Privacy Policy
MAPFLOW RECEPTION
PRIVACY POLICY
Effective Date: July 29, 2026 | Last Updated: July 29, 2026
This Privacy Policy applies to website visitors, prospective and current business customers, authorized customer personnel, and callers who interact with a receptionist powered or managed by MapFlow Reception. It should be read together with our Terms of Service and any plan-specific order or checkout terms.
1. Scope and Our Role
For website, prospect, account, billing, support, and business-administration information, MapFlow Reception generally determines why and how the information is used.
For information collected during calls on behalf of a business customer, MapFlow Reception generally processes that information to provide the receptionist service according to the customer’s instructions. The business customer may have its own privacy obligations to callers and remains responsible for its business practices, service delivery, and use of information delivered to its accounts.
We may separately use limited service data for billing, security, fraud prevention, quality assurance, troubleshooting, enforcing agreements, and complying with law.
2. Information We Collect
A. Website Visitors and Prospective Customers
When a business owner or representative visits our website, requests information, uses a pre-purchase contact form, or contacts us, we may collect:
name, business name, email address, telephone number, and optional message or question;
information submitted when requesting a demonstration, consultation, or support;
Internet Protocol address, browser type, device information, operating system, approximate location derived from an IP address, referral source, pages viewed, and interaction data;
cookie identifiers and basic website analytics information; and
communications and records of our response.
B. Customer Account and Onboarding Information
When a customer purchases or configures the service, we may collect:
legal and public business names, owner or authorized contact information, website, business telephone number, and service-area information;
business hours, services offered, service limitations, approved price ranges, frequently asked questions, pronunciation guidance, and other approved information the receptionist may communicate;
call-handling instructions, scheduling preferences, emergency and escalation rules, preferred calendar, and the telephone number designated to receive operational text alerts;
plan selection, included usage, overage rate, subscription status, invoices, payment status, and Terms acceptance records;
documents or text supplied for configuration, such as service lists, call scripts, FAQs, and business policies; and
technical information needed to connect telephone routing, calendar, messaging, and automation systems.
Customers should not submit account passwords, Social Security numbers, government identification, bank-account credentials, complete payment-card numbers, medical records, or other highly sensitive information through an intake form unless MapFlow Reception has expressly approved the collection method in writing.
C. Caller and Call Information
When a person calls a business using the service, we may collect or process:
caller ID, telephone number, call date, start and end time, connected duration, and technical call metadata;
the caller’s name, service address or location, requested service, description of the issue, urgency, preferred appointment time, and other information the caller chooses to provide;
the caller’s response to the recording and transcription disclosure;
an audio recording and machine-generated transcript when the caller consents;
a concise structured call summary, call status, and operational notes;
tentative appointment information written to a connected calendar; and
delivery records for operational alerts sent to the customer.
The service is not designed to collect payment-card credentials, Social Security numbers, financial-account credentials, health records, or other highly sensitive or specially regulated information from callers. Callers and customers should not provide such information through the service.
D. Payment Information
Payments are processed by Stripe or another payment processor. MapFlow Reception generally does not receive or store complete payment-card numbers. We may receive billing contact information, the last four digits and type of a payment method, payment status, transaction identifiers, subscription plan, invoices, refunds, disputes, and related records.
E. Support and Communications
We collect information contained in emails, support requests, onboarding discussions, technical reports, and other communications. We may record the date, time, participants, and resolution of support matters.
3. Sources of Information
We collect information:
directly from website visitors, customers, authorized customer personnel, and callers;
from business customers that configure the receptionist and provide instructions or connected-account details;
automatically from the website, telephone systems, and service logs;
from service providers that support payments, call processing, voice generation, messaging, calendars, hosting, analytics, and automation; and
from publicly available business sources when reasonably necessary to verify or configure customer-provided business information.
