R
raabet.ai
Legal & Compliance

Privacy Policy

Raabet.ai is an AI-powered operations platform for franchise home services businesses. This policy explains what data we collect, how we use it, and the rights you have over it.

Effective April 3, 2026 Raabet LLC CCPA Compliant
01

Information We Collect

Raabet.ai collects data in five broad categories, depending on which features your organization uses. We collect only what is necessary to operate the platform.

Account Data
  • Full name and email address
  • Role (owner, staff)
  • Organization (franchise) membership
  • Login timestamps and session metadata
  • Password hash (stored by Supabase Auth — we never see the plaintext password)
Business Integration Data
  • ServiceMinder CRM: contacts, appointments, proposals, invoices, service history
  • RingCentral: call logs, call recordings, SMS messages, voicemails
  • Gmail (optional, read-only): when you connect your Google account, we access Gmail with the gmail.readonly scope only. We read solely: (a) emails from lead-generation platforms (Scorpion, Angi, HomeAdvisor, Thumbtack, Gemstone Lights, and similar) and (b) emails where the sender matches a contact already in your Raabet customer database. We never read, store, or process any other email. We cannot send, reply to, delete, modify, or label any message. See Section 13 below for the full Google API Services disclosure.
AI-Processed Data
  • Call transcripts generated from audio
  • AI-generated call summaries, categorization, and action items
  • Contact memory profiles (facts, preferences, and opportunities extracted from calls)
  • Voice Intelligence Engine artifacts: personality profiles, playbooks, FAQ banks
  • AI-drafted SMS messages (reviewed and approved by staff before sending)
Usage & Device Data
  • Feature usage events (pages visited, actions performed)
  • API call logs (route, timestamp, response code)
  • Browser type and version
  • Operating system
  • IP address (used for rate limiting and security; not tied to a persistent user profile)

We do not collect payment card numbers directly. Billing is handled entirely by our payment processor (Paddle), and we store only a subscription status and customer reference ID.

02

How We Use Information

We use the information we collect for the following purposes:

We do not use your business data to train third-party AI models, sell advertising, or benchmark one franchise against another without explicit consent.

03

How We Share Information

We do not sell your personal data. We share data only with the service providers necessary to deliver the platform, and only to the extent required for each provider's specific function.

Vendor Purpose Data Shared
Google Gemini AI analysis — call analysis, intent parsing, SMS drafting, route optimization Call transcripts, contact context, task descriptions
ElevenLabs AI voice receptionist (Maya) — real-time conversational AI Live call audio (streamed during the call; not stored by ElevenLabs beyond the call)
Twilio Phone number provisioning and call routing for Maya Caller phone number, call routing metadata
RingCentral Calls, SMS, call recordings, voicemails — your primary business phone system Call audio, SMS content, call metadata (per your RingCentral account)
ServiceMinder CRM — contacts, appointments, invoices, proposals, and internal messaging Contact records, appointment details, service history, SMS/MMS message content (per your SM account)
Supabase User authentication Email address, password hash
Vast.ai GPU transcription (Voice Intelligence Engine onboarding only) Call recording audio — temporarily processed, then permanently destroyed
Sentry Error tracking and performance monitoring Anonymized error payloads; stack traces do not include customer content
Cloudflare Dashboard hosting and CDN Standard web traffic (IP address, request metadata)
Paddle Subscription billing Email address, subscription tier (payment card handled entirely by Paddle)
Intuit QuickBooks Online Accounting data — job costing, labor costs, expense tracking, profit margins Read-only access to invoices, expenses, employee records, and time entries (per your QBO account)
Google Calendar Calendar conflict detection and scheduling optimization Read-only access to calendar events and availability (per your Google account)
Scorpion Marketing attribution — lead source tracking, campaign performance, ad spend analytics Lead records, campaign data, attribution metadata (per your Scorpion account)

We may also disclose information when required by law, subpoena, or court order, or when we believe in good faith that disclosure is necessary to protect the safety of any person or to prevent fraud or abuse of our systems.

In the event of a merger, acquisition, or sale of substantially all assets, your data may be transferred to the successor entity. We will provide notice before your data becomes subject to a materially different privacy policy.

04

Call Recording & Transcription

Important: Raabet.ai processes call recordings to generate transcripts and AI-powered analysis. This section explains exactly how call audio is handled and how long it is retained.

Call recording is a core feature of the platform, subject to your organization's RingCentral configuration and applicable state laws (including California two-party consent requirements under Penal Code § 632). Your organization is solely responsible for ensuring that callers are notified of and consent to recording, as required by law.

How call audio flows through Raabet.ai

  1. Recording capture: Calls are recorded through RingCentral per your account's recording settings. RingCentral stores the audio file on its own infrastructure, governed by RingCentral's privacy policy.
  2. Download for transcription: After a call ends, Raabet.ai retrieves the recording file from RingCentral's API for transcription. The audio is held in temporary server memory only for the duration of the transcription process.
  3. Transcription: Audio is sent to our transcription engine (WhisperX, running on either our Hetzner server or a Vast.ai GPU instance for bulk onboarding jobs). Vast.ai instances are ephemeral and recordings are not persisted there after processing is complete.
  4. AI analysis: The resulting text transcript is sent to Google Gemini for intent classification, outcome categorization, action item extraction, and contact memory updates. The audio file is not sent to Gemini.
  5. Storage: The completed transcript, AI summary, and structured analysis are stored in your organization's database partition on our Hetzner PostgreSQL server. The original audio file is deleted from Raabet.ai's servers after transcription is confirmed complete. It remains in your RingCentral account per your RingCentral retention settings.
Data minimization: We do not permanently store call audio on Raabet.ai infrastructure. After successful transcription, the audio file is deleted from our systems. Only the text transcript and AI-derived metadata are retained.

