Privacy Policy
Last updated: May 2, 2026
This Privacy Policy explains how Client Launch (“we,” “us,” or “our”) collects, uses, and protects information in connection with the service provided at clientlaunch.com(the “Service”). It applies to our customers (the businesses who sign up) and to end-users (the customers our customers serve).
1. Information We Collect
Account information: name, email, business name, phone, billing details (processed by Stripe).
Communication data: calls placed and received through the Service (audio recording, transcript when consented), SMS messages sent and received, contact records you create or upload.
End-user identifiers:phone numbers, names, and (where provided) email addresses of the individuals our customers communicate with through the Service. These are categorized as “personal identifiers” under U.S. state privacy laws (e.g. CCPA/CPRA).
SMS opt-in records: evidence of consent for text messaging, including audio recordings and transcripts of verbal opt-ins captured by the AI receptionist, owner attestations made at the time a contact is added, and (when applicable) timestamped records of web-form checkbox submissions. These records are retained for as long as the underlying contact is active and for a reasonable compliance period thereafter.
Usage data: log data, IP address, browser type, pages viewed, feature interactions, and aggregate metrics about your account’s usage.
Integrations: when you connect Google Calendar or Google Business Profile, we receive the OAuth tokens you authorize and only the scopes you grant.
2. How We Use Information
- To provide, maintain, and improve the Service;
- To process payments and bill usage;
- To detect and prevent abuse, fraud, and platform safety violations;
- To send service announcements, security notices, and account-related email;
- To comply with legal obligations.
We do not sell personal information. We do not use customer call recordings or transcripts to train third-party AI models without your explicit consent.
3. Sharing With Service Providers
We rely on a small set of vetted sub-processors that handle parts of the Service:
- Twilio — telephony (calls, SMS).
- Vapi.ai — voice AI.
- Stripe — billing.
- Supabase — managed database and authentication.
- Vercel — application hosting.
- Resend — transactional email.
Each is bound by data processing terms requiring confidentiality and appropriate safeguards. We do not share personal data with third parties for their own marketing.
4. End-User Data & the Customer’s Role
When you (the business owner) use Client Launch to interact with your end customers, you are the data controller of those records. You are responsible for obtaining the legally required consents, providing your own privacy notice to those individuals, and honoring their data-subject rights. We act as a data processor on your behalf.
5. Call Recording & AI Disclosure
Inbound calls handled by the AI receptionist may be recorded and transcribed for your review and to improve the AI for your account. The AI identifies itself as an AI when asked. State law on one-party vs. two-party consent recording varies; you are responsible for ensuring your greeting and disclosures meet the law that applies to your business location.
6. SMS Consent & Opt-Out
The Service’s SMS features are limited to transactional and customer-care messages— appointment reminders, scheduling confirmations, on-the-way notifications, and post-service customer-feedback requests. Marketing or promotional SMS broadcasts are not sent on platform-provisioned numbers under any circumstance. A customer that wishes to send marketing SMS must register their own A2P 10DLC brand and campaign through Twilio (or another carrier) directly, using numbers they own and operate outside the Service.
Recipients of SMS sent via the Service can reply STOP, UNSUBSCRIBE, CANCEL, END, QUIT, OPTOUT, or OPT OUT to opt out at any time, which we honor automatically across all message types from that sender. Reply START or UNSTOP to opt back in. HELPreturns standard help text. You as the sender are responsible for ensuring you have the legally required prior express consent before sending any SMS, and for honoring opt-out requests received outside the Service.
Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. All other data sharing categories described in this Policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
6.1 How consent is captured
We support three consent-capture pathways. Each generates a durable record we retain for compliance audits and dispute resolution:
- Verbal AI capture. When a caller speaks with the AI receptionist and provides their phone number for follow-up, the AI reads the digits back and the caller verbally confirms before any messaging is sent. The audio recording and transcript are retained as proof of consent.
- Owner attestation. When a business owner manually adds or imports a contact, the owner attests that they have an existing relationship with the contact and the legally required consent. No automated messaging is sent until the owner explicitly schedules an appointment or sends a manual message.