4. How We Use Information
We may use personal information to:
operate, configure, test, maintain, and improve the receptionist service;
answer inbound calls, collect service-request details, produce structured summaries, create tentative calendar requests, and send operational alerts;
respond to questions, provide demonstrations, onboard customers, and deliver support;
process subscriptions, calculate connected call usage, assess overages, issue invoices, collect payments, and resolve billing disputes;
verify customer instructions and investigate technical problems, complaints, fraud, abuse, or security incidents;
conduct limited quality assurance and improve our internal prompts, call flows, workflows, and service reliability;
communicate service notices, billing information, policy updates, and administrative messages;
comply with law, legal process, regulatory obligations, and enforceable governmental requests;
enforce our agreements and protect the rights, safety, security, and property of MapFlow Reception, customers, callers, and others; and
create aggregated or de-identified statistics that do not reasonably identify a person or business.
We do not use identifiable caller recordings, transcripts, or summaries to train a public or general-purpose artificial intelligence model. We may use de-identified or aggregated service metrics to understand and improve system performance.
5. Automated and AI-Enabled Voice Technology
Calls may be answered using automated and AI-enabled speech, language-processing, and synthetic-voice technology. The receptionist must respond truthfully if a caller asks whether it is automated or AI-powered.
Automated systems can misunderstand speech, produce inaccurate information, or fail. Customers remain responsible for reviewing summaries, confirming tentative appointments, monitoring urgent alerts, and following up with callers.
6. Call Recording, Transcription, and Consent
Before a recorded intake begins, the receptionist is configured to provide a short disclosure substantially similar to: “Just so you know, this call will be recorded and transcribed for customer care and to prepare notes for the plumbing team. Is that okay?” The exact wording may vary to reflect the customer’s business and applicable law.
The receptionist should proceed with the recorded intake only after an affirmative response such as “yes,” “okay,” or an equivalent indication of consent.
If a caller declines:
the receptionist should not continue collecting a recorded service intake;
the system may use the telephone number displayed through caller ID to notify the customer that a callback was requested;
the caller may be told that the business will be notified; and
the call should end if the platform cannot stop recording or transcription during the call.
Recordings and transcripts are not routinely shared with the customer. Access is limited to legitimate operational purposes such as quality assurance, troubleshooting, investigating a complaint, resolving a dispute, security, legal compliance, or a separately approved written request.
7. Structured Call Summaries and Connected Customer Systems
After a call, workflow automation may extract selected information and create a concise operational summary. The summary may include the caller’s name, telephone number, service address, issue, urgency, preferred appointment time, status, and brief notes. We do not intentionally copy the full transcript into Google Sheets.
Depending on the customer’s configuration, summaries and related information may be:
written to a Google Sheet or another customer record system;
included in a tentative Google Calendar event;
sent by operational SMS to the telephone number designated by the customer; and
processed through n8n or comparable workflow-automation infrastructure.
Copies delivered to a customer-controlled Google account, calendar, spreadsheet, telephone, email account, or other system are controlled by that customer and may remain there until the customer deletes them. MapFlow Reception cannot guarantee deletion from customer-controlled systems, backups, screenshots, forwarded messages, or other copies outside our control.
8. Operational Text Messages
MapFlow Reception and its messaging providers may send automated operational text messages to a telephone number supplied by the customer. These messages may include new-call summaries, urgent-call alerts, appointment-request details, service notices, and onboarding or support communications. They are not intended as marketing messages to callers.
Customers are responsible for supplying a number they own or are authorized to enroll and for notifying any employee or other user of that number. Message and data rates may apply. A request to stop text alerts does not by itself cancel the customer’s subscription or other service obligations.
9. How We Disclose Information
We may disclose information in the following circumstances:
A. To the Business Customer
We disclose caller summaries, tentative appointment details, operational alerts, and related service information to the business customer and the customer-designated recipients for whom the receptionist is operating.
