CustomerRetentionAI by FrontDesk Global
Home Demo Pricing FAQ Sign in
← Back to CustomerRetentionAI

Privacy Policy

Updated September 27, 2026. Version 1.2.

This Privacy Policy explains how X3 E-Commerce LLC d/b/a FrontDesk Global (“FrontDesk Global”, “we”, “us”) collects, uses, and shares personal information in connection with CustomerRetentionAI (the “Service”).

We have built CustomerRetentionAI with three commitments: we do not sell personal information, we do not train AI models on customer data, and we treat all users — wherever they live — to the same baseline privacy rights.

1. Who is the Controller / Processor

When we provide the Service to you (our customer), you act as the “controller” of your customers' or tenants' personal information, and we act as a “processor” or “service provider” on your behalf, in the sense those terms are used in the GDPR, CCPA/CPRA, and similar laws.

When we collect personal information directly from you to manage our relationship with you (account, billing, support), we act as a controller. This Policy covers both relationships.

2. Information We Collect

2.1 Information you give us

  • Business details (name, what you do, how you talk)
  • Customer names, mobile numbers, e-mail addresses and visit dates you add, import or sync
  • Stripe or Square connection keys, if you connect them
  • Message drafts, approvals and replies

2.2 Account and billing information

  • Name, email address, phone number, business name and address.
  • Payment-method information processed by our payment provider, Stripe (we never see or store full card numbers).
  • Authentication credentials (passwords are stored hashed; we use OAuth where supported).

2.3 Information collected automatically

  • Device, browser, and connection metadata (IP address, user agent, language).
  • Usage logs (pages visited, actions taken, errors encountered).
  • Cookies and similar technologies — see Section 9.

3. How We Use Information

We use information to:

  • Provide and operate the Service, including the AI features described in our AI Disclosure.
  • Process payments and manage your subscription.
  • Communicate with you about your account, security, billing, and product updates.
  • Detect, prevent, and address fraud, abuse, and security incidents.
  • Comply with legal obligations and enforce our Terms.
  • Improve the Service through aggregated, anonymized analytics. We do not use the content of customer data to train AI models.

4. AI Processing

When CustomerRetentionAI uses AI to draft text, we send only the input needed for that task (for example, the customer’s first name, visit rhythm, and your business’s voice settings) to our AI provider, Anthropic. Anthropic processes it only to return output to us and does not use it to train its models. Details are in our AI Disclosure.

5. How We Share Information

We share information only as needed to operate the Service:

  • Sub-processors. We use trusted vendors for hosting, payments, e-mail, text messages, AI drafting, and cookieless site analytics. They are named in section 5A.
  • Your authorized integrations. We exchange data only with the services you connect: Stripe or Square, if you connect them.
  • Legal compliance. We may disclose information when required by law, valid legal process, or to protect rights, safety, and property.
  • Business transfers. If we are involved in a merger, acquisition, or asset sale, your information may be transferred. We will notify you and any successor will be bound by this Policy.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

5A. Customer Records, Visit History, and Payment Data

To provide CustomerRetentionAI, we process the following data only for the purposes stated:

  • Customer records (name, mobile number, e-mail, and visit dates) that you add, import, or sync.
  • Stripe or Square data, if you connect it. If you connect Stripe (with a read-only restricted key you create) or Square (with an access token you provide), we read customers and completed payments (date and amount) to build visit history. We never receive full card numbers, and you can disconnect at any time.
  • Messages and replies (the drafts you approve, the messages sent, and any replies we receive) are used to send messages and honor opt-outs. Comebacks are measured from new visits in your visit history, not from replies.
  • No private details in messages. Drafts never mention balances, amounts owed, or other private account details.
  • Opt-outs. Anyone who replies STOP gets no further texts from that business through the Service.

What we do not do with this data:

  • We do not sell it, and we do not share it with anyone other than the sub-processors listed below that are strictly necessary to run the Service.
  • We do not use it to train or improve AI models — ours or our vendors’.
  • We do not use it for advertising or to contact anyone on behalf of any business other than you.

Current sub-processors (vendors that process this data for us):

  • Cloudflare, Inc. — hosting, database, content delivery, security
  • Anthropic, PBC — AI text generation (Claude models)
  • Telnyx LLC — text-message (SMS) delivery
  • Resend, Inc. — transactional e-mail delivery
  • Stripe, Inc. — subscription billing and payment processing (we never see full card numbers)

5B. Text Messaging (SMS) Privacy

  • Mobile phone numbers are used only to send the messages the business set up in CustomerRetentionAI and to process replies (such as CONFIRM, STOP, or HELP).
  • No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent will not be shared with any third parties, except our SMS delivery provider (Telnyx) for the sole purpose of delivering messages.
  • We keep a record of each opt-out (STOP) so that business never texts the number again through FrontDesk Global unless the person opts back in (for example, by replying START).
  • Message and data rates may apply. Reply HELP for help or e-mail [email protected].

