Privacy Policy

Our role. For our customers' account information, we act as a controller. For the personal information of End Users that flows through the AI agent on a customer's behalf (call/chat content, contact details, appointment info), we generally act as a service provider/processor — we process it under the customer's instructions to provide the Service. Our customers are responsible for having a lawful basis and any required consents to collect and process End User information. See also our AI, Call Recording & Telephony Consent terms.

1. Information we collect

1.1 Account and billing

Name, business name, email, phone number, industry, sign-in identifiers, and configuration settings you provide. Payment details (card number, billing address) are collected and processed directly by Stripe; we do not store full card numbers — we retain limited billing metadata and Stripe identifiers (such as customer and subscription IDs).

1.2 Communications content processed for customers

To provide the Service, the AI agent processes inbound calls and messages, which can include call audio and/or transcripts, chat message content, caller/sender phone numbers and contact details, and the lead information, summaries, and metadata generated from those interactions. Call recording is off by default and only occurs where a customer enables it; when enabled, the customer is responsible for any required caller notice or consent.

1.3 Scheduling/calendar data

When a customer connects a calendar or booking system (Google Calendar, Microsoft Bookings, Cal.com, Acuity, Calendly), we process availability and appointment details (times, attendee name/email/phone, notes) needed to check availability and create bookings. For OAuth-based providers we store an OAuth refresh token to act on the customer's behalf; it is kept in restricted, backend-only storage.

1.4 Telephony / provisioning

When a customer provisions a phone number through us, we process the number, routing configuration, and call metadata (such as time, duration, and dialed number).

1.5 Usage, metrics, and device data

Interaction counts, call/chat metrics, feature usage, log data, IP address, and browser/device information, and cookies or similar technologies used to operate and secure the Service.

1.6 Support

Information you provide when you contact support or submit a bug/issue report, including any description or transcript you include.

2. How we use information

We use information to provide, operate, secure, and maintain the Service; authenticate users; process payments, subscriptions, renewals, add-ons, overages, and the dedicated line; answer calls/messages and capture leads on the customer's behalf; check availability and create appointments on connected calendars; generate transcripts, summaries, and metrics; provide support; detect and prevent fraud, abuse, and security issues; comply with legal obligations; and communicate with customers about their account and the Service.

We do not use customer or End User call/chat content to train general-purpose or third-party AI models. Any use to improve the Service is limited to de-identified or aggregated data.

3. How we share information

We do not sell personal information. We share information with: sub-processors and service providers that help us run the Service (Section 4), under contracts that limit their use; the customer, for End User information generated through that customer's agent (the core purpose of the Service); third parties you authorize (such as your connected calendar, CRM, or telephony); legal and safety recipients where required to comply with law, respond to lawful requests, enforce our Terms, or protect rights and safety; and a successor in connection with a merger, acquisition, or sale of assets, subject to this Policy.

4. Sub-processors

Sub-processorFunction
Stripe, Inc.Payment processing, subscription billing
Netlify, Inc.Website and serverless function hosting
Voiceflow, Inc.AI conversation/agent runtime for voice and chat
Twilio Inc.Phone number provisioning, call routing/transport
Clerk, Inc.Account authentication
Make (Celonis / integrated automation)Workflow automation between systems
Google LLCGoogle Calendar integration (when connected by a customer)
Microsoft CorporationMicrosoft Bookings / Graph integration (when connected)
Other calendar/CRM providers you connectScheduling / CRM (when connected)
AI language-model providers (via Voiceflow)AI language processing

Some sub-processors may process data outside your state. We update this list as our providers change.

5. Data retention

We retain account and billing information for as long as your account is active and as needed to comply with legal, tax, and accounting obligations. We retain call/chat transcripts, metrics, and lead data for the duration of your subscription plus 90 days, unless you request earlier deletion. OAuth tokens are retained until you disconnect the integration or close your account. On account closure we delete or de-identify personal information within 90 days, subject to legal retention requirements.

6. Security

We use reasonable technical and organizational measures to protect information, including encryption in transit, access controls, and storing secrets (such as OAuth tokens and API keys) in restricted backend storage. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or port your personal information and to opt out of certain processing. Customers can access and update much of their account data in-product. End Users should generally direct requests to the business (our customer) they interacted with, since that business controls the interaction; we will assist our customers as their service provider. To make a request to us, contact legal@inboundlyai.com. We will verify requests as required by law.

8. Children's privacy

The Service is not directed to children under 13, and we do not knowingly collect their personal information.

9. Communications

We may send you service and transactional messages (such as billing, security, and changes to the Service). Any marketing messages will honor opt-out requirements.

10. Changes to this Policy

We may update this Policy. Material changes will be notified (for example, by email or in-product) before they take effect. The "Last updated" date reflects the latest version.

11. Contact

Justin Logue d/b/a InBoundly
1405 Earl L Core Rd, PMB 1090
Morgantown, WV 26505
legal@inboundlyai.com