1. Introduction
This Privacy Policy describes how HandyMack Tech & Home Services LLC, doing business as StrideVoice (“StrideVoice,” “we,” “us,” or “our”), collects, uses, stores, and shares information in connection with our AI phone agent platform at stridevoice.com and console.stridevoice.com (the “Services”).
StrideVoice operates in two distinct roles with respect to personal data:
- As a data controller with respect to information provided by our Customers (the home service contractors — including HVAC, roofing, plumbing, electrical, handyman, and painting professionals — who subscribe to our platform) when they register accounts, configure services, and interact with our dashboard.
- As a data processoron behalf of our Customers with respect to personal data of third-party callers processed through the AI phone agent functionality. In this context, the Customer is the data controller and StrideVoice processes caller data at the Customer’s direction.
Please read this Policy carefully. By using the Services, Customers acknowledge and agree to the practices described herein.
2. Information We Collect
2.1 Information Customers Provide
- Account information: Name, business name, email address, phone number, business address, trade vertical (HVAC, Roofing, Plumbing, Electrical, Handyman, or Painting), and billing information collected during registration and account management.
- AI agent configuration:Business descriptions, services offered, pricing ranges, operating hours, frequently asked questions, custom instructions, and any other information entered into your agent’s knowledge base.
- Knowledge base documents: PDFs, documents, website URLs, and other files uploaded to configure your AI agents with business-specific knowledge.
- Payment information: Payment card details and billing address. Note: full card numbers are processed and stored by our payment processor, Stripe; we retain only tokenized payment references.
- Support communications: Emails, messages, and any other communications you send us.
- Integration credentials: API keys or OAuth tokens for third-party integrations (e.g., Google Calendar, CRM systems), encrypted at rest before storage.
2.2 Information Processed on Behalf of Customers (Caller Data)
When a caller contacts a Customer’s AI agent, we process the following information on behalf of the Customer:
- Caller phone number:The caller’s telephone number as delivered by the telecommunications network (CLID/ANI data).
- Voice recordings: Audio recordings of the call, if recording is enabled and legally permitted.
- Transcripts: Text transcriptions of the conversation generated by our speech-to-text processing.
- Inferred information: Caller name (if stated or available), service requested, appointment preferences, and other information derived from the conversation.
- Call metadata: Call timestamp, duration, call status, detected language, and AI-generated summaries.
2.3 Automatically Collected Information
- Usage data: Log data including IP addresses, browser type, pages visited in the dashboard, features used, and timestamps.
- Device information: Operating system, device type, and browser version.
- Cookies and tracking technologies: As described in our Cookie Policy at stridevoice.com/cookie-policy.
3. How We Use Information
We use Customer account information to:
- Provide, maintain, and improve the Services;
- Process payments and manage subscriptions;
- Send transactional communications (account confirmations, billing receipts, call summary notifications);
- Respond to support requests;
- Monitor service integrity and detect fraud or abuse;
- Comply with legal obligations;
- Analyze usage patterns to improve product features — using aggregate, de-identified data only; we do not use individual call content to train AI models without explicit consent.
We use caller data processed on behalf of Customers solely to:
- Operate the AI phone agent and facilitate the Customer’s call handling;
- Generate transcripts, summaries, and call logs for delivery to the Customer;
- Store recordings in accordance with the Customer’s configuration and applicable retention settings;
- Detect technical issues and improve service reliability.
4. Call Recording and Transcription
4.1 Customer Control
Call recording is controlled by the Customer and is enabled by default. Customers can disable recording for each AI agent through the dashboard. Every AI-answered call opens with a platform-level greeting that identifies the agent as an AI assistant and discloses that the call may be recorded; this disclosure cannot be disabled. If a caller verbally declines recording during a call, recording is stopped for that call and the caller’s choice is logged. Customers remain solely responsible for ensuring that recording is conducted lawfully, including obtaining any additional consent required from callers under applicable law.
4.2 Storage
Call recordings are stored and encrypted at rest by Telnyx using AES-256 encryption. Access to recordings is restricted to authenticated Customer accounts and StrideVoice personnel with a legitimate need for access.
4.3 Retention
The default retention period for call recordings is 90 days from the date of the call. Customers may configure longer or shorter retention periods within the limits of their subscription plan. Upon expiration of the retention period, recordings are automatically deleted from our systems.
