Privacy Policy
How Granvure collects, uses, discloses, and retains personal information.
- Effective
- July 22, 2026
- Version
- 2026-07-22
1. Scope
This Privacy Policy applies to Granvure’s websites, accounts, AI receptionist service, support, and related business operations. Granvure LLC is located at 7901 4th St N, STE 300, St. Petersburg, FL 33702. Customers control the business information and caller data they submit to the service; Granvure processes that data to provide the service.
2. Information we collect
- Account data, including name, organization, email, authentication identifiers, roles, and consent records.
- Business configuration, knowledge content, hours, routing, voicemail, transfer settings, and support communications.
- Subscription identifiers, plan, status, invoices, and billing events. Stripe receives payment-card details; Granvure does not store full card numbers or security codes.
- Call metadata, such as caller and destination numbers, timestamps, duration, status, routing outcome, and provider identifiers.
- AI conversation data, including transcripts, summaries, extracted intent, urgency, and follow-up information when generated by the configured service. Granvure does not enable call recording by default and discards provider recording URLs and secrets.
- Website and document content supplied for knowledge processing. Uploaded source files are processed for extraction and are not retained after extraction by the application.
- Calendar connection identity, configuration, encrypted access and refresh tokens, availability, and appointment details.
- Technical and security data, including session cookies, request metadata, audit events, error information, and rate-limit signals.
3. How we use information
- Provide, authenticate, secure, support, and bill for the service.
- Provision and operate customer-configured AI, telephony, knowledge, and scheduling workflows.
- Synchronize provider events, detect abuse, investigate errors, and preserve service integrity.
- Communicate transactional, security, billing, support, and policy information.
- Improve reliability and usability using operational information that is appropriately limited and protected.
- Comply with law, enforce agreements, and protect rights and safety.
4. Cookies
Granvure currently uses essential cookies for Supabase authentication and a short-lived, HTTP-only calendar OAuth state cookie. These cookies are necessary for sign-in, session refresh, security, and connected-calendar authorization. Granvure does not currently deploy advertising cookies or cross-site behavioral advertising trackers. See the Cookie & Privacy Notice for details.
5. How information is disclosed
Granvure discloses information only as needed to operate the service, follow customer instructions, complete transactions, protect the service, or comply with law. Current processor categories include cloud hosting and delivery (Vercel), authentication and database hosting (Supabase), payment processing (Stripe), AI voice and conversation processing (Vapi and its configured model/voice providers), telephony (Twilio when configured), email delivery, and calendar providers selected by the customer. Granvure does not sell personal information or share it for cross-context behavioral advertising as those terms are commonly defined.
6. Customer responsibilities and caller information
Business customers determine the purpose and configuration of their AI receptionist and are responsible for lawful notices, consent, call routing, retention, and handling of caller requests. Callers should contact the business they called about that business’s use of their information. Granvure will assist customers with appropriate requests where required.
7. Retention
Granvure retains information while an account is active and as reasonably necessary for service delivery, security, billing, dispute resolution, and legal obligations. Some records currently have no automated deletion schedule. Account deletion, caller-data deletion, exports, and legal holds require verified support handling. The Data Retention Policy describes current system behavior and limitations; it does not promise deletion that the product cannot yet automate.
8. Security
Granvure uses organization-scoped access controls, row-level security, encrypted transport, provider-secret separation, signed webhooks, protected server credentials, and audit controls. Calendar provider tokens are encrypted before storage. No security method is perfect, and Granvure cannot guarantee absolute security. Report suspected security issues to hello@granvure.com.
9. Rights and choices
Depending on location and applicable law, individuals may request access, correction, deletion, portability, or information about processing, and may appeal a denied privacy request. Granvure does not currently provide automated privacy-request or account-deletion controls. Submit a request to hello@granvure.com. We will verify identity and authority before acting and may retain information where legally permitted or required. Authorized agents must provide evidence of authority.
10. Children
Granvure is a business service not directed to children under 13, and we do not knowingly collect personal information directly from children under 13. Customers must not configure Granvure to collect children’s information without establishing all required authorization and safeguards.
11. International use
Granvure is operated from the United States. Information may be processed in the United States and other locations where service providers operate. Customers are responsible for confirming that their use is permitted in each relevant jurisdiction.
12. Changes and contact
We may update this policy prospectively and will post a new effective date. Privacy questions and requests may be sent to hello@granvure.com or Granvure LLC, 7901 4th St N, STE 300, St. Petersburg, FL 33702.
These policies describe Granvure’s current service and are not legal advice to customers about their own obligations.
