Last updated 2 August 2026

Privacy Policy

Openline answers inbound phone calls for local service businesses. That means we process callers' voices, their phone numbers, and what is said on the call. This page explains what is processed, how it is handled, how long it is kept, and how to have it removed.

1. Who is responsible for what

Openline sits in two different positions depending on whose information is involved, and the difference decides who you should talk to.

  • The business account. When a business signs up, we decide what we do with the account itself: the owner and team members, the business profile, the billing record, and the operational logs behind them. For that information Openline is the controller.
  • Calls, callers, and customers. When Openline answers the phone for a business, the business is the controller of its callers' and customers' information and Openline is its processor. We handle call content on that business's instructions, for the purpose of running its phone line, and for nothing else.

If you called a business and want to know what is held about you, contact that business. It decides what is kept, and it can correct it or ask us to delete it. We will help it answer you, but we will not act on its records without its instruction.

2. What Openline does with a phone call

Openline answers a business's inbound phone number with an automated receptionist. During a call the receptionist can answer questions about the business, look a caller up by phone number, create a customer record, check live availability, book, reschedule, or cancel an appointment, transfer the call to a number the business has configured, and send a short appointment confirmation by text when the caller agrees to receive one.

To do any of that we process the caller's voice, the number they are calling from, the number they dialed, and what is said on the call. There is no way to run the service without processing those things.

The demo on this site works the same way. If you start a browser call, your microphone audio is processed by our voice provider exactly as a phone call would be.

Running the service takes a small number of third-party providers: voice and telephony, hosting and storage, authentication, and payments. Each processes data on our behalf, under contract and on our instructions, only for the purpose of running the service. We do not sell personal information, we do not share it for advertising, and Openline does not train models on your call content.

3. Information we process

Account and business information

Your name, email address, profile image, and the identity our authentication provider gives us. For the business: its name, timezone, legal name, industry, address, phone, email, and website. The operational setup the receptionist speaks from, including locations, services, prices, staff, hours, closures, availability rules, the greeting and after-hours message, and the FAQ, policy, and business facts you publish to it. Team memberships, roles, and invitations.

Customer records

Display name, first and last name, phone numbers and email addresses with their consent status, any reference you import, notes your team writes, and appointments with their service, staff, location, times, status, and notes.

Call content

For each call: the provider call identifier, direction and status, the numbers on both ends, start and end time, duration, outcome, a summary, transcript segments with speaker and timing, the tool calls the receptionist made with their arguments and results, lifecycle events, and the recording when the provider produces one.

Text messages

Only when the text answering add-on is enabled: message threads with their contact number, status, and preview, and the body of each message in the thread.

Billing information

Your Stripe customer and subscription identifiers, the plan and price in force, invoice status, amounts and periods, disputes, and the usage records that count reception minutes against your allowance. Card numbers and bank details go to Stripe. Openline never receives or stores them.

Operational records

An audit log of what was changed in the dashboard and by whom, receipts for the webhook events our providers send us, and the keys that stop a retried request from doing the same thing twice. Recording links are redacted out of the webhook evidence we store, and API keys, authorization headers, payment details, and full transcripts are kept out of logs.

Website import

If you paste a website or listing during onboarding, we fetch that public page and extract hours, services, prices, and contact details as suggestions. Nothing extracted reaches the receptionist until you have reviewed and published it.

Feature requests

If you request a feature from our website, we store the email address or phone number you provide and the notes you write. We use them only to evaluate the request and follow up with you about it.

4. Recording, consent, and the automated disclosure

The receptionist identifies itself as an automated receptionist, and it delivers whatever automation or recording disclosure the business has configured, in the greeting, before the conversation starts.

Recording and wiretap law differs by state and by province. Some places require only one party on the call to consent. Others require every party to consent. Some require a specific disclosure before recording begins. The business using Openline is responsible for compliance in its own jurisdiction and in the jurisdictions its callers are in. Openline gives the business the greeting and disclosure controls and stores what those calls produce. It does not decide what the law requires of that business, and it cannot verify that a given greeting is sufficient where a given caller happens to be.

If you are a caller and you do not want your call handled this way, hang up and ask the business for another way to reach it, or ask the business to delete the record of your call.

5. How long information is kept

At our voice provider

The voice agent Openline creates is configured to store everything except personally identifiable information, with a retention window of 30 days. The provider removes what it classifies as personal information from what it retains, and what remains is deleted after 30 days. Recording links issued to us are signed and expire one hour after they are created.

In your Openline account

Calls, transcripts, summaries, recordings we have stored, customer records, and appointments stay in the business's account until the business deletes them or closes the account. We do not currently run a fixed automatic purge of call history. When we set one, the schedule will be stated here.

Billing and operational records

Invoices, payment records, and audit logs are kept for as long as tax, accounting, and dispute obligations require, which is normally longer than the account itself.

Feature requests

Feature requests are kept while we evaluate, plan, and follow up on them. You can ask us to delete your request at any time by writing to support@optimalapps.ca from the contact detail you submitted.

6. Separation between businesses

Every record Openline stores carries the identifier of the business it belongs to, and every request checks the signed-in person's active membership in that business before it returns anything. Calls, recordings, transcripts, customer records, and appointments are scoped to a single business.

They are never shared with another business on Openline, never pooled across accounts, and never sold. A business can only ever see the calls placed to its own numbers.

7. Access, correction, and deletion

  • Access. A business can see everything in its account from the dashboard: calls with their transcripts and summaries, customer records, appointments, team activity, and billing history.
  • Correction. Business details, customer records, and the knowledge the receptionist speaks from are editable in the dashboard at any time.
  • Deletion. A customer record and the call history attached to it can be deleted. Ask us from the dashboard, or write to support@optimalapps.ca from an address on the account, and we will confirm when it is done.
  • Closing an account. When a business closes its account we release the phone numbers we provisioned for it and, on request, delete its data other than the billing records we are required to keep.

Depending on where you live you may have further rights under laws such as the GDPR, the CCPA and CPRA, or PIPEDA, including the right to a copy of your information or to object to how it is processed. Write to us and we will tell you what we hold and route anything that belongs to a business's records to that business.

8. If you called a business that uses Openline

You did not sign up for Openline, and we did not choose to keep anything about you. The business you called did. It decides what is stored, and it can correct your record or ask us to delete it and its call history.

Contact the business first. If you write to us instead we will pass the request to the business, tell you that we have, and help it complete the deletion. What we will not do is change or delete a business's records on our own initiative.

9. How we protect information

Reaching a business's data requires a verified sign-in and an active membership in that business, checked on every request rather than trusted from the client. Callbacks from our voice and payment providers are verified by signature against the untouched request body before anything is written, and tenants are resolved from our own indexed identifiers rather than from anything the payload claims.

API keys, authorization headers, payment details, full transcripts, and recording links are kept out of logs and out of the stored webhook evidence. No system is perfectly secure, and we will not claim otherwise.

10. Where information is processed

Openline and the providers that run the service process and store information primarily in the United States. If you use the service or call a business that uses it from somewhere else, the information described here is transferred to and processed in the United States.

11. Children

Openline is a tool for businesses and is not directed to children. We do not knowingly collect information from children. If a child's information reaches us through a call to a business, the business can have that record deleted.

12. Changes to this policy

We will post changes on this page and update the date at the top. If a change materially affects what happens to call content, we will tell account owners by email or in the dashboard before it takes effect.

13. Contact us

Questions about this policy, a data request, or anything else covered here: support@optimalapps.ca. If you are a caller asking about your own record, please contact the business you called first, because it holds the record and decides what happens to it.