About This Policy
This Privacy Policy explains how your personal data is collected, used, disclosed, and protected when you use Caplo, a platform developed and operated by Caplo.
Your privacy is important to us. This policy complies with applicable United States federal and state privacy laws, including the California Consumer Privacy Act (CCPA) where applicable, and other relevant data protection regulations.
1. Information We Collect
We collect and process the following categories of personal data when you interact with Caplo:
1.1. Account Data
• Full name
• Email address
• Phone number
• Company name
• Country and language preferences
1.2. Payment and Financial Data
• Transaction details (top-up history, usage-based charges)
• Partial payment identifiers (via third-party processors)
• Invoices and billing data (required for tax and compliance)
Note: All payment data is processed by certified third-party providers in compliance with PCI-DSS standards. We do not store your credit card or bank information.
1.3. Usage and Communication Data
• Call duration, timestamp, routing metadata, and customer contact details
• Call recordings or audio files when recording is enabled for your workflow
• Call transcripts, AI-generated summaries, and extracted scheduling or lead details
• Message logs and delivery metadata for SMS and email
• WhatsApp Business Platform connection details when you connect WhatsApp through Meta Embedded Signup, including business account identifiers, phone number identifiers, display phone numbers, approved template metadata, webhook delivery events, and encrypted access credentials needed to operate the connected channel
• WhatsApp message content and delivery metadata that Caplo receives or sends for your connected business number, including customer phone numbers, message timestamps, conversation context, delivery status, and opt-out signals
• Gmail and Outlook Mail message metadata and body text needed to display customer email threads in Omni Box, draft human-approved replies, and maintain delivery audit records when you connect Google Workspace or Microsoft 365 mail capabilities
• Instagram DM and Facebook Messenger message content, sender identifiers, timestamps, and delivery metadata received through Meta webhooks when you connect those social messaging capabilities
• Transactional account emails such as verification codes, password resets, billing receipts, and operational notices
• AI configuration settings (custom scripts, triggers, workflows)
1.4. Technical and Log Data
• Device and browser type
• IP address and geolocation (approximate)
• Operating system and session data
• Activity logs and interaction history
2. How We Use Your Data
We use your data lawfully, fairly, and transparently for the following purposes:
• To provide, operate, and improve Caplo
• To authenticate your identity and manage account access
• To process payments and maintain your balance
• To detect and prevent fraud, misuse, or technical issues
• To respond to support requests and send service-related updates
• To deliver transactional emails such as account verification, password resets, billing confirmations, and service notices
• To connect, verify, and operate WhatsApp Business channels that you authorize through Meta Embedded Signup or manually configured WhatsApp Cloud API credentials
• To receive inbound WhatsApp messages, send approved WhatsApp replies or templates, maintain conversation history, honor opt-outs, and troubleshoot channel delivery issues
• To sync Gmail and Outlook Mail into Omni Box, summarize threads, draft replies for staff review, and send human-approved email responses without deleting or modifying mail in your mailbox in V1
• To receive Instagram DM and Facebook Messenger messages in Omni Box and send manual replies when Meta app permissions and review requirements are satisfied
• To monitor bounce, complaint, and suppression signals so we can protect deliverability and prevent abuse
• To analyze usage for performance and product improvements
• To comply with legal, tax, and regulatory obligations
We do not send optional marketing emails unless you have provided any consent required by applicable law. If we introduce optional promotional emails, they will include opt-out controls.
We do not use your data for automated decision-making or profiling unrelated to Caplo's intended service.
3. Lawful Bases for Processing
We process your personal data based on the following legal grounds:
• Contractual necessity: To fulfill our service obligations to you
• Legitimate interest: To monitor and maintain service performance
• Legal compliance: To fulfill tax, legal, and regulatory duties
• Consent: When required (e.g., for email marketing, optional cookies)
4. Data Sharing and Disclosures
We do not sell, rent, or lease your data. However, we may share limited personal data with:
4.1. Third-Party Service Providers
• Payment processors (e.g., Stripe) to handle secure transactions
• Telecommunication and messaging providers for call routing, SMS delivery, transactional email delivery, bounce processing, and complaint handling
• Meta and the WhatsApp Business Platform when you authorize a WhatsApp connection, including the data required to complete Embedded Signup, subscribe webhooks, send and receive WhatsApp messages, sync approved templates, and maintain channel health
• If you connect your own Twilio account through Twilio Connect, delegated Twilio account identifiers and related provisioning metadata needed to operate the connected phone workflow
• AI, transcription, and workflow providers that help us generate call summaries, transcripts, and automations
• Cloud hosting and infrastructure services (e.g., AWS, Google Cloud) for application hosting, storage, security, and observability
4.2. Legal Authorities
• If required by law, court order, or regulatory investigation
• To protect the rights and safety of Caplo, users, or the public
All third parties are bound by contractual obligations to protect your data in accordance with this policy.
5. Google, Microsoft, and Meta Platform Data
When you connect a Google, Microsoft, or Meta account to Caplo, that provider's own platform rules apply to the data Caplo receives, in addition to this policy.
5.1. Google API Services User Data Policy
Caplo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, and without exception:
• We use Google user data only to provide and improve the specific features you connected it to.
• We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
• We do not use Google user data for advertising, and we do not sell it.
