Privacy Policy | Mirylo
Mirylo logoMirylo Contact us

Legal

Privacy Policy

This policy explains how Mirylo collects, uses, discloses, retains, and protects information when you use our websites, MirylOS, connected integrations, and services.

Effective: August 27, 2026Last updated: August 27, 2026

Mirylo (“Mirylo,” “we,” “us,” or “our”) provides CRM implementation, integration, marketing attribution, call tracking, form, reporting, and analytics services through the MirylOS platform.

This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you visit mirylo.com, access MirylOS, connect a third-party integration, communicate with us, or otherwise use our services.

1Scope

This Privacy Policy applies to:

  • our public websites, including mirylo.com;
  • the MirylOS application at app.mirylo.com;
  • CRM, marketing, attribution, communication, form, call-tracking, and analytics services provided by Mirylo;
  • third-party integrations that a customer chooses to connect to MirylOS.

It does not govern the independent privacy practices of third-party services such as Meta, Google, GoHighLevel, Twilio, Yelp, or Thumbtack. Those services operate under their own terms and privacy policies.

2Our role

Depending on the context, Mirylo may act as:

  • a business or controller for information relating to our website visitors, customer accounts, billing contacts, and direct communications; and
  • a service provider or processor when we process CRM, contact, communication, advertising, or attribution data on behalf of a business customer.

Our business customers determine why and how their customer and lead data is collected. If your information was submitted to one of our customers, you may need to contact that business directly. We will assist the business with a valid privacy request where required.

3Information we collect

3.1Account and business information

We may collect:

  • name;
  • business name;
  • job title;
  • email address;
  • telephone number;
  • mailing or business address;
  • account and user identifiers;
  • login, authentication, and authorization information;
  • user roles and permissions;
  • customer support communications;
  • subscription, billing, and transaction information.

Payment card information may be processed directly by a payment provider. Mirylo does not intentionally store complete payment card numbers unless expressly disclosed.

3.2CRM and customer data

When a customer connects a CRM or imports data, MirylOS may process:

  • contact names;
  • email addresses;
  • telephone numbers;
  • mailing or service addresses;
  • lead source and channel;
  • qualification and job-type values;
  • tags and custom fields;
  • opportunities, pipeline stages, values, and outcomes;
  • appointments and calendar events;
  • assigned users and sales representatives;
  • form submissions;
  • notes and other customer-provided CRM information.

The exact data processed depends on the customer’s configuration and enabled integrations.

3.3Communication and call data

Where enabled and lawfully collected, we may process:

  • inbound and outbound telephone call records;
  • originating and destination telephone numbers;
  • call timestamps and duration;
  • call status and disposition;
  • voicemail;
  • SMS or other message metadata and content;
  • call recordings and transcriptions;
  • communication attribution and routing information.

Our customers are responsible for providing legally required notices and obtaining consent for calls, text messages, recordings, and transcriptions.

3.4Website, form, and attribution data

MirylOS may collect or receive:

  • visitor and session identifiers;
  • landing and referring URLs;
  • page views and form activity;
  • UTM parameters;
  • advertising click identifiers;
  • source, medium, campaign, ad, ad-set, keyword, and related attribution values;
  • telephone-link clicks;
  • displayed tracking numbers;
  • device, browser, operating system, IP address, and approximate location;
  • timestamps and interaction events.

We use this information to connect a customer’s marketing activity with leads and business outcomes.

3.5Advertising and marketing platform data

When an authorized customer connects an advertising account, MirylOS may receive:

  • platform user, business, and advertising-account identifiers;
  • advertising-account name, currency, and timezone;
  • campaign, ad-set, ad, form, and related identifiers and names;
  • campaign status and reporting dates;
  • spend, impressions, reach, clicks, and other reporting metrics made available by the connected platform;
  • OAuth permissions, authorization status, and token expiration information;
  • synchronization and diagnostic information.

Depending on the integrations enabled by the customer, this may include data from Meta Ads, Google Ads, Google Local Services Ads, Yelp, Thumbtack, GoHighLevel, or other authorized providers.

