Privacy Policy
Last Updated: December 6, 2025
1. Introduction
callins.ai ("we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered phone answering service, website, and related services (collectively, the "Services").
This Privacy Policy complies with applicable federal and state privacy laws, including but not limited to the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), Virginia Consumer Data Protection Act (VCDPA), and other state privacy laws.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, phone number, business name, business address, timezone
- Business Information: Restaurant details, menu information, hours of operation, agent configuration
- Payment Information: Processed securely through Stripe (we do not store complete payment card details)
- Communication Data: Phone call recordings, transcripts, SMS messages, voicemails
- Customer Data: Information about your customers including phone numbers, names, order details, reservation details, inquiries
2.2 Information Automatically Collected
- Usage Data: Call logs, interaction history, feature usage, response times
- Device Information: IP address, browser type, operating system, device identifiers
- Cookies and Tracking: We use cookies and similar technologies (see Section 9)
- Location Data: General location based on IP address or business address you provide
2.3 Information from Third Parties
- Authentication Providers: Google (if you use Google sign-in)
- Payment Processors: Stripe for payment processing
- Telecommunications: Twilio for phone services
- AI Services: OpenAI for language processing, Google Cloud for speech-to-text and text-to-speech
3. How We Use Your Information
We use collected information for the following purposes:
- Service Delivery: Operate AI phone answering, process calls, take orders and reservations, answer inquiries
- Account Management: Create and manage your account, authenticate users, process payments
- Customer Support: Respond to inquiries, troubleshoot issues, provide technical support
- Service Improvement: Analyze usage patterns, improve AI accuracy, develop new features
- Communication: Send service updates, billing notifications, marketing communications (with consent)
- Legal Compliance: Comply with legal obligations, enforce terms, protect rights and safety
- Fraud Prevention: Detect and prevent fraudulent activities, security threats
- Analytics: Understand service performance, generate business insights
4. Legal Basis for Processing (International Users)
For users in the European Economic Area (EEA), UK, or Switzerland, we process personal data based on:
- Contractual Necessity: Processing necessary to provide Services you requested
- Legitimate Interests: Improving Services, fraud prevention, security
- Legal Obligations: Compliance with applicable laws
- Consent: Where you have provided explicit consent (e.g., marketing)
5. How We Share Your Information
5.1 Service Providers
We share information with third-party service providers who perform services on our behalf:
- Twilio: Telecommunications infrastructure for phone calls and SMS
- OpenAI: AI language processing (GPT models)
- Google Cloud: Speech-to-text and text-to-speech services
- Stripe: Payment processing
- Cloud Hosting: Infrastructure providers (servers, databases)
5.2 Business Transfers
In the event of a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred to the successor entity. You will be notified of any such change.
5.3 Legal Requirements
We may disclose information when required by law or to:
- Comply with legal processes (subpoenas, court orders)
- Enforce our Terms of Service
- Protect rights, property, or safety of callins.ai, users, or the public
- Investigate fraud or security issues
5.4 With Your Consent
We may share information with third parties when you provide explicit consent.
5.5 We Do Not Sell Personal Information
We do not sell your personal information to third parties for monetary consideration. We do not share personal information for cross-context behavioral advertising.
6. Call Recording and Telecommunications Compliance
6.1 Call Recording Notice
ALL PHONE CALLS ARE RECORDED AND TRANSCRIBED. By using our Services or calling a phone number serviced by callins.ai, you consent to the recording and transcription of your calls. Recordings are used to:
- Process orders, reservations, and inquiries
- Train and improve AI models
- Quality assurance and customer service
- Legal compliance and dispute resolution
6.2 TCPA Compliance
We comply with the Telephone Consumer Protection Act (TCPA). By providing your phone number, you consent to receive calls and text messages related to your use of the Services. You may opt out at any time by contacting us or replying STOP to SMS messages.
6.3 Do Not Call Registry
Our Services allow you to maintain a Do Not Call list for your business. We respect these designations and will not process calls from blocked numbers on your behalf.
6.4 State-Specific Call Recording Laws
Some states require two-party consent for call recording. Our AI agent announces recording at the beginning of calls in compliance with applicable state laws. If you do not consent to recording, please disconnect immediately.
