Privacy Policy
Effective Date: May 30, 2026
Handled Calls LLC ("Handled Calls," "we," "us," or "our") provides call answering, AI receptionist, voicemail, transcription, SMS, booking, payment, review, dashboard, billing, support, and related business operations tools for service businesses. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit our website, create an account, use the Handled Calls service, contact us, call or message a business that uses Handled Calls, or otherwise interact with our services.
This policy applies to business owners, employees, contractors, team members, website visitors, account administrators, support contacts, callers, leads, job customers, payment recipients, review respondents, and other people whose information is processed through Handled Calls.
Handled Calls is primarily a business-to-business service. For end-customer, caller, job, message, and call data that we process on behalf of a business customer, the business customer is generally the controller, business, or similar party, and Handled Calls is generally the processor, service provider, contractor, or similar party. For account, billing, security, support, website, legal, compliance, and operational data, Handled Calls may act as an independent controller or business.
The Data Processing Addendum in our Terms and Conditions applies when we process Customer Personal Data on behalf of a business customer.
1. Personal Information We Collect
We collect personal information in the categories below. Not every category applies to every person or account.
Account And Business Information
We may collect business names, owner names, team member names, email addresses, phone numbers, passwords or authentication credentials, roles, permissions, account settings, billing settings, service areas, business hours, business type, service descriptions, AI instructions, greeting text, notification preferences, review links, support communications, and related business configuration.
Caller, Customer, And Job Information
When a business uses Handled Calls, we may process caller and customer information such as names, phone numbers, caller ID, job addresses, service requests, urgency, appointment dates and times, job notes, payment amounts, review status, follow-up notes, and other details provided during calls, voicemails, bookings, support interactions, payment flows, review flows, or dashboard entry.
Calls, Voicemails, Audio, Transcripts, And Follow-Up Records
Depending on business settings and provider configuration, we may collect or process voicemail audio, live AI call audio, call recordings, call metadata, voicemail transcripts, live call transcripts, AI summaries, suggested responses, follow-up notes, review responses, and payment-link metadata. Customer texts that your team drafts, sends, or replies to outside Handled Calls are your responsibility and may not be visible in the dashboard.
Calls and voicemails handled through Handled Calls may be recorded, transcribed, summarized, analyzed, and stored. We may process this information through providers such as Twilio, Retell AI, OpenAI, Anthropic, Railway, and other providers described below.
Billing And Payment Information
We use Stripe for subscription billing, invoices, payment method handling, billing portal features, and job payment checkout. We may receive and store Stripe customer IDs, subscription IDs, payment status, invoice status, payment amounts, usage records, billing email, billing name, customer phone metadata for payment links, and related payment metadata. We do not collect or store full card numbers, CVV codes, or bank account credentials.
Website, Device, Usage, And Diagnostic Information
We may collect IP address, browser type, device information, pages viewed, referring pages, request logs, approximate location derived from IP address, session events, feature usage, performance metrics, error logs, stack traces, security events, authentication events, and other diagnostic information. We use this data to operate, secure, maintain, troubleshoot, and improve the service.
Location And Address Information
We do not collect GPS location from a mobile device. We may process business addresses, customer job-site addresses, service-area addresses, and provider-derived geocoding or address validation data when you or a caller provide an address. If enabled, we may use Google Maps Platform or a similar provider to validate, display, geocode, or check service-area coverage for addresses.
Cookies And Similar Technologies
Our website and app may use cookies, local storage, session storage, pixels, or similar technologies to keep users signed in, remember preferences, secure sessions, measure basic usage, understand referral sources, troubleshoot issues, and improve the service. You may control cookies through your browser settings, but some features may not work properly if cookies or storage are disabled.
Sensitive Or Regulated Information
The service is not designed to collect protected health information, full payment card numbers, CVV codes, bank account credentials, government ID numbers, children's information, biometric identifiers, precise GPS location, or other highly sensitive or regulated information. Business customers and callers should avoid providing that type of information through calls, notes, prompts, or dashboard fields unless Handled Calls has signed a separate written agreement covering the use case.
