CallOrb CallOrb
Back to site

Legal

Privacy Policy

Last updated: July 16, 2026

  • Who we are
  • What we collect
  • Call recording & transcription
  • Why we collect it
  • Legal bases
  • Subprocessors & sharing
  • Retention
  • Security
  • Your rights
  • Cookies & sessions
  • Children's privacy
  • Changes to this policy
  • Contact us

1. Who we are

CallOrb is an AI voice receptionist product built and operated by Deebits, a company based in Canada ("CallOrb," "Deebits," "we," "us," "our"). CallOrb answers phone and web calls on behalf of the small businesses that sign up for it.

This policy covers two audiences, and different rules apply to each:

  • Business customers ("Customers," "you," if you run a CallOrb account) — for your account, billing, and configuration data, Deebits is the organization accountable for that information under Canadian privacy law.
  • Callers ("Callers," "you," if you're calling a business that uses CallOrb) — the business you called chose to use an AI receptionist to handle its calls. For the audio, transcript, and lead data generated by your call, Deebits acts as a service provider processing that data on the business's behalf, similar to how a phone system or answering service would.

Our approach is guided by the principles behind Canada's federal privacy law (PIPEDA) — accountability, limiting collection, transparency, and giving people access to their own information. If a business we serve is based in Quebec, we're aware that Quebec's Law 25 imposes additional obligations on that business (such as privacy impact assessments for certain projects), and we work with Quebec Customers in good faith to support their own compliance; we do not claim to satisfy Law 25 on their behalf.

This policy applies to the CallOrb website, the onboarding and owner dashboard/app, and the call experience served from our hosted call pages, phone numbers, and website widgets.

2. What we collect

We collect different categories of information depending on whether you are a Customer running an assistant or a Caller talking to one.

From Customers (account data)

  • Account and contact information: name, business name, email, and phone number. Sign-in is passwordless — a one-time email code (stored only as a salted hash) or Google sign-in; we never store passwords.
  • Business configuration: services, prices, hours, greeting, fact-sheet content, branding, and other assistant settings you provide.
  • Billing information. Card details are entered directly with our payment processor, Stripe — we never see or store your card number.
  • Notification destinations (email address, WhatsApp number, mobile device for push) used to deliver lead alerts, per your notification settings.
  • Usage data: call volume, minutes used, login activity, device/browser metadata, and diagnostic logs.

From Callers (caller & conversation data)

  • Live call audio. While a call is in progress, your voice is streamed in real time to Google's Gemini AI so it can understand you and respond. Whether the audio itself is stored depends on the business you called. Call recording is off unless that business turns it on. When it is off, we keep only a text transcript and an AI-generated summary. When it is on, you are told so by a spoken notice at the start of the call, and a recording of the call is stored encrypted and automatically deleted 90 days after the call — see Call recording & transcription below.
  • Transcripts of the conversation, generated automatically from that audio.
  • Lead data extracted from the conversation by AI — for example your name, a callback number, and the reason for your call ("intent") — which is shared with the business you called.
  • Technical metadata about the call: timestamps, duration, and connection information.

Cookies & session data

We keep cookies deliberately narrow: a session cookie (or, for the mobile app, a session token) to keep a Customer logged in, and a session identifier to connect a browser to our voice backend during a call. We do not use third-party advertising or cross-site tracking cookies. See Cookies & sessions below.

3. How call recording & transcription works

When a Caller starts a call with a CallOrb assistant — by phone or through a web widget — the audio is streamed in real time to Google's Gemini Live API, which understands the request and generates the assistant's spoken response. As part of this process:

  • The conversation is transcribed into text, and after the call ends, a short AI-generated summary is produced from that transcript. Where the Customer has not enabled call recording, the audio is not retained at all and the transcript and summary are what get stored and shown to them. Where the Customer HAS enabled call recording, a spoken notice plays before the conversation begins, the recording is stored encrypted in object storage, only that Customer can play it back, and it is deleted automatically 90 days after the call by a storage lifecycle rule.
  • On web calls, a visible on-screen notice is shown before the call connects, disclosing that Callers are speaking with an AI, that the call is transcribed, and that continuing constitutes consent to that transcription.
  • Recording and transcription consent rules for phone calls (for example one-party vs. two-party/all-party consent) vary by jurisdiction and by medium. Under our Terms of Service, the Customer (the business) is responsible for ensuring their greeting and use of the service satisfies whatever notification or consent requirements apply to their callers in their jurisdiction.

4. Why we collect it

  • To operate the AI receptionist: understand the Caller's request and generate a relevant spoken response.
  • To extract and deliver lead information (name, phone, intent) to the Customer by email, WhatsApp, mobile push, or other configured channel.
  • To provide the Customer a dashboard of calls, transcripts, and leads.
  • To bill Customers based on plan and usage (e.g., answered minutes, prepaid top-up minutes).
  • To maintain, secure, debug, and improve the service, including detecting abuse and technical issues.
  • To communicate with Customers about their account, billing, and service updates.
  • To comply with legal obligations and enforce our Terms of Service.

