Privacy Policy
Last updated July 30, 2026
Stack Space Solutions (“Stack Space”, “we”, “us”). Stack Space Solutions is a US-based business founded by Noah Gregory. Our registered business details are available on request — email us and we will send them. We make an all-in-one business platform — CRM, AI receptionist and AI employees, invoicing, messaging, and marketing tools — available at stackspacesolutions.com and app.stackspacesolutions.com (the “Service”). This policy explains what data the Service handles, why, and what your choices are. We have tried to write it the way the product is actually built, not the way policies are usually written.
The short version: we collect what the Service needs to work, we never sell personal data, we run no third-party advertising trackers, and you can ask us to delete your data at any time by emailing founder@stackspacesolutions.com.
1. Two layers of data — who is responsible for what
The Service holds two very different kinds of personal data, and the responsibilities differ:
- Your data as our customer. Your account details, billing information, business profile, and how you use the Service. For this data, Stack Space is the data controller: we decide how it is collected and used, as described in this policy. The same applies to visitors of our marketing site.
- Your customers’ data (end-customer data). The contacts, callers, invoice recipients, and messages you put into — or route through — the Service. For this data, you are the controller and Stack Space is a processor acting on your instructions. We store it, run it through the features you enable, and otherwise leave it alone.
Because you control the end-customer layer, you are responsible for your own legal bases toward your contacts: obtaining any consent required to record or transcribe calls in your jurisdiction, having lawful consent to text or email people, and honoring their privacy rights. The platform gives you tools for this (opt-out handling, suppression lists, unsubscribe links), but the legal obligation is yours.
2. What we collect
Account and organization data
- Name, email address, and a hashed password (we never store the plain password).
- Organization details: business name, logo, brand color, industry, timezone, business hours, support email, and how you heard about us.
- Team members and invitations (invitee email addresses), roles, and login timestamps.
Business profile and “Business Brain” content
Free-text descriptions of your business — services, pricing, audience, tone, FAQs, service area — plus knowledge items the AI learns from your website, pasted material, or (if you leave that setting on) summaries of its own calls. This content is used to personalize the AI that works for you.
CRM and end-customer data you store
Clients, contacts, leads, and deals: names, email addresses, phone numbers, postal addresses, job titles, social profile links, notes, custom fields, appointments (invitee name, email, phone), estimates including typed signatures, invoices, review requests and review text, and do-not-text/opt-out lists. Lead-discovery features also store publicly available business information (business name, contact details, website, social links).
Calls — recordings, transcripts, and AI analysis
Voice calls handled by the AI receptionist are recorded and transcribed. For each call we store the caller and receiving numbers, duration, a link to the recording, the full transcript, and AI-generated outputs: a summary, a sentiment label, and a structured recap (for example, next steps and a drafted follow-up email). See section 7 for the consent notice.
Messages sent and received through the Service
Emails and text messages you send and receive through your connected accounts pass through, and are stored by, the Service: inbound email bodies, subjects, and sender details; a log of every outbound email and SMS (recipient, subject, and a short preview); and campaign or template content you write. Outbound email is sent through your own connected mailbox, not a shared Stack Space mail server.
SMS and text messaging (consent, frequency, and rates)
When a business uses the Service to text its customers — appointment reminders, missed-call replies, review requests, estimate and invoice links, follow-ups, and occasional promotions — those recipients opt in by contacting the business (calling it, texting its number, booking an appointment, or submitting a form on the business’s website) and providing their mobile number. Message frequency varies. Message and data rates may apply. Recipients can reply STOP at any time to unsubscribe, or HELP for assistance.
Mobile phone numbers and SMS opt-in consent are never shared with, or sold to, third parties or affiliates for their own marketing or promotional purposes. Text-messaging consent is used only to deliver the messages a recipient asked to receive from the business they contacted; no mobile opt-in information is passed to anyone else.
Google user data (Limited Use)
When you connect a Google service — Google sign-in, Google Calendar, Search Console, or Google Business Profile — we access only the data needed to run the feature you connected: your basic profile for sign-in, calendar free/busy times and events to check availability and book appointments, your site’s Search Console performance data to show your SEO dashboard, and your Business Profile reviews to display and let you respond to them. Stack Space Solutions’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never sell Google user data, never use it for advertising, and never transfer it to third parties except as needed to provide the feature, comply with law, or as part of a merger with notice to you. Google user data is not used to train generalized AI models. You can disconnect any Google service at any time in Settings → Integrations, which revokes our access; you can also revoke access from your Google Account security settings.
Engagement tracking on messages you send
- Email opens: tracked emails include a small tracking pixel. When the recipient opens the email, we record the fact and time of the first open on the message log. We do not store the recipient’s IP address or browser details from the pixel.
