Back to home
Privacy Policy

PRIVACY POLICY

Last updated: February 13, 2026

Welcome to Spinabot. This Privacy Policy explains how Spinabot ("we," "us," or "our") collects, uses, shares, and protects personal information when you use our AI voice agent platform and related services (collectively, the "Services"). This policy applies to information we collect from our business customers ("Customers") and from end-users who interact with voice agents powered by our platform ("End-Users" or "Callers").

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our practices, please do not use our Services.

1. Information We Collect

1.1 Information from Customers (Business Users)

When you register for and use Spinabot as a business customer, we collect:

Account Information: Name, email address, company name, phone number, billing address, and payment information.

Profile and Configuration Data: Voice agent scripts, prompts, knowledge base content, integration settings, API credentials for third-party services, and custom configurations.

Usage Data: Information about how you use our dashboard, Services accessed, features utilized, call volumes, session logs, and interaction patterns.

Device and Browser Information: IP address, browser type and version, operating system, device identifiers, and referring URLs.

Communications: Content of messages you send to us, including support requests, feedback, and inquiries.

1.2 Information from End-Users (Callers)

When end-users interact with voice agents created by our Customers, we may collect:

Voice Audio Data: Real-time audio during voice conversations, processed temporarily for speech recognition and response generation.

Call Transcripts: Text transcriptions of conversations between end-users and voice agents.

Call Metadata: Phone numbers (caller ID), call duration, timestamp, call status, and routing information.

Conversation Content: Information voluntarily shared by end-users during calls, which may include names, contact details, appointment preferences, or other data relevant to the conversation purpose.

Call Recordings: Audio recordings of conversations when call recording is enabled by the Customer and appropriate consent has been obtained.

Technical Data: Device type, operating system, network information, and telephony provider details.

1.3 Information from Third-Party Sources

We may receive information from:

AI and Voice Service Providers: Data processed by OpenAI (for language models), speech-to-text providers, and text-to-speech providers.

Telephony Providers: Call routing data and telephony metadata from providers such as Twilio, LiveKit, and similar services.

Payment Processors: Transaction confirmation and billing information.

Analytics Services: Aggregated usage statistics and performance metrics.

CRM and Integration Partners: Customer data synchronized through authorized integrations.

2. How We Collect Information

We collect information through:

Direct Interactions: When you create an account, configure voice agents, use our dashboard, or contact support.

Voice Conversations: During real-time calls between end-users and AI voice agents.

Automated Technologies: Cookies, web beacons, log files, and similar tracking technologies on our website and platform.

Third-Party Integrations: Data shared when you connect Spinabot with CRMs, calendars, payment systems, or other authorized third-party services.

API Usage: Information transmitted when using our APIs to build or manage voice agents.

3. How We Use Your Information

We use the collected information for the following purposes:

3.1 To Provide and Improve Our Services

Process and facilitate voice conversations between end-users and AI agents

Convert speech to text and generate voice responses using AI models

Route calls and manage telephony infrastructure

Store and retrieve conversation transcripts and call recordings (when enabled)

Analyze usage patterns to improve platform performance and features

Develop new features and enhance existing functionality

3.2 Account and Service Management

Create and maintain your Customer account

Authenticate users and prevent unauthorized access

Process payments and manage subscriptions

Send service-related notifications, updates, and announcements

Provide customer support and respond to inquiries

3.3 Legal and Compliance Purposes

Comply with applicable laws, regulations, and legal processes

Enforce our Terms of Service and other agreements

Protect against fraud, abuse, and security threats

Resolve disputes and investigate violations

3.4 Analytics and Marketing

Understand how Customers use our Services

Generate aggregated, anonymized analytics and reports

Send promotional communications (with your consent where required)

Conduct research and development

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data based on the following legal grounds:

Contractual Necessity: Processing is necessary to perform our contract with you (e.g., providing the Services you requested).

Legitimate Interests: Processing is necessary for our legitimate business interests, such as improving our Services, preventing fraud, and ensuring security, provided these interests do not override your rights.

Legal Obligations: Processing is necessary to comply with legal or regulatory requirements.

Consent: Where required by law, we process data based on your explicit consent, which you may withdraw at any time.

5. How We Share Your Information

We do not sell personal information. We share information with the following categories of recipients:

5.1 Service Providers and Subprocessors

AI and NLP Providers: OpenAI and similar platforms that power our conversational AI capabilities

Speech Technology Providers: Third-party speech-to-text (STT) and text-to-speech (TTS) services

Telephony and Communication Providers: Twilio, LiveKit, and other telephony infrastructure providers

Cloud Infrastructure: Hosting providers that store and process data on our behalf

Payment Processors: Stripe, PayPal, or other payment service providers for billing and transactions

Analytics Platforms: Tools that help us understand usage patterns and improve our Services

Customer Support Tools: Platforms that enable us to provide customer assistance

All service providers are contractually obligated to protect your information and use it only for the purposes we specify.

5.2 Business Customers

Data collected from End-Users during interactions with voice agents is made available to the Customer who created and deployed that agent. Customers are responsible for their own use of this data in accordance with applicable privacy laws.

5.3 Legal Requirements and Protection

We may disclose information when required by law or in response to:

Valid legal processes (subpoenas, court orders, warrants)

Government or regulatory requests

Protection of our rights, property, or safety, or that of our users or the public

Enforcement of our Terms of Service

5.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the successor entity, subject to this Privacy Policy.

6. International Data Transfers

Spinabot is based in the United States. If you access our Services from outside the U.S., your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.

