnostic information, and security logs.
- Integration information: account identifiers, configuration data, and credentials or access tokens supplied to connect a third-party service. Customers should use the Service's supported credential controls and must not place secrets in message content.
Please do not provide information that is unnecessary for the business purpose. The Service is not intended for children's information.
3. How information is used
We use information as needed to:
- provide customer management, campaign, messaging, voice, analytics, automation, and support features selected by the organization;
- authenticate users, maintain sessions, route communications, record delivery or consent status, and administer integrations;
- protect the Service, troubleshoot errors, prevent abuse, and maintain reliability;
- respond to requests, provide service notices, and manage our business relationship;
- comply with law, enforce agreements, and protect rights, safety, and property; and
- improve the Service using operational information, subject to applicable law and customer agreements.
AI-enabled features process the information an authorized user chooses to submit or make available to that feature. Generated content can be inaccurate and must be reviewed by a person before use. A customer's use of AI features must comply with its agreement and applicable law.
4. Communications and third-party services
When an organization connects a channel or integration, the Service may exchange the minimum information needed to provide that feature with the provider selected or enabled by the organization. This can include cloud hosting and database services, authentication services, email/SMS/voice delivery, AI services, Meta and WhatsApp services, and other customer-selected integrations. Those providers process information under their own terms and privacy notices. The organization is responsible for reviewing and configuring its integrations.
We do not sell personal information for money and do not use customer contact lists for cross-context behavioral advertising. We disclose information to service providers acting for us, at the direction of the organization using the Service, with the person's permission, or as otherwise permitted or required by law. We may disclose information to protect the Service and its users or in connection with a corporate transaction, subject to appropriate safeguards.
5. Cookies, local storage, and logs
The Service may use browser storage and similar technologies to maintain a user session, remember preferences, support security, and operate the application. Cloud infrastructure and application components may create operational and security logs. Browser settings can control some storage, but disabling it may prevent the Service from working correctly.
6. Retention and deletion
We retain information for as long as reasonably needed to provide the Service, follow a customer's documented instructions, maintain security and business records, resolve disputes, and meet legal obligations. The organization's administrator should remove or correct customer records through the Service where available. On account termination or a verified request, we will delete or return information as provided by the applicable customer agreement and law. Information in protected backups and records we must retain may persist for a limited period or be retained where legally required; retained information remains subject to appropriate protections.
To request deletion of information held directly by American Iron, contact info@americanironus.com with the subject Privacy Request and identify the Service and account involved. Do not email passwords, access tokens, or sensitive identity documents. We may ask for reasonable information to verify the request. If the information was submitted by an organization using the Service, contact that organization first; it controls the record and can direct us as appropriate.
7. Privacy choices and rights
Depending on where a person lives and the role in which information was collected, applicable law may provide rights to access, correct, delete, obtain, or restrict certain personal information, or to withdraw consent. A person should send a request to the organization that collected the information or contact us at the address above. We will route requests to the responsible organization where appropriate and respond within the time required by applicable law. We may retain information needed to honor opt-outs, preserve suppression records, comply with law, or protect against fraud and abuse.
8. Security and international processing
We use administrative, technical, and organizational measures designed to protect information against unauthorized access, use, alteration, and loss. No online service or transmission can be guaranteed completely secure. Access to customer information should be limited to authorized users, and customers are responsible for safeguarding their accounts and integration credentials.
Information may be processed in locations where American Iron or its service providers operate. Where applicable law requires transfer safeguards, the parties will use the safeguards required by law or their written agreement.
9. Changes and contact
We may update this Policy when the Service or applicable requirements change. We will update the effective date above and provide notice through the Service or another reasonable channel when required. Contact info@americanironus.com for questions or requests.