2. Sources Of Personal Information
We collect personal information from:
- you, when you create an account, configure settings, use the dashboard, connect tools, start a trial, pay for the service, or contact support;
- your team members, when you invite or authorize them;
- callers and customers, when they call, leave voicemails, book appointments, provide addresses, pay through payment links, provide review-related feedback, leave reviews, or otherwise interact with a business using Handled Calls;
- service providers and subprocessors, such as Twilio, Retell AI, Vapi, Stripe, OpenAI, Anthropic, Railway, Sentry, Honeycomb, Google Maps Platform, and email providers;
- logs, diagnostics, fraud prevention, security, and observability systems; and
- publicly available or business-provided sources, such as business websites, review links, contact details, or service descriptions configured in the service.
3. How We Use Personal Information
We use personal information to:
- provide, operate, secure, monitor, and support Handled Calls;
- answer, route, record, transcribe, summarize, and analyze calls and voicemails;
- operate AI receptionist, voicemail, booking, scheduling, review, payment-link, customer-management, billing, and dashboard features;
- generate AI summaries, suggested actions, lead details, urgency classifications, spam classifications, service-area checks, and owner follow-up suggestions;
- create and maintain customer, job, call, booking, payment, follow-up, review, audit, and support records;
- send service-related communications, including account alerts, billing notices, and support messages;
- support compliance, suppression, and opt-out controls where a limited operational messaging configuration is enabled;
- process subscriptions, usage, invoices, payments, refunds, taxes, and billing support;
- authenticate users and protect accounts;
- detect spam, abuse, fraud, security issues, provider failures, carrier issues, and errors;
- troubleshoot and improve reliability, performance, deliverability, product quality, and support;
- comply with legal, regulatory, carrier, tax, accounting, security, privacy, and compliance obligations; and
- enforce our Terms and other policies.
4. Customer Messaging Privacy And Consent
Handled Calls is not currently a customer messaging platform for owner-authored customer texts. Business customers are responsible for drafting, sending, replying to, and keeping any required consent records for customer messages they send outside Handled Calls.
If a limited operational messaging configuration is enabled for an account, we may process message-related metadata, consent records, opt-out records, and provider records as needed to operate that configuration, honor opt-outs, prevent abuse, maintain sender reputation, and support compliance.
We do not sell, rent, or share mobile opt-in information or messaging consent data with third parties for their marketing or promotional purposes.
5. AI Processing And Model Training
Handled Calls uses AI providers to provide transcription, call handling, summaries, lead analysis, suggested responses, booking assistance, spam detection, service-area checks, and related features. Providers may include OpenAI for audio transcription, Anthropic for language analysis, and Retell AI, Vapi, or similar voice AI providers for live AI receptionist calls.
We do not permit our providers to use Customer Data to train public or general-purpose AI models where our provider plan or agreement gives us that control. We may use de-identified or aggregated operational metrics to improve service reliability, quality, security, performance, and product usage.
AI systems may generate inaccurate or incomplete results. Business users are responsible for reviewing and correcting AI-generated records, suggestions, and decisions.
6. How We Disclose Personal Information
We may disclose personal information as described below.
Service Providers And Subprocessors
We share personal information with service providers and subprocessors that help us operate Handled Calls. These providers process information on our behalf and for the purposes described in this policy.
Current or expected providers may include the following:
Twilio Purpose: Voice calls, voicemail recording, SMS, phone routing, phone numbers, and related communications infrastructure. Data categories: Phone numbers, call metadata, voicemail audio, call recordings, SMS content, and delivery metadata.
Retell AI Purpose: Live AI receptionist calls when enabled. Data categories: Call audio, live transcripts, caller details, and business instructions.
Vapi Purpose: Alternate voice AI provider if enabled. Data categories: Similar voice AI call data when used.
OpenAI Purpose: Audio transcription through Whisper or similar API services. Data categories: Voicemail or call audio for transcription.
Anthropic Purpose: Language analysis, summaries, lead extraction, suggested actions, and related AI-assisted workflows. Data categories: Transcripts, SMS content, job details, customer details, and business context.
Stripe Purpose: Subscription billing, invoices, payment method handling, billing portal, and job payment checkout. Data categories: Billing owner data, customer/payment metadata, invoice metadata, subscription status, and payment status.
