Legal
Privacy Policy
Last updated: July 5, 2026
Overview
This Privacy Policy explains how CrewAnswer handles personal information in connection with our AI phone-receptionist service. It works alongside our Terms of Service and, for business customers, our Data Processing Addendum.
1. Your role and ours
When your callers reach your business through CrewAnswer, the personal information in those calls — recordings, transcripts, summaries, and caller contact details — belongs to your organization's relationship with those callers. You are the party responsible (the controller) for that caller information: you decide what is collected and why, and you are responsible for giving callers any notice and obtaining any consent the law requires. CrewAnswer acts as your service provider (processor), handling that information to operate the service on your instructions, as described in our Data Processing Addendum. We give you tools to help — including a default recording disclosure in the greeting — but the choice of scripts, notices, and consent practices is yours.
For information about your own account — your organization's settings, your users, and your billing — CrewAnswer acts on its own behalf as the party responsible.
2. What we collect
the fields needed to read cached business information or send the REST actions you approve.
- Account and organization data: your organization's name and settings, your users' names and email addresses, phone numbers, and your configuration and workflow records.
- Call data: call audio recordings, transcripts, summaries, caller phone numbers and contact details, routing and disposition choices, and call metadata (times, duration, and outcomes).
- Billing data: plan and subscription details, billing metadata, and, to operate billing and to prevent and defend against fraud and payment disputes, the purchase IP address and billing address associated with a transaction. Card numbers are handled by our authorized payment processor; we do not store full card numbers.
- Support and product-usage data: support messages, and product usage and diagnostic logs needed to operate, secure, and improve the service.
- Business API data: if you configure Read URLs or Write URLs, we process
3. How we use data
We use personal information to:
We do not sell personal information, and we do not use it for third-party advertising. We send you transactional messages (such as receipts, renewal reminders, and service notices); we send marketing only with the consent the law requires, and you can opt out of marketing at any time.
- answer calls, run the scripts you approve, route urgent calls, and create summaries and transcripts;
- provide onboarding, support, billing, and tax handling, and to prevent and investigate abuse, fraud, and security incidents;
- operate, monitor, secure, maintain, and improve the service, including service reliability and diagnostics;
- maintain audit trails for account administration, incident response, deletion requests, and legal obligations; and
- establish, exercise, or defend legal or financial claims, including billing disputes and card chargebacks (see Section 7).
4. Recording, AI processing, and consent
CrewAnswer records calls and uses automated call-handling and transcription technologies to answer, transcribe, and summarize them. The default greeting discloses that the call may be recorded. A recording can capture a person's voice (which can be sensitive or biometric information in some jurisdictions) and may capture people other than the intended caller, so you are responsible for giving callers appropriate notice and obtaining any consent the law requires for your callers and their location, including all-party-consent requirements where they apply (see the Terms of Service). CrewAnswer records and transcribes call audio; it does not create voiceprints and does not use voice for biometric identification. We do not use your callers' recordings or transcripts to train general AI models. Our subprocessors and their data-handling terms are described at our subprocessors page.
5. Where data is stored and how it moves
CrewAnswer makes no Canadian data-location promise. Because data is stored and processed in the United States, it may be subject to access by United States courts, law enforcement, or national-security authorities under US law. We apply protections intended to keep the level of protection comparable to what applicable law requires — including the encryption and access controls described in Section 9 and the subprocessor obligations in our Data Processing Addendum — but we do not promise where data is located. Our current subprocessors are listed at our subprocessors page.
- Core service data: transcripts, summaries, caller contact details, account settings, and workflow records are processed on infrastructure in the United States.
- Recordings and statements: call recordings, call media, and billing statement files are stored with infrastructure and storage providers under United States jurisdiction.
- Backups, logs, secrets, and keys: backups, operational logs, secrets, and encryption-key material are stored or managed by infrastructure providers in United States regions.
- Call media in transit: while a call is answered and processed, call media may transit telephony, communications, and automated-processing providers in the United States.
6. How long we keep data
We keep personal information on two clocks:
Caller content (Tier 1). Recordings are kept for the retention period you configure — 30, 90, or 365 days, with a default of 90 days — except that charge-linked call recordings and transcripts are kept for at least 150 days from the call so we can establish, exercise, or defend against card chargebacks. Transcripts are otherwise kept for up to 24 months unless you request earlier deletion or a legal hold requires otherwise; contact us if you would like a shorter transcript-retention period for your organization. Operational logs are kept for no more than 30 days. If a card dispute is actually open, we may keep the disputed charge's recording, transcript, and usage row until the dispute closes plus a 30-day buffer, solely to establish, exercise, or defend the claim. Unrelated caller content and non-charge-linked caller content remain on the normal deletion clock.
