Last updated: August 11, 2026 (placeholder — confirm on publish)
This Privacy Policy describes how [Legal Entity Name, Inc.] (“PalmLine”, “we”, “us”) handles information in connection with the PalmLine bilingual AI voice receptionist service (the “Service”). We provide the Service to businesses (“Customers”) that use it to answer inbound calls and schedule appointments on their behalf.
Google API Services User Data Policy — Limited Use
PalmLine’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When a Customer connects a Google account, we access their Google Calendar data — specifically free/busy availability and calendar events — solely to check availability and to create, reschedule, or cancel appointments on the Customer’s behalf as part of the user-facing scheduling feature of the Service. Specifically, data obtained through Google APIs is:
- not used for advertising of any kind;
- not sold, rented, or transferred to third parties for their independent use;
- not used to train, develop, or improve generalized or standalone artificial intelligence or machine-learning models; and
- used only to provide and improve the appointment scheduling features the Customer explicitly enabled, and accessed by humans only where necessary for security, to comply with applicable law, or with the Customer’s explicit consent.
The same commitments apply to data we receive from other connected calendar and booking providers — including Microsoft (Outlook/Microsoft 365), Square, GoHighLevel, and Calendly. We request the minimum scopes needed to read availability and write appointments, and we use that data only to deliver the scheduling feature. Customers using Booksy connect their Google Calendar, which is governed by the Limited Use terms above.
Our store-nothing, PHI-conscious posture
PalmLine is designed to minimize the data it retains. We operate a store-nothing, PHI-conscious model: calls are handled in real time, and we do not build profiles of callers or retain call audio beyond what is operationally necessary to deliver and secure the Service. We intentionally avoid collecting protected health information (PHI). Callers should not be asked for, and should not provide, clinical or diagnostic details — only the information needed to schedule an appointment (such as a name, a phone number, and the requested service or appointment type).
Information we collect
Customer account information
Business contact and account details provided when a Customer signs up or configures the Service — such as business name, contact name, email address, phone number(s), locations, services offered, and hours of operation.
Caller information captured at booking
When PalmLine books, reschedules, or cancels on a call, it captures the limited details needed to create the appointment — typically the caller’s name and phone number and the requested service, date, and time. This information is written into the Customer’s connected calendar and belongs to the Customer.
Calendar and integration connection tokens
When a Customer connects Google, Microsoft, Square, GoHighLevel, or Calendly, we store the resulting access and refresh tokens encrypted at rest. These tokens are used only to perform the scheduling actions the Customer authorized and can be revoked at any time by disconnecting the integration.
Operational and diagnostic data
We process limited technical metadata — such as call timestamps, duration, language selected, and outcome (e.g., booked, transferred, callback captured) — to operate, secure, monitor, and improve the Service.
How we use information
- To answer calls and schedule appointments on the Customer’s behalf.
- To transfer calls to a human and to capture after-hours callback requests.
- To provide, maintain, secure, and improve the Service.
- To communicate with Customers about their account and support requests.
- To comply with legal obligations and enforce our terms.
We do not sell personal information, and we do not use connected-service data for advertising or to train generalized AI models.
Third-party service providers (sub-processors)
We rely on a small set of vendors to deliver the Service, under contractual confidentiality and data-protection obligations:
- Retell — real-time voice infrastructure used to conduct the phone conversation.
- Google Gemini — used to help generate and refine the Customer’s agent configuration and prompts. No caller personal information is sent for this purpose.
- Calendar & booking providers — Google, Microsoft, Square, GoHighLevel, and Calendly, used to read availability and write appointments as directed by the Customer.
Data retention
We retain information only as long as needed to provide the Service and for legitimate, documented business or legal purposes. Customer account data is retained for the life of the account; connection tokens are deleted when an integration is disconnected or the account is closed; operational metadata is kept for a limited period and then deleted or aggregated. Appointment records created in a Customer’s calendar are controlled and retained by the Customer under their own policies.
Security
We protect data in transit and at rest using industry-standard encryption, restrict access on a need-to-know basis, and apply administrative, technical, and organizational safeguards appropriate to the sensitivity of the data. No method of transmission or storage is perfectly secure, but we work continuously to protect the information entrusted to us.
Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or restrict the processing of personal information, and to revoke integration access at any time by disconnecting a provider. Because PalmLine typically acts as a processor on behalf of the Customer, callers should direct requests about appointment data to the business they called; we will assist that business in responding. To exercise rights directly with us, contact us using the details below.
Children’s privacy
The Service is intended for use by businesses and is not directed to children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by notifying Customers.
Contact us
Questions about this policy or our data practices can be sent to privacy@palmline.example.com (placeholder — replace “example.com” with your live domain), or by mail to [Legal Entity Name, Inc., Street Address, Miami, FL, USA].