Privacy Policy
This Privacy Policy explains how Efiling Solutions LLC ("we", "us") collects, uses, shares, and protects information when you visit our website at efiling-solutions.com or use our CPSC eFiling service (together, the "Service"). It does not cover third-party websites we link to, which have their own privacy policies.
Our role in handling your data
The Service is a business tool used by companies. For the compliance data inside a company's account — products, factories, lab reports, certificates, and any personal information appearing in them — we act as a service provider (processor): we handle that data on behalf of the customer company and under its instructions. For account registration details, website usage data, billing, and demo or contact inquiries, we act as the controller (business) and this policy describes our own practices. If your information appears inside another company's account (for example, you are named as a contact on a certificate), that company controls it; we will refer your request to them and assist them in responding.
Information we collect
- Account information — your name, email address, company name, and role, provided when an account is created for you or when you accept an invitation from your company's administrator.
- CPSC credentials — the CPSC eFiling API token and secret your company connects so we can file on your behalf. These are encrypted at rest with keys bound to your company and are never shown back, shared, or used for any other company's filings.
- Compliance data — the products, factories, lab test reports (including uploaded PDFs), and certificates you add to the Service, whether uploaded directly, imported at your direction, or sent through an intake channel (such as an email inbox or shared folder) your company connects.
- Billing information — payment cards are collected and stored by our PCI DSS–certified payment processor; card numbers never touch our servers. We retain only the card brand, last four digits, expiration date, and billing records.
- Demo and contact requests — the name, company, email, phone, and message you submit through our demo or contact forms.
- Security and usage logs — sign-in events, IP address, browser type, and an audit trail of actions taken in your account.
How we collect it: directly from you; from your company (when an administrator invites you or adds records that mention you); automatically when you use the Service (session and security logs); and from intake channels your company chooses to connect. We do not buy personal information from data brokers, and we do not collect precise geolocation, biometric, or health information.
How we use it
- To operate the Service: reading your lab reports — with the assistance of third-party AI providers (see sub-processors below), which process the content only to extract data and do not train on it — preparing certificates, and filing them to the CPSC eFiling registry at your direction.
- To secure accounts: two-factor authentication, brute-force protection, and audit logging.
- To respond to demo, support, and sales inquiries, and to follow up on them.
- To send service and account notices — filing results, alerts you configure, billing notices, and policy updates. We do not send third-party advertising.
- To maintain, troubleshoot, and improve the Service, using aggregated or de-identified information where possible.
- To comply with law, enforce our agreements, and prevent fraud and abuse.
- We do not sell your data, and we do not use one company's data for any other company.
Legal bases for processing (EEA, UK, and Switzerland)
Where the GDPR, UK GDPR, or similar law applies, we rely on the following legal bases:
- Performance of a contract — account information, CPSC credentials, compliance data, and billing, processed to provide the Service your company signed up for.
- Legitimate interests — security and audit logging, fraud and abuse prevention, service improvement, and responding to and following up on business inquiries. We balance these interests against your rights, and you can object at any time (see "Your rights and choices").
- Legal obligation — retaining billing and tax records and responding to lawful requests from authorities.
- Consent — for anything not covered above, we will ask separately, and you can withdraw consent at any time without affecting prior processing.
AI and automated decision-making
We use third-party AI services to help read the lab reports you upload and extract structured data from them, such as test results, dates, and product identifiers. Every AI-assisted extraction is presented to you for human review — with citations back to the exact location in the source document — before it is used in a certificate, and nothing is filed with the CPSC except at your direction. We do not use automated processing to make decisions about individuals that produce legal or similarly significant effects. Our AI providers process report content solely to perform the extraction, under terms that do not permit training their models on your data.
Data isolation
The Service is multi-tenant by design: every record is scoped to your company, credentials are encrypted with company-bound keys, and no customer can access another customer's data. Our staff do not have standing access to your data; any support access is explicit, time-limited, and audit-logged.
Where data lives; sharing
The Service runs on Cloudflare's global infrastructure, with data processed and stored in the United States. Uploaded PDFs are stored in private object storage; structured data is stored in our database. We share data only with: (a) the U.S. Consumer Product Safety Commission's eFiling system, at your direction; (b) the customs broker or other recipients your company designates; and (c) service providers that help us run the Service — cloud hosting and storage, transactional email delivery, AI-assisted reading of uploaded lab reports, and payment processing — each bound to use your data only to provide their service to us. A current named list of our sub-processors is available to customers on request; see our Security & Trust page. We do not sell or rent personal information, and we do not share it for cross-context advertising.
Security
We protect data with industry-standard measures: TLS encryption in transit, encryption at rest, company-bound encryption keys for CPSC credentials, mandatory two-factor authentication, brute-force lockouts, strict tenant isolation enforced in code and verified by automated tests, and audit logging. See our Security & Trust page for the full picture, including our responsible-disclosure policy. No system is perfectly secure; if we confirm a breach affecting your data, we will notify your account email without undue delay — our target is within 72 hours of confirmation — and as required by law.