- Web form (when offered).Where the Service exposes a public lead-capture form on the customer’s site, that form will present two separate, unchecked opt-in checkboxes — one for transactional and customer-care messages (appointment reminders, confirmations, on-the-way notifications, and post-service customer-feedback requests) and one for marketing or promotional messages — with links to this Policy and our Terms rendered directly under the checkboxes. The submission timestamp, IP address, and form URL are stored with the contact record. The marketing/promotional checkbox does not enable marketing through the Service.The Service never sends marketing SMS on platform-provisioned numbers. The marketing consent record is collected on the customer’s behalf so that, if the customer later registers their own separate A2P 10DLC brand and campaign for marketing using numbers they own and operate outside the Service, they have prior express written consent on file at the time of opt-in. Until and unless that separate customer-owned campaign exists, no marketing SMS is sent to that contact through any pathway.
- Inbound SMS to the business.When a consumer texts a Client Launch business number first, that inbound message establishes prior express consent for the business to reply within the same conversation and to send transactional follow-ups directly tied to the consumer’s inquiry (e.g. a quote, an appointment confirmation, a reminder for the appointment that was booked). Inbound-SMS consent does not extend to marketing or promotional broadcasts; sending those requires a separate opt-in captured through one of the pathways above. The inbound message is retained as the consent record.
6.2 Transactional vs. marketing messages
Recipients who opt in to transactional and customer-caremessages (e.g. appointment reminders, scheduling confirmations, on-the-way notifications, and post-service customer-feedback requests) are not automatically opted in to marketing or promotionalmessages. Each category requires its own affirmative opt-in, and a recipient can withdraw either consent independently. STOP applies to all messages from the sending number.
7. Data Retention
Active account data is retained while your subscription is active. After cancellation we retain it for up to 30 days to support reinstatement, then delete or de-identify it unless we are legally required to retain it longer (e.g. financial records under tax law, dispute records under Stripe’s rules).
8. Data Security
We take reasonable administrative, technical, and physical safeguards to protect personal information against unauthorized access, disclosure, alteration, and destruction. Measures include:
- Transport security: all data submitted through forms on clientlaunch.com and to our APIs is transmitted over HTTPS using TLS 1.2 or higher. Encrypted backups are stored at rest.
- Access controls: role-based access in our admin tooling; least-privilege access keys with our sub-processors; service-role database access restricted to server-side code paths and not exposed to browsers.
- Service-provider safeguards: sub-processors handling personal information (Twilio, Vapi, Stripe, Supabase, Vercel, Resend) are bound by data-processing terms requiring appropriate confidentiality and security controls.
- SMS opt-in records: consent timestamps, IP addresses, audio recordings (for verbal consent), and form URLs are retained as evidence of opt-in for the active life of the contact and a reasonable compliance period thereafter, and are not shared with any third party other than our SMS service provider for the sole purpose of message delivery.
- Anomaly monitoring & incident response: we monitor for anomalous activity and quarantine accounts that trigger our abuse rules. In the event of a data breach affecting your personal information, we will notify you and applicable authorities as required by law.
No system can be guaranteed 100% secure. If you have questions about our security practices or believe your information has been compromised, contact us at the address in Section 13.
9. Children’s Privacy
The Service is for businesses and is not directed at children under 13. We do not knowingly collect personal information from children.
10. Your Choices & Rights
Depending on your location, you may have rights under laws like GDPR or CCPA to access, correct, delete, or export your personal information. To exercise these rights, email support@clientlaunch.com. If you are an end-user (a customer of one of our customers), please direct these requests to the business that contacted you. If that business is unreachable or unresponsive, you may contact us directly at privacy@clientlaunch.com and we will assist within 30 days. To stop receiving SMS at any time, reply STOP to any message from the sending number; this works regardless of whether you contact the business or us.
11. International Transfers
We are based in the United States and our infrastructure runs in U.S. regions. By using the Service from outside the U.S., you consent to the transfer of your data to the U.S. for processing.
12. Changes to This Policy
We may update this policy as the Service evolves. Material changes will be announced via in-product notification or email. The date at the top of this page reflects the latest revision.
13. Contact
Questions about this policy or our data practices can be sent to support@clientlaunch.com or privacy@clientlaunch.com, or by mail to:
Client Launch LLC
Attn: Privacy
7901 4th St N STE 300
St. Petersburg, FL 33702
USA
See also our Terms of Service.