Privacy policy
Callahand Digital answers the phone for small service businesses after hours. Doing that means handling two kinds of information: what a business tells us about itself, and what a caller tells the receptionist.
This policy explains what we do with both, in plain language. It describes how the product works today rather than how we might like it to work — where something is not settled yet, it says so.
1. Privacy at Callahand
We built this service around a simple idea: the receptionist should collect what it needs to be useful to the business and its caller, and not much else. That shows up in concrete ways throughout this document — our own application does not store a recording or a full transcript of a call, what a caller says is not written down by us after the call, and the information sent to an outside language-model service is deliberately narrow. Section 4 explains what the companies that carry the call may do, which is a separate question.
Callahand Digital is the company behind the service and is responsible for the platform described here. We are a small Canadian company serving our first customers, and this is our first published privacy policy.
2. Who this policy applies to
Two groups of people, with different relationships to us:
- Businesses that use Callahand — the owner and any colleagues they invite. You hold an account with us and you decide how your receptionist is configured.
- People who call those businesses — you did not sign up for anything. You rang a plumber, an electrician or a similar business, and our receptionist answered. We handle your information on that business’s behalf and in order to do what you asked for.
If you are a caller and you want information about a call corrected or removed, the business you rang is the right first contact, because the record belongs to them. You can also write to us at support@callahanddigital.com and we will help.
3. Information we process
From a business using Callahand: account and sign-in details for the people you invite, your business name and contact details, the services you offer and what they cost, your hours and service area, your emergency rules, your appointment settings, where notifications should go, which calendar you have connected, and information about your plan and usage.
From a caller: the number you rang from, what you say you need, where the work is, when you would like it done, and whatever else you volunteer so the business can help you. We also keep a record of the call itself — when it started and ended, which receptionist configuration answered, what was offered, what was booked, and whether something still needs a person.
Not everything is stored. Callahand’s application does not intentionally store a full live-call transcript or recording as part of the V1 voice path. Within Callahand’s own live processing path, caller speech is held transiently for the active call and is not written to Callahand’s transcript storage. What remains afterwards is the structured outcome described above.
That is a statement about our own systems, not about everyone’s. Voice infrastructure providers may record, transcribe, or retain call data according to the configuration of the service and their applicable terms — see section 7 for who those providers are.
4. How the AI receptionist processes calls
The receptionist says it is an AI at the start of every call. That is built into the product rather than being a setting, and it cannot be quietly switched off.
A call reaches us through a telephone number and voice infrastructure operated by other companies. Those companies handle the call itself and the technical information needed to route and connect it. Certain voice and call metadata may be processed by our voice infrastructure providers according to our configuration and their applicable terms.
To work out what a caller means, the platform sends a deliberately small amount of information to an external language-model provider, once per turn:
- the single most recent thing the caller said;
- a one-word category for the question the receptionist just asked;
- the services the business currently offers, so a choice can be matched;
- the appointment times just read out, as opaque identifiers and the words used to say them;
- whether a selection was already pending.
What is not sent matters as much: no accumulating transcript, no business or account identifier, no caller phone number, no address, no email address, no appointment records and no credential. The model is asked to pick among options the platform supplies, and an answer outside those options is discarded.
The model does not decide anything on its own. Availability, whether a time is still free, and whether an appointment is actually made are determined by the platform and by your calendar, not by the model. Our application does not store the information it sends or the answer it receives. The external provider may process what it receives under its own infrastructure and privacy terms.
Safety. The receptionist checks what a caller says for signs of an emergency — a gas smell, smoke, flooding and similar hazards your business configures. When one is detected, ordinary intake stops and the caller is given the safety instructions the business has set. This is fixed logic rather than something the model decides, and once raised it is not withdrawn during the call. Callahand does not contact emergency services and is not an emergency, medical or dispatch service. In an emergency, a caller should hang up and dial the appropriate emergency number.
5. Appointments and connected services
When a business connects Google Calendar — currently the calendar service the platform supports — it authorises Callahand to check when the chosen calendar is busy and to create appointments on it. We use that connection for those purposes and nothing else, and we do not use it to read anything else in a Google account.
The credentials that connection produces are encrypted before they are stored, are never shown in a browser and are never written to a log. A business can disconnect its calendar at any time from the calendar screen in the app, which stops us using the connection. Additional integrations may be introduced as they become available.
An appointment record we create — the time, the service, the caller’s details needed to carry out the job, and the identifier the calendar gave it — is kept so the business has a reliable record and so we can tell whether a booking succeeded.
6. How we use information
We use what we hold to:
- answer calls and run the receptionist;
- understand what a caller is asking for;
- work out when a business is available;
- create appointments and confirm whether they were made;
- tell the business what happened on a call;
- maintain accounts and let the right people sign in;
- keep a record of administrative and security-relevant actions;
- detect and prevent abuse and security incidents;
- measure usage for billing;
- provide support when you ask for it;
- meet legal obligations that apply to us.
Callahand does not sell personal information. We do not use it for advertising, we do not build profiles for marketing, and we do not share it with anyone for those purposes.
