Privacy Policy
1. Introduction and Scope
1.1 This Privacy Policy ("Policy") describes how Fax Pigeon LLC, an Illinois limited liability company ("Company," "we," "us," or "our"), collects, uses, discloses, and protects information in connection with the cloud fax platform operated at faxpigeon.com and all associated features, functionality, and services (the "Service").
1.2 This Policy applies to all users of the Service, including users on free evaluation accounts and paid subscriptions.
1.3 Protected Health Information ("PHI") processed through the Service is governed by the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and the Business Associate Agreement ("BAA") between you and Company, published at faxpigeon.com/baa. In the event of any conflict between this Policy and the BAA with respect to PHI, the BAA shall control.
1.4 This Policy is subject to the Terms of Service published at faxpigeon.com/terms, which are incorporated herein by reference.
1.5 By creating an account or using the Service, you acknowledge that you have read and understand this Policy.
2. Information We Collect
2.1 Information You Provide Directly
- Account registration information: email address, display name, and password (stored only in hashed form).
- BAA signer details: name, professional title, and covered entity name.
- Fax content: PDF documents, images, and other files uploaded for transmission, PDF documents emailed to the Service's fax addresses for transmission (see Section 4.1(d)), or received through the Service.
- Contact data: names, fax numbers, categories, and notes associated with your fax contacts.
- Cover sheet fields: subject line, sender information, and recipient information entered when composing a fax.
- Electronic signatures: signature images stored in base64-encoded PNG format, associated with your account.
- Profile photos: optional images for a member's avatar, which we resize and store for display within the dashboard.
- Referral attribution: the referral code carried by a partner link you arrived through, kept in your browser's local storage for up to ninety (90) days, or the code you type at checkout; it is bound to your account once, as a code only, and the partner sees the referral by number, never by name.
- Optional inputs: cancellation reason (free text, provided at your discretion upon cancellation), send notes (freeform notes attached to outbound faxes), member comments (collaboration text on inbound faxes), and feedback or satisfaction scores.
2.2 Information Generated by the Service
- Fax metadata: sender and recipient fax numbers, transmission timestamps, page counts, delivery status, confirmation identifiers, protocol type, and transmission duration.
- Email-to-fax metadata: for an email you send to the Service's fax addresses, the sending address, the destination number, the email's authentication, spam, and virus verdicts, and the outcome (queued, refused, or discarded). The email itself is deleted as described in Section 4.1(d).
- Automated document analysis: document type classification, document summary, and extracted metadata fields (such as person name, reference number, sender organization, document date, status, and confidence score) generated from inbound faxes.
- Delivery proof certificates: masked fax numbers, page count, transmission duration, and confirmation identifiers.
- Audit logs: action type, user identifier, resource type, resource identifier, IP address, user agent, and timestamp for each logged event.
2.3 Information Collected Automatically
- IP address: for anti-abuse and rate-limiting purposes, stored only as a SHA-256 cryptographic hash. Hashes used for anti-abuse limits are retained for up to twenty-four (24) hours; hashes used for short-window request rate limiting are retained for a short period, at most a few hours, and then automatically deleted. Company does not store your IP address in plaintext for these anti-abuse purposes. IP addresses are recorded in plaintext in the Service's security audit log and agreement acceptance records, where they are retained for security monitoring, regulatory compliance, and evidentiary purposes as required by applicable law, including HIPAA. Audit log entries containing IP addresses are retained indefinitely and are not subject to the time-to-live applicable to anti-abuse records.
- Email address hash: stored as a SHA-256 cryptographic hash with a seven hundred thirty (730) day time-to-live, used for free-tier account deduplication and anti-abuse prevention.
- Referral code in local storage: when you arrive through a partner link, the partner's code and the time of arrival are kept in your browser's local storage for up to ninety (90) days after you last follow such a link, so that the referral can be bound to an account you later create (Section 2.1); the record holds nothing else and is discarded when it expires.
- Authentication session data: session tokens and authentication state managed through the Service's identity provider.
- CAPTCHA tokens: challenge-response tokens generated by the Service's CAPTCHA provider for bot prevention during account creation and authentication.
2.4 Information We Do Not Collect
- Payment card numbers: all payment processing is handled entirely by Stripe, Inc. Company does not receive, process, or store your credit card number, debit card number, or full payment card details.
