Privatlivspolitik
Sidst opdateret 14. september 2026
Overview
This policy describes how OrderVoice ("we", "us") handles information when a business uses our dashboard and AI phone agent — across twelve sectors: restaurants, clinics, salons, real estate, retail & e-commerce, home services, hotels, logistics, events & ticketing, travel & tours, standalone, personal assistant — when a caller speaks to that agent, and when anyone visits our public website. We collect only what we need to run the service, and we describe all of it here.
Roles
For account data and website analytics we are the controller. For the data the agent captures from callers — names, phone numbers, transcripts, orders, bookings, messages — the business that owns the phone line is the controller and we process it on their instructions; a data-processing agreement (DPA) is available on request.
Information we collect
Account data — your email address, the business name you give us, your sector, country, settings, and the email addresses of team members you invite.
Operational data — call metadata (phone numbers, duration, language, status, outcome), transcripts, summaries and — where the business has recording enabled — audio recordings, plus the orders, bookings, messages and text-message confirmations the agent captures or sends. History is grouped by caller phone number so the business can recognise repeat customers.
Catalog data — the items, services, rooms, listings or rates, prices, documents and hours you enter for the agent to reference.
Audit data — an internal log of changes to prices, availability, statuses, roles and settings, with who made them, so you can see who changed what.
Contact-form data — what you type into our contact form, the page it was sent from, any campaign parameters in the link you followed, and a salted hash of your IP address used only to limit abuse.
Website analytics — a first-party page-view record for our public pages. Each record holds the page path, the hostname of the referring site (never the full URL) and an anonymous per-browser identifier that we generate and store in your browser. We do not use third-party analytics or advertising trackers, and we do not record your IP address with page views. In the EU and UK the identifier is only written after you dismiss the storage notice. These records are deleted after 90 days.
Browser storage
We use your browser's local storage — not cookies — to remember choices on your device. Every key we set starts with ov.:
- ov.vid — the anonymous page-view identifier
- ov.theme — your colour theme
- ov.locale — your language and market
- ov.fontSize — your text-size setting
- ov.consent — that you dismissed the storage notice
- ov.ref — a referral code from a sign-up link, cleared once your account is created
- ov.selected_restaurant — the location you last viewed
- ov.notify — browser-notification preference
- ov.chime — new-work chime on or off
- ov.chime_volume — chime volume
- ov.autoprint — auto-print preference
- ov.orders_view — list or board view
- ov.usage_alert_pct — usage-alert threshold
- ov.dismissed-announcements — announcements you closed
- ov.orders_views — saved order-list views
- ov.orders_columns — which order-list columns you show
- ov.board_age_thresholds — board age-timer thresholds
- ov.palette_recent — recent command-palette picks
- ov.help_seen — which help tours you have seen
- ov.help_muted — help tours you switched off
- ov.sidebar_admin_open — whether the admin section of the sidebar is expanded
- ov.admin.selftests — admin self-test preferences (admins only)
- ov.admin_view_as — the tenant an admin is viewing as (admins only)
Session storage (cleared when the tab closes): ov.locale.synced — that we already checked your market this session, ov.signup_sector — the sector you picked, while Google sign-in completes. Your sign-in session is also kept in local storage by our authentication provider (Supabase, under a key beginning sb-). Clearing site data in your browser removes all of it.
Call recordings & transcripts
Calls are handled by a managed voice platform and are transcribed so the agent can capture what was asked for. Audio recording is a per-business setting; when it is on, the agent can announce it at the start of the call, and recordings are stored against the call so the business can review what was said. The business is responsible for telling callers that calls may be recorded or transcribed where the law requires it.
How we use information
To operate the service: routing calls, understanding and validating requests against your catalog and documents, taking bookings, sending records to the systems you connect, sending confirmation and reminder text messages when you enable them, showing your dashboard and analytics, sharing a status page with a customer when you send them the link, sending you account emails, and providing support. We do not use your data to train models, and we do not sell it.
Sharing & subprocessors
We share data with the vendors that power the service, each receiving only what it needs:
- Vapi — real-time voice platform, and the speech and language-model providers it uses to run the call.
- Twilio — telephony; and text messages (confirmations, reminders) when a business enables SMS.
- Supabase — database, authentication and file storage.
- Cloudflare — hosting, edge network and rate limiting.
- Resend — transactional email (invites, message notifications, contact-form notifications).
- Stripe — billing and invoices, when a business subscribes to a paid plan. We never see full card numbers.
- Google Fonts — the typefaces on our public pages are loaded from Google's servers, which receive your IP address and browser details as part of the request. Our security policy does not allow self-hosting them, so we disclose it here.
- Your own systems — the endpoint you set under Settings → Integrations (Zapier, Make, n8n, or a POS, PMS, CRM or booking system you connect).
Credentials for these vendors are held server-side and never sent to your browser. Some vendors process data outside your country; where the law requires it we rely on their standard contractual clauses or equivalent safeguards.
Data retention
Call data — transcripts, recordings, summaries, orders, bookings, messages and text-message logs — is kept for the retention period each business sets in Settings (30 days to 10 years; the default is 365 days). After that, personal details on calls, orders and bookings are redacted and messages are deleted automatically. Public page-view records are deleted after 90 days; contact-form submissions after 24 months. Account and catalog data is kept while the account is active. You can export your data or delete your business or your whole account from Settings at any time; deletion removes your calls, orders, bookings, customers, catalog, documents and secrets.
A business can also erase everything held about a single caller (by phone number) from Settings, for example when a customer asks to be forgotten.
Security
Every database query is scoped to your own business by row-level security, third-party keys stay server-side, inbound webhooks are verified against a secret unique to your business with replay protection, public endpoints are rate limited, document text is encrypted at rest, and two-factor sign-in is available on every account. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data. We do not currently hold a SOC 2 report or HIPAA certification.
Breach notification
If we become aware of a personal-data breach affecting your data we will notify the affected businesses without undue delay — and, where a law such as the GDPR applies, within 72 hours of becoming aware — with what we know, what we are doing, and what you should do.
Children
The service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16 through the dashboard; a caller's age is not something the agent asks for or infers. If you believe a child's data has reached us, contact us and we will delete it.
Your rights (GDPR / UK GDPR)
You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your supervisory authority. Our lawful basis for processing call data is the business's legitimate interest in answering its phone; for account data it is performance of our contract with the business.
Depending on where you live you may have the right to access, correct, export, restrict or delete your personal data, or to object to how we use it. Callers whose data a business has captured through the agent should contact that business first, as it controls that data; we will help the business respond. Contact us to exercise any of these rights.
Changes
When we change this policy we update the date at the top of this page and, for material changes, notify account holders by email.
Contact
Questions about privacy, or to reach our data-protection contact? Write to privacy@aarnikainnovations.com. OrderVoice is operated by Aarnika Innovations Corporation.