1. Who We Are & Scope of This Policy
OverFlow ("OverFlow," the "Services") is an AI voice-agent service that answers the missed and after-hours inbound calls of home-services businesses (for example, roofing, plumbing, HVAC, and electrical contractors). This Privacy Policy is published by Better Flow Ai, LLC ("we," "us," or "our"), a New York limited liability company with a registered business address at 36 Sunset Trail, Fairport, New York 14450.
This Policy explains how we handle personal information in two different roles:
- As the business we deal with directly — the "Customer." A "Customer" is a home-services business that subscribes to OverFlow. We collect account, contact, and billing information from Customers, and for that information we act as the business deciding how and why it is used (a "controller").
- As a service provider to the Customer — for "Caller" data. A "Caller" is a homeowner or other member of the public who telephones the Customer and whose call is answered by OverFlow. When OverFlow answers a Caller's call, records and transcribes it, and captures details about the Caller, we process that Caller information on behalf of and under the instructions of the Customer. In privacy law terms, the Customer is generally the "controller" / "business," and we act as the Customer's "service provider" / "processor."
This Policy does not cover the Customer's own websites, forms, CRM, or other handling of Caller data after it leaves OverFlow, nor any third-party service the Customer separately uses.
2. Categories of Personal Information We Collect
A. Caller personal information (collected on the Customer's behalf when a Caller phones the Customer's forwarded line):
- Voice recording of the call (audio).
- Transcript of the call (text).
- Name of the Caller (as given on the call).
- Callback number (the phone number provided or transmitted).
- Property address and ZIP code of the home or job site.
- Approximate location derived from the ZIP code (a ZIP-centroid point used for service-area checks and maps; never the street address).
- Problem description (what the Caller says is wrong — e.g., a roof leak).
- Derived urgency / emergency flag (an automated classification of how urgent the call appears).
B. Customer account information (collected directly from the subscribing business):
- Business and contact details (company name, account contact name, email, phone, business address).
- Billing references — we use a third-party payment processor and store tokenized references to a payment card; we do not store full card numbers (see Section 8).
- Configuration and settings (e.g., forwarding number, staff alert recipients, service radius).
C. Usage, device, and log data (collected automatically):
- Account dashboard usage, IP address, browser/device information, log and diagnostic data, and call metadata (date, time, duration, the OverFlow number dialed).
- Mobile push token and device platform (iOS/Android) — collected when a Customer's staff member signs in to the OverFlow companion app and enables notifications, and stored linked to that user's account solely to deliver the alerts described in Section 4 (new leads, new voicemails, inbound referrals, and Emergency Assist Network notices) to that device. Signing out of the app, disabling notifications, or uninstalling the app ends this collection and removes the stored token.
D. Website visitor data (collected automatically on our public website):
- Aggregate, cookieless page-view analytics — page path, referrer, country, and device category — via a privacy-first analytics service (Vercel Web Analytics). This measurement sets no cookies and stores no persistent identifiers: visits are counted with a short-lived anonymized hash that cannot follow a visitor across websites or over time, and query strings are stripped from our page URLs before they are recorded (referring-page URLs are limited by standard browser referrer policies). We do not use advertising or cross-site tracking cookies anywhere on the site.
- Referral-link measurement (first-party cookie). Some of our partners share a referral link of the form `overflowvoice.com/r/ABC12345`. If you arrive through one, we set a single first-party cookie named `bf_ref` on your browser and record the visit (the time, the referral code, the page you landed on, the host that referred you, and a coarse device category such as "mobile" or "desktop"). The cookie contains a randomly generated visitor identifier and the referral code; it is not readable by scripts, is never sent to any other website, and expires 90 days after your most recent referral-link visit. Its sole purpose is so that, if you later create an account, we can tell which partner introduced you and pay them the commission they are owed. We do not use it for advertising, cross-site tracking, profiling, or automated decision-making, and we do not sell or share it. Honoring opt-out signals: if your browser sends a Global Privacy Control (`Sec-GPC`) or Do Not Track (`DNT`) signal, we do not set this cookie at all. We still record that a visit to that referral link happened (its time, the code, the landing page, the referring host and a coarse device category), but without any identifier, so those visits cannot be linked to each other or to you, and cannot be attributed to a partner if you later sign up. You can also delete the cookie at any time in your browser settings; doing so simply means a partner may not receive credit for introducing you.
- Browser local storage is used only for strictly necessary functions: maintaining the sign-in session, and — if a signup is interrupted pending email confirmation — temporarily holding the details entered on the signup form in the visitor's own browser until the signup completes. It is not used for tracking.
