Legal

Privacy Policy

Last updated: July 7, 2026

1. Overview

This Privacy Policy explains how ClearLine365 ("ClearLine365", "we", "us") collects, uses, discloses, and safeguards information when you use our AI receptionist service for home-services businesses (the "Service"). It covers both our business customers and the callers whose calls the Service answers on a customer's behalf.

2. Information we collect

We collect the following categories of information:

  • Account information — business name, contact name, email address, phone number, billing details, and configuration settings for your assistant.
  • Caller information — when your customers call your business, we may collect a caller's name, phone number, and service address as part of capturing a lead.
  • Call recordings — audio recordings of calls handled by the Service.
  • Transcripts — text transcriptions and structured summaries derived from call audio.
  • Connected-calendar data — if you connect a calendar (such as Google Calendar), the appointment events the Service creates and manages there. See Section 7 for how we handle Google user data.
  • Usage and device data — log data, IP address, and analytics about how the Service is accessed and used.

3. How we use information

We use information to:

  • Operate, provide, and maintain the Service, including answering and triaging calls.
  • Capture, summarize, and deliver leads and appointment details to you.
  • Send transactional text messages to account owners — lead and appointment alerts to the registered business owner who opted in inside their account. We do not send text messages to our customers' own clients or callers. Every text includes opt-out instructions: reply STOP to stop receiving messages and HELP for help. Message and data rates may apply; message frequency varies. We do not use caller information for marketing.
  • Text-messaging consent & mobile information. Consent to receive text messages is collected through an explicit opt-in setting in the account portal, and is never a condition of purchase. No mobile information will be sold or shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent are not shared with any third parties, except with service providers acting on our behalf solely to deliver the requested messages. All other categories in this policy exclude text-messaging originator opt-in data and consent from any sharing.
  • Process payments and manage subscriptions and trials.
  • Improve, troubleshoot, and secure the Service.
  • Communicate with you about your account, support, and service updates.
  • Comply with legal obligations.

We do not sell personal information.

4. Third-party subprocessors

We rely on trusted third parties to deliver the Service. These currently include:

  • Telephony provider — to place, receive, and record phone calls and send text messages.
  • Hosting & database provider — to host the application and store your data.
  • AI model provider — to power the conversational assistant, transcription, and summarization.
  • Payment processor — to handle subscription billing; we do not store full payment-card numbers ourselves.
  • Calendar and integration providers you choose to connect — such as Google Calendar, to sync appointments the Service books.

Subprocessors process data only to provide their service to us. A current list is available on request at hello@clearline365.com.

5. Call recording notice & consent

The Service records and transcribes phone calls. Recording and consent laws vary by jurisdiction, and some require the consent of one or all parties to a call. If you are a ClearLine365 customer, you are responsible for ensuring callers are properly notified and that any required consent is obtained for calls handled on your behalf. We provide a configurable call-recording disclosure played at the start of a call, but you remain responsible for lawful use in your jurisdiction.

6. Data retention

We keep data only as long as it is needed:

  • Call recordings — recording audio is automatically deleted by a daily purge job after a retention window that depends on your plan: 15 days on Basic, 30 days on Starter, 60 days on Pro, and 90 days on Team. After that window the recording is permanently removed from our systems (the transcript remains available). When a recording has been purged, the app shows that it is no longer available under our retention policy.
  • Transcripts and caller details in call records — caller personal information (name, phone number, service address) and call transcripts are automatically redacted from call records approximately 12 months after the call. Anonymized call statistics (such as call counts, durations, and outcomes) are retained for the life of the account for reporting.
  • Leads, appointments, and messages — retained for the life of your account so your business history stays available to you.
  • Processing records — raw telephony webhook payloads and internal processing ledgers are purged on a rolling basis, generally within 30 days of successful processing.
  • Account deletion — you can delete your organization at any time from your account settings (or ask us to). To protect against accidental or unauthorized deletion, the account is first suspended and then permanently destroyed after a 7-day grace period. During that window the account owner can sign back in and cancel the deletion to fully restore the account — no need to contact us. On permanent deletion we remove your organization and all of its data — calls, leads, transcripts, messages, appointments, notifications, integrations, and stored recording audio — from our systems and release the phone number assigned to your account. We may retain limited billing and accounting records where required by law.

Our telephony provider retains its own copies of call recordings and related data subject to its own retention policy. When we purge a recording under the retention windows above, and when we permanently delete an account, we also delete the corresponding provider-side recording copies.

7. Google user data

If you connect Google Calendar to the Service, we request two Google OAuth scopes:

  • https://www.googleapis.com/auth/calendar.events — lets us create, update, and cancel the calendar events for appointments booked through the Service, and read the times of your existing events to check availability (see “Availability check” below).
  • https://www.googleapis.com/auth/calendar.calendarlist.readonly — lets us list the names of your calendars so you can pick which calendar the AI books into. It does not grant access to the contents of your events.

We use these scopes as follows:

  • Booking events. Under the events scope we create, update, and cancel the calendar events for appointments booked through the Service.
  • Availability check. Before the AI offers or books a time, it reads your existing events on the target calendar to see when you are busy. It reads only each event's start and end times (plus a status/transparency flag used to skip events that are cancelled or marked “free”) — never event titles, descriptions, guests, or other contents. These busy/free times are processed transiently in memory to answer that one availability question and are not stored in our systems.
  • What we store. The only event data we retain are the IDs of the events ClearLine365 itself creates, so we can update or cancel them later. We do not store the contents or times of your other calendar events.
  • Why. Solely to book appointments the AI receptionist schedules and keep them in sync with your calendar, and to avoid double-booking times you are already busy. We do not use Google user data for advertising, and we do not sell it.
  • Token storage & sharing. Your Google OAuth tokens are stored in an encrypted secrets vault, are never exposed to the browser, and are shared with no one.
  • Disconnecting. You can disconnect Google Calendar at any time in Settings → Integrations (we then revoke the token with Google and delete it from our systems) or via your Google Account permissions page.

ClearLine365's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, or export your information, and to object to or restrict certain processing (for example under the CCPA or GDPR). Contact us at hello@clearline365.com to exercise any available rights; we will verify your request and respond within the time required by law. If you are a caller whose call was handled on behalf of one of our customers, we may refer your request to that business, which controls the purposes of that processing.

9. Security

We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit, encrypted storage of integration credentials, and per-tenant access controls that isolate each business's data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date, and for material changes we will make reasonable efforts to notify you.

11. Contact us

Questions about this policy can be sent to hello@clearline365.com.