ETHIX Privacy Policy
Last updated: August 4, 2026
1. Introduction
This Privacy Policy explains how ETHIX, LLC ("ETHIX," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the ETHIX platform — our website, software, and related services (collectively, the "Services"). This Privacy Policy should be read together with our Terms of Service, which governs your use of the Services generally.
By accessing or using the Services, you agree to the collection and use of information as described in this Privacy Policy.
2. Who This Policy Covers
This Policy applies to:
- Subscribers — the licensed professionals and firms that create an Account and pay for a Subscription.
- Authorized users — individuals a subscribing firm adds to its Account (Admins, Team Members, Intake staff, or any other role).
- Guest-tier individuals — people who never create an account but interact with the Services because a subscriber referred them, requested their input, or shared a link with them, including recipients of a referral certificate, visitors to a Guest Portal page, and people who submit information through a public referral or "Join Network" form.
Where this Policy refers to "you," it means whichever of these categories applies to your interaction with the Services.
3. Information We Collect
a) Information you provide directly.
When you create an Account, we collect your name, email address, firm name, professional license or credential information (where applicable), and payment information (processed by our payment processor — see Section 6).
b) Information within Customer Data.
As described in our Terms of Service, Customer Data — the referral records, client identifiers, notes, documents, and other content you and your firm submit to the Services — belongs to you, not to us. We process it only as necessary to provide, secure, support, and improve the Services. Customer Data may include client initials or identifiers, practice area, fee arrangement details, and other information you choose to enter about a referral.
c) Information from guest-tier individuals.
When a subscriber sends a referral certificate, requests a status update, or shares a Referral Card, we collect limited information about the recipient — typically a name and email address — solely to deliver that specific communication or enable that specific interaction. Guest-tier individuals do not have an Account and are not required to provide any information beyond what's needed for the specific feature they're using (e.g., submitting a public referral, requesting to join a firm's network).
d) Information collected automatically.
Like most web services, we automatically collect certain technical information when you use the Services — IP address, browser type, device information, and usage data (such as which pages or features are accessed and when). This is used for security, troubleshooting, and improving the Services, not for advertising.
e) Information from third-party services.
If you connect a third-party integration (e.g., a practice management system), we may receive information from that service as necessary to provide the connected functionality, subject to that third party's own terms and privacy practices.
f) Cookies and similar technologies.
We use cookies and similar technologies (such as local storage) for purposes that fall into three categories:
- Strictly necessary — cookies required for the Services to function, such as keeping you logged in and remembering your session. These cannot be disabled without breaking core functionality.
- Functional — cookies that remember your preferences (such as light/dark mode) to improve your experience.
- Analytics — cookies that help us understand how the Services are used in aggregate, so we can identify and fix problems and improve features over time.
We do not use third-party advertising cookies, and we do not use cookies to track you across other websites. Most browsers let you control or delete cookies through their settings; doing so may affect the functionality of the Services.
4. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Services, including generating referral certificates, processing referral records, and enabling communication between referring parties.
- Process payments and manage subscriptions.
- Communicate with you about your Account, including security notices, billing, and — where you've opted in — product updates.
- Provide customer support.
- Monitor and improve the security, reliability, and performance of the Services.
- Comply with legal obligations.
We do not sell personal information or Customer Data to third parties. We do not use Customer Data to train any product, model, or service outside of Ethix, and we do not use it for advertising or marketing to third parties.
5. How Information Is Shared
a) Within a shared referral record.
As described in our Terms of Service, a referral record may be visible to more than one party — the sending professional, the receiving professional, their respective firms, and any guest participant granted access to that specific record. Information you place into a shared record becomes visible to those parties.
b) Within your firm.
If your Account is provisioned under a firm subscription, your firm's Admin(s) can access, manage, and export data associated with that Account, consistent with the role-based permissions described in the Services.
c) With service providers.
We share information with third-party vendors who help us operate the Services, including:
- Stripe — for payment processing. Stripe receives payment information directly; we do not store full payment card numbers ourselves.
