Legal
Privacy.
What we collect, why we have it, who else touches it, and what you can make us do about it.
Last updated
1. Who we are
Orabeam LLC is a Delaware limited liability company. We build and operate Orabeam: a website, a customer database and an AI front desk licensed to local service businesses in the United States. We are the controller of the data described in section 3.1. For the data a licensed business puts into its own system — its customers, its bookings, its recordings — that business is the controller and we are its processor. We act on its instructions, not on our own initiative.
2. The short version
- We do not sell personal information, and we never have.
- We run no advertising trackers, no third-party analytics and set no cookies at all. Our own funnel measurement is described in section 3.1 and records nothing that identifies you.
- Calls handled by the AI front desk are recorded, and every call opens by saying so before anything else is said.
- A licensed business owns its data and can export all of it — including call transcripts — at any time, on any tier.
- We use aggregated, anonymized patterns to improve the product. We do not train models on your customers’ identifiable data, and we do not hand your data to a model provider for their training.
3. What we collect
3.1 If you visit orabeam.com
If you type a business name into the lookup, we send that name to the Google Places API and read the business’s own public profile — name, address, hours, photos, rating. That is public information about a business, and we use it to build the mockup you asked for.
If you talk to Beam, the sales agent on this site, we store the conversation along with anything you volunteer in it: your name, your business, your metro, your email address, your phone number. We store it because you are telling us you might want to buy something, and we would rather keep the thread than make you repeat yourself. You can ask us to delete it — see section 12.
Our host and CDN process request metadata, including your IP address, in order to serve and protect the site.
We measure our own funnel — how many people who read a page started the demo, how many who finished it reached the pricing. It is first-party and deliberately thin: no cookies, no advertising pixel, no session recorder, and no third-party analytics product.A random identifier is kept in your browser’s session storage and dies when you close the tab; it is not linked to you, and it is not a login. We record the page path without its query string, the trade a page was about, and the campaign that referred you. We do not record your IP address, your device, your screen, or anything you typed.
3.2 If you license Orabeam
We hold your account identity, your billing relationship (managed by Stripe — we never see or store a card number), the configuration you give us, the price book you import, and the records your business creates in the system: contacts, jobs, quotes, invoices, bookings, messages.
We also write usage events — how many minutes the agents spoke, how many messages were sent, which features ran. These are operational metering records. They are how the bill is calculated and how we know what the service costs to run.
If you bring your own model API key, it is encrypted at rest with AES-256-GCM and used only to make calls on your behalf.
3.3 If you call a business that uses Orabeam
You are not our customer, but your data passes through our system, so this section is for you.
When you call a business whose phone is answered by the Orabeam front desk, we process your phone number, the audio of the call, a written transcript of it, and whatever you tell the agent — your name, your address, the problem you are calling about, the appointment you book. That information belongs to the business you called. We hold it on their behalf.
If you reply to a text message from that business, we process the message and your number in the same way.
4. Call recording, and the notice you hear
Every call the agent answers is recorded, and every call opens by saying so before any other business is done. There is no configuration that turns that notice off, no state in the conversation where it is skipped, and no plan on which it is optional.
The reason is not politeness. California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, Pennsylvania and Washington require the consent of all parties to record a call, and in several of them recording without it is a felony. A product that made that notice a toggle would be a product that lets its own customers commit a crime by accident.
If you do not consent, say so or hang up. Recording stops with the call, and a caller who asks for the recording to be deleted should contact the business they called; the business can delete it, and we will act on their instruction.
5. What the agent will and will not do
The front desk quotes only from the price book the business imported, within limits the business sets. If it cannot find a price it says so and offers to have a person confirm, rather than estimating. It books against real availability. It does not make medical, legal or financial claims, and it does not diagnose.
It is an automated system and it says so when asked. It is not a human being and it does not pretend to be one.
6. Why we process it
- To provide the service. Answering the call, writing the booking, sending the confirmation, rendering the site. Without this processing there is no product.
- To bill correctly. Usage events, and Stripe.
- To keep it working and secure.Logs, error reports, abuse prevention. Our logs carry a tenant identifier and a trace identifier so a fault can be found without reading the contents of anybody’s conversations.
- To improve the product, in aggregate only. See section 8.
- To comply with the law, including the consent and messaging rules described in sections 4 and 7.
7. Messaging consent
We do not send marketing text messages to consumers, and the system will not let a licensed business do it either without a recorded basis. Outbound SMS goes only to people who have consented, every message supports STOP and HELP, and quiet hours are enforced. This is a Telephone Consumer Protection Act requirement and it is enforced in the software rather than written in a guideline.