We do not use connected advertising accounts to create, edit, publish, pause, or delete advertisements unless a separate feature is expressly offered, authorized, and disclosed. The MirylOS Meta Ads reporting integration is designed to use read-only access.

3.6Technical and security information

We may collect:

  • authentication events;
  • IP addresses;
  • browser and device information;
  • application logs;
  • synchronization status;
  • error reports;
  • audit records;
  • security events;
  • requested URLs and timestamps.

We do not intentionally store passwords, access tokens, complete message content, or other confidential customer data in ordinary diagnostic logs.

4How we collect information

We may collect information:

  • directly from customers and users;
  • through forms and websites using MirylOS;
  • from a customer’s connected CRM;
  • from integrations expressly authorized by a customer;
  • through APIs and webhooks;
  • automatically through cookies, local storage, logs, and similar technologies;
  • from service providers working on our behalf.

5How we use information

We may use information to:

  • provide, operate, maintain, and secure MirylOS;
  • create and administer customer accounts;
  • synchronize authorized third-party data;
  • provide CRM, attribution, call-tracking, form, and marketing analytics;
  • connect marketing activity with leads, appointments, opportunities, and sales;
  • display reports, proof records, exports, and synchronization history;
  • process customer-requested CRM actions;
  • troubleshoot integrations;
  • detect fraud, abuse, security incidents, and technical failures;
  • provide customer support;
  • communicate about the service;
  • bill customers and administer subscriptions;
  • comply with legal obligations;
  • establish, exercise, or defend legal claims;
  • improve the reliability and usability of our services using aggregated or de-identified information.

We do not use one customer’s CRM contacts, advertising data, or business records to provide another customer with identifiable information.

6Legal bases

Where applicable law requires a legal basis, we process personal information based on one or more of the following:

  • performance of a contract;
  • consent;
  • legitimate business interests;
  • compliance with a legal obligation;
  • protection of legal rights;
  • processing performed on documented instructions from a customer acting as controller.

A user may withdraw consent where consent is the applicable basis. Withdrawal does not affect processing that occurred before the withdrawal.

7How we disclose information

We may disclose information to:

  • cloud hosting, infrastructure, database, and security providers;
  • authentication and identity providers;
  • CRM and communication platforms selected by a customer;
  • advertising and marketing platforms selected by a customer;
  • payment and billing providers;
  • professional advisers, including attorneys and accountants;
  • government authorities where legally required;
  • a successor in connection with a merger, financing, acquisition, restructuring, or sale of assets.

Service providers may process information only for contracted purposes and subject to appropriate confidentiality and data-protection obligations.

We may also disclose information at the direction of the applicable customer or user.

8Meta Platform Data

When a customer connects a Meta advertising account, MirylOS receives only data authorized by the customer and permitted by the approved Meta permissions.

We use Meta Platform Data to provide customer-requested marketing reporting and attribution. We do not:

  • sell Meta Platform Data;
  • use Meta Platform Data for unrelated advertising;
  • disclose one customer’s Meta data to another customer;
  • request advertising-management permissions when read-only reporting is sufficient;
  • expose access tokens to customers, browsers, or unrelated third parties.

Customers may disconnect Meta at any time. Disconnection stops future synchronization but does not automatically delete historical reporting records. A separate deletion request may be submitted as described in our Data Deletion Instructions.

Our use of Meta Platform Data is also subject to the Meta Platform Terms and Meta Developer Policies.

9Cookies and similar technologies

We may use cookies, browser storage, pixels, and similar technologies for:

  • authentication;
  • session management;
  • security;
  • user preferences;
  • service functionality;
  • analytics;
  • attribution.

Where required, we will request consent before using non-essential cookies.

Browser settings may allow you to block or delete cookies. Some parts of the service may not function properly if essential cookies are disabled.

If we use technologies that constitute a “sale” or “sharing” under applicable privacy law, we will provide the required notice and opt-out mechanism.

10Sale and sharing of personal information

Mirylo does not sell Meta Platform Data.

Subject to confirmation that our website does not use cross-context advertising technologies, Mirylo does not sell personal information or share personal information for cross-context behavioral advertising as those terms are defined by the California Consumer Privacy Act.

If our practices change, we will update this Privacy Policy and provide legally required privacy choices.

