⚠ DRAFT — NOT LEGAL ADVICE. These terms were generated with AI assistance and have NOT yet been reviewed by a licensed attorney. Do not rely on them for production use without independent legal review. Contact us to receive the current signed, attorney-reviewed version before onboarding paying operators.
GREETLY PRIVACY POLICY (v2026-02-01)
BuzzerAI ("we", "us") is a software service used by hospitality operators ("Operators") to manage guest waitlists, SMS notifications, phone-based AI reception, callback requests, and public "join" pages. This Privacy Policy explains what data we collect from Operators AND their guests ("Guests"), how we use it, and the rights available under the California Consumer Privacy Act as amended by CPRA ("CCPA"), the EU / UK General Data Protection Regulation ("GDPR"), Canada's PIPEDA, and similar laws.
1. WHO IS THE DATA CONTROLLER. When BuzzerAI is used by an Operator, the Operator is the primary data controller for Guest data. BuzzerAI acts as a data processor / service provider on the Operator's behalf. Both parties share responsibility for compliance with applicable law.
2. DATA WE COLLECT FROM OPERATORS. Business name, owner name, email address, hashed password (bcrypt), industry, business address, hours, chosen add-ons, subscription and payment metadata (via Stripe — full card numbers are NOT stored on our servers), Twilio credentials if you save them, feedback submissions, terms-acceptance initials + timestamp.
3. DATA WE COLLECT FROM GUESTS. Guest name, mobile phone number (E.164), party size, notes (allergies, seating requests, etc.), waitlist visit timestamps, to-go callback requests, chat transcripts with the AI receptionist, and (when the AI Voice Receptionist add-on is active) the phone number, spoken transcript, and — in Realtime mode — the raw audio stream of the phone call routed through OpenAI's Realtime API.
4. WHY WE COLLECT IT (LAWFUL BASES).
• Perform the service (contract) — sending SMS, seating guests, taking callbacks.
• Legitimate interest — analytics, product improvement, fraud prevention.
• Consent — where required (marketing SMS, call recording in two-party-consent jurisdictions).
• Legal obligation — tax records, compliance with lawful orders.
5. AI TRAINING DATA. We use third-party AI providers (currently OpenAI) via API. Under OpenAI's API data policy (as of the version date of this policy), data submitted via the API — including chat transcripts, function-call arguments, and Realtime voice streams — IS NOT used to train OpenAI's models. We DO NOT sell Guest data. We DO NOT use Guest data to train our own AI models. If a third-party provider's policy changes, we will update this document and notify Operators.
6. CALL RECORDING & TRANSCRIPTS. When the AI Voice Receptionist add-on is active, phone audio is transmitted in real time to Twilio and to OpenAI's Realtime API for transcription and response. Full call transcripts (both guest and AI turns) are stored in our database and shown to the Operator in the Voice call log. Recording disclosure is legally required in "two-party-consent" jurisdictions (e.g., California, Florida, Illinois, Massachusetts, Pennsylvania, Washington, and most EU member states). Operators are solely responsible for including an appropriate recording notice in the AI Receptionist greeting (e.g., "This call may be recorded for quality") and for complying with all applicable consent laws. See Terms §7 and §10.
7. THIRD PARTIES WHO PROCESS DATA. We share data only with the sub-processors necessary to run the service:
• Twilio Inc. — SMS + Voice transport (Guest phone, message body, call audio).
• OpenAI, L.L.C. — LLM chat + Realtime voice (transcript, audio stream, chat text).
• Stripe, Inc. — subscription payments (Operator billing info, payment method tokens only).
• MongoDB Atlas — application database (all app data).
• Cloud hosting (Kubernetes ingress providers) — request routing.
We do not sell or rent Guest or Operator personal data to advertisers, data brokers, or any other third party.
8. INTERNATIONAL TRANSFERS. Our servers and sub-processors may operate in the United States and other countries. Where required (EU/UK), we rely on the European Commission's Standard Contractual Clauses and equivalent instruments for cross-border transfers.
9. DATA RETENTION. Guest data is retained for as long as the Operator maintains an active BuzzerAI account plus a default retention window of thirty-six (36) months, unless the Operator or a Guest requests earlier deletion. Payment records are retained for seven (7) years to comply with tax law. Call recordings are retained for ninety (90) days unless the Operator changes the setting.
10. GUEST & OPERATOR RIGHTS (CCPA / CPRA / GDPR / PIPEDA).
You have the right to:
(a) know what personal data we hold about you;
(b) receive a portable copy of that data;
(c) request correction of inaccurate data;
(d) request deletion of your data;
(e) restrict or object to certain processing;
(f) opt out of the "sale" or "sharing" of your data (we do not sell or share);
(g) withdraw consent at any time where consent is the legal basis;
(h) lodge a complaint with your local data protection authority.
To exercise any right, email privacy@greetly.app (or the Operator directly for Guest-owned data). We respond within 30 days.
11. SECURITY. Data is encrypted in transit (TLS 1.2+). Passwords are stored using bcrypt with a random per-user salt. Twilio and OpenAI API keys stored on behalf of Operators are held in server-side environment or database records not exposed to the frontend. No system is perfectly secure; if a breach occurs affecting personal data, we will notify affected parties as required by law.
12. CHILDREN. BuzzerAI is not intended for use by anyone under 13 (16 in the EU). We do not knowingly collect personal data from children. Operators must not use the service to solicit or store data from children under the applicable age of digital consent.
13. COOKIES & TRACKING. We use the minimum cookies required for authentication (a JWT held in local storage) and no third-party advertising cookies. We do not implement Google Analytics or Meta Pixel on Guest-facing surfaces by default.
14. CHANGES TO THIS POLICY. We may update this policy. We will announce material changes in the operator dashboard and require Operators to re-acknowledge before continued use.
15. CONTACT. For privacy questions, data-subject requests, or complaints: privacy@greetly.app. Postal: (address to be added post-attorney-review).