CallCrewBook a demo

Privacy Policy

Effective date: July 15, 2026

Who we are: CallCrewAI is a trading name of Crewlabs Ltd ("CallCrewAI," "we," "us," "our"). We provide AI-powered call handling and admin automation for trades and field service businesses.

1. Scope

This Privacy Policy explains how we collect, use, share, and protect information when you:

  • visit our websites and landing pages, or submit a form on them (e.g., lead, demo, or event forms);
  • use our products and services (including AI agents that answer/route calls, schedule appointments, and log updates);
  • connect third-party accounts or integrations to CallCrewAI;
  • call or message a business that uses CallCrewAI (see Section 3).

2. Our role: controller vs. processor

If you use CallCrewAI under a company account, your company (our customer) is the data controller for content processed on its behalf — such as call recordings, transcripts, and its customers' contact details — and CallCrewAI acts as a processor on the customer's documented instructions. A Data Processing Addendum (DPA) is available to customers on request at support@callcrew-ai.com.

We act as a controller for the data we collect for our own purposes, such as our website visitors, leads, customer account and billing records, and marketing.

3. Callers & call recording

If you call or message a business that uses CallCrewAI, that business is the controller of your data; we process it on their behalf. Calls may be answered by an AI agent and may be recorded and transcribed where the business has enabled this. Consent and notice requirements for call recording and AI-generated communications vary by location; the business using CallCrewAI is responsible for complying with the laws applicable in the jurisdictions where its callers are located, including providing any required notices and obtaining any required consents. For questions or to exercise your rights over that data, contact the business you called; we will assist them in responding.

4. Data we access

Depending on features you enable and the permissions you grant, we may access and process:

Account & business profile data: name, email, phone, company name, service areas, and service details you provide (including via forms on our websites).

Communication & call data: call metadata (timestamps, caller ID, routing), voicemail, recordings and/or transcripts if enabled, AI-generated summaries and notes, and SMS routed through the service.

Google data (if connected):

  • Gmail: message metadata and (only with granted scope) message content necessary to send, draft, label, or read messages for enabled features.
  • Calendar: events you create or read to schedule and manage appointments.
  • Google Sheets: spreadsheet data you select for lookups or logging.

Microsoft data (if connected): Outlook mail and calendar data accessed via Microsoft Graph with the permissions you grant — message metadata and (only with granted permissions) message content necessary to send, draft, or read messages for enabled features, and calendar events we create or read to schedule and manage appointments.

Job management & accounting data (if connected): data from the job management or accounting tools you connect (e.g., jobs, work orders, invoices, customers, payments).

Usage & device data: log data (pages viewed, referrers, IP address), device/browser information, cookies or similar tech.

We only request the minimum Google API scopes necessary for the user-facing features you enable.

5. How we use data

We use information to:

  • operate and improve the service (answer/route calls, book appointments, send follow-ups, populate sheets/CRMs, post summaries);
  • display dashboards and analytics you request;
  • provide customer support and troubleshooting;
  • respond to enquiries and send service or marketing communications you have signed up for (you can opt out at any time);
  • protect against fraud, abuse, and security incidents; and
  • comply with legal, compliance, and audit obligations.

AI features: Our AI features may transform or summarize communications you authorize. We do not use identifiable customer content — such as call recordings, transcripts, and connected-account data — to train or fine-tune AI models, and we do not use it for advertising. We never use Google user data to train generalized AI models. Where we use third-party AI providers, they are contractually restricted to processing on our instructions for service delivery only. We may use de-identified and aggregated data to monitor, maintain, secure, develop, and improve our services, features, and models, provided it does not identify any customer or individual.

Automated decision-making: Our AI agents assist with communications, scheduling, and admin tasks. They do not make decisions that produce legal or similarly significant effects on individuals without human involvement.

6. Data sharing & subprocessors

We do not sell personal data. We may share data only with:

  • Service providers and subprocessors (listed below) under contract and subject to confidentiality and data protection obligations no less protective than this Policy.
  • Integrations you connect, as configured by you.
  • Legal/compliance recipients if required by law, to protect rights, or to ensure security.

