Checkout
Package selection, customer contact details, subscription status, and transaction identifiers are connected to a private WordPress purchase record.
Card details stay with Stripe.This page gives clients a practical view of the information used in each QCR workflow. It supplements the Privacy Policy and does not replace the signed Client Services Agreement.
Last updated: July 20, 2026Package selection, customer contact details, subscription status, and transaction identifiers are connected to a private WordPress purchase record.
Card details stay with Stripe.Business details, authorized signer, acceptance time, signature, and signing IP address are used to create the signed agreement record.
Copies go to QCR and the client.Business contacts, Google profile information, access status, goals, customer-list status, and setup notes are used to create the portal and plan fulfillment.
Access is limited to service delivery.The portal stores QCR scores, review baselines, competitor comparisons, progress, reports, priorities, and billing entitlement.
Each client account is access controlled.Public review text and relevant business context may be processed by an authorized AI provider to identify specific patterns and draft analysis.
QCR requires human review before publishing.Authorized users may enter customer contact, appointment, service, price, tip, employee, status, and note information. Configured automations may send necessary fields to the client's GHL workflow.
CRM data is not used for unrelated clients.QCR uses separate customer accounts, private client pages, role-based WordPress permissions, signed post-payment setup sessions, and verified Stripe webhook events. Clients are responsible for protecting their own login credentials and promptly reporting suspected access issues.
Do not upload payment card details, Social Security numbers, medical records, account passwords, or unrelated sensitive information. Customer fields in the CRM should be limited to information needed for appointments, service tracking, authorized follow-up, and team reporting.
QCR selects providers based on the function required and limits information shared to that function. Key providers may include Stripe, the website host and WordPress, email delivery providers, Google services, GoHighLevel, and OpenAI. Provider availability and policies can change, and material changes will be reflected in the Privacy Policy.
The production website and database should be backed up automatically to storage outside the production server, with multiple restore points and periodic restore testing. Email copies of agreements provide an additional business record but do not replace website and database backups.
QCR administrators should use multifactor authentication for WordPress, Stripe, hosting, domain/DNS, email, and delivery providers. WordPress, the active theme, and plugins should remain updated and monitored. Clients should remove former staff access and notify QCR when authorized contacts change.
Suspected incidents are investigated to identify affected systems and information, contain access, preserve relevant records, restore service, and provide required notices. Security concerns should be reported promptly to support@qualitycontrolreviews.com.