11Data isolation and security

MirylOS is a multi-tenant platform. Customer data is logically scoped to the specific business location or account to which it belongs.

We use administrative, technical, and organizational safeguards designed to protect information, including:

  • access controls;
  • tenant-scoped authorization;
  • server-side credential handling;
  • encrypted network connections;
  • controlled production access;
  • audit and security logging;
  • secrets management;
  • backup and recovery procedures.

No method of storage or transmission is completely secure. We cannot guarantee absolute security.

Customers must protect their login credentials, use appropriate access controls, and notify us promptly of suspected unauthorized access.

12Data retention

We retain information only for as long as reasonably necessary for the purposes described in this Policy.

Our intended retention schedule is:

  • customer account and CRM data: while the account or service relationship remains active;
  • OAuth and integration credentials: until disconnection, revocation, expiration, or termination;
  • historical reporting and attribution records: while required to provide the service or until a valid deletion instruction is received;
  • customer export period after termination: up to 30 days;
  • deletion from active systems after an approved request: generally within 30 days;
  • deletion through backup rotation: generally within 90 days;
  • security, synchronization, and audit logs: generally up to 12 months, unless a longer period is reasonably required;
  • billing, tax, contract, and legal records: for the period required by applicable law, which may be up to seven years.

We may retain information longer where required by law, necessary to resolve disputes, enforce agreements, prevent fraud, or protect legal rights.

Aggregated or de-identified information that cannot reasonably identify a person may be retained longer.

These periods must be aligned with actual MirylOS deletion jobs and backup policies before publication.

13Your privacy rights

Depending on where you live, you may have the right to:

  • request access to personal information;
  • request correction;
  • request deletion;
  • request a portable copy;
  • object to or restrict certain processing;
  • withdraw consent;
  • opt out of the sale or sharing of personal information;
  • limit certain uses of sensitive personal information;
  • appeal a denied privacy request;
  • receive equal service without discrimination for exercising privacy rights.

To submit a request, contact:

[email protected]

Include your name, business relationship with Mirylo, and enough information for us to identify the relevant account. Do not send passwords, access tokens, or sensitive credentials.

We may verify your identity and authority before completing a request. If Mirylo processes the information solely for one of our business customers, we may refer the request to that customer or act on its documented instructions.

Authorized agents may submit requests where permitted by law, subject to verification.

14California privacy notice

California residents may have rights to know, access, correct, delete, and obtain information about how personal information is collected, used, and disclosed. They may also have the right to opt out of sale or sharing and to receive non-discriminatory treatment.

In the preceding 12 months, we may have collected the following CCPA categories:

  • identifiers;
  • customer-record information;
  • commercial information;
  • internet or electronic network activity;
  • approximate geolocation;
  • audio, electronic, or communication information;
  • professional or employment-related information;
  • inferences derived from marketing and CRM activity.

We collect and use these categories for the business purposes described in this Policy.

We do not sell Meta Platform Data.

Requests may be submitted through [email protected] or through an available privacy request form in MirylOS. We will respond within the period required by applicable law.

15International data transfers

Information may be processed in countries other than the country where it was collected. Where required, we use appropriate contractual or legal safeguards for international transfers.

Customers requiring specific data residency or transfer terms should contact us before enabling the applicable service.

16Children

MirylOS is intended for businesses and authorized adult users. It is not directed to children under 13, and we do not knowingly collect personal information directly from children.

If you believe a child has provided information to us, contact [email protected].

17Third-party services

Third-party integrations are controlled by their respective providers. Mirylo is not responsible for a third party’s independent privacy practices, service availability, or changes to its APIs.

Disconnecting an integration from MirylOS does not necessarily delete information held independently by the third-party provider.

18Changes to this Policy

We may update this Privacy Policy to reflect changes in our services, legal obligations, or data practices.

We will update the “Last Updated” date and provide additional notice where required. Material changes will not apply retroactively where prohibited by law.

19Contact us

For privacy questions or requests:

Mirylo 16312 SE 318th St
Auburn, WA 98092
(206) 888-4481

Email: [email protected]

Support: [email protected]

Website: https://mirylo.com
© 2026 Mirylo. All rights reserved.