AutoVOC Privacy Policy
Effective Date: August 22, 2026
Last Updated: August 30, 2026

At AutoVOC, Inc. (“AutoVOC,” “we,” “us,” or “our”), we are committed to protecting the privacy, security, and integrity of the data collected through our software-as-a-service (SaaS) platform, mobile applications (the “App”), and website located at autovoc.ai and autovoc.net (collectively, the “Services”).

This Privacy Policy describes how we collect, use, process, and disclose information when you interact with our Services as an enterprise client, authorized employee/representative, or website visitor.

1. Our Role: Data Controller vs. Data Processor

To understand how your data is handled, it is important to recognize our legal role:

Data Processor / Service Provider: When AutoVOC processes voice recordings, conversation transcripts, customer metrics, or CRM integration data on behalf of an automotive dealership or business client (“Enterprise Customer”), AutoVOC acts as a Data Processor. The Enterprise Customer controls the data and determines the legal basis for processing.

Data Controller: AutoVOC acts as a Data Controller for information collected directly from visitors to our website, prospective enterprise clients, or individual user account credentials created to access the App.

2. Information We Collect

We collect information in three ways: directly from you, automatically through your use of our Services, and from third-party partners.

A. Information Provided Directly to Us

Account Credentials & Contact Info: Name, work email address, phone number, job title, and dealership affiliation when an enterprise account is provisioned or when you request customer support.

Support Inquiries: Messages, support tickets, or feedback submitted through our website or via support@autovoc.ai.

B. Customer Data (Processed on Behalf of Enterprise Customers)

In providing our Voice-of-the-Customer (VOC) AI analytics platform, we process data uploaded or captured via hardware (such as connected Rode Wireless Microphones) or mobile devices:

Voice Recordings & Audio Data: Raw audio captured during customer interactions at the dealership.

Transcripts & Sentiment Analytics: Automated speech-to-text transcriptions, sentiment analysis, rep performance metrics, and conversation key phrases.

CRM & Dealership Data: Customer names, phone numbers, vehicle interest, deal stage, and sales notes synced with the Dealership’s Customer Relationship Management (CRM) system.

C. Information Collected Automatically

Device & App Usage Data: Mobile device type, operating system version, unique device identifiers, IP address, system diagnostic logs, crash reports, and app interaction metrics collected when using the App via our diagnostic provider, Sentry.

Cookies & Tracking Technologies: On our website (autovoc.ai), we use essential cookies and basic analytics to understand site traffic and optimize user experience. We do not track users across third-party websites for targeted advertising.

3. How We Use Information

We use the information we collect for specific, limited business purposes:

Service Delivery: To operate, maintain, and provide the features of the AutoVOC platform and mobile application (App Functionality).

Conversation Analytics & CRM Sync: To process audio files, generate VOC insights, and synchronize data with the Enterprise Customer's CRM system (App Functionality).

AI Model Development & Optimization: To develop, train, tune, and validate AutoVOC’s proprietary machine-learning algorithms and artificial intelligence models using de-identified, aggregated, and anonymized data.

Customer Support: To respond to user inquiries, troubleshoot technical issues, and provide system updates.

Security & Diagnostics: To monitor app performance, detect security incidents, prevent fraud, capture crash logs via Sentry, and ensure compliance with our Master SaaS Service Agreement and Mobile Terms of Service (Analytics & Diagnostics).

4. Multi-Party Consent & Recording Disclosures

AutoVOC provides technology tools designed to assist automotive dealerships in analyzing customer communications. Under our Master SaaS Agreement, our Enterprise Customers and their authorized personnel are solely responsible for ensuring compliance with all federal, state, and local wiretapping, eavesdropping, and recording consent statutes (including multi-party consent laws in applicable jurisdictions). App users manually execute consent confirmations within the mobile software interface prior to initiating recording sessions. AutoVOC relies strictly on the Enterprise Customer to provide required notices and secure necessary consents.

5. How We Share & Disclose Information (Sub-Processors)

AutoVOC does not sell, rent, or monetize personal data or customer voice recordings. We do not sell personal information or share it with third parties for cross-context behavioral advertising (pursuant to the CCPA/CPRA). We only disclose information under the following limited circumstances:

Enterprise Customers: Transcripts, audio recordings, and analytics generated by authorized representatives are shared directly with the managing Enterprise Customer.

Third-Party Service Providers & Sub-Processors: We engage trusted third-party vendors to perform essential platform, infrastructure, and analytics functions on our behalf. All service providers are bound by strict contractual confidentiality and data security obligations. Our primary sub-processors include:

Clerk: Authentication, user access control, and identity management.

Cloudflare R2: Encrypted cloud storage for raw audio files.

