Privacy Policy

Last Updated: November 1, 2025

This Privacy Policy describes how Convey Stack Inc. (“Convey Stack”, “we”, “us”, or “our”) protects, collects, and uses information from our small business clients and leads. This policy applies to our websites conveystack.com and evergreeting.com, our educational courses, consulting services, EverGreeting marketing products, and all related offerings.

Definitions

For the purposes of this Privacy Policy:

  • Company refers to Convey Stack Inc., a federally incorporated Canadian company
  • Services refer to our educational courses, consulting services, EverGreeting marketing products, AI-powered services, websites, and all related offerings
  • Client/You refers to small businesses and their representatives accessing our Services
  • Personal Data means any information relating to an identified or identifiable individual or business
  • Usage Data refers to data collected automatically through use of our Services
  • End User refers to individuals who interact with your business through our Services (such as customers calling your business)

Our Role as Data Controller and Processor

Convey Stack acts as:

  • Data Controller for information we collect directly from you (our clients) for our own business purposes
  • Data Processor for end user information collected through our services on your behalf

When we process end user data on your behalf (such as customer calls, appointments, or contact information), you remain the Data Controller and are responsible for:

  • Having a compliant privacy policy that governs your relationship with your end users
  • Obtaining necessary consents from your end users
  • Complying with applicable privacy laws for your industry and jurisdiction

Information We Collect

Personal and Business Information

We collect information you provide when interacting with our services, including:

  • Business name and contact person’s name
  • Business email address
  • Business phone number
  • Business address (city, province/state, country)
  • Industry type and business size
  • Marketing preferences and requirements
  • Payment and billing information
  • Service-specific data related to your use of our products
AI-Powered Services and Voice Data

Some of our services use artificial intelligence to process communications, including phone calls, messages, and customer interactions.

What We Do:
  • Record and transcribe phone calls handled by our AI services. Recording is a prerequisite for generating AI-driven transcriptions and post-call summaries.
  • Process voice data to provide automated responses and service delivery
  • Use third-party service platforms and providers to deliver intelligent responses
  • Voice data may contain characteristics that could be considered biometric information; this is used solely for speech recognition, not biometric identification
AI Data Processing Safeguards:
  • Our service platform automatically detects and masks personally identifiable information (PII) such as credit card numbers or social insurance numbers before AI processing
  • We do not use your data or your end users’ data to train generalized public AI models
  • Voice AI outbound calls are automatically throttled to comply with FCC-friendly calling windows (10:00 AM – 6:00 PM in the contact’s time zone)
Your Responsibilities as Data Controller:

When using our AI-powered services, you are responsible for:

Call Recording Compliance:
  • Complying with all applicable call recording and consent laws in your jurisdiction
  • Providing proper notice to callers that calls are being recorded (we provide tools such as automated recording announcements to assist with this)
  • Obtaining required consent from callers where mandated by two-party consent laws
Opt-In Requirements:
  • Ensuring contacts have explicitly opted in before using automated Voice AI for outbound calls
  • Maintaining records of consent for SMS and voice communications
  • Complying with TCPA, CASL, and other applicable telecommunications laws
Industry-Specific Compliance:
  • If you operate in regulated industries (healthcare, finance, etc.), you are responsible for additional compliance requirements
  • Healthcare businesses handling Protected Health Information (PHI) must use HIPAA-compliant service tiers and sign required Business Associate Agreements
Our Responsibilities:
  • We ensure our service platforms and third-party AI providers process data solely to deliver our services under strict confidentiality agreements
  • We maintain SOC 2 Type II compliance and use platforms certified under the EU-U.S. Data Privacy Framework
  • We encrypt data at rest (AES-256) and in transit (TLS)

How We Use Your Information

Convey Stack Inc. uses collected information for:

  • Service Delivery: Providing courses, consulting, EverGreeting products, AI services, and all related offerings
  • Communication: Sending service updates, responding to inquiries, and providing customer support
  • Service Improvement: Analyzing usage patterns to enhance our offerings
  • Business Operations: Managing our business relationships and service offerings
  • Legal Compliance: Meeting regulatory and legal obligations

We do not share, sell, or disclose your information to unaffiliated third parties for their marketing purposes. We do not sell phone numbers or opt-in consent to third parties.

SMS and Email Communications
Consent
  • Transactional Messages: By providing your contact information, you consent to receive transactional messages related to your account, orders, or services, including appointment reminders, confirmations, and account notifications. Msg frequency varies. Msg & data rates may apply. Reply STOP to opt-out.
  • Marketing Messages: By separately opting in, you consent to receive marketing and promotional messages, including special offers, discounts, and product updates. Msg frequency varies. Msg & data rates may apply. Reply STOP to opt-out. Consent is not required to purchase.
Opt-Out Rights
  • SMS: Text “STOP” to any message to unsubscribe immediately
  • Email: Click “unsubscribe” in any email or contact us directly
  • All Communications: Email support@conveystack.com to update preferences
Data Sharing and Disclosure

We may share information ONLY in these limited circumstances:

  • Service Providers and Platforms: All service providers are bound by confidentiality agreements and process data solely to deliver our services. Data is hosted on secure infrastructure including Amazon Web Services (AWS) and Google Cloud Platform.
  • Affiliated Entities: With subsidiaries, parent companies, or affiliated entities under common control for the purpose of providing and improving our services.
  • Legal Requirements and Business Protection: When required by law, court order, government regulation, or to protect our rights, safety, or property.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets.
International Data Transfers

As we serve clients internationally, your information may be processed in different jurisdictions. We ensure compliance with:

  • PIPEDA (Canada)
  • CASL (Canadian anti-spam legislation)
  • GDPR and UK data protection laws (via EU-U.S. Data Privacy Framework certification and Standard Contractual Clauses)
  • Applicable US state privacy laws

Data is processed on platforms certified under international privacy frameworks and protected by appropriate safeguards.

Important Service Limitations
  • Emergency Services: Our AI-powered services are not designed for emergency dispatch or 911 services. Do not rely on these services for life-threatening emergencies.
  • Service Accuracy: AI-powered services may occasionally contain errors. Critical business decisions should be verified.
Data Retention

We retain your information only as long as necessary to:

  • Provide ongoing services
  • Maintain business records as required by law
  • Resolve disputes and enforce agreements
  • Comply with legal and regulatory requirements

Call recordings and transcripts are retained according to your service plan settings and can be configured based on your business needs.

Data Security

We implement industry-standard security measures including:

  • Encryption of data at rest (AES-256) and in transit (TLS)
  • Secure cloud infrastructure (AWS and Google Cloud Platform)
  • Limited access controls and multi-factor authentication
  • Regular security audits and SOC 2 Type II compliance
  • Automated PII detection and masking before AI processing

However, no internet transmission is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

Your Rights

You have the right to:

  • Access your personal information
  • Correct inaccurate data
  • Request deletion of your information (subject to legal requirements)
  • Opt out of marketing communications
  • Request data portability (where applicable)

To exercise these rights, contact us at privacy@conveystack.com

Cookies and Tracking

We use cookies and similar technologies to:

  • Maintain session information
  • Remember preferences
  • Analyze website traffic
  • Improve user experience

You can manage cookie preferences through your browser settings.

Children’s Privacy

Our Services are intended for businesses and business professionals. We do not knowingly collect information from individuals under 18 years of age.

Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or website notice. Continued use of our Services after changes indicates acceptance.

Contact Information

For privacy-related questions or concerns:
  

Convey Stack Inc.
Email: privacy@conveystack.com
Website: conveystack.com
  

This Privacy Policy was last updated on November 1, 2025. Please check this page periodically for updates.