Cloudflare
HTTPS, website delivery, application Tunnel connectivity, traffic protection, and related technical request information.
Cloudflare role and policiesPrivate-beta policy centre
These drafts explain how the private beta handles information, connected providers, calls, cancellation, and responsible use. They are not final commercial terms and do not open public signup, checkout, or downloads.
The product behaviour below is the current operating rule. The legal operator is now identified. The accountable Privacy Officer, verified privacy, support and billing contacts, mailing address, support commitment, refund terms, governing-law language, and commercial legal review must still be completed before sales open.
Current identity
Full drafts
Privacy and data handling draft
The subscribing business controls the submissions, caller information, recordings, transcripts, summaries, documents, inventory, legacy records, client and project records, and storage locations used in its work. The installed Trace Intake program handles that information for the business and writes it to the computer, network folders, and business drives selected during setup.
The business is responsible for having a lawful reason to collect and use information from its own customers, workers, callers, and other individuals; giving any notices and choices its activities require; deciding who on its team can access the delivered records; and maintaining appropriate business backups and retention rules.
The owner system keeps only information needed to operate the account and paid or sponsored service:
The owner dashboard is not designed to store form answers, lead contact details, caller recordings, transcripts, attachments, customer documents, inventory line items, legacy files, or business folder paths.
Owner-side information is used to authenticate access, provide selected modules, administer private-beta grants, manage subscriptions and refunds, enforce provider limits, secure callbacks and installations, respond to support or privacy requests, investigate technical or security incidents, meet accounting and legal obligations, and understand aggregate service health. It is not sold or used to build advertising profiles.
The current website has no advertising tracker, analytics service, contact form, public account creation, or checkout. Cloudflare provides HTTPS, delivery, and security and may process ordinary request information such as IP address, browser details, requested page, security signals, and timestamps under its own terms. No application ZIP or business record is served from this marketing site.
Safeguards include separate credentials for approved testers, encrypted local provider credentials, verified Stripe and Twilio callbacks, narrow owner-dashboard fields, spending limits, expiring grants, suspension and revocation controls, least-access provider projects or subaccounts, HTTPS, restrictive website security headers, and tests that block credentials and business records from release packages.
No system can promise absolute security. Suspected unauthorized access, loss, or disclosure must be contained, investigated, documented, and assessed for required customer, individual, provider, insurer, or regulator notice.
Connected providers
Trace Intake uses enabled providers only for the feature the business chooses. Those providers may process or temporarily retain limited information in Canada, the United States, and other countries where they or their subprocessors operate. Information in another country may be subject to that country's laws and lawful access processes. Provider locations and terms can change, so they must be reviewed again before commercial launch and when a material provider changes. The Third-Party Provider Directory identifies each role and links to the provider's current official policies.
HTTPS, website delivery, application Tunnel connectivity, traffic protection, and related technical request information.
Cloudflare role and policiesFuture checkout, subscriptions, invoices, refunds, payment-method handling, fraud prevention, tax, and accounting records. Trace Intake does not store full card details.
Stripe role and policiesTelephone-number provisioning, call connection, keypad selections, temporary recording, callback delivery, and provider usage or cost information for Answering Service.
Twilio role and policiesWhen enabled, transcription, classification, structured summaries, and other bounded AI tasks. API business inputs and outputs are not used for model training by default; provider abuse-monitoring and retention rules still apply.
OpenAI role and policiesGoogle Drive, OneDrive, Dropbox, or another locally synchronized folder is optional and controlled by the business. That provider's account, region, sharing, backup, and retention settings apply.
Storage roles and policiesTrace Intake must not silently enable a new provider or use operational information for a new purpose. A material new use requires an updated disclosure and, where required, fresh consent or customer approval.
Calls and transcription draft
The subscribing business decides why it uses Answering Service and is responsible for its caller notice, consent, retention, access, and alternative-contact practices. Before a call is recorded or transcribed, the configured greeting must clearly tell the caller that recording and transcription will occur, explain the business purpose, and provide an appropriate way to decline or use another contact method when required.
Trace Intake uses the call only to operate the answering workflow chosen by the business: play a greeting or menu, collect a message, transcribe it, prepare a structured summary, route the result, and deliver the package to the business-controlled storage locations. The business must not describe one purpose to the caller and later reuse the call for an unrelated purpose such as advertising, profiling, or staff training without the required notice and consent.
After both configured business storage roots confirm delivery, Trace Intake removes the remote Twilio recording. Delivered business copies follow the business's own retention and access rules. A caller's access, correction, or deletion request about a delivered recording must normally be handled by the business that received the call.
Trace Intake Answering Service is inbound business intake. It is not a 911, emergency, dispatch, medical, crisis, or life-safety service and must not be presented or relied on as one.
Cancellation, retention and deletion draft
Other subscribed modules continue. The cancelled module stops accepting new work at the end of its access period, while its setup and records on the business system remain in place for an easier return. Trace Intake does not delete delivered business records because a module is cancelled.
For Answering Service, the customer must separately choose whether to keep the Twilio number and accept the disclosed ongoing number-holding cost, or release the number and stop that provider cost. A released number may not be recoverable.
The commercial cancellation flow will provide two choices:
Billing, transaction, tax, accounting, fraud-prevention, security, dispute, consent, and legal-compliance records may be retained for the period reasonably required by law, provider rules, limitation periods, or an active dispute. A deletion receipt must explain what was deleted, what remains, why, and the expected completion date without exposing credentials.
Enabled providers may retain limited information under their own verified retention and legal obligations. Trace Intake cannot delete information that remains only on the customer's own drives; those files stay under the customer's control.
The private beta is owner-assisted. Authenticated self-service cancellation, 90-day restoration, provider cleanup, audit receipts, and permanent deletion must pass the documented release gates before public checkout opens.
Private-beta use draft
The private beta is provided for feedback and acceptance testing. Commercial warranties, service levels, support response times, limitation-of-liability language, indemnities, refund rules, and governing-law terms are not finalized and are not implied by this draft.
Access, correction and concerns
An individual may ask whether Trace Intake owner systems hold personal information about them and may request access or correction, subject to identity verification and applicable legal exceptions. Requests concerning a lead, recording, transcript, document, inventory record, or other file already delivered to a business should normally be directed to that business because Trace Intake owner systems do not hold the operational copy.
Private-beta testers use the direct owner-assisted channel supplied during onboarding for privacy questions, access or correction requests, cancellation, deletion, and incident reporting. Before commercial sales, William Osborne must designate the accountable Privacy Officer, publish a verified privacy email and mailing address, describe the response and complaint process, and identify any applicable regulator escalation route.
If a concern is not resolved directly, individuals may be able to contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada, depending on which law and organization apply.
What happens next
Tester feedback can improve clarity, but commercial policies will not be labelled final until the missing contact, support, billing, provider-review, and legal decisions are complete.