Privacy Policy
A few terms are still being finalised. They are marked Not settled yet below. Where a decision has not been made we say so, rather than state a number we would not stand behind. If one of them matters to you, email johnsontechstudio@gmail.com and we will tell you where it stands, in writing, before you rely on it.
This policy explains what Johnson Tech Studio LLC dba gig33 (“Johnson Tech Studio,” “we,” “us”) collects when you buy and use our service, why we collect it, who we share it with, and what you can ask us to do about it.
1. Two kinds of people are involved — read this part first
This service handles information about two different groups, and the rules are different for each:
- You, the business owner. We collect information about you and your business so we can build and run your service and bill you. This policy describes what we do with it, and for this information we are the one deciding what is collected and why.
- Your customers — the people who call your phone, chat on your website, or fill in your form. Their information passes through our system because you asked us to answer your phone and capture your leads. For that information, you decide what is collected and why, and we handle it on your behalf and on your instructions. The terms that govern how we handle it are in our Data Processing Addendum. You are responsible for telling your customers how you handle their information, and for having the right to give it to us. If your own privacy notice does not cover an AI answering your phone and writing down what callers say, it needs to.
If you are one of those callers or leads and you want your information removed, the fastest route is to ask the business you contacted. You can also email us at johnsontechstudio@gmail.com and we will pass it on and act on it where the record is ours to act on.
2. What we collect from you
- Your account: your email address. That is it — we do not use passwords. You sign in with a one-time link we email you.
- Your business details, from the setup form: business name, opening hours, service area, the services you offer, the reasons people contact you, the greeting you want callers to hear, when and to whom calls should be transferred (including those people’s names and phone numbers), how emergencies should be handled, your booking or scheduling links, your website address, what your chat should collect from visitors, the pages and content you want on your site, prices and policies you want the assistant to know, and anything you want the assistant to never say.
- Your phone setup: your existing business phone number, your phone carrier, your preferred area code, and when you want calls forwarded.
- How we reach you: the email address and mobile number you want lead alerts and summaries sent to, and how you want to be contacted about something urgent.
- Other people’s contact details you give us: if you ask us to send website install instructions to your web person, we collect and use that person’s email address.
- Your Google Business Profile link, if you paste it. This is a public link you type in. We do not connect to your Google account and we do not ask you to sign in to Google.
- Domain choices: the domain you want, or the one you already own, and your confirmation that your business should be its registered owner.
- Photos and your logo that you upload, and the descriptions you give us.
- What we read from your existing website. If you give us your website address, we visit up to five pages of it and pull out things like your business name, phone number, address, hours, services, and FAQs, so the assistant can be set up from your own information. We only read your own site, and only pages you can reach publicly.
- Your setup answers as you type them. We save your progress on our server so you can come back to it, and your browser also keeps a local copy so you do not lose your work.
- Change requests you send us, in your own words.
- Billing information. Stripe collects and holds your card details. We receive your email address, your business name, what you bought, the amounts, and whether payments succeeded or failed. We never see or store your full card number.
- Basic technical information needed to operate and troubleshoot the service, such as error reports and request logs.
We do not ask you for your business’s street address, your social media accounts, or your personal identification documents as part of setup.
3. Where the information comes from
- From you — the setup form, change requests, photos, and emails you send us.
- From the people who contact your business — callers, website chat visitors, and anyone who fills in a form on your site.
- From your own website, if you give us the address, as described above.
- From Stripe, which tells us whether a payment worked.
- From public business directories, including before a business becomes a customer, where the source allows it.
4. What we collect about your customers
This is the part most privacy policies are vague about. We are not going to be. If your plan includes the AI receptionist, chat, or lead follow-up:
- Phone calls to your AI receptionist are written down. We store a written transcript of what was said on the call, an AI-written summary of it, how the call ended, how long it lasted, and how many turns it took. You can read the full transcript in your account.
- We do not store a recording of the call, and we do not store the caller’s number from caller ID. Our telephone provider, Retell, runs the live call, hears the audio, and produces the transcript we store. Whether Retell keeps a copy of the audio on its own systems is governed by Retell’s settings and its own terms, not by ours. We have not published that setting here; ask us and we will tell you what it is set to on our account.
- Website chat conversations are stored in full — every message from the visitor and every reply.
- Lead records. When a caller or visitor asks you to get in touch, we store what they gave: their name, phone number, email address, the service they asked about, how urgent it is, and a note summarising what they need. A lead record is only created when someone leaves a phone number or an email address — without one there is no way to reach them, so there is nothing to store and we do not invent a contact. The conversation itself is still kept either way. We queue an alert containing the lead to the address you gave us for lead alerts, so treat anything in a lead as something that may travel by email to your inbox.
- Follow-up records, if you use Lead Recovery: which messages were sent to which lead, when, and whether they replied or asked to stop. People who reply STOP go onto a do-not-contact list that we keep so they are not messaged again.
- Call length and usage records for billing. These hold the length of the call and an internal call reference. They do not hold anybody’s name or number.