- Advertising identifiers: Company does not collect device advertising identifiers, mobile ad IDs, or similar tracking identifiers.
- Precise location data: Company does not collect GPS coordinates or precise geolocation data. The only location-related data is the IP address hash described in Section 2.3, which may be used to derive approximate geographic region for rate-limiting purposes.
- Biometric data: Company does not collect fingerprints, facial recognition data, voiceprints, or any other biometric identifiers.
3. How We Use Information
3.1 Service Provision
We use the information described in Section 2 to provide, operate, and maintain the Service, including:
- Transmitting and receiving faxes on your behalf;
- Generating cover sheets and merging electronic signatures onto documents;
- Performing automated classification and summarization of inbound fax documents;
- Generating delivery proof certificates;
- Managing your contacts and collaboration features;
- Processing subscription billing, overage calculations, and refunds; and
- Providing customer support.
3.2 Security and Compliance
We use information to protect the security and integrity of the Service and to comply with our legal obligations, including:
- Maintaining audit logs as required under HIPAA;
- Preventing abuse, fraud, and unauthorized access through IP address hashing, email address hashing, and rate limiting;
- Detecting and responding to security incidents; and
- Responding to lawful legal process and governmental requests.
3.3 Communications
We use your email address to send transactional communications related to the Service, including fax delivery notifications, billing alerts, practice invitations, number porting status updates, and periodic digest notifications. If you email a document to the Service's fax addresses, we use the sending address to identify your practice and to send you the status of that fax. No PHI is included in any email communication we send. Recipient and third-party fax numbers appearing in email notifications are masked. Your own fax number may appear, unmasked, in account-related notifications such as your welcome email and number-porting status updates.
3.4 Service Improvement
We may use aggregate, de-identified data to analyze Service usage patterns and improve the Service. No Protected Health Information is included in any analytics output. Information that has been de-identified in accordance with 45 CFR § 164.514 is no longer Protected Health Information; Company's broader use of de-identified information, including to develop products, services, and models, is described separately in Section 10.6. Diagnostic and error logs are kept entirely within our HIPAA-covered cloud infrastructure, as described in Section 6.2, and are not transmitted to any third-party error-monitoring service.
3.5 What We Do Not Use Information For
- We do not sell personal information that identifies you. For purposes of this Policy, "personal information" does not include information that has been de-identified in accordance with 45 CFR § 164.514. Company has never sold, and will not sell, identifiable personal information to any third party. Company may use de-identified information, which no longer identifies you and is no longer Protected Health Information, solely to improve the Service, as described in Section 10.6.
- We do not use personal information for advertising. Company does not serve advertisements and does not use your information to deliver targeted or behavioral advertising.
- We do not use identifiable Protected Health Information to train artificial intelligence models for our products. Our cloud analysis subprocessor does not train its models on your content. Automated document analysis processes fax content solely to generate classifications and summaries for your use, under the safeguards described in Section 6. We may create de-identified information, which is no longer Protected Health Information, and use it as described in Section 10.6.
- We do not share personal information for cross-context behavioral advertising.
4. How We Share Information
4.1 Service Providers
Company engages the following categories of third-party service providers to operate the Service:
(a) Cloud infrastructure (Google Cloud Platform): Stores, processes, and analyzes all Protected Health Information under a business associate agreement. This is the only service provider that stores PHI durably.
(b) Telecommunications carrier: Carries fax calls between the Service and the public switched telephone network. Company performs the fax protocol at both ends of every call, so no fax document is handed to this carrier in either direction: fax pages exist on the carrier's network only for the duration of a call, and the carrier holds no fax media to store. On that basis Company has determined that this carrier operates as a transmission conduit within the meaning of 45 CFR § 160.103 and is not a business associate of Company. The durable copy of every fax is held only in Company's HIPAA-covered storage. If Company's transmission arrangements ever change such that a carrier receives or retains fax media, Company will engage that carrier under a business associate agreement.
(c) Payment processor (Stripe, Inc.): Processes subscription billing and payment transactions. Stripe does not receive Protected Health Information. Payment card information is submitted directly to Stripe by you and is never seen by Company.