7. Data Retention
We retain personal information for as long as necessary to:
- Provide Services to you
- Comply with legal obligations (tax, accounting, legal retention requirements)
- Resolve disputes and enforce agreements
- Maintain business records
Typical Retention Periods:
- Account Data: Duration of account plus 7 years for legal compliance
- Call Recordings: 90 days to 3 years depending on business needs and legal requirements
- Transaction Records: 7 years for tax and accounting compliance
- Marketing Data: Until consent is withdrawn or account closure
8. Data Security
We implement reasonable technical and organizational measures to protect your information:
- Encryption: Data encrypted in transit (TLS/SSL) and at rest
- Access Controls: Role-based access, authentication requirements
- Infrastructure Security: Secure cloud hosting, firewalls, intrusion detection
- Regular Audits: Security assessments and vulnerability testing
- Employee Training: Privacy and security training for personnel
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your information.
9. Cookies and Tracking Technologies
9.1 Types of Cookies We Use
- Essential Cookies: Required for authentication and core functionality
- Analytics Cookies: Help us understand how you use our Services
- Preference Cookies: Remember your settings and preferences
9.2 Managing Cookies
You can control cookies through your browser settings. Disabling cookies may affect Service functionality.
10. Your Privacy Rights
10.1 California Residents (CCPA/CPRA)
California residents have the right to:
- Know: Request disclosure of personal information collected, used, and shared
- Delete: Request deletion of personal information (subject to exceptions)
- Correct: Request correction of inaccurate personal information
- Opt-Out: Opt-out of sale/sharing (we do not sell personal information)
- Limit Use: Limit use and disclosure of sensitive personal information
- Non-Discrimination: Not be discriminated against for exercising rights
Sensitive Personal Information: We collect precise geolocation (business address), account login credentials (email/password), call recordings (may contain personal conversations). This information is used solely to provide Services.
10.2 Colorado, Connecticut, Utah, Virginia Residents
Residents of these states have similar rights including:
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to data portability
- Right to opt-out of targeted advertising and sale of personal data
10.3 European Economic Area (EEA), UK, Switzerland (GDPR)
If you are in the EEA, UK, or Switzerland, you have the right to:
- Access your personal data
- Rectify inaccurate personal data
- Erase personal data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
- Lodge a complaint with supervisory authority
10.4 Nevada Residents
Nevada residents may opt-out of the sale of personal information. We do not sell personal information as defined under Nevada law.
10.5 How to Exercise Your Rights
To exercise any of these rights, contact us at:
- Email: [email protected]
- Mail: callins.ai, 651 N Broad St, Suite 201, Middletown, DE 19709
We will respond to verifiable requests within the timeframes required by applicable law (typically 30-45 days). We may request additional information to verify your identity.
10.6 Authorized Agents
You may designate an authorized agent to make requests on your behalf. The agent must provide proof of authorization.
11. Children's Privacy (COPPA Compliance)
Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children under 13. If we learn we have collected information from a child under 13, we will delete it promptly. If you believe a child has provided us with personal information, contact us immediately.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. When we transfer personal data internationally, we implement appropriate safeguards including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions
- Other legally approved transfer mechanisms
13. Third-Party Services and Links
Our Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
Key Third Parties: Stripe (payments), Twilio (phone services), OpenAI (AI), Google Cloud (speech services)
14. Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you and applicable authorities as required by law. Notification will be made without unreasonable delay and within timeframes required by applicable state and federal laws.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Material changes will be communicated via email or prominent notice on our website. Continued use of Services after changes constitutes acceptance of the updated Privacy Policy.
16. Contact Us
For questions, concerns, or to exercise your privacy rights, contact us:
callins.ai
Email: [email protected]
Address: callins.ai, 651 N Broad St, Suite 201, Middletown, DE 19709
For California residents, you may also contact the California Attorney General:
Office of the Attorney General
1300 I Street
Sacramento, CA 95814
Phone: (916) 445-9555
17. Accessibility
We are committed to ensuring this Privacy Policy is accessible to individuals with disabilities. If you need this Privacy Policy in an alternative format, please contact us.