Privacy Policy
Last Updated: July 1, 2026
1. Introduction
Ventruo, Inc. (“Ventruo,” “we,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform and services.
This Policy applies to Merchants (businesses using Ventruo), End Users/Callers (prospective customers who interact with Merchant AI employees), and Website Visitors.
2. Information We Collect
Provided Directly: Account registration (name, email, business name, phone), business content (services, pricing, service areas), payment information (processed by Stripe — we do not store raw card numbers).
Automatically Collected: Call recordings and transcripts, caller phone numbers and metadata, lead information captured during calls, usage data, and device/browser data for dashboard access.
From Integration Partners: If you connect HighLevel, Google Calendar, or other integrations, we may receive data from those services as directed by you.
3. How We Use Your Information
We use information to: provide and operate the Service; process billing; improve AI accuracy (using aggregate, de-identified data); prevent fraud; meet legal obligations; send transactional communications; and generate anonymized industry insights. No individual caller PII is included in aggregate models.
4. Call Recording and Caller Privacy
You are responsible for ensuring callers receive legally required notice before recording. Recording consent laws vary by state — see our Recording Consent by State documentation for guidance.
Callers wishing to request deletion of their recordings should contact the Merchant, who may forward deletion requests to privacy@ventruo.com. Call recordings are retained for 90 days by default.
5. How We Share Your Information
We do not sell your data. We share only with service providers necessary to operate the platform:
- Twilio — voice and SMS infrastructure
- OpenAI — AI processing (transcripts, prompts)
- Supabase — database hosting
- Vercel — web platform hosting
- Resend — transactional email
- Stripe — payment processing
- HighLevel (optional) — CRM if enabled by you
All processors are bound by data processing agreements consistent with this Policy.
6. Data Retention
Call recordings: 90 days. Transcripts: 12 months. Lead and account data: duration of account plus 30 days post-termination. Billing records: 7 years. Anonymized analytics: indefinite.
7. Your Rights
You have the right to access, correct, delete, or receive a portable copy of your personal information. California residents have additional rights under the CCPA/CPRA. EEA/UK residents have rights under GDPR including the right to object and to lodge complaints with supervisory authorities.
To exercise any rights, email privacy@ventruo.com. We respond within 30 days.
8. Data Security
We use encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, Row-Level Security on all data stores, and regular security reviews. No system is 100% secure; we will notify you of breaches as required by law.
9. Cookies
We use essential cookies (required for authentication) and analytics cookies (aggregate, non-advertising). No cross-site tracking or advertising cookies. Non-essential cookies can be disabled in browser settings.
10. Data Processing Agreement (DPA)
Merchants processing EEA/UK personal data may request our standard DPA at legal@ventruo.com. The DPA covers sub-processor notifications, breach notification (72 hours), data subject rights assistance, and deletion/return upon termination.
11. Changes and Contact
We will notify you of material changes 30 days before they take effect. For questions: privacy@ventruo.com
Ventruo, Inc. — privacy@ventruo.com — Last updated July 1, 2026