Who controls the business records?
The subscribing business controls the submissions, caller information, recordings, transcripts, summaries, documents, inventory, legacy records, client and project records, and storage locations used in its work. The installed Trace Intake program handles that information for the business and writes it to the computer, network folders, and business drives selected during setup.
The business is responsible for having a lawful reason to collect and use information from its own customers, workers, callers, and other individuals; giving any notices and choices its activities require; deciding who on its team can access the delivered records; and maintaining appropriate business backups and retention rules.
What does the Trace Intake owner system keep?
The owner system keeps only information needed to operate the account and paid or sponsored service:
- business, billing, and verified account-contact name and email;
- Stripe customer, subscription, purchase, invoice, refund, and transaction references;
- selected modules, entitlement status, access dates, and renewal or cancellation state;
- installation, account, grant, and access identifiers or secure hashes;
- the approved HTTPS connection address used by an installation;
- expiry, last-connection, usage-limit, spending-limit, and aggregate cost information;
- OpenAI project and Twilio subaccount or telephone-number references; and
- release version, service-health timestamps, security events, and technical incident codes.
The owner dashboard is not designed to store form answers, lead contact details, caller recordings, transcripts, attachments, customer documents, inventory line items, legacy files, or business folder paths.
Why is owner-side information used?
Owner-side information is used to authenticate access, provide selected modules, administer private-beta grants, manage subscriptions and refunds, enforce provider limits, secure callbacks and installations, respond to support or privacy requests, investigate technical or security incidents, meet accounting and legal obligations, and understand aggregate service health. It is not sold or used to build advertising profiles.
Marketing site information
The current website has no advertising tracker, analytics service, contact form, public account creation, or checkout. Cloudflare provides HTTPS, delivery, and security and may process ordinary request information such as IP address, browser details, requested page, security signals, and timestamps under its own terms. No application ZIP or business record is served from this marketing site.
Safeguards
Safeguards include separate credentials for approved testers, encrypted local provider credentials, verified Stripe and Twilio callbacks, narrow owner-dashboard fields, spending limits, expiring grants, suspension and revocation controls, least-access provider projects or subaccounts, HTTPS, restrictive website security headers, and tests that block credentials and business records from release packages.
No system can promise absolute security. Suspected unauthorized access, loss, or disclosure must be contained, investigated, documented, and assessed for required customer, individual, provider, insurer, or regulator notice.