Privacy Policy
Last updated: June 4, 2026
Template — pending legal review.
This document is the bhildOs starting template. It will be reviewed by counsel before bhildOs takes its first paying customer. If you're evaluating bhildOs and need a counter-signed version, email legal@bhildos.com.
Who we are
bhildOs (operated by bhild Inc., a Florida company) provides an AI voice receptionist and intake CRM for construction service businesses. This Privacy Policy describes the personal data we collect, why we collect it, who we share it with, and the rights you have to access, correct, or delete it.
Personal data we collect
We collect personal data in three contexts:
- Marketing site visitors (bhildos.com) — browser and device data (IP address, user agent, referrer), cookies and local-storage values used for attribution, and any information you submit via web forms (name, email, company, phone, message).
- bhildOs customers (account holders and their team members) — account credentials (email, hashed password or magic-link token), business profile (company name, address, service area, business hours), team roster, integration tokens for connected services (Google Calendar, HubSpot, Stripe), and billing details handled by Stripe.
- End-callers (people who phone a bhildOs customer's number) — phone number, voice recording, transcript, the structured lead extraction (name, address, service type, project description), and any attribution identifiers (Google click ID, Meta click ID) tied to that call.
How we use it
We use personal data only to:
- Provide the AI receptionist + intake CRM service.
- Route end-caller leads to the correct estimator or crew, send SMS reminders, and book appointments.
- Fire conversion events back to ad platforms (Google Ads, Meta, Microsoft Ads, Google Business Profile) when a customer has connected them — this is documented per-tenant and disabled by default until a tenant configures it.
- Send transactional email (lead alerts, weekly digest, magic-link logins).
- Bill customers and prevent fraud.
- Improve product quality — specifically the AI receptionist's knowledge base, prompt construction, and lead-qualification model. Customer call transcripts are NOT used to train any general-purpose model.
- Comply with legal obligations.
Call recording disclosure
Calls answered by the bhildOs AI receptionist are recorded. The AI announces the recording at the start of every call. Customers in two-party consent states (California, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, Washington — non-exhaustive) should configure their bhildOs account to play the disclosure as the first sentence of the greeting; this is on by default.
Who we share it with
We share personal data only with the subprocessors listed at /subprocessors, with affiliates of bhild Inc., and only as required by law (subpoena, court order, national security request). Tenants' data is logically isolated using Postgres row-level security; subprocessors receive only the minimum data needed for their function.
Your rights
Depending on where you live you may have rights to access, correct, delete, port, or opt out of sale/sharing of your personal data:
- California (CCPA/CPRA) — request access, deletion, correction, or opt-out of sale/sharing. We do NOT sell personal data. Email privacy@bhildos.com with the subject line "DSR" and we will fulfill within 45 days.
- EEA / UK (GDPR / UK GDPR) — right to access, rectification, erasure, restriction, portability, and to lodge a complaint with your supervisory authority. Same email.
- End-callers — if you called a bhildOs customer and want your call recording or transcript deleted, contact either the business you called OR email us. We will route the request to the correct tenant.
Retention
Call recordings and transcripts are retained for 365 days by default; tenants can shorten or extend this in their account settings. Account data is retained for the life of the account plus 90 days after closure. Legal-hold flags override these defaults.
Security
We use industry-standard encryption in transit (TLS 1.2+) and at rest. Integration credentials (OAuth tokens, API keys) are encrypted with AES-256 using a per-environment master key. Access to production data is restricted to a small number of platform engineers, all of whom are subject to background checks and confidentiality agreements.
International transfers
bhildOs is operated from the United States. If you access bhildOs from outside the US your personal data will be transferred to and processed in the US. For EEA / UK transfers we rely on Standard Contractual Clauses (SCCs) as part of our DPA — see /dpa.
Children
bhildOs is a B2B product. We do not knowingly collect personal data from anyone under 16. If you believe a child's data is in our systems, email privacy@bhildos.com.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via email to account owners and announced on this page. The "Last updated" date at the top of the page reflects the most recent revision.
Contact
Questions, DSR requests, or breach-notification queries: privacy@bhildos.com. Postal mail can be sent to bhild Inc., Florida, USA — email for the current mailing address.