Billing, consent, and dispute-evidence records (Tier 2). A limited set of records — billing statements, subscription and payment records, usage and call metadata (such as call counts, times, and durations), and your recorded acceptance of these terms — is kept as long as we need it for tax, accounting, and to establish, exercise, or defend billing, chargeback, or other legal claims, including after your account closes. This is the information we would use to show that a charge was authorized and the service was used. We keep only what we need, for only as long as we need it.
Deletion. After a valid deletion request and any grace window, we remove active records and destroy the tenant encryption key, so live data is unrecoverable without a live key grant, and backup-only copies age out as backup segments (about 72 hours) and snapshots (about 30 days) expire. We may retain the limited Tier 2 records above and the minimum Tier 1 charge-linked caller content needed for legal defense: undisputed charge-linked calls only until the 150-day chargeback floor expires, and disputed-charge evidence only until the dispute closes plus the 30-day buffer. We record that we did so, defer crypto-shredding only while retained Tier 1 content still needs the tenant key, and delete the retained evidence when it is no longer needed.
7. Payment disputes and representment disclosures
If a card charge is disputed, we may disclose to our payment processor and the relevant card networks, issuing bank, and dispute reviewers the minimum information needed to establish that the charge was authorized and the service was delivered — such as billing records, recorded terms acceptance, account-holder purchase IP address, billing email, statement files, and account-level usage metadata. We limit this to the disputed period and to what is needed to defend the claim.
Caller conversations are not routine representment evidence. If a dispute genuinely requires caller transcript excerpts, caller recording excerpts, caller contact metadata, IP-address-derived records, or similar third-party caller personal information, the disclosure must be minimized to the disputed period, redacted where possible, documented, and approved by counsel or the legal owner before submission. The lawful-basis note is that the disclosure is tied to establishing, exercising, or defending a legal or financial claim; it is separate from the retention carve-out and does not create permission to disclose unrelated caller content.
Because representment may involve cross-border disclosure of caller personal information to a payment processor, card network, issuing bank, or reviewer outside Canada, the Canadian PIPEDA/Law 25 analysis and counsel sign-off must be completed before publishing or operationalizing that disclosure path.
8. Your choices and rights
Organization owners can request access to, correction of, export of, or deletion of account and caller records by contacting [email protected]. We verify the requester, scope the request to the organization and records involved, and confirm completion or any required exception. Because you are responsible for your callers' personal information, we coordinate any request we receive directly from one of your callers with your organization, and we help you respond. Depending on where you or your callers are located, applicable law — which may include Canada's PIPEDA, provincial privacy laws such as British Columbia's Personal Information Protection Act (PIPA) or Québec's Law 25, or United States state privacy laws — may give rights of access, correction, portability, deletion, or complaint, and may give residents of some regions additional rights. We are continuing to build out our Québec Law 25 program, and some Québec-specific features remain in progress. You can opt out of marketing messages at any time.
9. Security
Privileged fields use application-layer encryption with per-tenant data-encryption keys. Recordings are encrypted; tenant deletion uses cryptographic erasure of the tenant key where applicable; data access is logged to an audit trail; and we maintain emergency controls intended to limit access during a security event. These are descriptions of the mechanisms we use, not a certification claim. No method of transmission or storage is completely secure, and no method is 100% secure. If a breach of security safeguards affecting personal information occurs, we will notify affected customers and any authorities as required by applicable law.
10. Subprocessors
CrewAnswer uses subprocessors for telephony, automated call handling, storage, authentication, billing, email, compute, backups, logs, secrets, and key management. The current categories of subprocessors are published at our subprocessors page. We update that page when a material subprocessor changes; customers with contractual notice rights should use their agreement's notice process.
11. Changes to this policy
CrewAnswer may review and update this Privacy Policy, the Terms of Service, and any applicable Data Processing Addendum at its discretion. The latest versions are always available at Terms of Service, Privacy Policy, and Data Processing Addendum, or by contacting [email protected] or [email protected]. When we make a material change, we will post the updated policy with a new effective date and, where appropriate, notify you.
12. How to reach us
Questions, requests, or complaints about privacy can be directed to our Privacy Officer at [email protected]. If you are not satisfied with our response, you may have the right to complain to your privacy regulator — for example, in Canada, the Office of the Privacy Commissioner of Canada or your provincial privacy commissioner (such as British Columbia's Office of the Information and Privacy Commissioner); in Québec, the Commission d'accès à l'information; or, in the United States, your state authority.
Mad Llama Studio Ltd. (operating CrewAnswer) · Attn: Privacy Officer · Suite 1500, 701 West Georgia Street, Vancouver, BC, Canada · [email protected]