Privacy policy
What Second Call collects, why, who sees it, and how to ask us about it. It covers our website, our free audit calls, the client dashboard and the campaigns we run for client businesses.
In this policy
Who we are and what this covers
Second Call ("we", "us") runs campaigns for businesses that bring their old leads back. We contact a business's past leads by AI phone call, text message and email, in that business's name, and book the people who are still interested onto its calendar.
This policy covers three groups of people:
- Business owners who visit our website, use the website chat, apply or book a free audit call with us.
- Clients: businesses that run a campaign with us, and the team members who sign in to their dashboard.
- Leads: people whose details a client business gives us so we can contact them for that business.
When we contact leads, we do it on the client business's behalf and follow its instructions. The business decides whose details to give us, and its own privacy policy also applies to what it does with them.
What we collect
When you apply or book a free audit
On our application form, or in the website chat, we ask for your name, your business's name, your email address and your mobile number. We also ask about your business: your industry, how many old leads you have and how old they are, where they came from, how they agreed to be contacted, which CRM you use, what a typical job is worth, how many new appointments you can take, whether you make the decision, and when you'd like to start.
We keep those answers along with your time zone, the time you book, whether you ticked the box agreeing to calls and texts, the exact wording of that box, the IP address the form came from, the page you applied from, and any campaign tags in the link that brought you to us (for example from an ad). If you reply to one of our texts, we keep your reply. If you ask our AI to call your phone as a demo, we keep a record of the request: your number, when, and whether the call went through.
When you use our website
- Chat. Your messages go to our server to get an answer. When our AI assistant is switched on, they are passed to Anthropic, which provides the AI model that writes the reply. We don't save chat conversations on our server. Your browser keeps the conversation until you close the tab.
- Voice demo. If you talk to our AI in your browser, your voice goes to ElevenLabs, which runs the conversation and may keep a recording and transcript of it.
- The list checker. "Check your list" reads your file inside your browser. The file isn't uploaded to us.
- Technical information. Our servers and our hosting provider log each request, including your IP address, your browser type and the page you opened. We use IP addresses to limit repeated form submissions and to keep the site secure.
- Cookies and browser storage. We set a cookie only when you sign in to the client dashboard, to keep you signed in. Your browser also keeps a few things on your own device: the chat conversation until you close the tab, a time you've picked while booking, and whether you prefer a 12- or 24-hour clock. We don't use advertising or analytics cookies, and we don't track you on other websites. Our pages load their fonts from Google Fonts, and the voice demo loads its code from jsDelivr, so those services receive your IP address when a page loads.
If you're a client
- Your account. The name and email address of each person on your account, a hashed (scrambled) copy of each password, and when each person last signed in.
- Your business. Its name, industry, the owner's first name, main phone number, website, postal address, time zone and working hours, where email replies should go, a mobile number for alerts if you add one, your guaranteed number, your price, and notes we keep about your account.
- Payments. What you've paid or been refunded, when, and how (for example card, bank transfer or check). We don't keep card numbers.
- Consent records. For every list you upload: the file's name and a fingerprint that identifies it, the consent statement you agreed to, how your leads gave their consent in your words, who agreed to the statement and the IP address they agreed from. We also keep the Do Not Call and other list checks recorded for you.
- Google Calendar, if you connect it. See Google Calendar.
About leads, from client businesses
A client gives us an export from its CRM. It usually has each lead's name, phone number, email address, what they asked about, when they got in touch, where they came from, and their state or address, along with any other columns in the export. While we contact a lead, we add a record of each call, text and email and when it went out; call recordings, transcripts and summaries; replies; appointments booked; and any request to stop.
We also keep do-not-contact records: phone numbers and email addresses that have opted out, that are on the business's own do-not-call list or the National Do Not Call Registry, or that have been reassigned to someone else.
If a client is a medical or dental practice, details about its patients can be health information. We handle them under the business associate agreement we sign with that practice, and only as it allows.
How we use it
- To run your free audit. We confirm your booking, send reminders by email and, if you agreed, by text, send the meeting link or call you at the time you booked, and prepare for the call.
- To see whether we can help. Your answers tell us whether your list fits our guarantee.
- To run client campaigns. We call, text and email each lead in the client's name, on the 30-day plan the client approved, and book appointments onto the client's calendar.
- To follow the rules. Before every call or text we check consent, Do Not Call lists and the hours we're allowed to contact someone. We honor opt-outs on every channel and keep records that show we did.
- To report to clients. Each client sees its own leads' calls, recordings, transcripts, replies and appointments on its dashboard, and gets alerts and a weekly report.
- To run and protect the service. We keep accounts secure, stop abuse, fix problems and improve how the service works.
- To meet our legal obligations and answer lawful requests.