5. Legal bases for processing

Where applicable data protection law requires a legal basis (for example under PIPEDA in Canada or comparable frameworks), we rely on:

  • Contract — processing Customer account data and Caller conversation data is necessary to provide the service the Customer has signed up for.
  • Consent — on web calls, Callers are notified that the call is with an AI and is transcribed, and continuing the call constitutes consent to that processing; Customers may also rely on this notice to help satisfy call-recording consent obligations in their jurisdiction, alongside their own greeting.
  • Legitimate interests — for security, fraud prevention, service improvement, and analytics, balanced against individual privacy interests.
  • Legal obligation — where we must retain or disclose information to comply with law.

6. Subprocessors & sharing

We share information with a limited, named set of service providers ("subprocessors") who process it on our behalf, strictly to deliver the CallOrb service. We do not sell personal information, and marketing email is never sent without consent — transactional messages (like lead alerts and account notices) are sent under Canada's Anti-Spam Legislation (CASL) as they relate directly to the service you use.

SubprocessorPurposeData involved
Google (Gemini API)Real-time AI processing of Caller speech and generation of the assistant's spoken responses; also produces the post-call summaryLive call audio (processed, not stored by us), transcript text
StripePayment processing and subscription billingBilling contact info and payment details (Stripe holds card data directly — we never see full card numbers)
TelnyxPhone number provisioning and call transport (inbound calling, and optional bridging to the business's own phone)Phone numbers, call signaling/connection metadata
AWS (United States — us-west-2, Oregon)Application hosting and database storageAll account, transcript, summary, and lead data described above
ResendTransactional email delivery (lead alerts, account notifications)Customer email address, lead summary content
Meta (WhatsApp Cloud API)Optional WhatsApp lead notifications, if configured by the CustomerCustomer WhatsApp number, lead summary content
ExpoMobile push notifications to the Customer's owner appDevice push token, lead/call summary content

We may also disclose information: (a) to comply with a legal obligation, court order, or governmental request; (b) to protect the rights, property, or safety of CallOrb, our Customers, or the public; or (c) in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality protections.

7. Retention

  • Customer account data is retained for as long as the account is active.
  • Call audio is not stored — it is processed in real time and discarded once the call ends.
  • Transcripts, summaries, and lead data are retained for as long as the Customer's account is active, so the Customer can access their call history, unless the Customer or a Caller requests earlier deletion.
  • Deleting a CallOrb account removes the associated business, agent, call, transcript, and lead data from our production database as part of account deletion.
  • We will delete or anonymize personal information upon a valid deletion request (see Your rights), except where we must retain it to comply with law, resolve disputes, or enforce agreements.

8. Security

We use safeguards appropriate to a service of our size and stage: encryption in transit (TLS) for data moving between browsers, our servers, and our subprocessors; passwordless sign-in (hashed one-time codes, Google sign-in) and opaque, revocable session tokens rather than long-lived credentials; and internal access controls that limit what our own staff can see (see below). No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

Internal access boundary: CallOrb's own operations staff, using our internal admin console, can see account-level metadata across Customers — things like plan, usage minutes, call counts, and whether a call captured a lead — to provide support and run the business. They cannot read call transcripts, AI-generated summaries, or the specific lead details (name, phone, intent) a Caller shared. That content stays scoped to the Customer's own dashboard.

9. Your rights

Depending on your location, you may have the right to access, correct, export, or delete the personal information we hold about you, to object to or restrict certain processing, and to withdraw consent where processing is based on consent.

  • Customers can access and export most account, call, and lead data directly from the dashboard, and can request full account deletion.
  • Callers who wish to access, correct, or delete a transcript or lead record associated with a specific call should contact the business they called, or contact us directly and we will coordinate with the relevant Customer.

To exercise any of these rights, email hello@deebits.ca. We will respond within a reasonable time and in accordance with applicable law. If you are not satisfied with our response, you may escalate a complaint to the Office of the Privacy Commissioner of Canada.

10. Cookies & session data

We use strictly necessary cookies/local storage for authentication (keeping Customers logged into the dashboard) and to maintain an active call session (e.g., a session identifier used to connect the browser to our voice backend). We do not currently use third-party advertising or cross-site tracking cookies. If that changes, this policy will be updated.

11. Children's privacy

CallOrb is intended for business use and is not directed at children. We do not knowingly collect personal information from children under 13 (or the relevant minimum age in your jurisdiction). If you believe a child has provided us with personal information, contact us and we will take appropriate action.

12. International data transfers

Data at rest — account, transcript, summary, lead data, and any call recordings — is stored on AWS infrastructure located in us-west-2 (Oregon, United States). We are a Canadian company, but your data is held in the United States and is therefore subject to United States law, including lawful access requests by US authorities. During a live call, your audio is processed in real time by Google's Gemini API, which may run its processing outside Canada; we are transparent that this real-time AI processing step is not confined to Canadian servers, Other subprocessors listed above may also process data in the countries where they operate. Where required, we rely on appropriate safeguards for cross-border transfers.

13. Changes to this policy

We may update this policy as our service, subprocessors, or legal obligations change. Material changes will be reflected by updating the "Last updated" date above, and where appropriate, by additional notice to Customers.

14. Contact us

Questions about this policy or how we handle your information can be sent to hello@deebits.ca. See also our Terms of Service for how the service itself is governed.

CallOrb

The AI receptionist that answers every call, 24/7, and turns it into a lead.

hello@deebits.ca

Product

How it works Features Pricing FAQ

Company

About Contact Get started

Legal

Privacy Terms

© 2026 Deebits. CallOrb is a product of Deebits.

Never miss a customer call again.