Railway & Vercel: API hosting, serverless execution, and web platform hosting. Supabase: Managed PostgreSQL database infrastructure for user and application metadata.

AssemblyAI: Automated speech-to-text audio transcription.

Anthropic & Fireworks AI: Advanced language intelligence and conversation analysis processing.

Sentry: Application performance monitoring, error tracking, and crash diagnostics.

CRM Integration Partners: Data is transmitted to third-party CRM platforms strictly as directed by the Enterprise Customer once an active CRM integration is established.

Legal Requirements: We may disclose information if required to do so by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our legal rights, privacy, or safety.

Business Transfers: In the event of a merger, acquisition, financing due diligence, or sale of company assets, customer data may be transferred as an asset under strict non-disclosure protections.

6. Data Security & Retention Windows Security We implement robust, industry-standard administrative, technical, and physical security measures designed to safeguard personal data and Customer Data against unauthorized access, destruction, loss, or alteration. This includes end-to-end encryption of data in transit (TLS/SSL) and at rest (AES-256).

Retention Windows

We adhere to specific retention windows depending on the data category:

On-Device Mobile Audio Copy: Temporary audio recordings stored locally on mobile hardware are automatically deleted immediately upon successful upload to AutoVOC cloud servers or upon user discard.

Server-Side Raw Audio Files: Retained for 90 Days following initial capture, after which raw audio is permanently purged from Cloudflare R2 storage unless otherwise required by the Enterprise Customer's Master SaaS Agreement.

Transcripts & Conversation Analytics: Retained for the duration of the Enterprise Customer agreement plus 30 days to provide ongoing CRM and analytics services.

Sentry Diagnostic & Crash Logs: Retained for 90 days before automated purge.

Anonymized & Aggregated AI Training Data: Fully de-identified and aggregated data stripped of all personal identifiers and dealership markers may be retained indefinitely solely to train, tune, and validate AutoVOC's artificial intelligence models.

7. Data Deletion & Account Requests

Enterprise users, dealership personnel, and end-consumers have clear pathways to request data deletion:

In-App Account Deletion: Authorized mobile application users may request account deletion directly within the mobile app settings via the "Request Account Deletion" control.

Web & Direct Deletion Requests: You may submit a data deletion request by emailing privacy@autovoc.ai.

Enterprise Customer Data: Because AutoVOC acts as a Data Processor for dealership interactions, requests from end-customers to purge specific sales transcripts or CRM records will be routed directly to the managing Dealership Administrator for review and execution.

8. Children's Privacy

The Services are strictly designed for enterprise commercial use by adult business personnel. The Services are not directed to, and AutoVOC does not knowingly collect or solicit personal information from, children under the age of 13 (or under 16 in the European Economic Area / United Kingdom). If we learn that we have collected personal data from a child under these ages without verified parental consent, we will promptly delete that information.

9. International Data Transfers

AutoVOC is headquartered in the United States, and all cloud infrastructure, databases, and sub-processors operate within the United States. If you access or use the Services from the European Economic Area (EEA), United Kingdom (UK), or other regions with laws governing data collection and use, please note that your personal data is transferred to and processed in the United States.

10. App Store & Mobile Disclosures

Apple App Store (iOS): The AutoVOC iOS App does not collect user data for targeted cross-app tracking. Data collected (including voice audio, user ID, and diagnostics) is linked to user accounts solely for App Functionality, Analytics, and Diagnostics.

Google Play Store (Android): Microphone permissions, device audio data, and diagnostic crash logs are processed strictly to deliver core conversation analytics and platform performance requested by the user's employer.

11. Your Data Rights & Choices (CCPA / GDPR)

Depending on your jurisdiction, you or your Enterprise Customer may have rights regarding your personal information under the California Consumer Privacy Act (CCPA/CPRA), GDPR, or applicable state laws, including the right to access, correct, port, or request the deletion of personal data held by AutoVOC.

No Sale / No Sharing: AutoVOC does not sell personal information or share personal data for cross-context behavioral advertising.

Enterprise Users / End Customers: Because AutoVOC processes conversation data on behalf of your Dealership, requests for data access or deletion should be directed to your Dealership’s administrator.

Direct Contact: For inquiries regarding personal data processed directly by AutoVOC, contact us at privacy@autovoc.ai.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect technological, operational, or legal changes. The updated version will be posted on this page with a revised “Last Updated” date.

13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

AutoVOC, Inc.
Attn: Legal & Privacy Team
1449 S. Michigan Ave., STE 13646
Chicago, IL 60605
United States

Email: privacy@autovoc.ai / support@autovoc.ai

Effective Date: August 22, 2026

Last Updated: August 30, 2026

At AutoVOC, Inc. (“AutoVOC,” “we,” “us,” or “our”), we are committed to protecting the privacy, security, and integrity of the data collected through our software-as-a-service (SaaS) platform, mobile applications (the “App”), and website located at autovoc.ai and autovoc.net (collectively, the “Services”).

