Guided pilot · invitations open · phone service activated after setup and testing
← CallMinded

YOUR INFORMATION, EXPLAINED

Privacy Policy

What we collect. Why we need it.
And the choices you have.

Effective September 30, 2026 · Guided pilot · Version 2026-09-30

Limited to the current pilot

Business setup and workflow testing. Hosted calls and real payments are not active; billing testing uses Stripe sandbox.

No advertising trackers

Essential sessions and first-party campaign labels are explained below.

A person handles requests

Ask for access, correction or deletion through our privacy contact.

01

Who we are and what this covers

CallMinded is operated by 9511-3148 Quebec inc. This policy explains how we handle personal information through our website, account onboarding and hosted guided pilot.

The hosted pilot lets businesses configure a workspace and explore workflows with fictional caller information. Live phone service, call recording, real payments, Google connections, mapping and calendar or CRM connections are not activated in these hosted workspaces. Hosted billing uses Stripe test mode only. Account emails, when enabled, support email verification, password recovery and service notices. We will update the relevant notices before enabling additional processing.

This service is intended for adult business users. Please do not enter real customer lists, health information, payment card details, government identifiers, passwords for other services or API keys in pilot forms or test scenarios.

02

Information we collect

  • Website enquiries: your name, contact email, business name, category and specialty, workflow notes and any submitted plan or currency preference. A request may include the page it came from and campaign labels.
  • Onboarding drafts: the details you enter, including optional business phone, website, address, hours, timezone, language preferences and usage preferences. Saving a draft and submitting a pilot request are separate actions.
  • Customer workspaces: the email and business name supplied by the person inviting you, your account identifier, a salted password hash, email-verification and recovery records, accepted pilot-terms version, plan choice, phone setup requests, business settings, draft and active configuration versions, simulated campaign data, follow-up notes and related activity history.
  • Security and technical information: session identifiers, invitation and sign-in activity, request timing and technical connection information. Our infrastructure processes network addresses to serve requests and limit abuse; login rate-limit identifiers are hashed.
  • Test billing: a workspace-to-Stripe customer identifier, test subscription and invoice status, minute balances, purchase and usage history, and renewal consent. Payment details are entered on Stripe-hosted pages; our application does not store full card numbers.
  • Communications: information you choose to send when contacting us for support or making a privacy request.

We receive information from you, the administrator who creates your invitation, and your use of the service. We do not buy marketing lists for this pilot.

03

Why we use it

We use this information to evaluate pilot requests, prepare business configurations, provide and secure workspace access, troubleshoot problems, support users and respond to privacy requests. We may review pilot feedback and configured workflows to improve the product.

Hosted configuration data is not currently sent to AI voice providers, and training general-purpose AI models is not part of this hosted pilot. We do not sell pilot personal information or share it for cross-context behavioural advertising. Submitting a pilot request does not subscribe you to a marketing newsletter, activate phone service or authorize a charge.

Where processing relies on your consent, you may withdraw it by contacting us. We will explain any effect on the requested service and any information we must retain for another lawful reason. We will provide notice and seek any required consent before using information for a new, incompatible purpose.

04

Your account and your callers

CallMinded manages website enquiries, account access and service administration. For information a business supplies about its own customers, that business determines the purpose of the customer interaction; CallMinded processes the information to provide the configured service on that business’s behalf.

If your request concerns a business you called, contact that business first. You can also contact our privacy contact with the business name and a brief description so we can help route the request. We verify identity and authority before disclosing another person’s information.

Real caller processing needs a separately verified call setup and appropriate customer terms and notices. This policy is not consent to record a call and does not replace the business’s own obligations to its callers.

05

Providers and international processing

Our hosted pilot and its application data are on a dedicated Vultr server in New Jersey, United States. Vultr supplies hosting and server backups. Authorized CallMinded personnel administer and support the pilot, including from Canada. Network and hosting providers process the technical information needed to deliver their services.

Information processed in another country may be accessible to its courts, law enforcement or other authorities under that country’s laws. We remain responsible for our handling of personal information and review service-provider access and safeguards.

The following connections are not active in hosted client workspaces: Telnyx for telephony, OpenAI for voice processing, Geoapify for address and distance checks, Google for sign-in or Business Profile import. Before activating a connection, we will explain the information it receives and the relevant choices. A listed future connection does not mean we currently send your hosted workspace data to it.