- Link clicks: links in outbound texts and campaign emails are wrapped in short tracking links. Each click increments a counter and records the time of the click; we do not record the clicker’s IP address or user agent.
Forms and funnels
When someone submits one of your forms or funnel pages, we store the submitted answers along with the submitter’s IP address and (for forms) browser user agent, which helps you and us tell real submissions from spam.
Usage metering and referral attribution
- Usage records for the metered features on your plan (AI actions, texts, voice minutes, lead lookups, social posts), so the in-app meter and billing are accurate.
- If you arrive through an affiliate link (
/r/<code>), a referral attribution cookie is set for 30 days so the referring affiliate is credited when you sign up. See section 8 on cookies.
Push notifications
If you enable browser push notifications, we store the push subscription for your browser (endpoint and delivery keys) so we can send you notifications. Notification content is sent transiently and not stored on the subscription.
Payment data
Payments are handled by Stripe. Card numbers never touch our servers and we never store them — we keep only Stripe references (such as customer and session identifiers) and invoice records.
Accounting data (QuickBooks Online / Intuit)
If you connect your QuickBooks Online account, you authorize us — through Intuit’s secure OAuth flow — to access only the accounting data needed to keep your books and the Service in sync: your company information, your customer list, and your invoices, payments, and related line items. We use this data solely to mirror invoices and payments between the Service and QuickBooks so you don’t have to enter them twice, and to show you sync status. We never sell or rent your QuickBooks data, never share it with third parties for their own purposes, and never use it to train AI models. We store only what is required to keep the two systems in sync (record identifiers and the fields shown above); we do not pull your full general ledger, payroll, or bank credentials. Each business connects its own QuickBooks account, and that data is isolated to that business. You can disconnect QuickBooks at any time in Settings → Integrations, which revokes our access; you can also revoke it from within your Intuit account, and you may email us to have any stored QuickBooks data deleted.
3. How we use data
- To provide the Service: run your CRM, answer your calls, send your messages, generate your documents.
- To personalize the AI that works for your business (using your business profile and content).
- To meter usage, bill correctly, and show you your live usage meter.
- To secure the Service, prevent abuse, and enforce opt-outs and suppression lists.
- To support you and to send you service communications about your account.
- To comply with legal obligations.
We do not sell personal data — yours or your customers’ — ever. We do not use end-customer data to advertise to anyone, and we run no third-party ad or analytics trackers on the Service.
SMS and text-messaging consent. When you provide a mobile number and opt in to text messages — either to Stack Space or to a business that uses Stack Space — we use that consent only to send the messages you asked for (appointment reminders, account and service notifications, replies to your inquiry, and, where you separately agreed, offers). Mobile information and SMS opt-in data are never shared with, sold to, or rented to third parties or affiliates for their own marketing or promotional purposes, and text-messaging originator opt-in consent is never shared with anyone. Message frequency varies, message and data rates may apply, and you can reply STOP at any time to opt out or HELP for help.
4. AI processing
The Service is built around AI, and different features route different content to different specialist providers. We want to be specific about which data leaves the platform and where it goes:
- Neo’s text “brain” — Anthropic (Claude). The text behind every AI feature — the in-app assistant, drafting, call and meeting summaries, sentiment, auto-replies, and analysis — is processed by Anthropic. The text sent for a given task (for example, a call transcript to summarize, a draft you ask Neo to write, or your business-profile content used to personalize replies) goes to Anthropic to generate the result.
- Phone receptionist calls — Vapi. Voice calls answered by the AI receptionist are carried by Vapi, which provides the telephony and the real-time speech handling for the call. The call audio and its transcript are processed by Vapi. When your receptionist answers, it is given your business profile, recent learned notes, and the caller’s history with you (name, recent call summaries, open estimates) so it can be useful; that context goes to Vapi for the duration of the call.
- In-person meeting transcription — OpenAI (Whisper). When you use the “record in person” feature, your device records the room and the recorded meeting audio is sent to OpenAI’s Whisper service to be transcribed into text. That audio can contain the voices and personal information of your customers, employees, and anyone else in the room, so only record where you have the right to. The returned transcript is then summarized by Anthropic like any other text.
- In-app assistant voice (text-to-speech) — OpenAI. When Neo speaks its replies aloud in the app, the text of the reply is sent to OpenAI’s text-to-speech service to be turned into audio. Only the text to be spoken is sent; if that service is unreachable, your browser’s own built-in voice speaks the reply instead, and we send it nowhere.
- Image generation — OpenAI. When you generate images in the Service, your prompt is processed by OpenAI to produce the image.
These providers process the content only to deliver the feature you triggered. We do not use, and do not permit these providers to use, your content or your customers’ content to train their models.