B. To Service Providers
We use service providers and infrastructure vendors to operate the service. Depending on configuration, these may include:
Hostinger or another website, hosting, analytics, or form provider;
Stripe or another payment processor;
Retell AI or another call-processing and conversational platform;
ElevenLabs or another speech-recognition, language-processing, or synthetic-voice provider;
Twilio and other telecommunications carriers or messaging providers;
Google Workspace services, including Google Calendar, Google Sheets, and email;
n8n and self-hosted or cloud-hosted workflow-automation infrastructure, including AWS Lightsail or comparable hosting;
security, fraud-prevention, monitoring, support, and professional-service providers; and
authorized contractors who require limited access to perform services and are subject to confidentiality or contractual restrictions.
These providers may process information under their own terms and privacy practices. We may replace a provider or use a comparable provider as our technology changes.
C. Legal, Safety, and Enforcement Reasons
We may disclose information when we reasonably believe disclosure is necessary to comply with law or legal process; respond to a valid governmental request; investigate fraud, abuse, or security incidents; enforce agreements; collect undisputed overdue amounts; or protect the rights, safety, and property of MapFlow Reception, customers, callers, or others.
D. Business Transfers
If MapFlow Reception is involved in a merger, acquisition, financing, sale of assets, reorganization, or transfer of the business, information may be disclosed or transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
E. With Consent or Direction
We may disclose information when a person or customer directs us to do so or provides consent.
10. No Sale of Personal Information or Targeted Advertising
MapFlow Reception does not sell personal information. We do not rent caller information, use caller information for third-party advertising, or use caller information for cross-context behavioral advertising. We do not send marketing messages to callers based on information collected through a service call.
We may use a customer’s business contact information to administer the customer relationship and communicate about MapFlow Reception services. A customer may opt out of optional promotional emails while continuing to receive transactional, billing, security, and service communications.
11. Cookies, Website Analytics, and Tracking
Our website may use cookies and similar technologies that are necessary for security, navigation, forms, checkout, and basic performance measurement. We may use Hostinger analytics or another basic analytics provider to understand traffic and improve the website.
At launch, we do not intend to use caller information for advertising pixels or cross-site behavioral advertising. If we later add nonessential analytics, advertising pixels, session-replay tools, or similar technologies, we will update this policy and provide any consent or opt-out mechanism required by applicable law.
Some browsers offer a “Do Not Track” setting. Because there is no universally accepted technical standard for responding to Do Not Track signals, our website does not currently respond to them. We do not currently sell or share personal information for cross-context behavioral advertising. If our practices change and applicable law requires recognition of a legally valid opt-out preference signal, we will implement an appropriate process.
12. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this policy, to satisfy customer instructions, resolve disputes, maintain business and tax records, protect the service, enforce agreements, and comply with law. Retention may vary by information type, customer configuration, and service provider.
Raw call recordings and machine-generated transcripts maintained in the call-processing platform are generally retained for up to 30 days and then scheduled for automatic deletion, unless a shorter period is configured or limited additional retention is reasonably necessary for a complaint, dispute, security incident, legal hold, or legal obligation.
Structured call summaries and connected-system records may be retained throughout the customer relationship and for a reasonable period afterward for service continuity, support, disputes, account closure, and legitimate business or legal purposes. Some records may remain longer at the customer’s request or in customer-controlled systems.
Customer configuration and onboarding information is generally retained for the customer relationship and a reasonable transition period after termination, unless longer retention is needed for reactivation, support, disputes, or legal obligations.
Billing, transaction, invoice, tax, contract, and consent records may be retained for up to seven years or longer when required by law or reasonably necessary to establish, exercise, or defend legal claims.
Operational SMS records, system logs, and data maintained by third-party providers are retained according to our account settings and the provider’s applicable retention practices.
Aggregated or de-identified information may be retained for longer because it does not reasonably identify a person.
Deletion from our active systems may not immediately remove information from disaster-recovery backups, security archives, or service-provider systems, where information may remain until ordinary deletion cycles complete.
13. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. Measures may include restricted account access, strong passwords, multifactor authentication where available, secure service-provider accounts, limited retention, access controls, encrypted transmission where supported, monitoring, and investigation of suspected incidents.
