Data we process
When your workspace is active, CallPorch processes the following on your behalf:
- Caller information: phone number, caller-provided name, and any contact details the caller shares (email, address) for booking or callback.
- Intake notes: structured answers to your configured intake questions (service type, urgency, insurance, preferred slot).
- Call audio and transcripts: when call recording is enabled for your workspace, the audio and the generated transcript of each call.
- SMS follow-up: the short confirmation, reminder, and YES / NO / STOP reply history tied to a call.
- Appointment preferences: the slot held, rescheduled, or declined for the caller against your calendar.
- Business rules: your scripts, escalation rules, on-call handoffs, and review-queue actions.
- Account data: staff names, work emails, and role assignments for the people in your workspace.
We do not request and do not want: payment card numbers, government IDs, full clinical history, full case files, or any sensitive detail not needed to route the call. If a caller volunteers something like that on a recorded call, your workspace's redaction settings apply.
Why we process it
We use the data above to:
- Answer, qualify, and route inbound calls for your team.
- Draft a review-ready note with a source trail for every booked field.
- Hold a calendar slot and send the SMS confirmation.
- Flag likely urgency and read your team's approved referral language.
- Maintain the audit history that lets owners see who saw what.
- Operate, secure, and improve the service (including diagnosing failures and preventing abuse).
We do not sell call data, do not train shared models on your transcripts, and do not share your recordings with third parties outside the integrations you connect.
Call recording and SMS consent
Recording and SMS-marketing consent rules vary by jurisdiction and by service line. CallPorch provides the tools — disclosure scripts, two-party recording prompts, opt-out handling, and SMS templates — but the business owner is responsible for configuring them to match the laws that apply to their callers and their state, province, or country.
STOP, UNSUBSCRIBE, and equivalent replies are honored automatically and added to a do-not-contact list at the workspace level. Removing a number from that list requires an explicit staff action recorded in the audit history.
Role-based access and audit trail
Access to call data inside a workspace is scoped by role — owner, staff, and view-only reviewer. Every view, export, change, and deletion is written to the audit history with a timestamp and an actor. Owners can export the audit log at any time.
On the CallPorch side, only a small number of operations engineers can reach production data, and only when responding to a specific support ticket or incident. Those accesses are also logged and reviewed.
Retention
Retention windows are configurable per workspace. Defaults:
- Call recordings: 90 days, then deleted.
- Transcripts and CallTrail Receipts: retained for 7 years when a workspace requests it for medical-record standards; otherwise 12 months.
- SMS history: 12 months.
- Immutable staff-interaction audit logs: 24 months.
Workspaces can shorten any of the above, or extend them where local recordkeeping rules require it. Deleting a workspace removes call audio, transcripts, intake notes, and SMS history within 30 days; encrypted backups age out within 90 days. Immutable audit logs are retained for their full window.
Export, correction, and deletion
Workspace owners can export call data and intake notes to CSV from inside the product. Callers and other data subjects can ask us to export, correct, or delete personal data tied to their phone number by writing to privacy@callporch.co with enough detail to identify the records (the business they called and the date range is usually enough).
We respond within 30 days. If your request would require a workspace owner's approval — for example, deleting intake notes from someone else's business — we will tell you and route the request to that owner.
Subprocessors and where data sits
CallPorch runs on managed cloud infrastructure with AES-256 encryption at rest and TLS 1.3 in transit. Current subprocessors: AWS (hosting and databases), the OpenAI API under an enterprise agreement (speech and language models), and Twilio (voice and SMS). Questions or the current list: security@callporch.co. We notify workspace owners of material subprocessor changes before they take effect.
Customer data is opted out of general LLM training by default. Any fine-tuning is performed within a per-tenant silo. Healthcare customers can request a BAA; HIPAA-compliant tenants run with database-level segregation.
Children
CallPorch is a tool for businesses. It is not directed at children. We do not knowingly collect data from a person under 13 (or the equivalent local age). If you believe a child's data has reached our systems, write to privacy@callporch.co and we will delete it.
Contact
Privacy questions and data requests: privacy@callporch.co. Security disclosures: security@callporch.co.
CallPorch, LLC — 1210 Hamblen Rd Ste 875, Kingwood, TX 77339. Reviewed each quarter.
CallPorch may route calls, draft SMS, and hold slots in Pending status. Final appointment confirmation, medical triage overrides, and pricing quotes require a human.
Questions about this page? Email support@callporch.co.
Plain-language summaries. Operative terms live in your signed agreement with CallPorch.