Last updated: May 4, 2026
Dealgrip ("we," "us," "our") provides AI-powered phone receptionist services for small businesses. This policy explains what data we collect, why we collect it, and how we protect it.
Account data — your name, email address, business name, and password (hashed, never stored in plaintext).
Business configuration — your phone number, business hours, services, AI greeting scripts, and notification preferences.
Call data — recordings, transcripts, and AI-generated summaries of inbound calls handled by your Dealgrip number. You own this data.
Lead data — name, email, phone, and any information captured from website lead forms.
Usage and billing — call counts, subscription status, and payment history (payment card details are processed by Stripe and never stored by us).
Audit events — login timestamps, IP addresses, and settings changes, retained for security and compliance.
Calls answered by your Dealgrip number are recorded and transcribed to generate summaries and lead captures. Call recordings are retained according to your account's data retention setting (default: 365 days). You can reduce the retention period or delete recordings at any time from your dashboard.
If your business is subject to call recording consent laws (e.g., California two-party consent), you are responsible for configuring your AI greeting to include the required disclosure.
We do not sell your data. We share data only with:
We may disclose data if required by law, court order, or to protect the safety of users.
You control your data retention period through your account settings: 30, 60, 90, or 365 days. Call logs are automatically purged after the retention period. Audit logs are retained for a minimum of 90 days. Account data is retained until you delete your account.
Depending on your location, you may have rights to:
To exercise these rights, email privacy@dealgrip.com or use the account deletion option in your dashboard settings.
We use TLS 1.2+ for all data in transit, AES-256 encryption for data at rest, and AES-256-GCM for sensitive field-level encryption. Passwords are hashed with scrypt. See our Security page for details.
We use no third-party advertising cookies. We use sessionStorage for form state persistence. We do not track users across sites.
Dealgrip is not a HIPAA-covered entity. If your business handles protected health information (PHI), you must not configure Dealgrip to collect or store PHI in call transcripts without a signed Business Associate Agreement. Contact legal@dealgrip.com to discuss enterprise agreements.
We'll notify you by email of material changes to this policy at least 14 days before they take effect.
Privacy questions: privacy@dealgrip.com