Maya AI Receptionist calls

When a caller reaches your Maya AI receptionist, the call is handled by ElevenLabs' Conversational AI platform via Twilio. The live audio stream is processed by ElevenLabs in real time to generate Maya's spoken responses. Call audio is not stored by Raabet.ai during the live call. After the call ends:

05

AI Processing

Raabet.ai uses Google Gemini and other AI models to provide intelligent features including call analysis, contact memory, SMS drafting, and Ask Raabet — a conversational AI agent for staff. This section explains how AI is used and its limitations.

What AI processes

Human review requirement

AI outputs are not infallible. All AI-generated content — including call summaries, contact notes, and SMS drafts — should be reviewed by a human staff member before being acted upon or communicated to customers. Raabet.ai does not guarantee the accuracy of AI-generated analysis or recommendations.

Confirm-before-execute (Ask Raabet trust system)

Ask Raabet uses a three-tier trust system to ensure staff maintain control over consequential actions:

AI model data use

Data sent to Google Gemini is governed by Google Cloud's data processing terms. Under Google's enterprise API agreements, data submitted via the API is not used to train Google's foundational models by default. We strongly recommend reviewing Google's current data processing addendum for your use case at cloud.google.com/terms/data-processing-addendum.

We do not share your business data with any AI provider for the purpose of model training without your explicit, written consent.

06

Data Retention

We retain data as long as your account is active and as required to provide the platform.

07

Multi-Tenant Data Isolation

Raabet.ai is a multi-tenant platform serving multiple franchise locations. Each franchise is a distinct organization within the system. We implement strict logical data isolation between organizations:

Shared infrastructure, isolated data: All franchises share the same database server and application infrastructure, but the logical isolation enforced by org_id filtering means your data is never commingled with or exposed to another franchise's users.
08

Data Security

We implement industry-standard security controls across all layers of the platform. The system has been assessed against OWASP ASVS (Application Security Verification Standard) criteria.

No security system is perfect. If you discover a potential security vulnerability in Raabet.ai, please disclose it responsibly to support@raabet.ai. We are committed to investigating and addressing security reports promptly.

09

Your Rights

You have the following rights with respect to the personal data we hold about you or your organization. To exercise any of these rights, contact us at support@raabet.ai.

👁
Right to Access

You may request a copy of the personal data we hold about you, including account information, call records, transcripts, and AI-derived notes associated with your organization.

Right to Correction

If any information we hold about you is inaccurate or incomplete, you may request that we correct it. Most account data can be updated directly within the platform.

🗑
Right to Deletion

You may request that we delete your personal data. For active accounts, deletion of specific records can be requested. For full account deletion, terminating your subscription initiates a 30-day export window followed by complete data purge.

💾
Right to Data Export

You may request a machine-readable export of your organization's data, including contacts, call records, transcripts, and appointments. Exports are available in JSON or CSV format. We will deliver the export within 30 days of a verified request.

🚫
Right to Object

You may object to specific uses of your data, such as using call transcripts to improve AI model prompts. Where technically feasible, we will honor such objections.

Right to Restrict Processing

In certain circumstances you may request that we restrict processing of your data while a dispute or correction request is being resolved.

We will respond to all data rights requests within 30 days. In complex cases we may extend this period by a further 30 days and will notify you of the extension. We do not charge a fee for reasonable rights requests.

10

CCPA — California Residents

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you additional rights regarding your personal information.

Categories of personal information collected

In the preceding 12 months, we have collected the following CCPA categories of personal information:

CCPA rights

How to submit a CCPA request

Submit verifiable consumer requests to: support@raabet.ai with the subject line "CCPA Privacy Request." We will verify your identity before processing the request and respond within 45 days (extendable by an additional 45 days with notice).

You may designate an authorized agent to submit a request on your behalf. The agent must provide written authorization signed by you, and we may verify your identity directly.

11

Children's Privacy

Raabet.ai is a business operations platform intended solely for use by adults in a professional capacity. The platform is not directed at children under the age of 13, and we do not knowingly collect personal information from children.

If you believe that we have inadvertently collected information from a child under 13, please contact us immediately at support@raabet.ai and we will take prompt steps to delete that information.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or other factors.

When we make material changes, we will:

Non-material changes (such as correcting typographical errors or clarifying existing practices without changing their substance) may be made without prior notice. Continued use of the platform after the effective date of a revised policy constitutes your acceptance of the updated terms.

We encourage you to review this policy periodically. The date at the top of this page indicates when it was last revised.

13

Google API Services — Limited Use Disclosure

This section describes how Raabet.ai uses information obtained through Google APIs (Gmail in particular). It applies only to franchise accounts that have chosen to connect a Google account in Settings → Integrations.

Scopes we request

No other Google scopes are requested. We do not access Google Drive, Calendar, Contacts, or any other Google service via this connection.

What messages we actually read

After the connection is granted, our mail poller fetches only message headers (From and Subject) for each new inbox item. We then evaluate the header against a strict allowlist before downloading the body. We download and read a message body only when one of the following is true about the sender:

For all other senders, the body is never downloaded, stored, logged, or processed — only the header is briefly seen in order to make this decision, and the headers are discarded from memory immediately after the decision.

How we use the messages we do read

Limited Use affirmation

Raabet.ai's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Storage, security, and deletion

How to revoke access

You can disconnect Raabet.ai from your Google account at any time in two ways:

14

Contact Information

If you have questions, concerns, or requests relating to this Privacy Policy or the handling of your data, please contact us:

Raabet LLC

We aim to respond to all privacy-related inquiries within 5 business days. For urgent security matters, please include "URGENT" in the subject line of your email.