Legal

Privacy Policy

Last updated: August 16, 2026

1. Overview

This Privacy Policy explains how ClearLine365 ("ClearLine365", "we", "us") collects, uses, discloses, and safeguards information when you use our AI receptionist service for home-services businesses (the "Service"). It covers both our business customers and the callers whose calls the Service answers on a customer's behalf.

2. Information we collect

We collect the following categories of information:

  • Account information — business name, contact name, email address, phone number, billing details, and configuration settings for your assistant.
  • Caller information — when your customers call your business, we may collect a caller's name, phone number, and service address as part of capturing a lead.
  • Call recordings — audio recordings of calls handled by the Service.
  • Transcripts — text transcriptions and structured summaries derived from call audio.
  • Connected-calendar data — if you connect a calendar (such as Google Calendar), the appointment events the Service creates and manages there. See Section 7 for how we handle Google user data.
  • Team location data — if a team member turns on location sharing, the mobile app collects the device's precise location, accuracy, and time while that member is on duty. When the member grants background access, collection can continue when the app is in the background or closed. Sharing is optional, can be turned off at any time, and is visible only to authorized members of the same business for dispatch and live-map features.
  • Booking photos — photos a signed-in team member chooses to take or select from the device photo library and attach to an appointment. We do not access photos the member does not choose for upload.
  • Notification and device identifiers — a push-notification token, device platform, and optional device name used to route account and dispatch notifications to the correct signed-in device.
  • Usage, diagnostics, and device data — log data, IP address, app or browser details, and error/diagnostic information used to operate, secure, and troubleshoot the Service.
  • Onboarding and setup measurement — when you install the ClearLine365 app, it creates a random identifier on your device. We use this identifier solely to measure how account setup and onboarding perform — for example, how long each step takes and where people get stuck — so we can make setup faster and more reliable. When you sign in, the identifier is associated with your account. It is never used for advertising, never used to track you across other companies' apps or websites, and never sold or shared with third parties. Measurement records are retained for about 13 months (400 days at most) and then deleted. If you delete your account, the identifier is retired and your measurement records are permanently disconnected from you.

3. How we use information

We use information to:

  • Operate, provide, and maintain the Service, including answering and triaging calls.
  • Capture, summarize, and deliver leads and appointment details to you.
  • Show authorized dispatchers where opted-in, on-duty team members are located so they can assign and route work. We do not use team location for advertising.
  • Store and display booking photos that team members choose to attach to jobs.
  • Deliver account, lead, appointment, and dispatch notifications to signed-in devices.
  • Send transactional text messages to account owners — lead and appointment alerts to the registered business owner who opted in inside their account. We do not send text messages to our customers' own clients or callers. Every text includes opt-out instructions: reply STOP to stop receiving messages and HELP for help. Message and data rates may apply; message frequency varies. We do not use caller information for marketing.
  • Text-messaging consent & mobile information. Consent to receive text messages is collected through an explicit opt-in setting in your account settings, and is never a condition of purchase. No mobile information will be sold or shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent are not shared with any third parties, except with service providers acting on our behalf solely to deliver the requested messages. All other categories in this policy exclude text-messaging originator opt-in data and consent from any sharing.
  • Process payments and manage subscriptions and trials.
  • Improve, troubleshoot, and secure the Service.
  • Communicate with you about your account, support, and service updates.
  • Comply with legal obligations.

We do not sell personal information.

4. Third-party subprocessors

We rely on trusted third parties to deliver the Service. These currently include:

  • Telephony provider — to place, receive, and record phone calls and send text messages.
  • Hosting & database provider — to host the application and store your data.
  • Security and abuse-prevention provider — to evaluate limited browser, device, and network signals and present a security challenge on authentication forms when needed.
  • AI model provider — to power the conversational assistant, transcription, and summarization.
  • Payment processor — to handle subscription billing; we do not store full payment-card numbers ourselves.
  • Calendar and integration providers you choose to connect — such as Google Calendar, to sync appointments the Service books.
  • Email delivery provider — to send account, lead-alert, and sign-in emails, including verification codes, to you.
  • Mobile notification provider — to route push notifications to the devices where signed-in users enable them.
  • Error-monitoring provider — to receive limited diagnostic details when the application fails or performs unexpectedly.

Subprocessors process data only to provide their service to us. A current list is available on request at hello@clearline365.com.

We also use open reference data that is stored with the Service rather than sent to anyone: ZIP-to-town data © GeoNames, licensed CC BY 4.0. It lets us correct the town on a captured address when the ZIP code makes the spelling clear.