Stripe processes test billing identifiers, subscription and invoice records, and the test payment details you enter on its hosted pages. No real payments are collected. Brevo provides transactional email delivery. When account emails are enabled, Brevo receives your recipient address and account-service message, including one-time verification or recovery links, and returns delivery information for troubleshooting. Email does not subscribe you to marketing.

We may disclose information when required by law, to respond to a valid legal request, or where permitted and necessary to protect people or the service. External websites linked from our site have their own privacy practices.

06

Voice, transcripts and recordings

The hosted configuration pilot does not receive live calls or record audio. Separately arranged voice tests require their own setup and notice before a call. Enrolling in a workspace does not enroll you in such a test.

When voice service becomes available, processing spoken audio, retaining a transcript, creating a summary and saving an audio recording will be explained separately. Turning recording off does not prevent the processing needed to understand a call or prepare its request. Recording and transcript purposes, controls, access and retention must be defined before activation.

07

How long information stays

Different records have different purposes. The current pilot uses the following retention and expiry behaviour:

Current pilot retention
InformationCurrent handling
Website pilot requests90 days. Records older than 90 days are removed when the website service starts or a new request is submitted.
Onboarding draftsExpire seven days after the setup session is created. Expired drafts are removed at service startup or when a new draft is created. Submitting a request creates a separate enquiry record.
Workspace and account recordsKept while the pilot workspace exists. There is no automatic workspace-deletion timer. Removal is handled through a verified request to our privacy contact; revoking sign-in alone does not delete the workspace.
Access and security recordsClient sessions expire after eight hours or one hour of inactivity; invitations expire after seven days. Verification and password-reset links expire after 30 minutes. Encrypted email bodies are cleared after sending or expiry; delivery status remains for support. Token expiry prevents access, but is not immediate deletion of every related record. Activity history and diagnostic records are reviewed manually for support and security needs.
Backup copiesApplication backups retain the latest 14 completed snapshots. Vultr automatic backups retain the two most recent server backups. Rotation depends on successful backup runs, so these are snapshot counts, not guaranteed numbers of days.

Deletion from an active workspace does not instantly erase older backups. Backup copies are used for recovery and are removed through rotation. If a backup is restored, deletion requests must be reapplied. We may retain specific information where required by law or necessary for a documented dispute or security investigation, and will explain applicable limits when handling a request.

08

Cookies, campaign labels and tracking

We use first-party browser storage for the following purposes:

  • Onboarding: an essential cookie lets you resume a setup draft in the same browser for up to seven days.
  • Client sign-in: a secure, HttpOnly session cookie keeps you signed in, subject to the session limits above.
  • Campaign labels: recognized UTM labels and the entry page may be stored in browser session storage and attached to an enquiry you submit. Avoid putting personal information in campaign URLs.

No third-party advertising pixels or analytics services are enabled. Website interaction events currently remain in page memory rather than being sent to an analytics provider. We do not currently change site behaviour in response to a browser’s Do Not Track signal. No sale or advertising sharing takes place whether or not a Global Privacy Control signal is present.

You can clear this site’s browser data or block cookies in your browser; doing so may sign you out or prevent a draft from being resumed. We will update this policy and introduce any required choices before enabling advertising or analytics integrations.

09

Access and protection

We use HTTPS for public connections, salted password hashes, expiring sessions, sign-in rate limits and workspace access controls. Platform administration is separate from client access and requires additional authentication. Access is limited to people who need it to operate or support the service.

No system can guarantee absolute security. If you believe information has been exposed or an account has been misused, contact our privacy contact. We investigate reports and provide notifications where applicable law requires them.

10

Access, correction, deletion and complaints

You may contact us to ask what personal information we hold about you, request access or correction, request deletion or withdrawal of consent, or raise a complaint. Other rights, including portability or review of a decision about your request, may apply depending on your location and the circumstances.

Include the email associated with your enquiry or account, the relevant business name and the kind of request. Please do not send passwords, payment card details, API keys or identity documents in your first message. We may ask for proportionate verification before acting. A representative acting for you may need to show authorization.

We review requests manually, explain any permitted exceptions and respond within the period required by applicable law. You may also complain to the privacy regulator with jurisdiction, including the Commission d’accès à l’information du Québec or the Office of the Privacy Commissioner of Canada, as applicable.

11

Contact and policy updates

PRIVACY CONTACT

Privacy Officer

9511-3148 Quebec inc. · CallMinded

privacy@callminded.com

We will post changes on this page with an updated date. For significant changes, we will provide an additional notice in the service or directly where appropriate, and obtain consent when required. This policy describes privacy practices; subscription terms and any future data-processing agreement are separate documents.

Back to top ↑