- Our web pages load font files from Google Fonts; as with any third-party content delivery, Google receives the visitor's IP address and user agent when serving the files. During the payment step, our payment processor's hosted checkout component may use strictly necessary cookies or storage for security and fraud prevention.
3. Sources of Personal Information
- From the Caller, during the call — everything the Caller says, plus the call audio and connection details.
- From the Customer — account, contact, billing, and configuration information, and the call forwarding that routes a Caller to OverFlow.
- Automatically — log, device, usage, and call-metadata information generated when the Services are used.
- From our service providers — for example, telephony/connection data from our voice and SMS provider, and a normalized/validated address from our geocoding provider.
4. How and Why We Use Personal Information
We use Caller personal information only to provide the Services to the Customer and as the Customer instructs, including to:
- Answer the call, deliver the locked opening disclosure (recording + AI), and triage the Caller's need.
- Record and transcribe the call.
- Capture and structure the lead (name, callback number, property address/ZIP, problem, urgency).
- Provide general, non-emergency safety and waiting tips (for example: place buckets under a leak; "tarp only if it's safe — never climb the roof"; shut off water or gas where appropriate; photograph damage for insurance; and "if you are in danger, hang up and call 911"). OverFlow never quotes prices, never promises insurance outcomes, and never claims to be human.
- Send a lead alert text, email, and — where the Customer's staff use the OverFlow companion app — mobile push notification to the Customer's staff, plus a daily digest to the Customer. Push is also used to alert staff to a new voicemail (caller name or number plus a short summary), an inbound referral from another OverFlow business (that Caller's name plus a short problem summary), and Emergency Assist Network notices (which name the emergency and contain no Caller identity). Push alerts may appear on a locked device screen.
- Send a confirmation text to the Caller only if the Caller gave verbal consent on the call (see Section 7).
We use Customer account and usage information to operate, secure, support, and improve the Services; to authenticate users; to bill and collect; to communicate about the account; and to comply with law.
5. How We Disclose Personal Information
We share personal information with the following categories of recipients, each acting under contract on our behalf or the Customer's behalf:
- The Customer. Caller lead data (recording, transcript, and captured fields) is delivered to the Customer that received the call — this is the entire purpose of the Services.
- Other OverFlow businesses. (a) If a Caller agrees on the call to be referred to a specific nearby business, that business receives the Caller's name, callback number, property address, problem description and urgency so it can follow up. (b) If the Customer has opted in to the Emergency Assist Network, then while a declared emergency is active in the Customer's area, other opted-in OverFlow businesses in the same trade nearby can see, on their dashboard map, the approximate (ZIP-code-level) location, problem type, urgency level and hour of each overflow call, and the Customer sees theirs. No Caller name, phone number, address, recording or transcript is shared this way.
- Subprocessors / service providers, by category:
- Hosting and database/authentication (multi-tenant cloud database and app hosting).
- Voice and SMS (telephony, call connection, SMS delivery).
- Voice AI (the conversational agent, which relies on a large-language-model provider).
- Payments (card tokenization and billing; receives Customer billing data, not Caller data).
- Email delivery (alerts and digests).
- Geocoding (address validation/normalization).
- Mobile push delivery (relay of lead alerts to Customer staff devices, and the Apple/Google platform push services that carry them).
- Legal, safety, and protection. We may disclose information to comply with law, legal process, or a lawful request; to enforce our agreements; or to protect the rights, safety, or property of any person — including in connection with the safety situations the agent is designed to flag.
- Business transfers. In a merger, financing, acquisition, or sale of assets, information may be transferred subject to this Policy.
A current list of named subprocessors is available on request at admin@overflowvoice.com.
We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) and similar laws. We do not use Caller recordings, transcripts, or lead data for advertising.
6. Call Recording & AI Disclosure
Every call OverFlow answers is recorded and transcribed. At the very start of the call, before any triage, the agent delivers a locked opening disclosure that (a) states the call is being recorded and (b) states that the Caller is speaking with an automated/AI assistant, not a human. A Caller who does not wish to be recorded can hang up. The agent never claims to be human.
7. SMS Messages (Consent, STOP, HELP)
OverFlow uses SMS for two purposes:
- Lead alert texts to the Customer's staff (the people the Customer designates), as part of the account relationship.
- Confirmation texts to the Caller — sent only if the Caller gives verbal consent during the call. If the Caller does not consent, no confirmation text is sent.
All program texts include "Reply STOP to opt out." Reply STOP to stop messages and HELP for help. Message and data rates may apply; message frequency varies. Carriers are not liable for delayed or undelivered messages. Mobile opt-in data and consent are not shared with third parties for their own marketing.