Call transcripts and call summaries are retained for 365 days by default, configurable by the Customer; a nightly retention job removes transcript and summary content older than the configured window. Call metadata (timestamps, duration, outcome) is retained for the duration of the Customer’s subscription plus 30 days after termination, to allow Customers to export their data before deletion. Following account closure and the export window, call data is deleted or anonymized.
4.4 Automated Transcript Redaction
All call transcripts are processed through automated sensitive-data detection before storage. This system identifies and permanently redacts the following categories of information from transcripts:
- Credit and debit card numbers (validated using the Luhn algorithm to avoid false positives);
- Card security codes (CVV/CVC);
- Card expiration dates mentioned near card-related context;
- Social Security numbers;
- Bank account and routing numbers.
Redaction occurs before the transcript is written to our database. The original unredacted text is never stored. Redacted values are replaced with tokens (e.g., [CARD_REDACTED]) so that the conversation context remains readable while the sensitive data is permanently removed.
4.5 Recording Purge on Detection
If sensitive financial data is detected in a call transcript, the associated call recording URL is automatically removed from our records. This prevents access to an audio recording that may contain spoken financial information, even though the text transcript has been redacted.
5. AI Processing and Caller Memory
5.1 AI Model Processing
StrideVoice uses third-party large language models (“LLMs”) to power AI phone agent conversations, generate call transcripts, and perform post-call analysis. When a call is processed by our platform:
- Live conversation processing (speech-to-text, the conversational LLM, and text-to-speech) is orchestrated and hosted by Telnyx on its AI platform. The specific conversational model may change as we tune the platform; conversation data for live calls is processed within Telnyx’s infrastructure;
- After each call, the redacted transcript is sent to Anthropic, PBC for post-call quality analysis, which extracts structured data including call intent, priority classification, caller sentiment, outcome, and quality score;
- StrideVoice does not use Customer call data to train, fine-tune, or improve third-party AI models. Our AI providers process call data solely for inference in the course of delivering the Services and are engaged under terms that do not permit use of that data for model training;
5.2 Caller Memory Profiles
StrideVoice maintains caller profiles on behalf of Customers to enable personalized service across multiple calls. When a returning caller contacts a Customer’s AI agent, the system may retrieve prior interaction context (such as the caller’s name, previous service requests, and appointment history) to provide a more helpful experience.
Caller memory profiles are:
- Stored per-Customer and subject to the same tenant isolation (row-level security) as all other Customer data — one Customer cannot access another Customer’s caller profiles;
- Derived from call transcripts and metadata processed on behalf of the Customer;
- Retained for the duration of the Customer’s subscription. Caller profiles are deleted when a Customer’s account is terminated, following the same retention schedule as other call data;
- Subject to deletion upon request from the Customer or from a caller who contacts the Customer to exercise their privacy rights.
5.3 Post-Call AI Analysis
After each call, the redacted transcript is sent to an AI model for quality analysis. This analysis produces structured data including a quality score, intent classification, caller sentiment, call outcome, priority level, and identified knowledge gaps. All post-call analysis is performed on redacted transcripts only — sensitive financial data is never sent to any AI model.
AI-generated insights (quality scores, sentiment, booking outcomes, knowledge gap reports) are stored per-Customer with the same tenant isolation guarantees as raw call data.
5.4 No Model Training on Customer Data
StrideVoice does not use caller data or call transcripts to train, fine-tune, or improve AI models. Our LLM providers process call data solely for real-time inference and post-call analysis, and do not retain it for model training purposes.
5.5 Automated Decision-Making
StrideVoice’s AI agents make automated decisions during calls, including classifying call urgency (emergency vs. routine), routing calls to appropriate agents or emergency contacts, and determining responses based on Customer-configured instructions. These automated decisions directly affect the caller experience. Customers are responsible for reviewing and configuring the rules that govern these automated decisions. No automated decisions are made that produce legal effects or similarly significant effects on callers without human oversight by the Customer.
6. Payment and Financial Data
StrideVoice does not collect, store, or process credit card numbers, CVVs, bank account numbers, or other payment card data. If a caller inadvertently speaks financial information during a call, our automated redaction system detects and permanently removes it from the transcript before storage (see Section 4.4).
All subscription payments are processed exclusively through Stripe, a PCI DSS Level 1 certified payment processor. StrideVoice never has access to your full card number — all payment data is handled directly by Stripe’s secure infrastructure. We retain only tokenized payment references for billing purposes.
Automated redaction is a best-effort security measure. While our system uses industry-standard pattern matching and Luhn validation, we cannot guarantee detection of every possible format or language in which financial data might be spoken. Customers should instruct their callers to use secure payment links rather than sharing card details verbally.