- Reviews and review requests, if and when that product is switched on: your customers’ names, phone numbers, email addresses, what service they bought and when, and whether they agreed to be contacted — plus the reviewer names and review text published on your Google listing. This is not switched on today.
The assistant is instructed to collect only what it needs — a name, a phone number, what the caller wants, how urgent it is, and an address when the job needs one — and never to ask for card numbers, bank details, Social Security numbers, or other sensitive information. It is not built for health records, and you should not configure it to collect them.
We also tell the visitor, not just the assistant. Instructing an AI not to ask does nothing about someone who volunteers a card number anyway — and whatever they type lands in the stored transcript. So both chat surfaces carry a visible notice asking people not to send passwords, full card numbers, Social Security numbers or other highly sensitive information, and saying why: what they type is sent to an AI service to be answered. If somebody sends one anyway, tell us and we will remove it.
Recording notice. The assistant tells callers that it is a virtual (AI) assistant, and it also tells them at the start of the call: “This call is recorded and transcribed, so we have a written copy.” That announcement always plays, on every call, and no business can switch it off — it is not a setup option and there is no setting for it. Some states require every party to a call to consent to being recorded, and we are not willing to transcribe a stranger’s call without telling them. We cannot advise any business on what its state requires, and the announcement playing is not a guarantee of compliance with any particular law.
Being told is not the same as being asked. The assistant announces that the call is recorded and transcribed and then carries on; it does not ask the caller to agree and it does not wait for an answer. We record, per conversation, whether that announcement was in force — not that anyone consented, because nobody was asked. We would rather say that plainly than let the word “consent” do work it has not earned.
5. Why we use it
- To build, host, run, and support your website, assistant, and follow-up.
- To answer your calls and chats and deliver your leads to you.
- To take payment, send invoices and receipts, and manage your subscription.
- To contact you about your service — setup, changes, problems, and billing.
- To keep records of opt-outs, do-not-contact requests, and what happened in your account.
- To keep the service secure, prevent abuse and fraud, and fix things that break.
- To meet our legal and tax obligations, and to resolve disputes.
We do not sell personal information. We do not use your business information, your call transcripts, or your customers’ details to train AI models of our own, and we do not share them with other customers. The AI companies listed below process the text in order to generate a response, under their own terms.
6. The companies we share it with
We use other companies to run parts of the service. Each one receives only what it needs for its part.
- Stripe — payments, subscriptions, invoices, and the billing portal. Receives your name, email, card details, business name, and the amounts charged.
- Supabase — our database, sign-in, and file storage. Nearly everything described in this policy is stored here, including your setup answers, your call transcripts and chat logs, your lead records, and your photos.
- Retell AI — the telephone and voice provider. It runs the live phone call, hears the caller’s audio, and produces the transcript and summary we store.
- Anthropic — the AI that writes the website chat’s replies, interprets the change requests you send us, and (when that product is switched on) drafts review replies. It receives the approved facts about your business, the visitor’s messages, and the text you type.
- OpenAI — used two ways. It converts questions and your approved business facts into a searchable form so the assistant can find the right answer, and it is the default language model that Retell runs the phone conversation on.
- Vercel — hosts the application and operates the AI gateway that routes our requests to Anthropic and OpenAI.
- Cloudflare — the registrar and DNS provider we use for domains. When a domain is registered for you, your business is recorded with the registrar as its owner, which means your business’s registrant details go to the registrar.
- Google — we use Google’s public business directory to look up publicly listed business information, including before a business becomes a customer. If and when the reviews product is switched on and you connect your listing, Google will also be the source of your reviews and the place replies are published.
- Unsplash — the stock photo library the sample pictures on your site come from. We choose those pictures ourselves in advance, and every one of them is fetched through our own server and served from our own address. Your visitors’ browsers never contact Unsplash, so it is never told who is looking at your site. If we add another stock library, we will name it here first.
- Our email provider — we send email (sign-in links, lead alerts, receipts, and follow-ups) through an email delivery service, which therefore handles the contents of those emails. We have not named the provider on this page; ask us and we will tell you which one we use.
- Error monitoring — error reports stay in our own server logs. We do not currently send them to a third-party error-monitoring service. If we start, we will name it here first.
Not settled yet — we have not finished verifying, for every company above, its exact legal entity, the region it stores data in, its own data-processing terms, how long it keeps things, and who it passes data to in turn. We are not going to state those as facts before we have checked them. Ask about a specific provider and we will tell you what we currently know and what we do not.
Text messaging is not switched on. When we do enable it, text messages will be sent through Twilio, and we will update this policy before that happens.
We also share information:
- with our own staff, who need access to build and support your service;
- with professional advisers — a lawyer, an accountant, an insurer — where they need it;
- when the law requires it, or to protect someone’s safety or our legal rights;
- with a buyer, if our business is sold or merged — we will tell you if that happens.
A referral partner who introduced you to us can see that you became a customer and what you bought, so they can be paid. Partners cannot see your call transcripts, your chat logs, or your customers’ contact details.
7. Cookies, tracking, and advertising
We use the cookies needed to keep you signed in and to remember your appearance preference. That is the whole of it.
