Privacy notice

Effective 2 September 2026

The short version: the public page has no analytics or advertising pixels. Card-backed trial checkout is hosted by Stripe, so CallGROW does not receive your full card number or CVC. CallGROW stores a limited encrypted billing record for subscription status and private-workspace provisioning. The operator workspace uses an essential sign-in cookie and processes communications through CallGROW's telephone provider.

Who handles the information

CallGROW handles subscription administration, private-workspace provisioning and operation of the service. Stripe handles hosted checkout and payment-method processing under its own privacy terms.

Public website visitors

The hosting service may process ordinary technical request information, such as IP address, browser information, requested page, time and security events, to deliver and protect the site. CallGROW does not add analytics, advertising cookies or cross-site tracking to this public page.

Trial checkout and billing

Stripe Checkout collects your name, email, billing details and payment method to create the card-backed trial and recurring subscription. Stripe sends CallGROW limited signed events containing identifiers for the checkout session, customer and subscription, your checkout name and email, selected seat count, subscription status and trial end. CallGROW encrypts that limited event record at rest and uses it to provision the private workspace, administer the subscription, prevent duplicate processing and resolve billing issues.

CallGROW does not request, receive or store your full card number or CVC. Stripe may process payment and identity information in other countries and retains it under its own legal and security obligations. The Stripe billing portal lets you manage or cancel the subscription.

Authorised operator workspace

A successful sign-in creates a strictly necessary, secure session cookie named cg_session. It expires after 12 hours or when the service restarts. Passwords are handled as one-way password hashes; the service does not need to store the readable password.

When an authorised operator uses a deployed workspace, it may handle contact names and phone numbers, message content, call and message events, approximate provider costs, configuration choices, and professional background the operator saves about a contact, such as a public profile address, a headline, a biography, awards, employment history and education. Those records support the requested calling and messaging service. The operator is responsible for telling the people they contact how their information is used and for having any consent or other lawful basis required for calls, messages and recordings.

Inbound SMS that is only a standard opt-out or opt-in keyword is also stored on a suppression list, together with any numbers or email addresses the operator adds by hand. That list is used to block further texts or emails (and, when the operator records a do-not-call entry, further calls) to that contact. Removing an entry requires a recent sign-in.

Optional recordings and call intelligence

Call recording is off by default. An administrator may enable it only after determining the rules that apply to the team's calling locations and destinations. When enabled, the agent must confirm that the recipient agreed before CallGROW will create the call. Telnyx records the connected call and produces the transcript. If AI summaries are enabled, the transcript is sent to the workspace's OpenAI API project to create a summary, objections, commitments, next steps and coaching notes. The OpenAI request is configured not to store the response.

Transcripts and reviews are encrypted at rest in the workspace and are available only to the agent who made the call and authorised managers. Administrators choose a retention period of 7 to 365 days. Deleting a contact's communication history also deletes call-intelligence records matched to that phone number. Operators should not record sensitive information unless it is necessary and lawful.

Saved voicemail recordings

An authorised agent may record a short personal voicemail through the browser microphone. The recording is converted locally to a WAV file, validated by CallGROW and stored privately under that agent's account in the isolated workspace. It is sent to Telnyx only when the agent deliberately starts a voicemail drop or enables the per-call automatic machine-answer option. It is not published at a public URL, used for biometric identification or sent to OpenAI. The agent can preview, replace or delete it at any time.

Service providers and location

The public service is hosted by Fly.io, billing and card collection are provided through Stripe, telephone and optional recording services are provided through Telnyx, and optional AI narration and call reviews use OpenAI. HubSpot, contact enrichment providers and email providers process information only when the workspace administrator connects those services. CallGROW does not sign in to LinkedIn or collect from it. An administrator may connect a licensed enrichment provider, and a lookup then sends that provider the contact's profile address or email address so it can return the profile details it already holds. These providers may process information in countries other than your own.

Retention and security

Billing event records are kept only as long as reasonably needed to provision and administer the subscription, prevent duplicate processing, resolve disputes and meet legal, tax or accounting obligations. Workspace records remain in the isolated deployment until the operator deletes them or the service ends, subject to backups and legal requirements. CallGROW uses encryption at rest, password access, secure cookies, restrictive browser policies, spend controls and signed provider webhooks, but no online service can promise absolute security.

Your choices and requests

You can manage or cancel the subscription through the Stripe billing portal linked from the checkout confirmation page.

Delete your CallGROW account

If you have a CallGROW operator account, you can request deletion:

  1. In the app: Settings → Delete account (when available), or
  2. Email with subject “Privacy / account deletion request” and the email you use to sign in. You can also use the Support page.

When we delete an account we remove or irreversibly anonymise the workspace member record, session credentials, and personal profile fields we hold for that member, subject to backups and records we must keep for law, tax, fraud prevention or billing disputes. Shared workspace data owned by another organisation (for example team lead lists) may remain under that organisation’s control.

You may also ask for access to or correction of information linked to you, or make a privacy complaint, using the same support contact. Enough information may be requested to verify the request and find the relevant record. Some records may need to be retained where the law permits or requires it.

Changes

Material changes will be posted here with a new effective date. If a proposed customer setup introduces materially different data handling, that handling should be described in the written scope before activation.