5. Subprocessors and connected services
Providers we use to run the Service for everyone, and what each one receives:
- Stripe — payment processing and payouts; billing details and Stripe references.
- Anthropic (Claude) — the text brain behind every AI feature; receives the text of the task (transcripts, drafts, business content, chat) to generate a result.
- Vapi — phone receptionist calls; receives call audio, call transcripts, phone numbers, and the caller context described in section 4.
- OpenAI — in-person meeting transcription (recorded meeting audio sent to Whisper), in-app text-to-speech (the reply text Neo speaks aloud), and image generation (your prompt).
- Twilio — SMS delivery, phone numbers, and the telephone line that carries receptionist calls; receives message content and phone numbers.
- Firecrawl — retrieval of publicly available web data for website import, lead discovery, and outreach personalization; receives the search terms and the addresses of the pages fetched.
- DataForSEO — search-result and map-ranking checks; receives the search terms, your business name, and the locations checked.
- Unipile — social messaging and posting on the accounts you connect (LinkedIn, Instagram, Facebook); receives the message content and the profile data of the conversations it carries.
- Hostinger — application hosting.
Services you may choose to connect, which then process your data under their own terms:
- Your own email mailbox (SMTP/IMAP credentials you supply) — all your outbound email is sent through it.
- Google (calendar), Microsoft (calendar), and Zoom, via OAuth.
- QuickBooks Online (Intuit), via OAuth — to sync your invoices and payments; receives and returns the accounting data described above.
- Your LinkedIn, Instagram, and Facebook accounts — carried by Unipile, named above.
- Your own Stripe account — for collecting payments from your customers.
- Optional add-on: a managed dedicated text number (on Twilio).
- Your own Twilio or Firecrawl account, where you connect one instead of using ours.
6. Security
- Connected-service credentials (such as your mailbox password and integration keys) are encrypted at rest with AES-256-GCM and are never returned to the browser.
- Data is encrypted in transit with TLS.
- The Service is multi-tenant with organization-scoped isolation: every query is scoped to your organization, and sub-accounts are isolated from each other.
- Passwords are stored only as one-way hashes.
No system is perfectly secure, but we treat your credentials and your customers’ data as the most sensitive things we hold.
7. Call recording notice
Calls handled by the AI receptionist may be recorded and transcribed, and the transcript is processed by AI to produce summaries and follow-ups. Call-recording consent laws vary — some jurisdictions require all parties to consent. If you use the voice features, you are responsible for complying with the recording-consent laws that apply to you and your callers, including any required disclosures at the start of a call.
8. Cookies
The Service sets a small number of first-party cookies:
- A session cookie to keep you signed in.
ss_ref— referral attribution when you arrive through an affiliate link; expires after 30 days.- A cookie remembering which sub-account you are viewing (agency accounts).
- Short-lived (about 10 minutes) state cookies during Google, Microsoft, or Zoom connection flows.
There are no third-party advertising or analytics cookies, pixels, or scripts on the Service.
9. Retention and deletion
- We keep your data for as long as your account is active, so the Service can work.
- You can request deletion of your account and data at any time by emailing founder@stackspacesolutions.com. We will delete it except where we must retain records (for example, billing and tax records) for legal reasons.
- Deleted data may persist in encrypted backups until those backups are purged on their normal cycle.
- For end-customer data, we act on our customer’s instructions: if you are someone’s contact and want your data removed, you can contact the business that holds it, or contact us and we will pass the request along and assist.
10. Your rights
Wherever you live, we honor these rights on request: access to the personal data we hold about you, correction of inaccurate data, deletion, portability (a copy in a usable format), and objection to or restriction of certain processing. To exercise any of them, email founder@stackspacesolutions.com from the address on your account (or with enough information for us to verify you). We respond within the timelines applicable law requires.
California residents (CCPA/CPRA)
- Categories we collect: identifiers (name, email, phone), commercial information (subscriptions, invoices), internet activity on the Service (usage metering, message engagement), audio (call recordings), and professional information (business profile).
- We do not sell personal information and we do not share it for cross-context behavioral advertising.
- You have the right to know, the right to delete, the right to correct, and the right not to be discriminated against for exercising these rights. Email us to exercise them; you may also use an authorized agent.
11. Children
The Service is a business tool and is not directed to anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, email us and we will delete it.
12. International transfers
We are based in the United States and process data there. If you use the Service from outside the US, your data will be transferred to and processed in the US, which may have different data-protection laws than your jurisdiction.
13. Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated through the Service, and the “last updated” date above always reflects the current version.
14. Contact
Stack Space Solutions · Noah Gregory, founder · founder@stackspacesolutions.com · stackspacesolutions.com