(d) Email provider (Amazon Web Services): Delivers the account-related emails described in Section 3.3, which never contain Protected Health Information, and receives the emails you send to the Service's fax addresses for faxing. A document you email for faxing is received over an encrypted connection, held encrypted only until the Service creates the fax, and then deleted; any copy a fault leaves behind is removed by an automatic expiry rule within two (2) days of arrival. It is Protected Health Information from the moment it arrives, and this provider processes it under a business associate agreement with Company. The path before the email reaches Company runs through your own email provider, which this Policy does not cover.
(e) Network security and edge infrastructure providers: Provide DDoS protection, rate limiting, and content delivery. Company has assessed these providers as operating in the role of conduits, and they do not retain request content.
Company maintains a current list of its service providers and makes this list available to Covered Entities upon written request.
4.2 Legal Requirements
Company may disclose information when required by law, regulation, legal process, or governmental request, or when Company reasonably believes that disclosure is necessary to protect the rights, privacy, safety, or property of Company, its users, or the public, or to enforce the Terms of Service.
4.3 Business Transfers
In connection with a merger, acquisition, reorganization, or sale of all or substantially all of Company's assets, information may be transferred to the acquiring entity, subject to this Policy and the BAA.
4.4 Referral Partners
If you reached the Service through a referral partner's link or code (Section 2.1), that partner's dashboard shows your practice as a numbered referral, with the month it was referred, its status (including whether it still holds a paid plan), and the partner's own share of the subscription charges Company collected from it. The partner is never shown your name, your email address, your fax number, your documents, or any other information that identifies you, and the partner agrees under the Referral Program Terms not to attempt to identify you.
4.5 With Your Consent
Company will share identifiable personal information with third parties other than those described in this Section 4 only with your explicit prior authorization. This requirement does not apply to information that has been de-identified in accordance with 45 CFR § 164.514, which is no longer personal information and which Company uses solely to improve the Service, as described in Section 10.6.
5. Data Retention
5.1 Company retains information in accordance with the following schedule. Retention periods are expressed as maximum durations ("up to"), not minimum durations. Company may delete information before the stated maximum for operational or legal reasons.
| Data Type | Active Account | After Cancellation | After Account Deletion |
|---|---|---|---|
| Fax documents (PDFs), paid plans | Retained for duration of account | Retained as a secure archive for your continued access; destroyed on your request | Held for the seven (7) day recovery window, then permanently destroyed (see Section 5.5) |
| Fax documents (PDFs), free evaluation | Retained for duration of account; exportable and deletable at any time | Not applicable | Held for the seven (7) day recovery window, then permanently destroyed (see Section 5.5) |
| Records of an ended practice plan (faxes, contacts, comments) | N/A | Retained securely; accessible to and exportable by the Owner; destroyed on the Owner's request | Held for the seven (7) day recovery window, then permanently destroyed (see Section 5.5) |
| Fax metadata | Retained for duration of account | Retained (non-PHI) | Held for the seven (7) day recovery window, then permanently destroyed (see Section 5.5) |
| Emails sent to the Service's fax addresses (the received email and its attachment) | Deleted once the fax is created; any copy a fault leaves behind is removed by an automatic expiry rule within two (2) days of arrival; the fax itself is retained as a fax document | Not retained | Not retained |
| Automated analysis annotations (document classifications, summaries, and extracted fields) | Retained for duration of account | Destroyed when fax documents are destroyed | Destroyed when the associated fax documents are destroyed |
| Contacts | Retained for duration of account | Retained for your continued access; deletable at any time | Held for the seven (7) day recovery window, then permanently destroyed (see Section 5.5) |
| Electronic signatures | Retained for duration of account | Retained for your continued access; deletable at any time | Held for the seven (7) day recovery window, then permanently destroyed (see Section 5.5) |
| De-identified information | Company may de-identify information in accordance with 45 CFR § 164.514 and uses it solely to improve the Service; it is not sold, licensed, or disclosed to any third party (no longer Protected Health Information); see Section 10.6 | Company may retain de-identified information | Company is not required to delete information already de-identified before your request (no longer Protected Health Information); see Section 10.6 |
| Audit logs | Retained indefinitely | Retained indefinitely | Retained indefinitely (compliance) |
| IP address hashes (anti-abuse) | Up to 24 hours | Up to 24 hours | Up to 24 hours |
| Email address hashes (anti-abuse) | Up to 730 days from creation | Up to 730 days from creation | Retained until its 730-day expiry, except where the hash records that an account was deleted, that a one-time refund was used, or that a free allowance was converted; those records are kept permanently and do not expire |
Free evaluation accounts retain their fax history for the life of the account, the same as paid plans. You can export or delete your documents at any time, and you may request deletion of your account and its data by emailing [email protected] (see Sections 5.4 and 5.5).