Our own outbound email to prospective customers is commercial email under CAN-SPAM. Any such message will identify itself as such, carry a working unsubscribe link honoured within ten days, and carry our physical mailing address in the message itself, which is where the statute asks for it.
8. AI, and what we learn from you
Conversations are sent to a language-model provider for the duration of a turn so the agent can respond. We use providers under terms that prohibit training on our data, and we do not grant any provider the right to train on yours.
We do improve the product from what happens on it, and we want to be exact about the limits of that. We use aggregated and anonymized information — patterns, rates, distributions, the shapes of conversations that work and conversations that fail — across all businesses using Orabeam. Aggregated means combined across many businesses so that no single one is identifiable. Anonymized means personal identifiers are removed and not re-attached.
We do not use your customers’ identifiable data, your price book, your customer list or your recordings to build anything for anybody else. The corresponding grant of rights is in section 9 of the Terms, stated in the same words, because a learning right described one way in a privacy policy and another way in a contract is a learning right nobody can rely on.
9. Who else processes it
These are our subprocessors — the specific services that touch data in order for the product to work. “Trusted third parties” tells a reader nothing, so here is the list.
| Service | Region | What it sees, and why |
|---|---|---|
| Google Cloud (Cloud Run, Cloud Tasks, Secret Manager) | United States / EU | Runs the application and stores secrets. Sees whatever the application processes. |
| Supabase (Postgres) | United States | The database of record. Customer records, bookings, quotes, transcripts, usage events. |
| Cloudflare | Global edge | Serves and protects the sites. Sees request metadata and IP addresses in transit. |
| Stripe | United States | Payments. Sees billing identity and card data — we never see or store a card number. |
| Twilio | United States | Telephony and SMS. Sees phone numbers, call audio and message content. |
| Resend | United States | Transactional email: receipts, magic links, booking confirmations. |
| Loops | United States | Behavioral email: onboarding and product updates. Sees name and email address. |
| Anthropic and Google (Gemini) | United States | The language models behind the agents. See conversation content for the duration of a turn. |
| Mapbox | United States | Geocoding and travel-time estimates. Sees service addresses, not customer identities. |
| Google Places API | United States | Reads a business's own public Google profile when you look it up. |
We do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act.
10. How long we keep it
- While you are a customer, your business records are kept as long as you want them. You control deletion inside the product.
- Call recordings and transcripts follow the retention period the business configures. Where it sets none, our default is twelve months.
- If you stop paying, your data is not deleted. The site, the bookings and the customer list keep working — that is the point of owning the license — and you can export everything at any time.
- If you ask us to delete it, we delete it from live systems within 30 days and from backups as those backups age out, within 90 days.
- Billing and tax records are kept as long as the law requires, which is longer than either of us would choose.
11. Security
Every table in the database carries a tenant identifier and is protected by row-level security, so one business cannot read another’s data even if the application asks it to. That is enforced at the database, not in application code, and there is a test suite whose whole job is to prove it for every table.
Secrets live in a managed secret store and never in the repository. Customer-supplied model keys are encrypted at rest with AES-256-GCM. Traffic is encrypted in transit.
No system is perfect. If we discover a breach affecting your personal information we will tell you and the relevant regulator within the time the law requires, and we will tell you what we actually know rather than what sounds best.
12. Your rights
Depending on where you live — California, Delaware, Colorado, Connecticut, Virginia, Texas, and a growing list of others — you have some or all of the following rights. We extend them to everyone rather than checking your address first.
- Know what we hold about you and why.
- Get a copy, in a portable format.
- Correct it if it is wrong.
- Delete it, subject to the retention above.
- Opt out of sale or targeted advertising — which is already the case, as we do neither.
- Not be discriminated against for exercising any of these.
If you called a business that uses Orabeam and want your data deleted, ask that business — they control it. If they instruct us to delete it, we will.
We will not charge you for a request, and we will answer within 45 days.
13. Children
Orabeam is sold to businesses and is not directed at children. We do not knowingly collect personal information from anyone under 13. If a business using Orabeam serves minors — a paediatric dental practice, for example — the personal information involved is that business’s to handle under its own obligations, and we process it only on its instructions.
14. Changes
When we change this policy materially we will change the date at the top and tell current customers by email before it takes effect. We will not make a material change quietly and date it retroactively.
15. Contact
To exercise any right in section 12, or to ask anything about this policy, use the assistant on orabeam.com — it reaches a person, and a request made through it is logged with a date so the 45-day clock in section 12 starts when you send it.
16. This is a draft
This policy was written to describe accurately what the software does. It has not been reviewed by an attorney. It is not legal advice and you should not rely on it as the final word until counsel has read it. Read the Terms →