Legal

Privacy Policy

This policy explains how OpenDesk handles information when businesses and their customers use our AI-powered communications and operations service.

Effective September 18, 2026

Information we collect

  • Account and business information, such as names, email addresses, business details, team membership, services, hours, policies, and preferences.
  • Customer interaction data, such as phone numbers, messages, call audio when recording is enabled, transcripts, booking requests, support conversations, and related outcomes.
  • Integration data authorized by a business, including provider account identifiers, granted permissions, and tokens needed to operate connected services.
  • Payment and transaction details. Payment card information is handled by payment providers and is not stored directly by OpenDesk.
  • Technical data, such as IP address, browser and device information, timestamps, diagnostics, and security events.

How we use information

We use information to provide and secure the service; answer calls and messages; generate transcripts and summaries; schedule appointments; process authorized workflows; publish approved content; improve reliability; prevent abuse; provide support; and meet legal obligations. We do not sell personal information.

AI processing and communications

OpenDesk uses automated systems to understand requests and prepare or perform business-authorized actions. AI output can be incomplete or incorrect and should be reviewed when appropriate. Businesses are responsible for giving any notices and obtaining any consents required for recording, messaging, or automated communications in their jurisdiction.

Service providers and integrations

We share information only as needed with infrastructure, communications, AI, analytics, authentication, payment, and other service providers that help operate OpenDesk. When a business connects a third-party service such as Google, Meta, TikTok, Stripe, Supabase, Twilio, or another provider, information is also handled under that provider's terms and privacy policy.

Business customers and tenant isolation

Businesses control the information they submit and the workflows they enable. OpenDesk separates business data by tenant and applies access controls designed to prevent one business from accessing another business's information. A business may direct how we process its customer data, subject to law and our service agreement.

Retention and deletion

We retain information only while needed to provide the service, maintain security and records, resolve disputes, or satisfy legal requirements. Retention periods vary by data type and business configuration. Businesses may disconnect integrations and request account or personal-data deletion. See our Data Deletion Instructions.

Security

We use administrative, technical, and organizational safeguards designed to protect information, including encrypted secrets, authenticated server-side mutations, and tenant-scoped access controls. No system is completely secure, and we cannot guarantee absolute security.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information. You may also object to certain processing or withdraw consent where consent is the basis for processing. Requests can be submitted through your authenticated OpenDesk account or, for a business's customer, directly to that business.

Children

OpenDesk is a business service and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13.

Changes and contact

We may update this policy as the service or law changes. We will post the updated policy here and revise the effective date. Privacy questions and requests may be submitted through the authenticated OpenDesk dashboard.