Privacy

Help travels. Private context stays.

Spillway processes only the contractor, homeowner, provider, scheduling, proof, and billing information needed to install and operate the service.

Version spillway-privacy-2026-08-v1. This production draft is grounded in implemented behavior and is marked for attorney review.

Information processed

Spillway may process contractor account and business information; user and authorization records; homeowner or customer names and phone numbers; authorized call recordings and transcripts; conversation content; scheduling, appointment, CRM, job, estimate, and proof evidence; provider identifiers; billing-provider references; and operational telemetry needed to run and secure the service.

Payment-card details are collected by Stripe-hosted surfaces. Spillway stores provider references and billing state, not raw card numbers or security codes.

Purposes and service providers

Information is used to install, operate, secure, support, measure, and bill Spillway Calls; verify tenant-specific provider capabilities; recover eligible inspection decisions; reconcile delivery, scheduling, proof, and billing truth; prevent abuse; and comply with applicable obligations.

Authorized providers may include cloud hosting and database services, Stripe, Twilio, Zapier, ServiceTitan, contractor communications providers such as CallRail, RingCentral, Dialpad, or Quo, transcription providers, and other subprocessors required for the contractor's configured service. Each receives only the information needed for its bounded role.

Private context and public surfaces

Help travels. Private context stays. Homeowner Customer Situation content, transcripts, phone numbers, provider credentials, prompts, and internal identifiers are not published through public product pages or analytics payloads.

Contractor-facing and operator surfaces use tenant-bound access and allowlisted projections. Public homeowner surfaces receive only the bounded information required for that experience.

Retention, controls, and requests

Records are retained for operational continuity, security, dispute handling, financial recordkeeping, proof integrity, and applicable legal obligations. Cancellation does not automatically delete historical proof or financial records. Provider connections can be revoked, and product-level pause and offboarding controls prevent new consequential activity.

Contractors may contact payton@spillwaycalls.com about access, correction, deletion, disconnection, or privacy questions. A request may be limited where retention is necessary for security, contractual, financial, or legal reasons.

Security and legal disclosures

Spillway uses tenant isolation, credential references, signed webhook verification, replay protection, idempotency, explicit capability evidence, and bounded kill switches. No certification is claimed by this statement.

Information may be disclosed when required by law, to protect rights and safety, to investigate abuse, or in connection with a business transaction subject to appropriate protections. The production policy should receive legal review before launch.