5.1.1 Your records stay available until you delete them. Company keeps your fax documents and associated records available for as long as you want them, so your history remains accessible whenever you need it. Company does not delete your records on any schedule, and canceling your subscription never deletes anything. Your records are destroyed only when you request deletion (deleting your account is such a request), subject to the recovery window described in Section 5.5. The maximum durations in the schedule above describe how long certain operational items are kept; they do not impose a deadline by which Company destroys your fax documents.
5.2 Non-PHI metadata, including audit logs, may be retained indefinitely for legal compliance, dispute resolution, and enforcement of the Terms of Service.
5.3 Records of an Ended Practice Plan. When a practice's plan ends without account deletion, fax documents, contacts, comments, and associated metadata generated during the plan's active period are retained indefinitely and remain available to the Owner to export. Such retained data is accessible only to the natural person who is the Owner of the practice at the time the plan ends. Workforce members who were part of the practice do not retain access to the retained data following their removal. Account deletion by the Owner, or an explicit destruction request, results in destruction of all retained data.
5.4 Exporting Your Data. You may obtain a copy of your data at any time. Every account, including free evaluation accounts, may download its individual fax documents through the Service; this per-record download is a guaranteed access right. Paid accounts may also generate a self-serve bulk export and may request an administrator-assisted export from Company, including after the account has been closed. Free evaluation accounts may generate a bulk export of their records through the Service, and per-record download remains guaranteed on every tier. If you request a downloadable export of your data, Company delivers it only through a secure, time-limited link. Export files are retained for a limited time to support delivery and re-download, and are then automatically and permanently deleted. An export is provided solely for your retrieval and is not used for any other purpose. Company will not condition export of, or access to, your records on any payment dispute.
5.5 Deleting Your Data and the Recovery Window. Company honors deletion requests on every tier, and deleting specific records never requires deleting your account. You may ask Company to delete specific records or all of your account's data; every account, including free evaluation accounts, may do this through self-serve controls, and you may also request deletion by emailing [email protected]. The scope of a deletion request is fixed at the time you make it and includes only the records identified then; records created after you make the request are not affected by it. Deleting a single fax is immediate: once you confirm it, the fax is permanently destroyed, with no recovery window. For every other deletion, the records within its scope are scheduled for destruction and retained for a recovery window of seven (7) days. During this window the deletion may be undone, by you while you can sign in, or by Company support at your request (including where you have requested deletion of your account itself), so an accidental deletion can be reversed before it finalizes. Once the recovery window closes, Company permanently destroys the live, working copy of the records and renders them beyond use, and they can no longer be recovered. Any residual copies that remain in Company's short-term disaster-recovery backups are kept only for disaster recovery, are never restored or used for any other purpose, and age out of those backups automatically within ninety (90) days. Deletion destroys the affected fax documents, their stored files, and the automated-analysis annotations and extracted fields associated with them; a record of the fact of deletion is retained in the audit log. This Section concerns your identifiable records; it does not require the destruction of information that was already de-identified before your request, and after your request Company does not create new de-identified information from the records you asked to delete, as described in Section 10.6.
6. Data Security
6.1 Company implements administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of information processed through the Service, in compliance with the HIPAA Security Rule (45 CFR Part 164, Subpart C). Additional detail regarding Company's security practices is available at faxpigeon.com/hipaa.
6.2 Security measures include, without limitation:
- Encryption of data in transit using Transport Layer Security (TLS) version 1.2 or higher on every application connection;
- Encryption of data at rest using Advanced Encryption Standard (AES) with 256-bit keys;
- Encryption of emails received at the Service's fax addresses, in transit and at rest; each is deleted once the fax is created, and any copy a fault leaves behind is removed by an automatic expiry rule within two (2) days of arrival;
- Authentication and access controls;
- Automatic session termination after a period of inactivity;
- Append-only audit logging of all significant system events;
- Maintenance of diagnostic and error logs within our HIPAA-covered cloud infrastructure, with no transmission of PHI to any third-party error-monitoring service; and
- Role-based access controls.