No method of transmission, storage, or automated processing is completely secure or error-free. We cannot guarantee absolute security. Customers are responsible for securing their own accounts, devices, calendars, spreadsheets, telephone numbers, and recipients of operational messages.
14. Customer Responsibilities and Restricted Information
Customers must provide accurate instructions, maintain lawful authority over connected accounts and telephone numbers, limit access to authorized personnel, and use caller information only for lawful business purposes. Customers are responsible for any privacy notices, permissions, and industry-specific requirements that apply to their business beyond the recording and transcription disclosure provided through the service.
Unless MapFlow Reception gives prior written approval and an appropriate additional agreement is in place, customers may not intentionally configure the service to collect or process:
Social Security numbers, government identification numbers, passwords, authentication codes, or financial-account credentials;
complete payment-card information;
medical records, protected health information, or information subject to HIPAA;
information regulated by specialized financial, insurance, education, employment, or health-privacy laws; or
other highly sensitive information not reasonably necessary for routine call intake.
15. Your Privacy Choices and Requests
Subject to applicable law and reasonable verification, a person may contact support@mapflowmarketing.com to request:
access to or a description of personal information MapFlow Reception maintains about the requester;
correction of inaccurate information;
deletion of information controlled by MapFlow Reception;
an explanation of how information was used or disclosed; or
withdrawal from optional promotional communications.
To protect privacy, we may verify a requester using information such as the telephone number used during a call, approximate date and time of the call, the business called, caller name, email confirmation, account information, or other reasonably necessary details. We will not provide call information to someone we cannot reasonably verify.
A deletion request may be limited where retention is reasonably necessary for billing, taxes, fraud prevention, security, disputes, legal compliance, enforcing agreements, or another lawful purpose. We cannot delete copies controlled by a customer or another independent third party. We may retain de-identified information that cannot reasonably be linked to the requester.
16. California Privacy Notice
California law may provide residents with privacy rights depending on the law and whether it applies to MapFlow Reception. The California Consumer Privacy Act applies only to businesses meeting specified statutory thresholds. Regardless of whether those thresholds apply, we accept reasonable access, correction, and deletion requests as described above, subject to verification and lawful exceptions.
During the preceding 12 months, the categories of personal information we may have collected include identifiers; customer records; commercial and transaction information; Internet or electronic network activity; audio information; approximate geolocation derived from an IP address and service addresses supplied for a service request; professional or employment-related business information; and inferences or operational summaries derived from call content.
We collect, use, and disclose those categories for the business and commercial purposes described in this policy. We do not sell personal information or share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes of inferring characteristics about a person.
We will not discriminate against a person for exercising a privacy right provided by applicable law.
17. Children’s Privacy
The website and service are intended for business and commercial use and are not directed to children under 13. We do not knowingly collect personal information directly through the website from children under 13. A child may be incidentally mentioned or present during a household service call; the service is not intended to create profiles about children. If you believe a child under 13 submitted personal information directly to us, contact support@mapflowmarketing.com.
18. United States Processing
MapFlow Reception is operated from California, United States. Information may be processed and stored in the United States and other locations where our service providers operate. Those locations may have different data-protection laws than the person’s state or country of residence.
19. Third-Party Websites and Services
Our website and service may link to or integrate with third-party websites and services. Their privacy practices are governed by their own notices and agreements. MapFlow Reception is not responsible for the independent privacy or security practices of a customer, Google, Stripe, Retell AI, Twilio, a voice provider, a telecommunications carrier, or another third party.
20. Changes to This Privacy Policy
We may update this Privacy Policy as our service, technology, providers, or legal obligations change. We will post the updated policy on our website and revise the “Last Updated” date. If a material change significantly affects how we use client or caller information, we may provide additional notice to active customers by email, account notice, checkout notice, or another reasonable method. Material changes will apply prospectively unless otherwise required by law or consented to by the affected person.
21. Contact Us
For privacy questions, requests, or complaints, contact:
This Privacy Policy is intended to describe MapFlow Reception’s current privacy practices. It is not a substitute for legal advice regarding a customer’s own privacy obligations.