Privacy Policy
Last updated: July 22, 2026
This Privacy Policy explains how VERACO LLC (“CoServe,” “we,” “us”) collects, uses, shares, and protects personal information when you visit our websites, book a demo, or use the CoServe platform and its AI communication tools (together, the “Service”). It also explains the choices and rights you may have. By using the Service you acknowledge this Policy.
1. Our two roles: businesses and their callers
CoServe is a business-to-business service. We handle personal information in two distinct roles:
- As a “controller” (or “business”) for information about our own customers, prospects, affiliates, and website visitors — for example your account details, billing information, and marketing-site analytics. This Policy governs that information.
- As a “processor” (or “service provider”) for information about the people who call, text, or submit leads to businesses that use CoServe (“End Users”). We process End User information — such as call recordings, transcripts, voicemails, messages, phone numbers, and appointment details — on behalf of and at the direction of the business you contacted. That business is responsible for its own privacy practices and legal notices. If you are an End User (for example, you called a business that uses CoServe), please direct privacy questions and requests to that business; we will assist the business in responding as required by our Data Processing Addendum.
2. Information we collect
2.1 Information you provide
- Account and profile: name, email address, phone number, password or sign-in credentials, business name and details, and team member information.
- Business configuration: the settings, greetings, business hours, services, pricing, FAQs, and other knowledge you configure for your AI tools, including content you ask us to import from your website.
- Carrier registration information: to register your business for compliant text messaging (A2P 10DLC), we collect legal business information such as legal name, address, business type, and tax identifiers (for example an EIN), which we share with our telephony provider and, through it, with carriers and their registries.
- Payment information: processed by Stripe. We receive limited billing details (such as card brand, last four digits, and billing status) but never store full card numbers.
- Communications with us: demo requests, support tickets, emails, and survey responses.
- Affiliate information: if you join our affiliate program — your name, email, payout email, and referral activity.
2.2 Information processed when your tools run
- Voice calls: caller phone numbers, call metadata (time, duration, routing), audio, recordings, real-time and stored transcripts, and AI-generated summaries.
- Text messages: message content, phone numbers, delivery metadata, and opt-out records.
- Leads and contacts: names, phone numbers, emails, appointment and job details, and notes captured by your tools or entered by your team.
2.3 Information collected automatically
- Usage and device data: IP address, browser and device type, pages viewed, referring URLs, and interactions with the Service, collected via cookies and similar technologies (see our Cookie Policy). Our marketing site uses Google Tag Manager to load analytics and advertising tags.
- Referral data: if you arrive via an affiliate link, we record the referral code and set a cookie so the affiliate can be credited.
- Log and security data: authentication events, API activity, and diagnostic logs.
3. How we use information
- Provide the Service: answer and route calls, send text-backs and lead follow-ups, transcribe and summarize conversations, book appointments, send reminders and notifications, and show you activity in your dashboard.
- Billing and account management: process subscriptions, meter usage, maintain credit balances, process auto-reloads you configure, and prevent fraud and abuse.
- Communicate with you: transactional emails (receipts, digests, alerts), support responses, and — with your consent where required — marketing communications you can opt out of at any time.
- Improve and secure the Service: debug issues, monitor performance, develop features, and protect against unauthorized access, using aggregated or de-identified data where practicable.
- Comply with law: meet legal, tax, accounting, carrier-registration, and regulatory obligations, and enforce our agreements.
We do not sell personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act. We do not use Customer Data or End User communications to train generalized AI models, and our agreements with AI providers prohibit them from doing so.
4. AI processing
Features such as the AI Receptionist send audio, transcripts, and relevant business context to third-party AI providers (currently OpenAI) in real time to transcribe speech, generate responses, and summarize conversations. This data is shared only as necessary to deliver the feature, under contracts that restrict the provider from using it for purposes other than providing the service to us (including a prohibition on training their models with it). AI output may be inaccurate; the business you interact with is responsible for how it uses that output.