Railway Purpose: Application hosting, database, deployment, storage, and infrastructure. Data categories: Hosted application data and Customer Data.
Sentry Purpose: Error monitoring and diagnostics when enabled. Data categories: Error context, user/account identifiers, request metadata, and stack traces.
Honeycomb/OpenTelemetry Purpose: Observability, tracing, reliability diagnostics, and performance monitoring when enabled. Data categories: Request/trace metadata, hashed identifiers, tenant context, and operational telemetry.
Google Maps Platform Purpose: Address validation, geocoding, maps, service-area checks, and related location features when enabled. Data categories: Business and customer address data.
Google Firebase Purpose: Mobile push registration and notification delivery when enabled. Data categories: Account-linked device registration token and notification content.
Postmark Purpose: Account, security, billing, and support email when enabled. Data categories: User email address and message metadata.
We may add, replace, or remove providers as our service evolves. We use commercially reasonable safeguards and contractual protections for providers that process personal information on our behalf.
Business Account Users
Information processed for a business account may be visible to the account's owners, admins, employees, contractors, and authorized users according to the account's role and permission settings. This may include caller information, transcripts, recordings, customer records, job records, payment status, review status, messages, and audit history.
Business Customers And Their Customers
If you call, message, book with, pay, or otherwise interact with a business that uses Handled Calls, we may disclose your information to that business and its authorized users so the business can respond, provide service, schedule work, request payment, request feedback, or manage its customer relationship.
Legal, Safety, Carrier, And Compliance
We may disclose information if we believe doing so is reasonably necessary to comply with law, legal process, carrier or messaging compliance requirements, provider requirements, tax obligations, security investigations, fraud prevention, abuse prevention, or to protect the rights, safety, and property of Handled Calls, customers, callers, users, service providers, carriers, or others.
Business Transfers
If Handled Calls is involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, personal information may be transferred as part of that transaction, subject to appropriate protections.
With Consent Or Direction
We may disclose information when you direct us to do so, configure the service to do so, or otherwise provide consent.
7. Selling, Sharing, And Advertising
Handled Calls does not sell personal information. Handled Calls does not share personal information for cross-context behavioral advertising. Handled Calls does not use caller, customer, SMS, call, voicemail, payment, or review data for third-party advertising.
We do not share mobile opt-in information or SMS consent data with third parties for their marketing or promotional purposes.
We may use de-identified or aggregated information for analytics, reliability, security, benchmarking, and service improvement. We do not attempt to re-identify de-identified information except to test whether de-identification is effective or as permitted by law.
8. Data Retention
We retain personal information for as long as reasonably needed to provide the service, operate your account, support your business, comply with legal and carrier obligations, resolve disputes, maintain security, preserve audit history, enforce suppression rules, and enforce our agreements.
Default retention practices include:
- temporary call-routing cache data: about 1 hour;
- service-area/geocoding cache data: about 30 days;
- processed webhook retry records: about 90 days;
- SMS send logs: about 180 days;
- voicemail recording pointers: about 180 days, while provider audio may follow the provider's own retention policy;
- voicemail transcript/details and SMS message bodies: about 730 days;
- review records: about 730 days;
- audit logs: about 7 years;
- SMS consent records: about 4 years;
- SMS STOP/suppression records: retained indefinitely as needed to honor opt-outs;
- customer, job, user, business setting, and billing identifier records: retained while the business account is active; and
- end-customer data for ended subscriptions: deleted or redacted about 30 days after subscription end, while retaining billing, audit, consent, suppression, security, tax, accounting, dispute, and legal records as needed.
Retention windows may be changed by configuration, law, provider limits, business requirements, security needs, support needs, or operational needs. We may retain certain information longer where required or permitted by law, including billing, tax, audit, security, fraud prevention, dispute, suppression, and compliance records. We may delete, redact, de-identify, or archive data earlier where appropriate.
9. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These may include HTTPS and HSTS in public environments, provider-managed encryption, role-based access controls, multi-factor authentication options, webhook signature validation, audit logs for transcript access and administrative actions, secrets management, data redaction, suppression lists, error monitoring, backup and restore processes, and restricted administrative access.