We don't use a lead's details for our own marketing, and we don't use one client's leads for another client. The one exception protects the lead: a STOP sent to our shared texting number stops every client's calls and texts to that number.
Recent bookings on our website
Our website can show a short notice that a business recently booked a free audit, such as "A dental practice in Texas booked a free audit". It appears only for real bookings from the last 14 days, and shows only the kind of business, the state (worked out from the phone number's area code) and how long ago it was booked. It never shows a name.
AI calls, recordings and transcripts
Our AI assistant places campaign calls through ElevenLabs, using phone numbers from Twilio. Every call starts by saying that it's an AI calling for the business, and that the call is recorded. If the person asks to stop, the call ends and they're opted out of every channel.
ElevenLabs records each call and turns it into a transcript and a short summary. We store the transcript, the summary and how the call ended (for example, booked or not interested), and show them to the client whose lead it was. The recording itself stays with ElevenLabs. We fetch it only when someone signed in to that client's account plays or downloads it.
Texts and emails
We only text people who agreed to receive texts: business owners who tick the consent box when they apply or book with us, leads whose consent the client business has confirmed to us in writing, and clients who add a mobile number for alerts. Leads without that consent get email only.
- Reply STOP to any of our texts to stop them. Reply HELP for help.
- A STOP to a campaign text also stops that campaign's calls and emails to you.
- Every campaign email says who it's from, why you're getting it, and has a one-click unsubscribe link. Unsubscribing stops every call, text and email from that campaign.
How often we text, and what it costs, is in the text message terms.
Google Calendar
Clients can connect a Google Calendar so our AI books appointments into time that's really free. When a client connects, Google asks them to allow these permissions:
- openid, email
- To see which Google account was connected, so Settings can show it.
- calendar.freebusy
- To see when the calendar is busy. Google returns busy times only: never event titles, descriptions or guests.
- calendar.events
- To add an event for each appointment we book, and to delete that event if the appointment is cancelled.
That is all we do with it. We read busy times so we never book over an existing event, and keep them for up to a minute. Each appointment event holds the appointment's details and, when we have it, the lead's email address as a guest, so Google sends them the invitation. We store the connection's access tokens and the connected account's email address. We never read your other events, never use calendar data for advertising, never sell it, and never share it with anyone other than the client it belongs to. Nobody on our team looks at it unless the client asks us to help, or it's needed for security or required by law.
Second Call's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
To disconnect, click Disconnect in Settings on your dashboard. We revoke our access at Google and delete the stored tokens. You can also remove Second Call at myaccount.google.com/permissions.
How long we keep it
- Applications and audit bookings: while we're talking about working together, and then only as long as we need them for the reasons in this policy.
- Client accounts and campaign data: for as long as you're a client, and afterward as long as we need them to settle the guarantee, keep financial records and show that we followed the law.
- Consent records, Do Not Call checks, and records of calls and texts: at least four years, because that is how long a claim about a call or text can generally be brought.
- Opt-outs: for good, so we never contact that number or address again.
When we no longer need information, we delete it or remove what identifies you. If you ask us to delete your information, we keep only what we need to keep honoring your opt-out and to meet the record-keeping duties above.
How we protect it
- Our website and dashboard use encrypted connections (HTTPS).
- Passwords are stored only in hashed form. Invitation and password links expire, and repeated wrong passwords are blocked for a while.
- Each client can see only its own data. Our own admin pages need a separate password.
- We act on messages from Twilio and ElevenLabs only after checking they really came from them.
- The keys to outside services are kept in our server settings, never in our code.
No system is perfectly secure. If a breach affects your information, we'll tell you as the law requires.
Your choices and rights
- Texts: reply STOP.
- Calls: tell the AI on the call that you don't want more calls, or email us.
- Emails: use the unsubscribe link at the bottom of any campaign email.
- See, correct or delete your information: email us at support@usesecondcall.com. We may need to check that the request is really from you. If you're a lead, we'll also tell the business that gave us your details, since it decides what happens to its own records.
Depending on where you live, for example California, Colorado, Connecticut, Virginia or another state with a privacy law, you may have more rights: to know what we hold about you, to correct or delete it, and to appeal if we turn down your request. We'll honor them, answer within the time that law sets, and won't treat you differently for using them. We don't sell personal information or share it for targeted advertising, so there's nothing to opt out of there.
Children
Our website and service are for businesses and adults. We don't knowingly collect information from children under 13. If you think a child has given us information, email us and we'll delete it.
Changes to this policy
We'll update this policy when what we do changes. The date at the top shows the current version. If a change is significant, we'll email clients before it takes effect.
Contact us
Questions or requests about your information: write to Second Call at support@usesecondcall.com.
If you heard from us on behalf of a business we work for, you can also reply STOP to a text, use the unsubscribe link in an email, or contact that business directly.
Our terms of service cover the rest of how our service works.