8. Payment Information
Billing is handled by a third-party payment processor. When a Customer subscribes (including starting the 14-day free trial that auto-renews to a paid monthly subscription unless cancelled), the card is tokenized by the processor. We never receive or store full payment card numbers — only tokens and limited transaction references needed to manage billing. Card data is handled under the payment processor's terms and security.
9. Data Retention and Deletion
We retain personal information only as long as needed for the purposes in this Policy, to provide the Services to the Customer, to comply with legal, tax, and accounting obligations, to resolve disputes, and to enforce our agreements.
- Caller call data is retained on the Customer's behalf under our standard retention schedule: call audio recordings — 90 days; call transcripts — 12 months; structured lead fields (name, callback number, address, problem) — 24 months. After the applicable period the data is deleted or anonymized in the ordinary course, subject to legal retention requirements and routine backup cycles. When the Customer instructs deletion, or on termination, we will delete or return Caller data as provided in the Customer agreement.
- Referral and emergency-map sharing. A referral record shared with another OverFlow business follows the same schedule as the structured lead fields it copies (24 months). Emergency-map visibility lasts only while the emergency is active; it reads the call's ZIP-level location, which ages out with call transcripts (12 months).
- Customer account and billing data is retained for the life of the account and for up to seven (7) years afterward as required for legal, tax, and audit purposes.
- Referral-link visit records (Section 2.D) — records containing the `bf_ref` visitor identifier are deleted automatically 90 days after the visit, by a scheduled daily job. The resulting attribution record, which stores only which partner code introduced an account and no visitor identifier, is kept as a commercial and accounting record for as long as we may owe or have paid commission on that account. Deleting an account also deletes that account's referral visit records and removes the visitor identifier from its attribution record.
10. Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, tenant isolation in our multi-tenant database, and use of vetted subprocessors under contract. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Your Privacy Rights and How to Exercise Them
Depending on where you live and the role we play with your data, you may have rights to access, correct, delete, or obtain a copy of your personal information, to opt out of certain processing, and to be free from discrimination for exercising your rights.
How Callers exercise rights (no account needed). A Caller has no OverFlow account. Because we typically process Caller data as the Customer's service provider, the Customer (the business you called) is usually the right party to handle your request, and we may forward your request to that Customer and assist them. To make a request directly to us, email admin@overflowvoice.com with enough detail for us to locate your information (for example, the business you called, your callback number, and the approximate date and time of the call). We will verify your request using the information associated with the call before acting on it, and we will not use that information for any other purpose.
How Customers exercise rights. Account holders can contact us at admin@overflowvoice.com or admin@overflowvoice.com, or use in-account tools where available.
Authorized agents. You may use an authorized agent to submit a request where the law allows, subject to verification.
11.1 California Residents (CCPA/CPRA)
If you are a California resident, you may have the right to: know/access the categories and specific pieces of personal information we collect, use, and disclose; correct inaccurate information; delete your information; and opt out of "sale" or "sharing" of personal information and of certain uses of sensitive personal information.
- We do not sell or share your personal information (as defined under the CCPA/CPRA), so there is no "Do Not Sell or Share My Personal Information" action needed; if this ever changes, we will provide that link and honor opt-out preference signals (such as Global Privacy Control).
- Sensitive personal information. Call audio and the contents of a call can include sensitive information. We use such information only to perform the Services as described and not for purposes that would require a separate right-to-limit option under the CCPA/CPRA.
- For Caller data, we generally act as a service provider to the Customer and will assist the Customer (the "business") in responding to verified consumer requests.
12. Children's Privacy
The Services are intended for businesses and adults. OverFlow is not directed to children under 18, and we do not knowingly collect personal information from children. A Caller who reaches OverFlow is presumed to be an adult contacting a home-services business. If we learn we have collected personal information from a child in a manner not permitted by law, we will delete it.
13. International Users
OverFlow is offered in and operated from the United States and is currently intended for U.S.-based businesses and Callers only. We do not currently offer the Services outside the United States. If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with local law.
14. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the "Version" and effective date above and, where appropriate, provide additional notice. Material changes will be communicated as required by law. Your continued use of the Services after an update takes effect means you accept the revised Policy.
15. How to Contact Us
Questions, requests, or privacy concerns:
- Privacy requests / general privacy: admin@overflowvoice.com
- Support: admin@overflowvoice.com
- Privacy contact / data protection: Privacy Administrator, Better Flow Ai, LLC — admin@overflowvoice.com
- Mailing address: Better Flow Ai, LLC, 36 Sunset Trail, Fairport, New York 14450
This Policy is governed by the laws of New York, without regard to its conflict-of-laws rules.