1. Scope and roles
This draft applies to information handled by the Trace Intake private-beta website, account controls, sponsored access service, and installed modules. The subscribing or testing business controls the operational information it collects from customers, callers, workers, suppliers, and other individuals. The installed program processes that information for the business and writes it to storage locations the business selects.
The Trace Intake owner system administers access, billing readiness, provider resources, limits, and general service health. It is deliberately designed not to receive the operational contents of customer files.
2. Information handled
On the business system
The installed program may handle company settings, routing rules, selected storage locations, submissions, attachments, caller identity, recordings, transcripts, summaries, client and project records, inventory information, legacy files, review markers, audit receipts, and encrypted provider credentials.
On owner systems
- business, billing, and verified account-contact name and email;
- Stripe customer, subscription, purchase, invoice, refund, and transaction references;
- module entitlements, access status, renewal and cancellation dates;
- installation, grant, account, and access identifiers or secure hashes;
- approved HTTPS connection address;
- expiry, last-connection, usage, spending-limit, and aggregate provider-cost information;
- OpenAI project, Twilio subaccount, and telephone-number references; and
- release version, service-health timestamps, security events, and technical incident codes.
Excluded from the owner dashboard
Form answers, lead contact details, call audio, transcripts, attachments, customer documents, inventory line items, legacy files, and business folder paths are not owner-dashboard fields.
Website requests
The website has no advertising tracker, analytics product, public contact form, signup, or checkout. Cloudflare may process ordinary request and security information such as IP address, browser details, requested URL, timestamps, and threat signals.
3. Purposes
Owner-side information is used only to authenticate access, administer private-beta grants, provide selected modules, prepare or manage billing, enforce provider limits, secure callbacks and installations, respond to support and privacy requests, investigate technical or security incidents, meet accounting or legal duties, and evaluate aggregate service health. It is not sold, rented, or used to build advertising profiles.
A material new purpose must be identified before the information is used. Fresh consent or customer approval will be obtained where required.
4. Providers and processing countries
Enabled features may send the minimum necessary information to providers in Canada, the United States, and other countries where those providers or their subprocessors operate. Information processed outside Canada may be subject to the laws and lawful-access processes of that country.
- Cloudflare: HTTPS, website delivery, Tunnel connectivity, traffic protection, and technical request information.
- Stripe: future checkout, subscription, invoices, refunds, payment handling, fraud prevention, tax, and accounting. Trace Intake does not store full payment-card details.
- Twilio: telephone-number provisioning, call connection, keypad selections, temporary recording, signed callbacks, and provider usage/cost information.
- OpenAI: bounded transcription, classification, and structured-summary tasks. API business inputs and outputs are not used for model training by default; provider abuse-monitoring and retention rules still apply.
- Customer-selected storage: Google Drive, OneDrive, Dropbox, or another synchronized folder is optional and governed by the business's own account and provider choices.
Provider roles, current official policy links, data-processing terms, and subprocessor lists are maintained in the Third-Party Provider Directory.
5. Retention and deletion
Active account information is kept while needed to provide and secure the selected service. After full cancellation, the customer will choose either eligible profile/setup retention for up to 90 days, with an exact scheduled deletion date, or immediate eligible owner-side deletion after a second confirmation.
Billing, transaction, tax, accounting, fraud-prevention, security, dispute, consent, and legal-compliance records may remain for the period reasonably required by law, provider rules, limitation periods, or an active dispute. Providers may retain limited information under their own verified obligations.
Trace Intake does not delete business records already delivered to customer-controlled computers, folders, networks, or drives. Twilio recordings are removed remotely after both configured business storage roots confirm delivery; delivered copies follow the business's retention rules.
6. Safeguards and incidents
Safeguards include HTTPS, encrypted local provider credentials, isolated tester projects or subaccounts, signed Stripe and Twilio callbacks, expiring grants, spending limits, suspension and revocation, narrow administrative fields, restrictive website headers, release allowlists, and automated checks that block credentials and business records from packages.
No service can promise absolute security. A suspected loss, unauthorized access, use, or disclosure must be contained, investigated, documented, and assessed for any required notice to affected customers, individuals, providers, insurers, or regulators.
7. Access, correction and concerns
An individual may ask whether owner systems hold personal information about them and request access or correction, subject to identity verification and legal exceptions. A request about an operational submission, call, recording, document, inventory item, or legacy record should normally go to the business that collected it because that business holds the delivered copy.
Private-beta testers use the direct owner-assisted channel supplied during onboarding. Before sales open, a working public privacy address, mailing address, response process, accountable Privacy Officer, and complaint-escalation information must appear here.
8. Changes and contact
Material changes will be dated, explained, and presented before they apply where notice or consent is required. This draft does not create a commercial contract. The final version must be reviewed for the actual provider configuration, product launch location, and applicable law.