Legal Information

Privacy Policy.

This Privacy Policy explains how Excelsior Service Group collects, uses, stores, and shares information when you visit our website, complete an assessment, request information, schedule a meeting, communicate with us, or use our services.

Effective Date PASTE-EFFECTIVE-DATE
Last Updated PASTE-LAST-UPDATED-DATE
01

Who This Policy Covers

This Privacy Policy applies to information collected by Excelsior Service Group, also referred to in this policy as “ESG,” “we,” “our,” or “us,” through:

  • Our website and landing pages;
  • Online forms, assessments, questionnaires, and surveys;
  • Appointment and consultation scheduling tools;
  • Email, text-message, telephone, and chat communications;
  • Customer relationship management and client portals;
  • Payment, proposal, onboarding, and service-delivery processes; and
  • Other interactions in which this Privacy Policy is displayed or referenced.

By using our website or voluntarily providing information to us, you acknowledge the practices described in this Privacy Policy.

02

Information We May Collect

Information You Provide

We may collect information that you voluntarily provide when you contact us, complete an assessment, request a service, schedule a meeting, subscribe to communications, submit a form, make a purchase, or become a client.

Contact Information

Name, email address, telephone number, mailing address, company name, job title, and preferred contact method.

Business Information

Industry, services, business size, service area, operational processes, goals, challenges, technology, and customer journey.

Assessment Information

Answers submitted through the ClientFlow Assessment™, questionnaires, audits, intake forms, and discovery processes.

Transaction Information

Purchased services, invoices, payment status, transaction dates, and billing-related information.

Communication Information

Emails, text messages, call details, chat messages, support inquiries, meeting notes, feedback, and other correspondence.

Client Project Information

Documents, business rules, workflows, content, credentials, service requirements, and other materials provided for a project.

Information Collected Automatically

When you use our website, certain information may be collected automatically by our website platform, analytics providers, hosting providers, advertising tools, or other service providers. This may include:

  • Internet Protocol address;
  • Browser type and operating system;
  • Device type and device identifiers;
  • Approximate geographic location;
  • Referral source and pages visited;
  • Date, time, and duration of website activity;
  • Links, buttons, forms, or features used; and
  • Cookie, pixel, and similar technology data.

Information From Other Sources

We may receive information from service providers, referral partners, social-media platforms, payment processors, scheduling platforms, analytics providers, public business directories, or other sources permitted by law.

03

How We Use Information

We may use personal and business information to:

  • Respond to questions, requests, and inquiries;
  • Provide assessments, recommendations, proposals, and consultations;
  • Determine whether an ESG service is appropriate for a business;
  • Schedule, confirm, and manage appointments;
  • Deliver, maintain, support, and improve our services;
  • Create and manage customer, prospect, and client records;
  • Process purchases, invoices, subscriptions, and payments;
  • Send service-related notices, reminders, and updates;
  • Provide educational, promotional, or marketing communications;
  • Understand website usage and improve the customer experience;
  • Protect our website, systems, clients, and business from misuse;
  • Comply with legal, tax, accounting, and contractual obligations;
  • Resolve disputes and enforce our agreements; and
  • Carry out other purposes disclosed when information is collected.
04

Email and Text-Message Communications

Service Communications

We may send communications necessary to respond to your request, deliver a service, confirm an appointment, provide an assessment, send an invoice, manage an account, or communicate about an active business relationship.

Marketing Communications

When permitted by law and based on the consent or preferences you provide, we may send information about ESG services, resources, events, articles, offers, and business updates.

Text Messages

When you provide a mobile telephone number and consent to receive text messages, ESG may send appointment reminders, requested information, service updates, follow-up messages, and promotional communications consistent with the consent provided.

!

Text-Message Terms

Message frequency may vary. Message and data rates may apply. You may reply STOP to opt out of nonessential text messages and HELP for assistance. Consent to receive marketing text messages is not a condition of purchasing ESG services.

Opting out of marketing communications does not prevent us from sending necessary transactional, account, appointment, security, legal, or service-related communications.

05

Cookies, Pixels, and Analytics

Our website and service providers may use cookies, pixels, tags, scripts, local storage, and similar technologies to operate the website, remember preferences, measure performance, understand visitor activity, improve services, and support advertising or marketing efforts.

Types of Technologies We May Use

  • Essential technologies: Required for website functionality, security, forms, and sessions.
  • Analytics technologies: Help us understand how visitors use our website and which content is useful.
  • Preference technologies: Remember selections or improve the website experience.
  • Marketing technologies: May help measure campaigns, understand referrals, or deliver relevant advertising.

You may be able to manage cookies through your browser settings, device settings, consent banner, or the preference controls provided by a third-party service. Blocking some technologies may affect website functionality.

06

How We May Share Information

ESG may share information with third parties when reasonably necessary to operate the business, provide services, comply with the law, or protect legitimate interests.

