Privacy stance
This is the working posture, not a generic template. It pairs with the compliance matrix on /compliance — if you want to read the TCPA, AI-disclosure, and FCC stance before reviewing what is collected, start there. The five sections below cover intake, calls, retention, third parties, and your rights, in that order.
1 · What we collect
On intake
The intake form is the postmark on every engagement. It collects the full business + contact record the agent will act on — name, email, business name, vertical, the current stack (calendar, CRM, phone system), weekly call volume, and the top pain point the practice is trying to move. Nothing else is pulled in; nothing is inferred from a third-party list.
On the call
When the agent picks up or places a call, it captures the audio and the transcript, the AI-disclosed opening line, and the booking outcome (booked / qualified / not a fit). The transcript is what we tune the agent against between passes — it is the working artifact for the engagement, and it stays tied to the lead record it came from.
On SMS
For the SMS confirmations and follow-ups the agent places, Twilio handles deliverability and TCPA safeguard metadata — opt-in capture, opt-out status, message status callbacks. The thread of SMS messages between the agent and a contact lives in the workspace alongside the call transcript and the booking record.
2 · How we use it
The data the intake form and the calls collect is used for the jobs the engagement exists to do — and for nothing else. We do not sell it, we do not share it with advertising networks, and we do not repurpose it into a service we have not told you about.
To run the engagement.
Qualify the lead against the criteria your practice sets, book the appointment in the calendar that is already your system of record, hand off to the right person on your side, and send the SMS confirmation that closes the loop.
To tune the agent on the practice’s voice.
The transcript is what we tune against between weekly passes — phrasing, qualification questions, booking handoff. The persona is consistent across the call and the follow-up text because the tuning is anchored to real transcript, not generic script.
To confirm scope.
When you send the rights request described in section 5, the data we hold is what lets us answer it. The intake record, the call transcripts, the booking record, and the SMS thread are exactly the surfaces a rights request reads against.
To respond to rights requests.
When a contact asks to access, correct, delete, or export their data, we run that against the same systems we just named. We do not hold a parallel set of records under a different retention clock.
3 · Retention & deletion
Contact-form submissions
Messages sent through /contact and intake submissions are retained for the duration of the engagement, plus a reasonable wind-down window so we can close out scoping, hand back any artifacts, and respond to a late-arriving question. When the engagement ends, the records roll off the active workspace on the same wind-down clock.
Call recordings & transcripts
Call audio and the matching transcript are kept for QA and for the weekly tuning passes that keep the agent on the practice’s voice. A contact who has asked for deletion, or an engagement that has ended, takes the relevant transcripts and recording pointers out of the active queue; a small audit trail of the deletion itself is kept so we can answer the follow-up question.
Deletion on request
If you want something deleted before the engagement ends — a transcript, a contact record, an SMS thread — the channel for that request is the same one as everything else on this page: a real person reads it and runs it through the workflow. We confirm deletion in writing, with what was removed and what remains.
4 · Third parties
The integrations on /integrations are the same five processors who touch data on a live engagement. Each one sees only what its job requires — no advertising-threaded pipeline, no resale, no secondary reuse.
Twilio
SMS deliverability + TCPA safeguard.
Sends the SMS confirmations and follow-up text the agent places; carries the opt-in / opt-out metadata the consent posture on /compliance is anchored to.
HubSpot
CRM / lead record.
Stores the lead and contact record the intake form produces — the canonical CRM copy for the engagement, scoped to the fields the practice configured.
RingCentral
Call carrier for office practices.
Carries the inbound and outbound voice for practices whose phone system is RingCentral. Audio and call metadata live where the practice already expects them.
Google Calendar
Booking system of record.
Holds the booked slot the agent confirmed on the call — the calendar the practice already lives in is the system of record for the appointment.
Jobber
Dispatch system of record for home services.
Stores the dispatch record when an HVAC / plumbing / electrical job moves from a booked call to a scheduled dispatch. Same posture as the CRM slot, scoped to the trade.
5 · Your rights & how to reach us
A contact, a practice, or a regulator can ask for any of the four standard rights against the data described in sections 1–4. We treat each request as a scoped engagement of its own — it is read, owned, and answered by a real person inside our team, not by a queue.
Access
A copy of the data we hold for a contact record, an intake submission, or a call transcript — delivered in a portable format.
Correct
A correction against any field that is wrong, stale, or was supplied at intake and has since changed on the practice side.
Delete
Removal of a specific record (a transcript, an SMS thread, a contact) from the active workspace, with a written confirmation of what was removed.
Export
A pull of the full record set tied to the engagement — transcripts, intake fields, booking record, SMS thread — in the format your team can actually use.
The channel is the same regardless of which right you are exercising: write to threadbay@polsia.app or send a note through /contact. A founder reads every request and comes back within one business day with the concrete next step — what we need from you, the timeline, and the person on our side who owns the answer.
Privacy stance — working, not boilerplate
If a data flow, retention window, or processor scope above is not the answer you were looking for, send the question through the contact surface and we’ll write back with where the answer lives — not a link to a template.
Or email threadbay@polsia.app directly.