This Privacy Policy describes how we collect, use, process, and disclose information when you interact with our Services as an enterprise client, authorized employee/representative, or website visitor.

1. Our Role: Data Controller vs. Data Processor

To understand how your data is handled, it is important to recognize our legal role:

  • Data Processor / Service Provider: When AutoVOC processes voice recordings, conversation transcripts, customer metrics, or CRM integration data on behalf of an automotive dealership or business client (“Enterprise Customer”), AutoVOC acts as a Data Processor. The Enterprise Customer controls the data and determines the legal basis for processing.

  • Data Controller: AutoVOC acts as a Data Controller for information collected directly from visitors to our website, prospective enterprise clients, or individual user account credentials created to access the App.

2. Information We Collect

We collect information in three ways: directly from you, automatically through your use of our Services, and from third-party partners.

A. Information Provided Directly to Us

  • Account Credentials & Contact Info: Name, work email address, phone number, job title, and dealership affiliation when an enterprise account is provisioned or when you request customer support.

  • Support Inquiries: Messages, support tickets, or feedback submitted through our website or via support@autovoc.ai.

B. Customer Data (Processed on Behalf of Enterprise Customers)

In providing our Voice-of-the-Customer (VOC) AI analytics platform, we process data uploaded or captured via hardware (such as connected Rode Wireless Microphones) or mobile devices:

  • Voice Recordings & Audio Data: Raw audio captured during customer interactions at the dealership.

  • Transcripts & Sentiment Analytics: Automated speech-to-text transcriptions, sentiment analysis, rep performance metrics, and conversation key phrases.

  • CRM & Dealership Data: Customer names, phone numbers, vehicle interest, deal stage, and sales notes synced with the Dealership’s Customer Relationship Management (CRM) system.

C. Information Collected Automatically

  • Device & App Usage Data: Mobile device type, operating system version, unique device identifiers, IP address, system diagnostic logs, crash reports, and app interaction metrics collected when using the App via our diagnostic provider, Sentry.

  • Cookies & Tracking Technologies: On our website (autovoc.ai), we use essential cookies and basic analytics to understand site traffic and optimize user experience. We do not track users across third-party websites for targeted advertising.

3. How We Use Information

We use the information we collect for specific, limited business purposes:

  1. Service Delivery: To operate, maintain, and provide the features of the AutoVOC platform and mobile application (App Functionality).

  2. Conversation Analytics & CRM Sync: To process audio files, generate VOC insights, and synchronize data with the Enterprise Customer's CRM system (App Functionality).

  3. AI Model Development & Optimization: To develop, train, tune, and validate AutoVOC’s proprietary machine-learning algorithms and artificial intelligence models using de-identified, aggregated, and anonymized data.

  4. Customer Support: To respond to user inquiries, troubleshoot technical issues, and provide system updates.

  5. Security & Diagnostics: To monitor app performance, detect security incidents, prevent fraud, capture crash logs via Sentry, and ensure compliance with our Master SaaS Service Agreement and Mobile Terms of Service (Analytics & Diagnostics).

4. Multi-Party Consent & Recording Disclosures

AutoVOC provides technology tools designed to assist automotive dealerships in analyzing customer communications. Under our Master SaaS Agreement, our Enterprise Customers and their authorized personnel are solely responsible for ensuring compliance with all federal, state, and local wiretapping, eavesdropping, and recording consent statutes (including multi-party consent laws in applicable jurisdictions).

App users manually execute consent confirmations within the mobile software interface prior to initiating recording sessions. AutoVOC relies strictly on the Enterprise Customer to provide required notices and secure necessary consents.

5. How We Share & Disclose Information (Sub-Processors)

AutoVOC does not sell, rent, or monetize personal data or customer voice recordings. We do not sell personal information or share it with third parties for cross-context behavioral advertising (pursuant to the CCPA/CPRA). We only disclose information under the following limited circumstances:

  • Enterprise Customers: Transcripts, audio recordings, and analytics generated by authorized representatives are shared directly with the managing Enterprise Customer.

  • Third-Party Service Providers & Sub-Processors: We engage trusted third-party vendors to perform essential platform, infrastructure, and analytics functions on our behalf. All service providers are bound by strict contractual confidentiality and data security obligations. Our primary sub-processors include:

    • Clerk: Authentication, user access control, and identity management.

    • Cloudflare R2: Encrypted cloud storage for raw audio files.

