Privacy notice
Last updated [date] · [Legal entity name], Indiana, USA
What we collect
- Calls to a ShopBoss hotline: caller phone number, call recording, transcript, an AI summary, and what the caller tells the receptionist (name, service address, the job, preferred time, budget).
- Jobs: schedule, assigned tech, status updates, notes, photos and the customer’s signature collected on site.
- Shop accounts: owner name, email, password (stored hashed), techs’ names and phone numbers, working hours.
- Devices: push-notification subscriptions for crew phones, and a sign-in cookie. We don’t use advertising or tracking cookies.
- Security logs: IP address and the page requested. Private links and keys are masked in the logs.
Why
To answer calls, book and dispatch jobs, remind customers, keep spam and fraud off the schedule, and support the shop. We don’t sell personal information.
Who processes it for us
- Voice AI and call recording: Vapi [and its model providers].
- Hosting: [provider].
- Push notifications: the browser’s push service (Google, Mozilla, Apple or Microsoft).
- Text messages and email: [SMS provider], [email provider], only once they’re switched on.
Call recording
Calls may be recorded and transcribed. The receptionist says so at the start of the call. [Confirm the greeting wording and the consent rules for the states you serve.]
How long we keep it
- Recordings and transcripts: [90 days], then deleted.
- Jobs and job history: while the account is active, or until the shop deletes them.
- Server logs: [14 days]. Backups: [30 days] rolling, then overwritten.
- When a shop deletes its account, its jobs, recordings, transcripts, photos, messages and sign-in links are deleted at once. Copies in backups expire on the backup schedule.
Your choices
Customers can ask the shop, or us at [privacy@yourdomain], for a copy of their data or for it to be deleted. Shop owners can export or delete everything from Account & data.
Security
Encrypted connections (HTTPS), hashed passwords, one-time sign-in links, sessions that expire, and access limited by role.
Contact
[Legal entity], [mailing address], [privacy@yourdomain].