Privacy Policy

Effective July 1, 2026

1. What we collect

We collect only what is necessary to run the service:

  • Business information: your business name, phone number, timezone, and service hours.
  • Customer phone numbers: the phone numbers of people who call your business line. We store these to match repeat callers and to send SMS confirmations after appointments are booked.
  • Call data: timestamps of calls, whether they were answered, and whether the AI called back.
  • Call transcripts and summaries: AI-generated summaries of calls handled by the Ghost voice agent.
  • Appointment and quote data: details of appointments booked and quotes given by the AI on your behalf.
  • Billing information: your subscription status. Payment card details are handled entirely by Stripe — we never see or store your card number.

2. How we use it

We use this information solely to provide the Ghost service — routing calls, booking appointments, sending SMS confirmations, and displaying your dashboard. We do not sell your data or use it for advertising.

3. Third-party services

Ghost relies on the following third-party services to function:

  • Twilio — handles inbound phone calls and outbound SMS messages. Your customers' phone numbers and SMS content pass through Twilio.
  • Vapi — powers the AI voice agent. Call audio is processed and transcribed by Vapi. Vapi's privacy policy governs how they handle call audio.
  • Stripe — handles subscription billing. Your payment information is governed by Stripe's privacy policy.
  • Supabase — stores all application data (calls, appointments, customers, etc.) in a hosted Postgres database in the United States.

4. Call recording disclosure

Calls handled by the Ghost AI agent are processed by Vapi and may be recorded and transcribed. Summaries of these calls appear in your dashboard. You are responsible for disclosing call recording to your customers as required by applicable law.

5. Data retention

We retain your data for as long as your account is active. If you cancel, we retain your data for 30 days to allow for account recovery, after which it is deleted. You may request immediate deletion by contacting us.

6. Your customers' data

You are the data controller for your customers' information (their phone numbers, names, appointment details). We process this data on your behalf as a data processor. You are responsible for having a lawful basis to process your customers' data and for your own privacy disclosures to them.

7. Security

Data is stored in a Supabase Postgres database with role-based access control. Access to your dashboard is protected by a password. We use HTTPS for all data in transit. No security measure is foolproof — if you believe your account has been compromised, contact us immediately.

8. Contact

Questions about this policy or requests to delete your data: hello@myghost.io.