Privacy Policy
Version 2026.08.09 · Effective August 9, 2026
This Privacy Policy explains how AppointmentJump (legal entity pending) (“we”) collects and uses information in connection with AppointmentJump.
1. Roles
We are the controller for account, billing, and website data. For caller audio, transcripts, and booking details processed when we answer calls for an HVAC customer, we generally act as a service provider / processor on behalf of that customer, who remains responsible for their relationship with callers.
2. Information we collect
- Account: name, email, business info, phone numbers
- Billing: handled by Stripe (we do not store full card numbers)
- Telephony: call metadata, recordings, transcripts, summaries
- Calendar: OAuth tokens and events we create via Google
- Knowledge base / website content you provide or authorize us to scrape
- Logs, device/usage data, and support messages
- SMS content to owner/on-call contacts
3. Voice and sensitive data
Calls may be recorded and transcribed. Voice audio may be treated as sensitive or biometric-adjacent under some state laws. We do not sell voiceprints. Customers must provide legally required recording notices. Do not submit PHI, government IDs, or full payment card data into knowledge bases or prompts. We do not sign HIPAA BAAs.
4. How we use information
To provide the Service (answer calls, book, escalate, bill), secure accounts, prevent fraud, support customers, and comply with law. By default we do not use customer call audio/transcripts to train third-party foundation models.
5. $1 card verification
Stripe may place a temporary $1 charge that is refunded to verify a card. Your bank may show a pending charge briefly.
6. Sharing and subprocessors
We use vendors listed on our Subprocessors page, including:
- Supabase — Database, auth, file storage
- Vercel — Application hosting
- Stripe — Payments and card verification
- Twilio — Phone numbers, voice, SMS
- Retell — Voice AI orchestration
- Cartesia — Text-to-speech voice synthesis
- Google — Google Calendar OAuth and events
We do not sell personal information. We may disclose information if required by law or to protect rights and safety.
7. Google user data
Google Calendar data is used only to provide calendar features (availability and booking) in accordance with Google API Services User Data Policy, including Limited Use requirements. We do not use Google user data for ads.
8. Retention
Default retention for recordings and transcripts is 30 days, unless a longer period is configured or legal hold applies. Analytics rollups and billing/acceptance records are kept longer as needed. After account closure we delete or anonymize data within a reasonable period except where retention is required.
9. Security
We use reasonable safeguards (including encryption in transit, access controls, and tenant isolation). No method of transmission or storage is perfectly secure.
10. Your rights
Depending on your location, you may request access, correction, deletion, or export of personal information. Contact privacy@example.com. We may verify your identity. California residents may have additional CPRA rights; we do not sell or share personal information for cross-context behavioral advertising.
11. Children
The Service is a B2B product and is not directed to children.
12. International
The Service is hosted primarily in the United States.
13. Contact
AppointmentJump (legal entity pending)
[Company mailing address pending]
privacy@example.com