    • Railway & Vercel: API hosting, serverless execution, and web platform hosting.

    • Supabase: Managed PostgreSQL database infrastructure for user and application metadata.

    • AssemblyAI: Automated speech-to-text audio transcription.

    • Anthropic & Fireworks AI: Advanced language intelligence and conversation analysis processing.

    • Sentry: Application performance monitoring, error tracking, and crash diagnostics.

  • CRM Integration Partners: Data is transmitted to third-party CRM platforms strictly as directed by the Enterprise Customer once an active CRM integration is established.

  • Legal Requirements: We may disclose information if required to do so by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our legal rights, privacy, or safety.

  • Business Transfers: In the event of a merger, acquisition, financing due diligence, or sale of company assets, customer data may be transferred as an asset under strict non-disclosure protections.

6. Data Security & Retention Windows

Security

We implement robust, industry-standard administrative, technical, and physical security measures designed to safeguard personal data and Customer Data against unauthorized access, destruction, loss, or alteration. This includes end-to-end encryption of data in transit (TLS/SSL) and at rest (AES-256).

Retention Windows

We adhere to specific retention windows depending on the data category:

  • On-Device Mobile Audio Copy: Temporary audio recordings stored locally on mobile hardware are automatically deleted immediately upon successful upload to AutoVOC cloud servers or upon user discard.

  • Server-Side Raw Audio Files: Retained for 90 Days following initial capture, after which raw audio is permanently purged from Cloudflare R2 storage unless otherwise required by the Enterprise Customer's Master SaaS Agreement.

  • Transcripts & Conversation Analytics: Retained for the duration of the Enterprise Customer agreement plus 30 days to provide ongoing CRM and analytics services.

  • Sentry Diagnostic & Crash Logs: Retained for 90 days before automated purge.

  • Anonymized & Aggregated AI Training Data: Fully de-identified and aggregated data stripped of all personal identifiers and dealership markers may be retained indefinitely solely to train, tune, and validate AutoVOC's artificial intelligence models.

7. Data Deletion & Account Requests

Enterprise users, dealership personnel, and end-consumers have clear pathways to request data deletion:

  • In-App Account Deletion: Authorized mobile application users may request account deletion directly within the mobile app settings via the "Request Account Deletion" control.

  • Web & Direct Deletion Requests: You may submit a data deletion request by emailing privacy@autovoc.ai.

  • Enterprise Customer Data: Because AutoVOC acts as a Data Processor for dealership interactions, requests from end-customers to purge specific sales transcripts or CRM records will be routed directly to the managing Dealership Administrator for review and execution.

8. Children's Privacy

The Services are strictly designed for enterprise commercial use by adult business personnel. The Services are not directed to, and AutoVOC does not knowingly collect or solicit personal information from, children under the age of 13 (or under 16 in the European Economic Area / United Kingdom). If we learn that we have collected personal data from a child under these ages without verified parental consent, we will promptly delete that information.

9. International Data Transfers

AutoVOC is headquartered in the United States, and all cloud infrastructure, databases, and sub-processors operate within the United States. If you access or use the Services from the European Economic Area (EEA), United Kingdom (UK), or other regions with laws governing data collection and use, please note that your personal data is transferred to and processed in the United States.

10. App Store & Mobile Disclosures

  • Apple App Store (iOS): The AutoVOC iOS App does not collect user data for targeted cross-app tracking. Data collected (including voice audio, user ID, and diagnostics) is linked to user accounts solely for App Functionality, Analytics, and Diagnostics.

  • Google Play Store (Android): Microphone permissions, device audio data, and diagnostic crash logs are processed strictly to deliver core conversation analytics and platform performance requested by the user's employer.

11. Your Data Rights & Choices (CCPA / GDPR)

Depending on your jurisdiction, you or your Enterprise Customer may have rights regarding your personal information under the California Consumer Privacy Act (CCPA/CPRA), GDPR, or applicable state laws, including the right to access, correct, port, or request the deletion of personal data held by AutoVOC.

  • No Sale / No Sharing: AutoVOC does not sell personal information or share personal data for cross-context behavioral advertising.

  • Enterprise Users / End Customers: Because AutoVOC processes conversation data on behalf of your Dealership, requests for data access or deletion should be directed to your Dealership’s administrator.

  • Direct Contact: For inquiries regarding personal data processed directly by AutoVOC, contact us at privacy@autovoc.ai.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect technological, operational, or legal changes. The updated version will be posted on this page with a revised “Last Updated” date.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

AutoVOC, Inc.

Attn: Legal & Privacy Team

1449 S. Michigan Ave., STE 13646

Chicago, IL 60605

United States

Email: privacy@autovoc.ai / support@autovoc.ai