No method of transmission or storage is completely secure. We cannot guarantee absolute security. Business customers are responsible for configuring their accounts safely, managing access, securing devices, and notifying us promptly of suspected unauthorized access.
10. Your Choices And Rights
Depending on your location and relationship with Handled Calls, you may have rights to access, correct, export, delete, restrict, object to, or opt out of certain processing of personal information.
Business account admins may access export and deletion tools in the dashboard where available. If you cannot sign in or prefer to submit the request outside the app, use our account and data deletion page. It explains how to submit a request, what the request covers, and what information may need to be retained. We normally complete verified deletion requests within 30 calendar days and will explain if a legal or operational exception requires more time.
End customers, callers, or SMS recipients may contact the business they called, messaged, booked with, paid, or otherwise interacted with to exercise rights related to that business's records. You may also contact Handled Calls, and we will route or handle the request as appropriate based on our role and legal obligations.
SMS recipients may opt out of Handled Calls customer SMS by replying STOP or a similar supported keyword. They may reply START to opt back in where supported.
You may unsubscribe from non-essential emails where an unsubscribe mechanism is provided. We may still send transactional, security, billing, support, and service-related communications.
11. State Privacy Notices
Residents of certain U.S. states may have additional privacy rights under state privacy laws, including rights to know, access, correct, delete, port, opt out of sale or sharing, and limit certain uses of sensitive personal information.
Handled Calls does not sell personal information or share personal information for cross-context behavioral advertising. We process sensitive information only as needed to provide and secure the service, comply with law, honor customer instructions, and support the business customer.
Categories of personal information we may collect include:
- identifiers, such as name, email address, phone number, account ID, customer ID, caller ID, and business contact details;
- commercial information, such as subscription status, payment metadata, service requests, job details, review status, and transaction records;
- internet or electronic activity information, such as device data, browser data, pages viewed, feature usage, logs, and diagnostics;
- audio, electronic, or similar information, such as voicemail audio, call recordings, transcripts, SMS content, and customer communications;
- geolocation-related information, such as business addresses, job-site addresses, service-area information, geocoding data, and approximate location derived from IP address;
- professional or employment-related information, such as business role, company name, team membership, and account permissions;
- inferences and AI-generated information, such as call summaries, urgency classifications, suggested actions, spam classifications, and service-area outputs; and
- sensitive personal information, only where incidentally included in calls, messages, addresses, account security data, or other records and only as needed to provide and secure the service.
To exercise privacy rights, contact us at hello@handledcalls.com or use our account and data deletion page. We may need to verify your identity and, for end-customer records, may need to coordinate with the business customer that controls the relevant account.
12. Data Processing Addendum
The Data Processing Addendum in our Terms and Conditions applies when Handled Calls processes Customer Personal Data on behalf of a business customer as a processor, service provider, contractor, or similar role. The DPA describes processing details, customer instructions, confidentiality, subprocessors, security measures, Security Incident notice, Data Subject request assistance, return/deletion, service-provider restrictions, and international transfer terms.
If you need a separately signed DPA, vendor review, or security questionnaire, contact hello@handledcalls.com.
13. Children's Privacy
Handled Calls is not directed to children under 13 and is intended for business use. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us and we will take appropriate steps.
14. International Users
Handled Calls is operated in the United States. If you access or use the service from outside the United States, you understand that your information may be processed and stored in the United States or other locations where our service providers operate.
If applicable Data Protection Laws require a transfer mechanism for Customer Personal Data, the DPA in our Terms describes how we address those transfer requirements.
15. Changes To This Policy
We may update this Privacy Policy from time to time. The updated version will be posted with a new effective date. If changes are material, we may provide additional notice through the website, dashboard, email, or other reasonable means. Your continued use of the service after an updated policy takes effect means the updated policy applies to your use of the service.
16. Contact
Questions or requests about this Privacy Policy may be sent to:
Handled Calls LLC
901 Farnam Street, Apt 360
Omaha, NE 68102
Email: hello@handledcalls.com
Phone: 712-308-6719