5C. Linked Customer Records, Text-Message Rules, and AI Features (Updated September 27, 2026)

One customer timeline inside your business account. If your business uses more than one FrontDesk Global product (for example CustomerRetentionAI and PreventNoShows), we link records that refer to the same customer — matched by phone number or e-mail address — so you can see one timeline of that customer’s visits, messages, reviews, testimonials, and calls across your FrontDesk Global products. Linking happens only inside your own business account. We never link, merge, or share customer records between different businesses, and one business can never see another business’s customers.

Two kinds of text-message consent. Each business keeps separate consent records for each phone number:

  • Informational texts — messages about something the customer asked for or booked, such as appointment reminders and confirmations, feedback requests after a visit, and replies to the customer’s own questions.
  • Marketing texts — promotional messages such as win-back offers and discounts. These are sent only to people who agreed to receive marketing texts from that business.

Quiet hours. Automated texts are sent only between 8:00 a.m. and 9:00 p.m. in the business’s local time. A text that comes due outside that window waits until the window opens.

STOP works per business. Replying STOP to a text from a business stops all further texts from that business through any FrontDesk Global product. It does not stop texts from other, unrelated businesses that also use FrontDesk Global; reply STOP to their messages separately. Replying START to that business opts the number back in. Reply HELP for help, or e-mail [email protected].

AI features and private review matching. Where a FrontDesk Global product suggests which of your customers may have written a public review (by comparing the reviewer’s public display name and timing with your own customer records), that suggestion is shown only to you inside your account. It is never included in a public review reply, never shown to the reviewer or anyone else, and never used to train AI models. For healthcare businesses (such as dental, medical, therapy, chiropractic, pharmacy, and med spa), review matching is off by default. AI is never used to put private customer details into public replies.

5D. Newer Features and the Data They Use (Updated September 27, 2026)

  • Consent records and sign-up page. When a business records a customer’s agreement to texts, we store how they agreed and any note. If a customer signs up on the business’s own sign-up page (or its QR code), we store the consent wording shown, the page, the date and time, the IP address, the browser, and the first name they entered.
  • Open-slot offers (with PreventNoShows). If the business also uses PreventNoShows, we read its cancelled appointments to offer the time to opted-in regulars. The first person to claim it is booked into PreventNoShows.
  • Early warning. We use events from the business’s other FrontDesk Global products (for example a low-star review the owner linked to the customer, a complaint call, or a no-show) to raise a private warning for that customer. It is shown only to the business.
  • “Why’d you drift?” survey. Answers are stored with the customer. A “last visit wasn’t great” answer is sent privately to the business by e-mail and is never published or used to ask for a review.
  • Inbox. Customer replies are stored and shown to the business so it can respond.
  • Free “Who’s gone quiet?” report. The file you choose is analysed entirely in your web browser. It is not uploaded to us and we do not store it.

6. Retention

We retain Your Content for as long as your account is active. After termination, we retain it for at least 30 days to support export, then delete it within 90 days unless we are required to retain it longer for legal or accounting purposes. Account and billing records are retained for the period required by tax and accounting law (typically seven years).

7. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Delete information, subject to legal retention requirements.
  • Object to or restrict certain processing.
  • Receive a copy of your information in a portable format.
  • Withdraw consent for processing based on consent.
  • Opt out of any sale or sharing of personal information (we do not sell or share, but the right is preserved).
  • Lodge a complaint with a data-protection authority.

To exercise these rights, email [email protected]. We will verify your identity and respond within the time required by your jurisdiction (typically 30 to 45 days).

8. International Transfers

We are based in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where our service providers operate. For transfers from the European Economic Area, the United Kingdom, and Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.

9. Cookies and Similar Technologies

We use a small number of cookies to keep you signed in, remember your preferences, and measure aggregate usage. We do not use third-party advertising cookies. You can manage cookie preferences in your browser; blocking certain cookies may break parts of the Service.

10. Children

The Service is not directed to children under 16, and we do not knowingly collect information from them. If you believe a child has provided us information, contact [email protected] and we will delete it.

11. Security

We protect information using industry-standard administrative, technical, and physical safeguards, including encryption in transit (TLS 1.2+) and at rest, role-based access controls, and continuous security monitoring. No system is perfectly secure; if you suspect unauthorized access to your account, contact [email protected] immediately.

12. Changes to This Policy

We may update this Policy. We will notify you of material changes by email or in-app notice at least 30 days before the changes take effect.

13. Contact

Privacy questions: [email protected]. Mailing: X3 E-Commerce LLC d/b/a FrontDesk Global, Michigan, United States.

X3 E-Commerce LLC d/b/a FrontDesk Global • Michigan, United States

CustomerRetentionAI
Sister tools under FrontDesk Global
TheAutoReply TestimonialCollect PreventNoShows FreshLocalSEO ReplaceReceptionist CustomerRetentionAI
View the bundle →
Home · Demo · Pricing · FAQ · Terms · Privacy · AI Disclosure
Questions? [email protected]
A product of FrontDesk Global · X3 E-Commerce LLC · Howell, Michigan