5. How we share information
We share personal information only as described below:
- Service providers (subprocessors): vendors that host and operate parts of the Service on our behalf, listed in the table below and in our Data Processing Addendum. Each receives only the data needed for its function and is bound by contractual confidentiality and data-protection obligations.
- Carriers and registries: business and campaign information required for phone-number provisioning and A2P messaging registration.
- The business you interact with: if you are an End User, your calls, messages, and details are provided to the business you contacted — that is the purpose of the Service.
- Legal and safety: when we believe disclosure is required by law, legal process, or a government request, or is necessary to protect the rights, safety, or property of CoServe, our customers, or others, or to detect and prevent fraud or abuse.
- Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case this Policy will continue to apply to previously collected data until updated.
- With your direction or consent: for example, when you connect your Google or Microsoft calendar.
Current subprocessors:
- Google Cloud / Firebase — Cloud hosting, databases, authentication, and file storage (United States).
- Twilio — Telephony, phone numbers, SMS delivery, and A2P campaign registration (United States).
- OpenAI — Real-time speech, transcription, and language-model processing for AI features (United States).
- xAI — Optional alternate real-time voice engine for AI phone answering (United States).
- Stripe — Payment processing, subscriptions, and billing (United States).
- Resend — Transactional and notification email delivery (United States).
6. Cookies and analytics
We use cookies and similar technologies for sign-in, security, preferences, affiliate referral attribution, and analytics. Our marketing site loads tags through Google Tag Manager, which may include Google Analytics and advertising tags. See the Cookie Policy for details and choices, including how to control cookies in your browser. Our cookie banner and Google Consent Mode default analytics/ad storage to denied until you Accept. We honor Global Privacy Control (GPC) in supporting browsers. We do not currently respond to legacy “Do Not Track” signals.
7. Retention
We keep personal information for as long as needed to provide the Service and for legitimate business purposes such as billing, dispute resolution, security, and legal compliance. As a rule: account data is kept while your account is active; call recordings, transcripts, and messages are kept while the owning business’s account is active or until the business deletes them; and billing records are kept as required by tax and accounting law. When you close your account, we delete or de-identify your data within 30 days, except where longer retention is required by law or needed to resolve disputes or enforce agreements. Backups are purged on a rolling schedule thereafter.
8. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, tenant isolation, and audit logging. No system is perfectly secure, and we cannot guarantee absolute security. If we learn of a breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law.
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to restrict or object to certain processing, and to not be discriminated against for exercising those rights. This includes rights under state privacy laws such as the California Consumer Privacy Act and similar laws in other states, and — if they apply to you — the GDPR or UK GDPR.
- Self-serve: you can access and update most account information in your dashboard, and unsubscribe from marketing emails via the link in each message.
- Requests: email privacy@coserve.ai to exercise any right. We will verify your identity (and, for agent requests, the agent’s authority) and respond within the time required by law. If we decline a request, you may appeal by replying to our decision, and you may lodge a complaint with your local supervisory or consumer protection authority.
- End Users: if your data was collected by a business using CoServe, we will refer your request to that business and assist it as its processor.
10. Children
The Service is for businesses and is not directed to children under 13 (or the higher age required by local law), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact privacy@coserve.ai and we will delete it.
11. International transfers
We are based in the United States and process data there and in other countries where our subprocessors operate. If you access the Service from outside the U.S., you understand that your information will be transferred to and processed in the U.S., where privacy laws may differ from those in your jurisdiction. Where required, we use appropriate safeguards (such as standard contractual clauses) for cross-border transfers.
12. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you by email or in the dashboard and update the “Last updated” date above. Your continued use of the Service after the effective date constitutes acknowledgment of the updated Policy.
13. Contact us
Privacy questions or requests: privacy@coserve.ai. General support: support@coserve.ai or a support ticket from your dashboard.