7. Caller Privacy
Individuals who call a Customer’s business number do not have a direct relationship with StrideVoice and have not agreed to StrideVoice’s Terms of Service. StrideVoice processes caller data solely on behalf of and at the direction of the Customer, who is responsible for ensuring lawful processing of caller data.
Callers should direct privacy requests to the business they called. If a caller contacts StrideVoice directly with a request to access, correct, or delete their call data (e.g., recordings or transcripts), we will forward the request to the Customer on whose behalf the data was collected. StrideVoice will assist Customers in responding to such requests as required by our Data Processing Agreement.
StrideVoice does not sell caller personal data. Caller data is not used for advertising, profiling, or any purpose other than providing the Services to the Customer.
Customers are required by our Terms of Service and Acceptable Use Policy to comply with applicable call recording disclosure laws, which may require an automated announcement at the start of each call informing callers that the call is being recorded by an AI agent.
8. Data Sharing and Sub-Processors
We do not sell personal information. We share data only as follows:
8.1 Sub-Processors
We use the following sub-processors to deliver the Services. Each sub-processor is bound by contractual data protection obligations consistent with this Policy and applicable law:
| Sub-Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Telnyx LLC | Telephony, STT/TTS, AI assistant orchestration, phone number provisioning, call recording storage, cloud storage for knowledge base documents | Call audio, call recordings, transcripts, caller phone numbers, call metadata, knowledge base documents | United States |
| Stripe, Inc. | Payment processing, subscription management, invoicing | Customer name, billing address, payment card information | United States |
| Supabase, Inc. | Database hosting, authentication, row-level security enforcement | Customer account data, agent configurations, call records and transcripts, tenant settings | United States |
| Cloudflare, Inc. | CDN, DDoS protection, WAF, DNS | Web traffic metadata | United States / Global CDN |
| Resend, Inc. | Transactional email delivery (account notifications, call summaries, billing alerts) | Customer email addresses, email content | United States |
| Anthropic, PBC | Post-call analysis only | Call transcripts, caller statements, conversation context | United States |
| Railway Corporation | Application hosting for customer dashboard and backend API | Customer account data, API requests, application logs | United States |
| Google LLC | Sign in with Google (OAuth), Google Calendar integration for appointment scheduling, Google Sheets call-log sync (each only when enabled by the Customer) | OAuth tokens, calendar event data, call summary rows synced to Customer-owned spreadsheets | United States |
| Functional Software, Inc. (Sentry) | Application error monitoring. Performance tracing and session replay are disabled to keep conversation content out of error reports | Error reports, stack traces, request metadata | United States |
| Telegram Messenger Inc. | Optional operator messaging bridge (only when the Customer connects Telegram): mirrors customer SMS threads to the Customer’s Telegram workspace | Caller phone numbers, SMS message content, call notifications | Global (Telegram-operated data centers) |
| Hetzner Online GmbH | Cloud server hosting for StrideVoice-managed workflow automation (post-call analysis routing, notifications, retention scheduling) | Redacted call transcripts, call metadata, notification content in transit | United States (Ashburn, Virginia) |
| Microsoft Corporation | Microsoft Calendar and Microsoft Teams integrations | OAuth tokens, calendar event data, meeting and routing metadata | United States |
| Infisical, Inc. | Secrets and environment variable management for application configuration | Application secrets, API keys (no Customer personal data) | United States |
8.2 Legal Requirements
We may disclose information if required to do so by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation; (b) protect the rights, property, or safety of StrideVoice, our customers, or the public; or (c) detect, prevent, or investigate fraud, security breaches, or technical issues.
8.3 Business Transfers
In the event of a merger, acquisition, asset sale, or reorganization, personal data may be transferred to the successor entity. We will provide notice of such a transfer and any material changes to this Privacy Policy.
9. Data Retention
We retain Customer account data for the duration of the subscription and for up to 30 days after account termination to allow data export. Following that period, account data is deleted or anonymized, except where we are required to retain it for legal, regulatory, or audit purposes (typically up to 7 years for financial records).
Call recordings are retained for 90 days by default, and call transcripts and summaries for 365 days by default, each configurable by the Customer within subscription limits and enforced by a nightly retention job. Call metadata is retained for the subscription term plus 30 days post-termination.
Customers may export their data at any time through the dashboard. Upon request following account termination, we will delete personal data within 30 days, except where retention is legally required.