5. Call recording notice & consent

The Service records and transcribes phone calls. Recording and consent laws vary by jurisdiction, and some require the consent of one or all parties to a call. If you are a ClearLine365 customer, you are responsible for ensuring callers are properly notified and that any required consent is obtained for calls handled on your behalf. Cara always plays a call-recording notice at the start of every call, on every plan, and it cannot be turned off. You remain responsible for lawful use in your jurisdiction.

6. Data retention

We keep data only as long as it is needed:

  • Call recordings — recording audio is automatically deleted by a daily purge job after a retention window that depends on your plan: 15 days on Basic, 30 days on Starter, and 60 days on Pro. After that window the recording is permanently removed from our systems (the transcript remains available). When a recording has been purged, the app shows that it is no longer available under our retention policy.
  • Transcripts and caller details in call records — caller personal information (name, phone number, service address) and call transcripts are automatically redacted from call records approximately 12 months after the call. Anonymized call statistics (such as call counts, durations, and outcomes) are retained for the life of the account for reporting.
  • Leads, appointments, and messages — retained for the life of your account so your business history stays available to you.
  • Team location points — precise points are deleted when a member turns sharing off and are otherwise automatically deleted after approximately 24 hours. Going off duty pauses new collection. The member can also remove the app's location permission at any time in device settings.
  • Booking photos — retained with the associated appointment until an authorized user deletes the photo or the organization is permanently deleted.
  • Push-notification tokens — retained while associated with a signed-in device, removed when the device unregisters or the provider reports that the token is no longer valid, and deleted with the user account.
  • Processing records — raw telephony webhook payloads and internal processing ledgers are purged on a rolling basis, generally within 30 days of successful processing.
  • Account deletion — you can delete your organization at any time from your account settings (or ask us to). To protect against accidental or unauthorized deletion, the account is first suspended and then permanently destroyed after a 7-day grace period. During that window the account owner can sign back in and cancel the deletion to fully restore the account — no need to contact us. On permanent deletion we remove your organization and all of its data — calls, leads, transcripts, messages, appointments, notifications, integrations, and stored recording audio — from our systems and release the phone number assigned to your account. We may retain limited billing and accounting records where required by law.
  • A single customer's data — an owner or admin can also request erasure of a single customer's data from that customer's call page; it completes after a 30-day hold and our review.

Our telephony provider retains its own copies of call recordings and related data subject to its own retention policy. When we purge a recording under the retention windows above, and when we permanently delete an account, we also delete the corresponding provider-side recording copies.

7. Google user data

If you connect Google Calendar to the Service, we request two Google OAuth scopes:

  • https://www.googleapis.com/auth/calendar.events — lets us create, update, and cancel the calendar events for appointments booked through the Service, and read the times of your existing events to check availability (see “Availability check” below).
  • https://www.googleapis.com/auth/calendar.calendarlist.readonly — lets us list the names of your calendars so you can pick which calendar the AI books into. It does not grant access to the contents of your events.

We use these scopes as follows:

  • Booking events. Under the events scope we create, update, and cancel the calendar events for appointments booked through the Service.
  • Availability check. Before the AI offers or books a time, it reads your existing events on the target calendar to see when you are busy. It reads only each event's start and end times (plus a status/transparency flag used to skip events that are cancelled or marked “free”) — never event titles, descriptions, guests, or other contents. These busy/free times are processed transiently in memory to answer that one availability question and are not stored in our systems.
  • What we store. The only event data we retain are the IDs of the events ClearLine365 itself creates, so we can update or cancel them later. We do not store the contents or times of your other calendar events.
  • Why. Solely to book appointments the AI receptionist schedules and keep them in sync with your calendar, and to avoid double-booking times you are already busy. We do not use Google user data for advertising, and we do not sell it.
  • Token storage & sharing. Your Google OAuth tokens are stored in an encrypted secrets vault, are never exposed to the browser, and are shared with no one.
  • Disconnecting. You can disconnect Google Calendar at any time in Settings → Integrations (we then revoke the token with Google and delete it from our systems) or via your Google Account permissions page.

ClearLine365's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, or export your information, and to object to or restrict certain processing (for example under the CCPA or GDPR). Contact us at hello@clearline365.com to exercise any available rights; we will verify your request and respond within the time required by law. If you are a caller whose call was handled on behalf of one of our customers, we may refer your request to that business, which controls the purposes of that processing.

9. Security

We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit, encrypted storage of integration credentials, and per-tenant access controls that isolate each business's data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date, and for material changes we will make reasonable efforts to notify you.

11. Contact us

Questions about this policy can be sent to hello@clearline365.com.