Privacy Policy

Last updated: July 15, 2026

This Privacy Policy explains how Efiling Solutions LLC ("we", "us") collects, uses, shares, and protects information when you visit our website at efiling-solutions.com or use our CPSC eFiling service (together, the "Service"). It does not cover third-party websites we link to, which have their own privacy policies.

Our role in handling your data

The Service is a business tool used by companies. For the compliance data inside a company's account — products, factories, lab reports, certificates, and any personal information appearing in them — we act as a service provider (processor): we handle that data on behalf of the customer company and under its instructions. For account registration details, website usage data, billing, and demo or contact inquiries, we act as the controller (business) and this policy describes our own practices. If your information appears inside another company's account (for example, you are named as a contact on a certificate), that company controls it; we will refer your request to them and assist them in responding.

Information we collect

How we collect it: directly from you; from your company (when an administrator invites you or adds records that mention you); automatically when you use the Service (session and security logs); and from intake channels your company chooses to connect. We do not buy personal information from data brokers, and we do not collect precise geolocation, biometric, or health information.

How we use it

Legal bases for processing (EEA, UK, and Switzerland)

Where the GDPR, UK GDPR, or similar law applies, we rely on the following legal bases:

AI and automated decision-making

We use third-party AI services to help read the lab reports you upload and extract structured data from them, such as test results, dates, and product identifiers. Every AI-assisted extraction is presented to you for human review — with citations back to the exact location in the source document — before it is used in a certificate, and nothing is filed with the CPSC except at your direction. We do not use automated processing to make decisions about individuals that produce legal or similarly significant effects. Our AI providers process report content solely to perform the extraction, under terms that do not permit training their models on your data.

Data isolation

The Service is multi-tenant by design: every record is scoped to your company, credentials are encrypted with company-bound keys, and no customer can access another customer's data. Our staff do not have standing access to your data; any support access is explicit, time-limited, and audit-logged.

Where data lives; sharing

The Service runs on Cloudflare's global infrastructure, with data processed and stored in the United States. Uploaded PDFs are stored in private object storage; structured data is stored in our database. We share data only with: (a) the U.S. Consumer Product Safety Commission's eFiling system, at your direction; (b) the customs broker or other recipients your company designates; and (c) service providers that help us run the Service — cloud hosting and storage, transactional email delivery, AI-assisted reading of uploaded lab reports, and payment processing — each bound to use your data only to provide their service to us. A current named list of our sub-processors is available to customers on request; see our Security & Trust page. We do not sell or rent personal information, and we do not share it for cross-context advertising.

Security

We protect data with industry-standard measures: TLS encryption in transit, encryption at rest, company-bound encryption keys for CPSC credentials, mandatory two-factor authentication, brute-force lockouts, strict tenant isolation enforced in code and verified by automated tests, and audit logging. See our Security & Trust page for the full picture, including our responsible-disclosure policy. No system is perfectly secure; if we confirm a breach affecting your data, we will notify your account email without undue delay — our target is within 72 hours of confirmation — and as required by law.

International data transfers

The Service is operated from and hosted in the United States, and your data is transferred to and processed there. Where applicable data-protection law requires safeguards for international transfers — for example, for customers in the EEA, the United Kingdom, or Switzerland — we rely on appropriate transfer mechanisms such as the European Commission's standard contractual clauses (and the UK and Swiss equivalents), which we will enter into with your company on request as part of its agreement with us.

Legal disclosures

We may disclose information if required by law, subpoena, or court order, to enforce our Terms of Service, or to protect the rights, safety, or property of our users, the public, or the Service. If Efiling Solutions LLC is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction under the same protections in this policy, and we will notify you of any change in ownership.

Cookies and tracking

We use only essential cookies: a signed session cookie that keeps you logged in and an optional "remember this device" cookie for two-factor authentication. We do not use advertising, analytics, or cross-site tracking cookies, tracking pixels, or session-replay tools. The app also uses your browser's local storage for interface preferences (such as table column layouts); this information stays on your device and is not used to identify or track you. Because we do not sell or share personal information or track you across other sites, there is nothing for browser signals such as "Do Not Track" or Global Privacy Control to opt out of — you receive the same protections either way. Note that blocking essential cookies in your browser will prevent sign-in from working.

Retention and deletion

Your rights and choices

You can update your account details, rotate your CPSC credentials, and change your password at any time in Settings. Depending on where you live, you may also have the right to:

To exercise these rights, contact us or email privacy@efiling-solutions.com. We will verify your request — normally via your account email — and respond within the time required by applicable law: for requests under the GDPR or UK GDPR, within one month (which we may extend by up to two further months for complex or numerous requests — if so, we will tell you within the first month and explain why); for requests under U.S. state privacy laws, generally within 45 days. You may use an authorized agent where the law allows; we will ask for proof of authorization. If we decline a request, we will explain why, and you may appeal by replying to our decision; depending on your U.S. state, you may also contact your state Attorney General. If you are in the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with your data-protection supervisory authority (in the UK, the Information Commissioner's Office).

U.S. state privacy disclosures

For residents of California and other U.S. states with privacy laws (including Colorado, Connecticut, Virginia, and Texas): in the preceding 12 months we have collected the categories of personal information described in "Information we collect" above — identifiers (name, email, company, role), professional information, commercial information (billing records), internet activity (sign-in and usage logs), and the business documents your company provides. We collect them from the sources and for the purposes described above, and disclose them only to the service providers and recipients listed in "Where data lives; sharing" for business purposes. We have not sold personal information, have not shared it for cross-context behavioral advertising, do not use it for targeted advertising or for profiling that produces legal or similarly significant effects, and do not collect or use sensitive personal information except as needed to provide the Service. Because we do not sell or share personal information, no opt-out is required. We do not offer financial incentives in exchange for personal information. The rights and request process above apply, including the right to appeal a denied request.

Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16; if you believe a child has provided us information, contact us and we will delete it.

Changes

If we make material changes to this policy, we will update this page and the date above and notify your account email before the changes take effect where required by law. Prior versions of this policy are available on request.

Contact

Questions about this policy or your data? Email privacy@efiling-solutions.com or use our contact form. For security concerns, email security@efiling-solutions.com.