10. Data Security
StrideVoice employs industry-standard technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption of data in transit using TLS 1.3;
- Encryption of call recordings at rest using AES-256;
- Encryption of sensitive credentials (API keys, integration tokens) using AES-256-GCM before database storage;
- Row-level security (RLS) enforcing tenant data isolation at the database level;
- Automated security alert emails on new logins, password changes, and authentication factor changes;
- Least-privilege access: production data access is limited to personnel who require it to operate the Services;
- Automated vulnerability scanning and dependency auditing on every build.
For a full description of our security practices, see our Security page at stridevoice.com/security. No system is perfectly secure, and StrideVoice cannot guarantee that unauthorized parties will never be able to defeat our security measures.
11. Your Rights
Depending on your location, you may have certain rights regarding your personal data:
- Access: The right to request a copy of the personal data we hold about you.
- Correction: The right to request that we correct inaccurate or incomplete personal data.
- Deletion: The right to request that we delete your personal data, subject to legal retention requirements.
- Portability: The right to receive your data in a structured, machine-readable format.
- Objection: The right to object to certain processing of your personal data.
- Restriction: The right to request that we restrict processing in certain circumstances.
To exercise these rights, contact us at [email protected]. We will respond within 30 days. Callers whose data was processed by an AI agent should direct requests to the business they called; we will assist that business in responding.
12. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). This section supplements our general Privacy Policy.
12.1 Categories of Personal Information Collected
In the preceding 12 months, StrideVoice has collected the following categories of personal information from Customers: Identifiers (name, email, phone number); Commercial information (subscription details, billing history); Professional information (business name, trade vertical); Internet activity (usage logs, IP addresses); Audio data (call recordings, where applicable); and Inferences drawn from the above.
12.2 Your California Rights
- Right to Know: You may request disclosure of the specific pieces of personal information we have collected about you, the categories collected, the categories of sources, the purposes for collection, and the categories of third parties with whom we share data.
- Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions (e.g., legal obligations, active transactions).
- Right to Correct: You may request that we correct inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: StrideVoice does not sell or share personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
12.3 Submitting CCPA Requests
To submit a verifiable consumer request, contact us at [email protected] with “CCPA Request” in the subject line. We will verify your identity before processing your request. We will respond within 45 days (extendable to 90 days with notice). Authorized agents may submit requests on your behalf with written authorization.
12.4 CCPA and Caller Data
StrideVoice acts as a service provider with respect to caller data under CCPA. Callers who are California residents and wish to exercise their CCPA rights with respect to call recordings or transcripts should contact the business that operates the AI agent (i.e., the Customer). StrideVoice will provide reasonable assistance to Customers in responding to such requests.
13. GDPR Notice
StrideVoice is currently a U.S.-based service targeting U.S. home service contractors. We do not actively market to or process data from individuals in the European Economic Area (EEA), United Kingdom, or Switzerland. If you are located in those regions and are using the Services, this section applies to you.
Where GDPR applies, we process personal data on the following legal bases:
- Contract: Processing necessary to provide the Services under our Terms of Service.
- Legal obligation: Processing required by applicable law.
- Legitimate interests: Security monitoring, fraud prevention, and service improvement.
- Consent: For optional features or communications where required.
EEA/UK individuals have the rights described in Section 11. You may also lodge a complaint with your local supervisory authority. Our Data Processing Agreement (stridevoice.com/dpa) addresses GDPR processor obligations, including the use of Standard Contractual Clauses where applicable for international data transfers.
Our principal data sub-processors (Telnyx, Stripe, Supabase, Cloudflare, Resend, Anthropic, Railway, Google, Microsoft, Sentry, and Infisical) process data in the United States, and our workflow automation infrastructure is hosted in Hetzner’s Ashburn, Virginia data center. The optional Telegram operator bridge is operated by Telegram Messenger Inc. globally. Data transfers are covered by applicable transfer mechanisms.
14. Children’s Privacy
The Services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us at [email protected] and we will take steps to delete such information.
If a child calls a Customer’s AI agent, we process that call on behalf of the Customer. Customers should configure their agents with appropriate disclosures and should not intentionally direct their agent services toward minors.
15. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will update the “Last updated” date above and, where required by applicable law, provide advance notice by email or through the Services.
Your continued use of the Services after the effective date of the updated Policy constitutes your acceptance of the revised Policy.
16. Contact
For privacy questions, data requests, or to report a concern, contact us at:
Privacy — HandyMack Tech & Home Services LLC, operating the StrideVoice productPhoenix, Arizona
Email: [email protected]