Template — legal review required

This document is a starter template generated for the DoorCall AI MVP. It is not legal advice and must be reviewed and adapted by a qualified attorney before production use.

Privacy Policy

Last updated: August 2026 (template)

1. Who we are

DoorCall AI (“we”, “us”) provides an AI receptionist and appointment-booking platform for garage-door repair companies (our “Customers”). This policy explains how we handle personal information for (a) Customers and their team members, and (b) people who call a Customer's business line answered by our service (“Callers”).

2. Information we collect

  • Account data: name, email, password hash, role, workspace membership.
  • Business configuration: services, service areas, hours, notification recipients.
  • Call data processed on behalf of Customers: caller phone number, name, service address, problem description, call transcripts, structured summaries, and — when the Customer enables it — call recordings.
  • Billing data: subscription status and plan; card details are held by our payment processor (Stripe), never by us.
  • Technical data: logs, correlation identifiers, and security events.

3. How we use information

  • To answer, transcribe, summarize, and route calls for the Customer.
  • To book appointments and send transactional notifications (email/SMS).
  • To operate, secure, and improve the service.
  • To bill subscriptions and enforce plan limits.

We do not sell personal information and do not use Caller data for advertising. Transactional SMS includes opt-out handling; we do not send marketing messages disguised as transactional updates.

4. Call recording and AI disclosure

The receptionist always discloses that it is an AI assistant. Call recording is controlled by each Customer and, when enabled, a recording disclosure is stated on the call. Recording-consent laws vary by jurisdiction; each Customer is responsible for obtaining legal advice for the jurisdictions where it operates.

5. Sharing

  • With processors that power the service: hosting, database (Supabase), voice (e.g., Vapi), telephony/SMS (e.g., Twilio), email (Resend), payments (Stripe), calendar (Google) — each bound by contract.
  • With the Customer whose line was called: Callers' information belongs to that business relationship.
  • When required by law or to protect safety.

6. Retention and deletion

Call data is retained according to the Customer's retention configuration. Customers can export their workspace data and request deletion; deletion requests are honored after a 30-day recovery window.

7. Security

We use tenant isolation with row-level security, encrypted integration tokens, signed access to recordings, and audit logging. No method of transmission or storage is 100% secure.

8. Your rights

Depending on your state (e.g., California residents under the CCPA/CPRA), you may have rights to access, correct, delete, or port personal information. Callers should direct requests to the business they called; we support our Customers in fulfilling them.

9. Contact

privacy@doorcall.example