CA Clear Access
Features Pricing Talk to us Sign in
Book a demo
1. Who this covers 2. What we collect 3. How we use it 4. Call recordings 5. Who we share with 6. Security 7. Retention and deletion 8. Your rights 9. Where we operate 10. Changes 11. Contact

Privacy Policy

Clear Access Media LLC · Effective date: to be set at launch
DraftThis document has not been reviewed by a lawyer. Every statement in it is accurate to how the software actually behaves today, which is what makes it a useful starting point — but it has no effective date and it is not yet a commitment. Counsel reviews it before launch.

1. Who this covers

Two different groups of people, and the difference matters.

Our customers. Businesses that open a workspace, and the people at those businesses who sign in. For their information, we are the controller.

The people our customers call. Contacts imported from a customer's own CRM or uploaded as a list. We hold their names and phone numbers, but we did not choose to collect them and we have no relationship with them. For that information our customer is the controller and we act only as a processor on their instructions.

If you were called by a business using Clear Access and want your information corrected or removed, the business that called you controls it. Contact them. We will help them act on your request, and if you reach us instead we will pass it on and tell you who they are.

2. What we collect

From customers: name, email address, workspace name, and the business identity details required for carrier registration (legal name, EIN, address). Payment card details go directly to Stripe and never reach our servers.

On our customers' behalf: contact names and phone numbers, call metadata (numbers dialled, timestamps, duration, outcome, agent notes), call recordings where a customer has enabled them, and the record identifiers needed to write activity back into their CRM.

Automatically: standard service logs including IP addresses, for security and abuse prevention.

3. How we use it

To place and log calls, enforce the compliance gate, sync with integrations a customer connects, bill subscriptions, and keep the service running and secure.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. Under the CCPA and CPRA we act as a Service Provider to our customers. We do not use one customer's lead data for anything other than that customer's workspace, and we never use it to train models.

4. Call recordings

Recording is off by default and stays off until a workspace owner turns it on for a specific campaign.

Before it can be enabled for live calls, the owner must confirm in writing that they obtain consent to record wherever the law requires it. Roughly a dozen US states require every party on the call to consent, and other countries are stricter. The software will refuse to place a live recorded call until that confirmation is on file — but we do not and cannot verify that consent was actually obtained. That responsibility sits with the business making the call.

Recording audio is stored by our telephony provider rather than by us. When a recording is deleted under the retention rules below, we delete it there as well as here.

5. Who we share with

Only the providers the service runs on, each receiving the minimum needed to do its job:

  • Twilio — call delivery, phone numbers, and recording storage.
  • Stripe — subscription billing. Card details go to Stripe directly.
  • Postmark — transactional email (password resets, confirmations, receipts).
  • Fly.io — application hosting.
  • Our managed PostgreSQL and Redis providers — data storage.
  • Integrations a customer connects themselves, such as their CRM. Those connections are made by the customer and can be disconnected by them at any time.

We will tell customers before adding a new provider that handles personal information. We do not share data with anyone else, and we do not disclose it to law enforcement without valid legal process.

6. Security

Stated plainly because every item is something the software actually does:

  • Integration credentials are encrypted at rest with AES-256-GCM, and are never returned by the API once stored.
  • Passwords are hashed with scrypt. API keys and rep dialer links are stored hashed and cannot be recovered after they are issued — only reissued.
  • Every workspace is isolated in the database, not merely in application code.
  • Traffic is encrypted in transit, and plain HTTP is redirected.
  • Setup links used for onboarding are scoped to a narrow set of operations, expire, and can be revoked.
  • Resetting a password ends every existing session for that account.

No system is perfect. If you believe you have found a vulnerability, email the address below and we will respond.

7. Retention and deletion

Call records, outcomes, notes and recordings are kept for 24 months by default and then permanently deleted, including the recording audio held by our telephony provider. A workspace can set a shorter window, or ask us to suspend deletion entirely if they are under a legal hold.

Account and billing records are kept for as long as the account is open and afterwards only as long as tax and accounting law requires.

When a workspace is closed, its data is deleted. Customers can request deletion sooner by contacting us.

8. Your rights

Depending on where you live you may have the right to access, correct, delete, or receive a copy of personal information held about you, and not to be discriminated against for exercising those rights.

If you are our customer, email the address below. We verify the request and act within 30 days.

If you were called by one of our customers, that business holds your information and decides what happens to it. Ask them. If you contact us we will identify them for you and pass the request along.

9. Where we operate

Clear Access is operated from the United States and its infrastructure is located in the United States. It is currently offered to customers in the United States, and this policy is written to US law.

We are evaluating other markets. If we begin serving customers elsewhere — the United Kingdom, the European Union, or Australia among them — additional obligations apply, including different rules on call recording and separate do-not-call registration. We will update this policy and tell affected customers before that happens, not after.

10. Changes

If we change this policy in a way that materially affects how personal information is handled, we will notify customers by email before it takes effect. Older versions are available on request.

11. Contact

Clear Access Media LLC · hello@clearaccessmedia.org

For privacy requests, put “Privacy” in the subject line so it reaches the right person.

CA Clear access, in every direction. ยท Clear Access Media LLC
Terms Privacy Sign in