International data transfers
The Service is operated from and hosted in the United States, and your data is transferred to and processed there. Where applicable data-protection law requires safeguards for international transfers — for example, for customers in the EEA, the United Kingdom, or Switzerland — we rely on appropriate transfer mechanisms such as the European Commission's standard contractual clauses (and the UK and Swiss equivalents), which we will enter into with your company on request as part of its agreement with us.
Legal disclosures
We may disclose information if required by law, subpoena, or court order, to enforce our Terms of Service, or to protect the rights, safety, or property of our users, the public, or the Service. If Efiling Solutions LLC is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction under the same protections in this policy, and we will notify you of any change in ownership.
Cookies and tracking
We use only essential cookies: a signed session cookie that keeps you logged in and an optional "remember this device" cookie for two-factor authentication. We do not use advertising, analytics, or cross-site tracking cookies, tracking pixels, or session-replay tools. The app also uses your browser's local storage for interface preferences (such as table column layouts); this information stays on your device and is not used to identify or track you. Because we do not sell or share personal information or track you across other sites, there is nothing for browser signals such as "Do Not Track" or Global Privacy Control to opt out of — you receive the same protections either way. Note that blocking essential cookies in your browser will prevent sign-in from working.
Retention and deletion
- While your account is active — we keep your compliance records because CPSC recordkeeping rules require certificates and supporting records to be retained for years; superseded certificates are archived rather than deleted so your filing history stays provable. You can delete products, reports, and uploaded PDFs at any time from the app.
- If your company cancels — your data remains available for export for at least 90 days (see our Security & Trust page). After that, we delete your company's data — including stored CPSC credentials — on request, completing verified deletion requests within 30 days, except for specific records we must retain to comply with law, resolve disputes, or enforce agreements.
- Backups — deleted data ages out of our automated backups within 30 days of deletion.
- If you leave a company that uses the Service — its administrators can remove your user account at any time, which disables your access immediately. Your name may remain in that company's audit trail and filing history, which we maintain on the company's behalf as part of its compliance records. To request deletion of your own account information, email privacy@efiling-solutions.com; where the information sits inside a customer's account, we will coordinate with that company.
- Security and audit logs — retained for the life of your account for security and compliance purposes. When your company's data is deleted, associated logs are deleted with it, except the minimal records described above.
- Demo and contact inquiries — kept as long as needed to respond and follow up; you can ask us to delete your inquiry at any time.
- Billing records — retained as required by tax and accounting law.
Your rights and choices
You can update your account details, rotate your CPSC credentials, and change your password at any time in Settings. Depending on where you live, you may also have the right to:
- know what personal information we hold about you and receive a copy of it, in a portable format;
- correct inaccurate personal information;
- delete your personal information;
- restrict or object to certain processing, including processing based on legitimate interests;
- withdraw consent where processing is based on consent;
- not be discriminated against for exercising any of these rights.
To exercise these rights, contact us or email privacy@efiling-solutions.com. We will verify your request — normally via your account email — and respond within the time required by applicable law: for requests under the GDPR or UK GDPR, within one month (which we may extend by up to two further months for complex or numerous requests — if so, we will tell you within the first month and explain why); for requests under U.S. state privacy laws, generally within 45 days. You may use an authorized agent where the law allows; we will ask for proof of authorization. If we decline a request, we will explain why, and you may appeal by replying to our decision; depending on your U.S. state, you may also contact your state Attorney General. If you are in the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with your data-protection supervisory authority (in the UK, the Information Commissioner's Office).
U.S. state privacy disclosures
For residents of California and other U.S. states with privacy laws (including Colorado, Connecticut, Virginia, and Texas): in the preceding 12 months we have collected the categories of personal information described in "Information we collect" above — identifiers (name, email, company, role), professional information, commercial information (billing records), internet activity (sign-in and usage logs), and the business documents your company provides. We collect them from the sources and for the purposes described above, and disclose them only to the service providers and recipients listed in "Where data lives; sharing" for business purposes. We have not sold personal information, have not shared it for cross-context behavioral advertising, do not use it for targeted advertising or for profiling that produces legal or similarly significant effects, and do not collect or use sensitive personal information except as needed to provide the Service. Because we do not sell or share personal information, no opt-out is required. We do not offer financial incentives in exchange for personal information. The rights and request process above apply, including the right to appeal a denied request.
Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16; if you believe a child has provided us information, contact us and we will delete it.
Changes
If we make material changes to this policy, we will update this page and the date above and notify your account email before the changes take effect where required by law. Prior versions of this policy are available on request.
Contact
Questions about this policy or your data? Email privacy@efiling-solutions.com or use our contact form. For security concerns, email security@efiling-solutions.com.