- SendGrid — for delivering transactional emails, including referral certificates, status update requests, and account notifications.
- Our hosting/infrastructure provider — for storing and running the Services.
Each of these vendors is contractually limited to using information only as necessary to provide their service to us, and is prohibited from using it for their own independent purposes.
d) For legal reasons.
We may disclose information if required by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
e) In a business transfer.
If ETHIX is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to the same protections described in this Policy (or a materially similar policy).
6. Payment Information
Payments are processed by Stripe. We do not directly store your full payment card details. Stripe's own privacy practices govern the information you provide directly to them during checkout.
7. Data Retention
a) During an active subscription.
We retain Customer Data for as long as your Account remains active, so the Services can function as intended.
b) After cancellation.
Following expiration or termination of your Subscription, Customer Data remains available for export for thirty (30) days, after which we may delete it in the ordinary course, subject to any legal retention obligation and our backup cycles (below).
c) Backup copies.
In addition to standard infrastructure backups used to protect against system failure, we maintain a single, periodically refreshed backup copy of each active subscriber's referral data, held separately from the live system for disaster-recovery purposes. This backup is refreshed approximately once a month; when a new backup is created, the prior backup is deleted, so only the most recent backup is retained at any given time. Backup copies are subject to the same security protections described in Section 8 of this Policy. Following cancellation of a Subscription, we will delete the associated backup copy consistent with the thirty (30) day retention period described in Section 7(b) above.
8. Security
We maintain administrative, physical, and technical safeguards designed to protect information, including encryption of data in transit and at rest, role-based access controls, and separation between different customers' data. Access to Customer Data by ETHIX personnel is limited to what is necessary to provide, secure, and support the Services, and is not used to browse or review individual customer records outside of that purpose. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your Choices and Rights
a) Access and export.
You can export your Customer Data at any time through the Services' built-in export functionality.
b) Communication preferences.
You may opt out of non-essential communications (such as the automated monthly backup email) through your Account settings. We may still send essential communications related to your Account, billing, or security. Ethix currently sends communications by email only — we do not send marketing text messages or place marketing phone calls.
c) State privacy law rights.
Depending on where you live, applicable state privacy laws may give you the right to:
- Know and access the categories and specific pieces of personal information we have collected about you.
- Correct inaccurate personal information we maintain about you.
- Delete personal information we have collected from you, subject to certain exceptions (such as information we're required to retain by law).
- Opt out of the sale or sharing of your personal information. ETHIX does not sell personal information, and this right is not applicable to our current practices.
- Non-discrimination — we will not deny you the Services, charge different prices, or provide a different level of service because you exercised any of these rights.
To exercise any of these rights, contact us at contact@ethixlaw.com. We may need to verify your identity before completing certain requests. You may also designate an authorized agent to make a request on your behalf, subject to our ability to verify that authorization. We will respond to verified requests within the timeframe required by applicable law.
d) Guest-tier individuals.
If you're a guest-tier individual who received a certificate, a status update request, or a Referral Card link and would like your information removed from our systems, you may contact us at contact@ethixlaw.com using the process described above.
10. Children's Privacy
The Services are not directed to children, and we do not knowingly collect personal information from anyone under the age of thirteen (13), consistent with the federal Children's Online Privacy Protection Act (COPPA). If we learn that we have inadvertently collected information from a child under 13, we will take steps to delete it.
Separately, and for business reasons rather than a children's-privacy requirement, our Terms of Service require that all Account holders be at least eighteen (18) years of age, since the Services are designed for licensed professionals and their staff. This 18+ eligibility requirement is distinct from the COPPA-based statement above — it reflects who the Services are built for, not an additional children's-privacy compliance obligation.
11. International Data
The Services are intended for use by professionals licensed and operating within the United States. If you access the Services from outside the United States, your information will still be processed and stored in the United States.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice consistent with the update process described in our Terms of Service.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at contact@ethixlaw.com.

