Privacy Policy

What we collect from a phone call, how long we keep it, who touches it, and the four things we will never do with it.

Last updated September 21, 2026 · Rivet Dispatch · rivetdispatch.com

Draft — not yet reviewed by an attorney.

This is a working draft written alongside the product so the engineering and the paperwork say the same thing. It is not legal advice and it is not in force. Before the first paying customer it needs review by counsel licensed in our state, with particular attention to the call-recording consent, the TCPA scope of inbound-only answering, and the founding-price commitment.

1.Whose data this is

When a homeowner calls a contractor who uses Rivet, the contractor is the business responsible for that customer relationship. Rivet is their service provider: we process call content on the contractor’s behalf and on their instructions, and for no independent purpose of our own.

This policy covers both audiences: the contractors who buy Rivet, and the callers whose calls we answer. Callers may also want the shorter Call Recording & AI Notice.

2.What we collect

From callers, during a call:

  • Audio of the call, once the recording notice has played.
  • A written transcript of what was said.
  • The structured details the caller gave in order to book: name, callback number, service address, what is wrong, and the time window they chose.
  • The caller ID and the time and length of the call.
  • Whether the caller agreed to a confirmation text, and whether they asked not to be recorded.

From contractors:

  • Account and contact details, including the mobile number alerts go to.
  • The business knowledge you enter so the assistant can answer well: trades, hours, services, pricing, service area, and your instructions to it.
  • Billing information, which is handled by our payment processor. We never see or store full card numbers.
  • Ordinary product usage and error logs.

3.The four things we do not do

We do not use call content to train AI models. Not ours, not a vendor’s. There is no tier, toggle or roadmap item that turns this on, and our speech, language and voice vendors are contractually bound to zero retention and no training on our traffic.

We do not create voiceprints. We do not perform voice authentication, speaker identification, or any analysis of vocal characteristics to identify or profile a person. Speaker labels in a transcript come from the fact that the caller and the assistant are on separate audio channels — never from acoustic analysis of a voice.

We do not sell or share personal information as those terms are used in California and other state privacy laws. We do not run advertising, and we do not place third-party advertising or analytics pixels on signed-in pages.

We do not take payment card numbers over the phone. The assistant is instructed to refuse them outright. If a deposit is needed, it is handled by a secure link sent by text.

4.What we use it for

  • Answering calls, booking appointments, and writing them to the calendar you connected.
  • Sending you the summary, the booking alert, and the emergency escalation.
  • Showing you calls, transcripts and recordings in your dashboard.
  • Metering your minutes and billing you accurately.
  • Keeping the service working, secure, and free of abuse.
  • Meeting our legal obligations and keeping the consent evidence the law requires us to keep.

5.What we strip out before storing

A transcript of a home-services call routinely contains a physical address and, from time to time, things a person said without thinking. Before a transcript is written to storage we automatically remove payment card numbers, Social Security numbers, and bank routing and account numbers, replacing them with a redaction marker. The same redaction runs on any text sent to the summarizer.

We never email a full transcript. Emails link to it behind a login. The summary text message carries the minimum useful detail only — who called, their number, what is wrong, and the time window.

6.How long we keep it

WhatHow long
Call audio90 days by default. You can set anything from 7 to 365 days.
Transcripts12 months by default, configurable by you.
Booking records (name, number, address, job, appointment)The life of your account plus 90 days — this is your business record.
Consent recordsThe life of your account plus 5 years.
Training data derived from callsNone is ever created.
Everything, after you close your accountPurged within 30 days, and we will confirm it in writing if you ask.

Shorter is safer, which is why the defaults are short. A retention schedule that only exists in a privacy policy is worse than none, so deletion runs as an automated job and is monitored.

7.Who else touches it

We use a small number of vendors to run the service. Each is bound to process data only for us, to retain nothing, and not to train on it.

  • Telephony and text messaging — carrying the call and the SMS.
  • Speech recognition and speech synthesis — turning audio into text and back.
  • A large language model provider — understanding the call and drafting the summary.
  • Cloud hosting and database — in the United States.
  • Google Calendar or Microsoft Graph — only if you connect one, and only with the narrow permissions described below.
  • Payment processing — for your subscription. They see your card; we do not.

The current named list is available on request and will be published here before launch. We will give notice before adding a subprocessor that processes call content.

8.Calendar access, specifically

If you connect Google Calendar, we request exactly two permissions: the ability to see when you are free or busy, and the ability to manage events on a calendar we create ourselves, named “Jobs booked by Rivet”. We cannot read the contents of your other events, and we never request access to your email.

If you connect Outlook or Microsoft 365, we request permission to read and write calendar events so we can check availability and create the job. We do not request mail permissions.

Access tokens are encrypted with AES-256-GCM before they are stored, using a key that is never kept in the database. You can disconnect at any time from Settings, which deletes the stored tokens.

9.Text messages and consent

We text the contractor at the number they gave us, having agreed to it at signup. Message frequency varies with call volume, and message and data rates may apply.

Reply STOP to any message to stop it immediately, or HELP for help. We honor STOP in real time rather than taking the ten business days the rules allow, and we honor it however it is phrased — “stop texting me” and “take me off this” work exactly as well as the word STOP. After a STOP we send exactly one confirmation and then nothing.

A number added to an account by somebody other than its owner gets a request for consent first and receives nothing else until it replies YES.

We text a caller only when they said yes on the call, and only about their own appointment. We do not send marketing texts, and Rivet cannot be used to send them.

10.Your rights

Depending on where you live you may have the right to know what we hold about you, to get a copy, to correct it, to delete it, and to appeal a refusal. We do not sell or share personal information, so there is nothing to opt out of there.

If you were a caller to a business that uses Rivet, that business decides what happens to their customer records. Write to us at privacy@rivetdispatch.com and we will route your request to them and help them answer it. If you simply want your call recording deleted, ask us and we will delete it.

If you are a contractor, most of this is self-serve in Settings, and anything that is not, we will do for you on request.

11.Security

  • Every row of customer data is isolated per account at the database level, not just in application code.
  • Third-party tokens are encrypted at the application layer, with the key held outside the database.
  • Access to production data is limited to the people who need it, and administrative actions are logged with a required reason.
  • We are a small team and we will tell you plainly if something goes wrong. If a breach affects your data we will notify you within 72 hours of confirming it.

12.Children, and where we operate

Rivet is a business tool and is not directed at children. We operate in the United States and store data in the United States. We do not currently offer the service in the European Economic Area or the United Kingdom.

13.Contact

Rivet Dispatch · privacy@rivetdispatch.com

Open items for counsel: the named subprocessor list and change-notice mechanism; the service-provider restriction language, quoted verbatim from the applicable statute, in the Data Processing Addendum; and the precise wording of the caller-facing rights channel where the contractor, not Rivet, is the responsible business.