• We do not use Google Workspace APIs data to develop, improve, or train generalized artificial intelligence or machine learning models. Content is processed only to produce the specific output you requested for your own account, and it is never added to any shared or general-purpose training corpus.
• Humans do not read your Google user data except with your explicit permission for a specific support issue, where required for security or abuse investigations, or where required by law.
5.2. Google scopes Caplo requests and why
• Gmail (read): to display your customer email threads inside Omni Box so your team can answer them in one place.
• Gmail (send): to send a reply that you or your team have approved, from your own connected mailbox.
• Google Calendar: to check availability and create, update, or cancel bookings made through your assistant.
• Google Sheets: to append call and lead records to a spreadsheet you nominate by ID. Caplo does not browse or list your Drive.
• Google Business Profile: to read and manage the business locations and customer reviews you choose to connect.
• Basic email address: to show which Google account is connected and to keep multiple connections apart.
Caplo requests each of these only when you enable that specific feature, and never as a bundle.
5.3. Microsoft 365 and Microsoft Graph
Outlook Mail and Outlook Calendar data is used only to operate the mail and booking features you connected, on the same terms set out in 5.1. Microsoft does not provide an application-level token revocation endpoint, so when you disconnect, Caplo deletes its stored credentials immediately and you can additionally remove Caplo's standing access from your Microsoft account permissions page.
5.4. Meta Platform data
WhatsApp, Messenger, and Instagram message content received through Meta is used only to operate your connected channels in accordance with the Meta Platform Terms and Developer Policies. It is not used for advertising, is not sold, and is not used to train generalized AI models.
5.5. Disconnecting and revoking access
You can disconnect any connected account at any time from Settings. On disconnect, Caplo revokes the access grant with the provider where the provider supports revocation, deletes its stored access and refresh tokens, and stops all further access. Deleting your Caplo account revokes every connected grant immediately; see Section 9.
6. International Data Transfers
Your data is primarily stored and processed in the United States. If we transfer your data internationally, we ensure appropriate safeguards are in place, such as:
• Standard Contractual Clauses where required
• Data processing agreements with international service providers
• Compliance with applicable cross-border data transfer regulations
7. Data Retention
We retain personal data based on necessity:
• For as long as your account is active
• Communications records such as recordings, transcripts, summaries, and transactional email logs only for as long as needed to provide the service, support support and dispute resolution, and satisfy legal obligations
• WhatsApp connection credentials, WABA identifiers, phone number identifiers, template metadata, and webhook records for as long as the WhatsApp channel remains connected or as needed for security, audit, billing, support, and legal obligations
• For legal compliance (e.g., accounting, tax) for up to 5 years
• For security, abuse prevention, and deliverability protection, including suppression records for bounce or complaint events, for up to 24 months after the relevant event unless a longer period is required by law
After this period, your data will be anonymized or securely deleted.
8. Data Security
We take your data security seriously. Measures include:
• TLS/SSL encryption for all data in transit
• Access control and authentication for account and admin systems
• Firewall and intrusion detection systems
• Regular security audits and vulnerability assessments
Our team follows best practices in secure software development and GDPR-compliant data handling.
9. Your Data Protection Rights
Under applicable privacy laws, you have the right to:
• Access your personal data
• Correct inaccurate or outdated data
• Request deletion of your data under certain conditions
• Restrict processing of your data
• Object to data processing based on legitimate interest
• Object to direct marketing or opt out of optional promotional communications where offered
• Withdraw consent at any time (where consent is the basis)
• Data portability – receive your data in a machine-readable format
• Lodge a complaint with the appropriate regulatory authority
California residents may have additional rights under the CCPA, including the right to know what personal information is collected and the right to opt-out of the sale of personal information.
You may ask us to disconnect a WhatsApp Business channel and delete associated Meta/WhatsApp connection records where deletion is not restricted by security, fraud prevention, billing, dispute-resolution, or legal-retention obligations.
9.1. Deleting your account and data yourself
You do not need to contact us to delete your data. Sign in and go to Settings, then Account, then Delete account. You will be asked to type your account email to confirm.
What happens immediately, at the moment you confirm:
• Every connected Google, Microsoft, and Meta grant is revoked with the provider, and Caplo's stored access and refresh tokens are deleted.
• Every connected channel is disconnected and stops receiving or sending messages.
• You receive a confirmation code and a public status URL you can check at any time, including after the account is gone.
What happens next:
• Your account and all associated data are permanently erased 30 days after the request. The delay exists only so you can reverse an accidental deletion; no third-party access remains open during it.
• You can cancel the deletion from the same Settings screen at any point during those 30 days.
• Records we are legally required to keep, such as invoices and tax records, are retained for the periods described in Section 7 and are not linked to an active account.
If you cannot sign in, email legal@getcaplo.com from your account address and we will process the deletion for you.
To exercise any other right, email: legal@getcaplo.com
10. Children's Privacy
Caplo is intended for use by businesses and individuals aged 18 and over. We do not knowingly collect data from minors. If we become aware of such data, it will be deleted promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
• Legal changes
• Service updates
• Security enhancements
We will notify you of significant changes via email or in-app notification at least 7 days before changes take effect. The "Effective Date" at the top will be updated accordingly.
12. Contact and Privacy Officer
If you have questions or concerns about this policy or your personal data, please contact us:
Email: legal@getcaplo.com
If you believe your data rights have been violated, you may contact the appropriate regulatory authority in your jurisdiction.