Service Providers

We may use service providers that support:

  • Website hosting and landing pages;
  • Customer relationship management;
  • Forms, assessments, surveys, and scheduling;
  • Email, telephone, text-message, and chat communications;
  • Payment processing and invoicing;
  • File storage, productivity, and project management;
  • Analytics, advertising, and website performance;
  • Automation, integration, and workflow delivery;
  • Professional, accounting, legal, and technical support; and
  • Security, fraud prevention, and system maintenance.

Business Transfers

Information may be disclosed in connection with an actual or proposed merger, acquisition, financing, reorganization, sale of assets, transfer of services, or similar business transaction.

Legal and Safety Reasons

We may disclose information when we reasonably believe disclosure is necessary to comply with law, regulation, legal process, or a governmental request; enforce an agreement; investigate suspected misconduct; prevent fraud; or protect the rights, safety, and property of ESG, our clients, users, or others.

With Your Direction or Consent

We may share information with another party when you ask us to do so, authorize the disclosure, or use a service that requires the information to be transferred.

Sale of Personal Information

ESG Does Not Sell Personal Information for Monetary Compensation.

We may use analytics, advertising, and business-service providers that process information on our behalf or according to their own privacy policies. Certain privacy laws may define some advertising or data-sharing practices more broadly than an ordinary sale.

07

Payment Information

Payments may be processed by third-party payment providers. ESG may receive transaction details such as the customer’s name, contact information, purchased service, payment amount, transaction date, invoice status, and limited payment-method information.

Complete payment-card information is generally collected and processed directly by the applicable payment provider rather than stored by ESG. Payment providers process information according to their own terms and privacy policies.

08

How Long We Retain Information

We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:

  • Respond to inquiries and provide requested services;
  • Maintain prospect, customer, and client relationships;
  • Complete contracts and projects;
  • Maintain business, accounting, tax, and transaction records;
  • Comply with legal and regulatory obligations;
  • Resolve disputes and enforce agreements;
  • Protect the security and integrity of our systems; and
  • Maintain appropriate backup and archival records.

Retention periods may vary based on the type of information, the nature of the relationship, contractual requirements, legal obligations, and legitimate business needs.

09

Data Security

ESG uses reasonable administrative, organizational, technical, and physical safeguards designed to protect information against unauthorized access, loss, misuse, disclosure, alteration, or destruction.

However, no website, storage platform, transmission method, or security system can be guaranteed to be completely secure. You should use caution when sending sensitive information electronically and should not submit confidential credentials or highly sensitive information through ordinary website forms unless specifically requested through a secure method.

10

Your Choices and Privacy Rights

Depending on where you live and the laws applicable to ESG, you may have the right to request that we:

  • Confirm whether we maintain personal information about you;
  • Provide access to certain personal information;
  • Correct inaccurate information;
  • Delete certain information;
  • Provide a portable copy of certain information;
  • Restrict or object to certain processing;
  • Honor an applicable opt-out request; or
  • Explain the categories of information we collect and disclose.

These rights are not absolute. We may retain or continue processing information when permitted or required by law, including for security, legal compliance, transaction completion, recordkeeping, dispute resolution, or other legitimate purposes.

How to Submit a Request

Submit a privacy request using the contact information listed at the end of this policy. Include enough information for us to understand and respond to your request. We may need to verify your identity before completing a request.

11

California Privacy Notice

This section applies only to the extent that California privacy law applies to ESG and to the personal information involved.

Eligible California residents may have rights concerning access, correction, deletion, disclosure, portability, and certain uses or disclosures of personal information. Eligible residents may also have the right not to receive discriminatory treatment for exercising applicable privacy rights.

Categories of Information

Depending on your interaction with ESG, we may collect identifiers, contact information, commercial information, internet or network activity, approximate location information, professional or business information, communication records, and inferences based on information you provide.

Selling and Sharing

ESG does not sell personal information for monetary compensation. To the extent that any analytics or advertising practice is considered “sharing” or a “sale” under applicable California law, eligible residents may submit an opt-out request using the contact information below or any privacy-control mechanism made available on the website.

Authorized Agents

An eligible California resident may use an authorized agent to submit a request where permitted by law. We may request evidence of the agent’s authority and may independently verify the request with the resident.

12

Children’s Privacy

ESG’s website and services are intended for businesses and adults. They are not directed to children under 13, and ESG does not knowingly collect personal information online from children under 13.

A parent or legal guardian who believes a child has provided personal information to ESG may contact us so we can review and, where appropriate, delete the information.

14

Changes to This Privacy Policy

ESG may update this Privacy Policy periodically to reflect changes in our services, technology, vendors, legal obligations, or information practices.

The revised policy will be posted on this page with an updated “Last Updated” date. Material changes may also be communicated through the website, email, or another appropriate method.