For transfers from the EEA, UK, or Switzerland to the U.S., we rely on:

Standard Contractual Clauses (SCCs): We implement EU-approved SCCs with our service providers to ensure adequate data protection.

Adequacy Decisions: Where applicable, we rely on adequacy decisions by the European Commission or other relevant authorities.

Additional Safeguards: We implement supplementary measures to protect data transferred internationally.

7. Data Retention

We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Specific Retention Periods:

Account Information: Retained while your account is active and for a reasonable period thereafter to comply with legal obligations and resolve disputes.

Voice Audio Data: Real-time audio is processed temporarily and typically not stored unless call recording is enabled. Temporary processing occurs only for the duration necessary to generate transcripts and responses.

Call Transcripts and Recordings: Retained according to Customer preferences (typically 30-90 days, or as configured), unless longer retention is required by law or the Customer's business needs.

Metadata and Analytics: Aggregated and anonymized data may be retained indefinitely for analytical purposes.

Payment Records: Retained for the period required by tax and accounting regulations (typically 7 years).

Upon account deletion or termination, we will delete or anonymize your personal information within a reasonable timeframe, except where retention is required for legal, regulatory, or legitimate business purposes.

8. Call Recording Notice and Consent

Important Notice Regarding Call Recording:

Our platform allows Customers to enable optional call recording features. When call recording is activated:

The Customer is responsible for obtaining any necessary consent from End-Users before recording conversations, in accordance with applicable laws (including federal and state wiretapping and recording laws).

Customers must provide clear notice to End-Users that calls may be recorded.

Spinabot provides tools and features to facilitate consent collection (such as automated notices), but ultimate compliance responsibility rests with the Customer.

If you are an End-User and do not wish to be recorded, please inquire with the business you are calling and discontinue the call if recording is not acceptable to you.

9. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

9.1 Rights for All Users

Access: Request a copy of the personal information we hold about you.

Correction: Request correction of inaccurate or incomplete information.

Deletion: Request deletion of your personal information, subject to certain exceptions.

Opt-Out of Marketing: Unsubscribe from promotional emails via the link in such emails or by contacting us.

9.2 GDPR Rights (EEA, UK, Switzerland)

If you are located in the EEA, UK, or Switzerland, you have additional rights:

Data Portability: Receive your data in a structured, commonly used format and transmit it to another controller.

Restriction of Processing: Request restriction of processing in certain circumstances.

Object to Processing: Object to processing based on legitimate interests or for direct marketing purposes.

Withdraw Consent: Withdraw consent at any time where processing is based on consent.

Lodge a Complaint: File a complaint with your local data protection authority.

9.3 CCPA/CPRA Rights (California Residents)

California residents have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Right to Know: Request disclosure of the categories and specific pieces of personal information we collect, use, and disclose.

Right to Delete: Request deletion of your personal information.

Right to Opt-Out: Opt-out of the "sale" or "sharing" of personal information. We do not sell personal information as defined by the CCPA/CPRA.

Right to Correct: Request correction of inaccurate personal information.

Right to Limit Use of Sensitive Information: Limit use of sensitive personal information (where applicable).

Non-Discrimination: You will not receive discriminatory treatment for exercising your privacy rights.

9.4 Other State Privacy Laws

If you reside in Virginia, Colorado, Connecticut, Utah, or other states with comprehensive privacy laws, you may have similar rights to access, delete, correct, and opt-out. Please contact us to exercise these rights.

9.5 How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@spinabot.com. We will respond to your request within the timeframe required by applicable law (typically 30-45 days). We may need to verify your identity before processing your request.

10. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience, analyze usage, and deliver personalized content.

Types of Cookies We Use:

Essential Cookies: Necessary for the website and platform to function properly (e.g., authentication, session management).

Analytics Cookies: Help us understand how visitors use our Services (e.g., Google Analytics).

Functional Cookies: Remember your preferences and settings.

Marketing Cookies: Track visitors across websites to display relevant advertisements (where applicable).

You can control cookies through your browser settings. However, disabling certain cookies may affect the functionality of our Services. For more information about cookies and how to manage them, visit www.allaboutcookies.org.

11. Security Measures

We take the security of your information seriously and implement industry-standard technical, administrative, and physical safeguards, including:

Encryption of data in transit (TLS/SSL) and at rest

Access controls and authentication mechanisms

Regular security audits and vulnerability assessments

Employee training on data protection and security practices

Secure data centers and infrastructure

Incident response and breach notification procedures

While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, and you use our Services at your own risk.

12. Children's Privacy

Spinabot is not intended for use by individuals under the age of 18, and we do not knowingly collect personal information from children. Our Services are designed for business use only. If we become aware that we have inadvertently collected information from a child under 18, we will take steps to delete such information promptly.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@spinabot.com.

13. Third-Party Links and Services

Our Services may contain links to third-party websites, applications, or services that are not operated by us. This Privacy Policy does not apply to such third-party services. We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you access.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

Update the "Last Updated" date at the top of this policy

Notify you via email or through a prominent notice on our website or platform

Where required by law, obtain your consent to the changes

We encourage you to review this Privacy Policy periodically. Your continued use of our Services after changes are posted constitutes your acceptance of the updated policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@spinabot.comWebsite: www.spinabot.comMailing Address: [4207 Hana Rd, Edison, NJ, 08817]

For GDPR-related inquiries, EU residents may also contact our Data Protection Officer (if applicable) at the email address above.