Training. Callahand does not use call content, caller information or business information to train models of its own, and we have not approved customer or caller information being used for unrelated model improvement. We cannot speak for what an external provider does inside its own systems: providers we use handle information according to the terms and settings that apply to our account with them.
7. Service providers and international processing
Running this service means using other companies. Service providers we use may include:
- Telephony and voice infrastructure — a telephone number and SIP routing provider (Telnyx), and a voice platform (Retell) that handles the audio of a call, turn-taking, and the events that tell us a call has started or ended.
- Language-model processing — an external provider (OpenAI) that receives the narrow context described in section 4 and returns a structured answer.
- Calendar — Google, when a business connects Google Calendar.
- Database and hosting — Supabase for the managed PostgreSQL database, Vercel for the web application, and Fly.io for the service that holds a call connection open.
- Transactional email — Callahand may use an email delivery provider (Zedmail) for messages such as address verification, operational notices and call summaries to a business. We do not send marketing email.
- Payments — Callahand may use a payment processor (Stripe) to take subscription payments from a business and to issue its receipts and invoices. It receives the business name and a billing contact address, and it holds the card details directly; card numbers do not reach Callahand and are not stored in our systems. It receives nothing about your callers or your calls.
These providers process information in order to perform those functions for us. We do not publish a definitive list of their own sub-processors or of how long each one keeps what it receives; those are matters for their terms, and we would rather point you to them than summarise them inaccurately.
Where processing happens. Callahand uses cloud providers that may process or store information in Canada and in other jurisdictions. When information is processed in another jurisdiction, it may be subject to the laws of that jurisdiction. If you need specifics for a particular provider before going live, ask us and we will tell you what we know in writing.
The public website sets no cookies. The signed-in application uses a small number, and each one exists to make signing in work:
- a session cookie, so you stay signed in;
- a cookie recording which business you are currently working in, when your account has more than one;
- a short-lived cookie used while connecting a calendar, which is cleared as soon as the connection finishes or fails.
Callahand does not use advertising trackers, marketing pixels or third-party analytics. There are no third-party scripts on this site.
9. How long information is kept
We keep information only as long as it is reasonably needed for the purposes in this policy, and for operational, security, contractual and legal reasons. How long that is depends on the type of information: a record of a call and its outcome is useful to a business for a while afterwards; the record of who changed a setting is useful for longer; things we never store are not a question at all.
Records that expire carry their own expiry and the reason they were kept, written when the record is created rather than decided later. We are still finalising the schedule on which expired records are removed, and we would rather tell you that than publish a retention period we are not yet enforcing automatically. If you need a specific commitment for your business, ask us.
Two categories are simple on our side, because there is nothing for us to keep: Callahand’s application does not intentionally store a recording or a full live-call transcript as part of the V1 voice path. How long a voice infrastructure provider keeps call data it handles is set by that service’s configuration and its own terms, not by this policy.
10. Security
The safeguards that matter most here:
- each business’s data is separated, and every read and write is authorised on the server against the account making the request — never by what a screen chooses to show;
- credentials for connected services are encrypted before storage and are bound to the business they belong to;
- administrative actions require a signed-in account with an appropriate role;
- connections to providers are made over encrypted transport, with the narrowest permissions the task needs;
- security-relevant actions — connecting a credential, publishing a configuration, changing who has access — are recorded;
- when a provider does not confirm an action, the platform treats it as unresolved rather than assuming success, so a caller is never told something was booked when it may not have been.
No service can promise that nothing will ever go wrong, and we are not going to. Callahand holds no security or privacy certification and has not completed a third-party audit; our security and privacy page describes how the platform is built in more detail, including what we do not claim.
11. Customer and caller choices
If you use Callahand: you can see and change your business configuration in the app, disconnect a connected calendar at any time, and ask us for access to, correction of, or deletion of information we hold about your account. Write to support@callahanddigital.com and a person will answer.
If you called a business: the record of your call belongs to that business, so asking them directly is usually fastest. You can also write to us and we will help you reach the right place, and we will act on requests we are able to act on.
Telling callers about the AI receptionist. We designed the service to be transparent: it identifies itself as an AI on every call, and that cannot be turned off. That is our part. Businesses using Callahand should make sure callers receive any further notices, and give any consents, required for their own use case and jurisdiction — what is required varies by province, by industry and by the kind of call, and one universal notice is not sufficient everywhere. If you are not sure what applies to you, ask your own adviser; we are happy to describe exactly how the product behaves so you can put the question properly.
Privacy inquiries: support@callahanddigital.com.
12. Children’s information
Callahand is designed for business use and is not directed to children. We do not knowingly collect information from children through our website or our accounts.
13. Changes to this policy
This policy takes effect on 18 September 2026. We will update it as the product changes — this is our first version, and the service is young.
When we change it, the revised policy and its new effective date appear on this page. If a change materially affects how we handle information belonging to a business using Callahand or to its callers, we will also tell affected businesses directly.
14. Contact us
Questions about this policy, or about anything we hold: support@callahanddigital.com. A person reads that mailbox and will answer directly.
If you need detail this page does not cover — for a client, an insurer or your own counsel — ask, and if the honest answer is “not yet”, that is the answer you will get.