Skip to main content
Smiley NicholsReception

Privacy notice

A review draft describing the application's current data handling. It must be checked against the operator's actual business practices and provider settings before adoption.

1. Our role and your contractor's role

Smiley Nichols LLC operates Smiley Nichols Reception and its website and agency workspace. For calls and appointments handled for a contractor, that contractor ordinarily determines why its customer data is processed, while Smiley Nichols LLC provides the configured Smiley Nichols Reception service. Final controller/processor roles and instructions must be recorded in the customer agreement. Contact the business you called about its service records, or contact Smiley Nichols Reception for help identifying the appropriate request route.

2. Information the application handles

Website inquiries may include a contact name, company, phone, email, website, trade, estimated call volumes, and business goals. Workspace records include account name/email, password hashes, session tokens, tenant permissions, invitation state, and configuration audit events. Hosting and authentication may process IP addresses, browser information, request metadata, and security logs.

Contractor records may include caller phone/name, supplied email or service address, service requests, urgency, approved customer context, appointment windows/status, provider identifiers, structured outcomes, duration, and sentiment or frustration estimates. These estimates may be inaccurate and are operational indicators, not decisions about a person's eligibility, credit, employment, or rights.

3. Transcripts, audio and retention

Smiley Nichols Reception does not store call audio in this application. Its voice and connectivity providers necessarily process call media; their own retention settings and agreements must be reviewed separately. Do not interpret the application's no-audio-storage design as a promise that a provider retains nothing.

The contractor can choose full transcript retention, summary-only storage, or no conversation-text retention. Full turns are saved only in full mode. In no-text mode, operational facts and a generic outcome summary can still remain, alongside leads and appointments. Changing the setting governs subsequent processing; it does not automatically erase previously saved records or provider copies.

The current application does not enforce an automatic record-purge schedule. Before commercial use, the operator and contractor must agree and implement retention periods for records, logs, backups, and provider copies. Retain only what is needed for the service, security, agreed obligations, or law; arrange authorized deletion when it is no longer needed.

4. Purposes and service providers

Use is limited to operating and securing the service, responding to inquiries, onboarding accounts, handling agreed contractor workflows, resolving failures, and producing service reports. Access is restricted by role and tenant membership. The current code contains no advertising pixels, behavioral-advertising integration, or data-sale workflow; actual business practices must continue to match the adopted notice.

Configured providers include Vercel for hosting, Neon for PostgreSQL storage, Better Auth software for authentication, and ElevenLabs for voice AI. Connected Google Calendar or Jobber accounts process scheduling information when authorized. Resend is the optional transactional invitation-email provider. The applicable connectivity provider also processes call routing data. Provider terms, subprocessors, locations, and independent retention practices require review; no blanket US-only processing or zero-provider-retention promise is made.

5. Google Calendar data

When authorized, the integration requests owned-calendar-event and FreeBusy permissions. It uses busy windows to constrain availability and creates or updates the service's appointment events. Encrypted access and refresh tokens are stored server-side to maintain that connection. Smiley Nichols Reception does not request Gmail inbox access through this connection.

An authorized operator can disconnect the integration in the client workspace. The Google account owner can also revoke access in their Google account permissions. Disconnecting does not itself delete historical appointment events or Smiley Nichols Reception's appointment ledger. Google user data is used for the scheduling features the customer authorizes, not advertising or training a general-purpose AI model.

6. Cookies and account invitations

Essential authentication cookies maintain sign-in sessions; temporary integration-state cookies protect authorization handoffs. The application does not add a marketing-cookie consent banner because no advertising-cookie functionality is configured. Browser and hosting behavior should be reassessed if analytics or marketing tools are introduced.

Invitation emails contain a private, expiring link. Only a token hash is retained in the invitation record. Do not forward the link. An existing account must sign in to accept an invitation; an invitation does not overwrite its password. Email-provider acceptance alone does not prove inbox delivery.

7. Access, correction and deletion requests

Contact luke@smileynichols.com or the contractor responsible for your service record to request access, correction, deletion, or an explanation of processing. Identify the business and the minimum information needed to locate the record. We may need proportionate identity and authority checks before disclosing or changing records. Do not send a password or government ID unless a secure, necessary verification process is separately agreed.

Applicable rights, deadlines, appeals and exceptions depend on the law and the parties' roles. Indiana and Kentucky privacy statutes include scope thresholds and exemptions; this draft does not assume coverage or waive rights. If a request is denied, ask for the reason and the applicable appeal process. The legal-review checklist requires a documented response process before adopting this notice.

8. Security and service boundaries

The application uses password hashing, server-side secrets, encrypted integration tokens, bounded inputs, role checks, and tenant-scoped access. No system is risk-free. Report suspected unauthorized access promptly without including credentials in the report.

The service is intended for contractor businesses and their authorized adult users, not for children or healthcare workflows. Do not intentionally collect children's data, health records, or other unnecessary sensitive information. If such data is received accidentally, contact the operator so it can be handled appropriately.

9. Notice changes

The final adopted notice must name the legal operator and effective date. Material changes should be communicated before they take effect when required. This review edition is not evidence of completed legal review, regulatory certification, or a guaranteed deletion timeline.

10. Optional field location and directions

Workspace users can explicitly enable their device's location to estimate distance from where they are working. Permission is never requested automatically. Current coordinates are held only in the active browser tab, are not sent to Smiley Nichols Reception's server or saved as a location history, and stop updating when the tab is hidden or location is disabled. Device location accuracy varies; stale or imprecise fixes use the business-address fallback when available.

Selecting Calculate distance sends the saved service address and the contractor's registered business address to the US Census address-range geocoder. It does not send caller names, phone numbers or the workspace user's live coordinates. Approximate straight-line estimates are not driving mileage or arrival-time promises. Selecting a directions link sends the destination and chosen origin to Apple Maps or Google Maps, whose own privacy practices apply. No geocoding occurs simply from opening a workspace page.