6.3 Company uses commercially reasonable administrative, physical, and technical measures, including those described above, to protect your information. As with any electronic system, no method of transmission or storage can be guaranteed to be completely secure, and Company therefore cannot warrant absolute security.
7. Data Processing Location
7.1 All Protected Health Information and account data stored by the Service is stored within the United States.
7.2 Fax calls, and certain network-security and content-delivery functions, may route through infrastructure located in the United States or Canada. Such routing is transient; application traffic remains encrypted in transit, and fax pages exist on the carrier's telephone network only for the duration of a call. No fax content is handed to the transmitting carrier for storage at any point: the durable copy of every fax is written directly into United States storage.
7.3 Company does not store Protected Health Information or account data outside of the United States.
8. Your Rights
8.1 Access. You may view your account information and fax documents at any time through the Service dashboard.
8.2 Correction. You may update your personal information, including your display name and notification preferences, through the Service dashboard.
8.3 Deletion. You may delete specific records, or your whole account, at any time, subject to the prerequisites described in the Terms of Service: deletion is available on every tier, through self-serve controls on every account, or by emailing [email protected], and is subject to the seven (7)-day recovery window described in Section 5.5. Deleting your account immediately revokes your access and, after the recovery window, permanently destroys your data. To keep your records, cancel your subscription instead; cancellation never deletes anything (see Section 5).
8.4 Notification Preferences. You may control email notification settings through the Service dashboard.
8.5 Always-Available Downloads. You may download your individual fax documents through the Service dashboard at any time, on every tier (including free evaluation accounts). Per-record download is a guaranteed access right, and it does not expire on a fixed schedule: your documents stay available on an indefinite basis and are removed only when you delete them under Section 5.5. Where you have requested deletion of your account, Company support can still undo it or retrieve your data during the recovery window, as described in Section 8.6.
8.6 Export and Recovery. Beyond per-record download, paid accounts may generate a self-serve bulk export and may request an administrator-assisted export from Company; free evaluation accounts may likewise generate a bulk export of their records through the Service. After you request deletion of your account, you may still ask Company, by emailing [email protected], to undo the deletion or to provide a copy of your data, at any time before the recovery window closes. Company will verify your identity before acting, and will deliver any export only through a secure, time-limited link and never to an unverified requester.
9. HIPAA and State Privacy Laws
9.1 HIPAA Preemption
Protected Health Information processed through the Service is governed by HIPAA and the BAA between you and Company. To the extent that state privacy laws exempt PHI maintained by a business associate subject to a business associate agreement, such PHI is not subject to those state privacy laws.
9.2 California Residents
To the extent that the California Consumer Privacy Act (Cal. Civ. Code §§ 1798.100 et seq.) or the California Privacy Rights Act applies to personal information that is not PHI, Company acknowledges that California residents may have certain rights with respect to such non-PHI personal information. As used here, "personal information" does not include information that has been de-identified in accordance with 45 CFR § 164.514. Company does not sell personal information that identifies you. Company does not share personal information for cross-context behavioral advertising. Company does not sell de-identified information. Company may de-identify information from Protected Health Information by an applicable HIPAA de-identification method and uses it solely to improve the Service; the methods, commitments, and protections are described in Section 10.6.
9.3 Other State Privacy Laws
Residents of states with privacy laws of general application may have additional rights with respect to personal information that is not PHI. To exercise any such rights, contact Company at [email protected]. Company will respond to verified requests in accordance with applicable law.
10. Automated Document Analysis
10.1 The Service uses automated analysis to classify and summarize inbound fax documents. This processing generates document type classifications, document summaries, and extracted metadata fields to assist you in managing your fax workflow.
10.2 Automated analysis is performed on Google Cloud Platform under the business associate agreement described in Section 4.1.
10.3 The automated analysis processes fax content solely to generate the outputs described in Section 10.1 and for no other purpose. The analysis is performed by a cloud subprocessor engaged under our HIPAA business associate agreement.
10.4 Automated analysis does not make decisions about individuals. It classifies document types and generates summaries. No action is taken with respect to any individual based solely on the output of the automated analysis system.