Current subprocessors and service providers:

  • Anthropic — large language model inference powering AI features such as call understanding, summarization, and agent responses.
  • OpenRouter — routing of AI model requests to third-party large language model providers.
  • OpenAI — large language model inference (accessed via our AI infrastructure) powering AI features such as call understanding, summarization, and agent responses.
  • ElevenLabs — conversational voice AI, text-to-speech, and speech-to-text for AI voice agents.
  • Twilio — telephony infrastructure for inbound/outbound calls and SMS.
  • Google Cloud (including Firebase and Google Maps Platform) — cloud hosting, database, authentication, storage, geocoding, and related infrastructure services.
  • Amazon Web Services — website hosting and related infrastructure.
  • Stripe — payment processing and billing.
  • Resend — transactional email delivery (e.g., confirmations and notifications).
  • PostHog — product analytics to understand and improve how the service is used.
  • Coval — AI agent testing and quality evaluation.
  • Cekura — AI agent testing and quality evaluation.
  • Cloudflare — bot protection and security for our website forms.

We will update this page before adding or replacing a subprocessor that processes customer personal data and, for customers, give reasonable prior notice. If you object on reasonable data protection grounds, contact us and we will work with you in good faith to resolve the concern.

7. Data storage & protection

We apply administrative, technical, and physical safeguards to protect your data, including:

  • encryption in transit and at rest,
  • access controls and the principle of least privilege,
  • confidentiality obligations for personnel who process personal data,
  • monitoring and auditing.

If we become aware of a personal data breach affecting data we process on a customer's behalf, we will notify the customer without undue delay (and in any event within 72 hours). No system is perfectly secure; report concerns to support@callcrew-ai.com.

8. Data retention & deletion

  • We retain information for as long as necessary to deliver the service and meet legal obligations. As a guide: call recordings, transcripts, and related AI outputs are retained for the duration of the customer's subscription (or shorter where the customer configures earlier deletion); leads and enquiries for up to 24 months after our last contact with you; and billing and tax records for as long as required by law.
  • When a customer's subscription ends, we delete or return customer data at the customer's choice. Unless otherwise agreed, customer data may be deleted 30 days after termination; on written request within that period we will provide an export in a commonly used, machine-readable format.
  • Users may request deletion of their account data at any time.
  • You may also disconnect integrations at any time, including revoking CallCrewAI's Google access via Google Account Permissions.
  • Backups may persist for a limited time before permanent deletion.

9. Google API Services Disclosure

Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. In particular, we:

  • use Google data only to provide or improve user-facing features that are prominent in our app;
  • don't sell Google data or use it for ads;
  • don't transfer it except as needed to provide features, for security, to comply with law, or with your consent;
  • don't allow humans to read data unless you consent, it's necessary for security or compliance, or aggregated/anonymized for internal operations.

10. Cookies

Our websites use cookies and similar technologies in these categories:

  • Strictly necessary — required for the site and service to work (e.g., security, session management);
  • Analytics — help us understand how the site and service are used so we can improve them;
  • Marketing — where used, help us measure and improve our marketing.

You can manage preferences through your browser settings and, where shown, our cookie banner. Blocking strictly necessary cookies may affect how the service works.

11. Legal bases

Depending on your location, we process personal data on grounds such as:

  • performing our contract with you or our customer,
  • pursuing legitimate interests (e.g., security, product improvement),
  • your consent (e.g., for marketing/cookies),
  • compliance with applicable law.

12. Your rights & choices

You may:

  • access, rectify, or delete your data,
  • object to or restrict processing,
  • request data portability (where applicable),
  • withdraw consent at any time (where processing is based on it),
  • revoke connected-account access at any time,
  • opt out of marketing communications,
  • reply STOP to opt out of SMS messages.

To exercise these rights, email support@callcrew-ai.com. If your data is processed on behalf of a business you interacted with, we may refer your request to that business as controller. You also have the right to lodge a complaint with the data protection or privacy authority in your country of residence, place of work, or where the issue occurred.

13. International transfers

Some of our subprocessors process data in other countries (for example, in the United States). Where personal data is transferred across borders, we rely on recognized safeguards where required — such as the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or an adequacy decision — and apply additional measures where appropriate.

14. Children

Our services are not directed to children under 16, and we do not knowingly collect such data.

15. Changes to this Policy

We may update this Policy and will update the "Effective date." Material changes will be communicated via the service or email.

16. Contact us

Questions? Contact us at support@callcrew-ai.com