- No advertising pixels, no cross-site tracking, no session replay. None is installed. When we locked down what the site is allowed to load, we checked the pages that are actually served and found no analytics package, no third-party tag, and no external tracker of any kind.
- We do not share your information, or your customers’, with advertising companies, and we do not use it for targeted advertising.
- If we ever add analytics or advertising technology, we will name it on this page and provide whatever choice the law requires, before it goes live.
Not settled yet — whether any of the above counts as a “sale” or a “share” under a particular state’s privacy law is a question we have not put to a lawyer. What we can tell you is the factual position above, which is what those definitions get applied to.
8. Where it is stored
Our providers store data in the United States. If you need the exact region a particular provider holds your data in, ask us and we will tell you.
This service is built and sold for businesses in the United States. We do not offer it as a service that meets European or United Kingdom data-protection requirements, and we do not have the transfer arrangements those regimes require. If your business needs them, this is not the right product for you yet, and we would rather tell you now.
9. How long we keep it — the honest answer
We do not currently delete anything on a fixed schedule. Call transcripts, chat logs, lead records, setup answers, and photos are kept until you ask us to delete them or your account is closed.
Since the last version of this policy we have built and scheduled a nightly routine that would remove the contents of old call and chat transcripts and keep only the summary. It runs every night — and it deletes nothing. It is deliberately set to rehearse: it counts what it would remove, writes that down, and stops. Turning it on for real takes two separate deliberate acts by a person, and neither has been done. So retention today is still indefinite, and we are not going to describe a schedule we are not keeping to.
These are the periods that routine is aimed at, so you can see where this is going:
- Call and chat transcripts — 90 days, then the text is removed and the summary kept. A shorter 30 days where we know a caller was never given the recording notice; that can only be a call from before the announcement became mandatory, because it cannot be switched off now.
- Lead records — not touched by that routine at all. Deleting a lead you paid to receive is a bigger decision than trimming a transcript, and it is not going to happen automatically without telling you first.
- Billing and tax records — kept for as long as the law requires.
- Do-not-contact records — kept for as long as we operate the service, because deleting an opt-out would mean somebody could be messaged again.
Not settled yet — none of the periods above is a commitment yet, and the ones the routine does not cover — lead records, setup answers, photos, account data, security logs — have no schedule at all. Until a schedule is actually running, this section keeps saying “until you ask us” rather than naming a number we do not yet keep to. You can ask us to delete any of it at any time — see the next section.
10. Your choices and your rights
You can ask us to:
- tell you what information we hold about you or your business;
- give you a copy of your business content and your lead records;
- correct anything that is wrong;
- delete your information, or a specific record — including a specific call transcript or lead;
- stop sending you marketing email (service and billing emails will continue while you are a customer).
Email johnsontechstudio@gmail.com from the address on your account and tell us what you want. We may need to check it is really you before we act. Some information we have to keep — billing records, and records we need to defend a legal claim.
If one of your customers asks you to delete their information, tell us and we will remove their lead record and the transcript of their conversation from your account.
We will not treat you worse for exercising a privacy right, and if we turn a request down we will tell you why and you can come back to us about it.
Depending on where you and your customers live, privacy laws may give additional rights, and may require us to respond within a set time. Not settled yet — we have not yet worked out which of those laws apply to us (several turn on revenue and volume thresholds), so this page states no response deadline and no formal appeal process. That takes no right away from you: if a law gives you one, you have it, and asking us is how you use it.
11. How we protect it
- Traffic to the service is encrypted in transit, and data is stored with our providers’ encryption at rest.
- Our database enforces per-business access rules, so one customer cannot read another customer’s leads or transcripts.
- Sign-in is passwordless. The links we email work once and expire after one hour.
- Where we hold an access token for a connected account, it is encrypted before it is stored, and our database refuses to store one that is not.
- Records of what happened in your account deliberately store references and reasons rather than names, phone numbers, or message contents.
One thing you should know about photos: images that appear on your website are served publicly, the same way any website image is. They live at long, unguessable addresses that cannot be browsed or listed, but anyone who has the exact address can view one. Do not upload anything you would not be willing to publish on your website.
No system is perfectly secure, and we cannot guarantee that one is.
12. Children
This is a service for businesses. It is not directed to children, and we do not knowingly collect personal information from children under 13. If you believe a child’s information has reached us through your service, tell us and we will remove it. Do not configure the service to collect information from children without asking us first.
13. Changes to this policy
We may update this policy. When we do, we will change the version and effective date at the top of this page, and if the change materially affects how we handle your information we will email you at the address on your account.
14. How to reach us about privacy
Privacy questions and requests: johnsontechstudio@gmail.com, or by post at Johnson Tech Studio LLC, 4319 Country Brook Dr, Dallas, TX 75287, United States. Not settled yet — we do not have a separate privacy mailbox or a self-service request form yet. The address above is a real, monitored inbox and is the right place to send a privacy request until one exists and is published here.
Privacy questions, or to make a request: johnsontechstudio@gmail.com