10.5 Company does not use identifiable Protected Health Information to train, improve, or develop any machine learning or artificial intelligence model, and Company never sells Protected Health Information. Company may create de-identified information in accordance with 45 CFR § 164.514 and use it to operate, improve, and develop its services, analytics, and models. Once de-identified, such information is no longer Protected Health Information. Company's use of de-identified information is described in Section 10.6.
10.6 De-Identified Information. Company may de-identify Protected Health Information processed through the Service in accordance with the HIPAA Privacy Rule, 45 CFR § 164.514, using the Safe Harbor method (45 CFR § 164.514(b)(2)) or the Expert Determination method (45 CFR § 164.514(b)(1)). De-identified information no longer identifies you and is no longer Protected Health Information or governed by the Business Associate Agreement. Company uses de-identified information solely to operate, analyze, improve, and develop the Service, and does not sell, license, or otherwise disclose it to any third party. The protected internal key Company uses to link records is kept strictly confidential, is never shared, and is used for no other purpose; if Company ever re-identifies a record, that record is again Protected Health Information and is again governed by the Business Associate Agreement. Company does not sell, and has never sold, Protected Health Information.
What this means for your data. This Section concerns only de-identified information. The reasons Company retains your identifiable records are described separately in Section 5 (continued access to your historical records, your retention and legal-hold needs, and legal compliance). Because de-identified information is no longer linked to you, two things follow. First, once you ask us to delete specific records, we do not create any new de-identified information from those records. Second, de-identified information that already existed before your deletion request is not affected by that request, because it is no longer Protected Health Information and can no longer be connected to you. Deletion of your identifiable records and account is described in Sections 5.4 and 5.5.
11. Cookies and Tracking Technologies
11.1 The Service does not set cookies for authentication. Your signed-in session is maintained using security tokens stored by your browser and managed by our identity provider; these tokens are necessary for the operation of the Service.
11.2 The Service does not use advertising or cross-site tracking cookies. Service providers engaged for payment processing and security may set cookies strictly necessary for fraud prevention; these are not used for advertising. The Service also uses your browser's local storage to hold the referral code from a partner link for up to ninety (90) days, as described in Section 2.3; that record is used only to attribute your referral and never for advertising or tracking.
11.3 The Service may collect aggregate performance metrics to monitor Service availability and performance. These metrics are anonymous, do not identify individual users, and never include the content of your faxes or Protected Health Information.
11.4 Because the Service uses only the storage and cookies strictly necessary for its operation and security, and no advertising or tracking cookies, no cookie consent banner or opt-in mechanism is required under applicable law.
11.5 Do Not Track and Global Privacy Control. The Service does not track users over time or across third-party websites, so there is no tracking activity to alter in response to browser "Do Not Track" (DNT) or Global Privacy Control (GPC) signals. The Service does not sell personal information that identifies you and does not share personal information for cross-context behavioral advertising, so such signals do not change how the Service processes your information.
12. Children
12.1 The Service is not directed to individuals under the age of eighteen (18).
12.2 Company does not knowingly collect personal information from individuals under the age of eighteen (18).
12.3 If Company becomes aware that it has collected personal information from an individual under the age of eighteen (18), Company will take prompt steps to delete such information.
13. Breach Notification
13.1 In the event of a breach of unsecured Protected Health Information, Company will notify affected users in accordance with applicable federal and state law, including the BAA.
13.2 Company's breach notification obligations with respect to PHI are set forth in detail in the BAA. The BAA provides that Company will notify affected covered entities without unreasonable delay and in no event later than thirty (30) calendar days after discovery of a breach.
13.3 For personal information that is not PHI, Company will provide breach notification in accordance with the laws of the states in which affected individuals reside.
14. Changes to This Policy
14.1 Company may update this Policy from time to time to reflect changes in its practices, legal requirements, or for other lawful purposes.
14.2 For material changes to this Policy, Company will provide notice by email to the address associated with your account at least thirty (30) days before the effective date of the revised Policy.
14.3 Your continued use of the Service after the effective date of any revised Policy constitutes your acceptance of and agreement to be bound by the revised Policy.
14.4 If you do not agree to any revised Policy, you must cancel your account before the effective date of the revision.
15. Contact
If you have questions about this Policy or Company's privacy practices, you may contact us at:
Fax Pigeon LLC 211 W. Wacker Drive, Ste 120, PMB 2449, Chicago, Illinois 60606
© 2026 Fax Pigeon LLC. All rights reserved.