Trust

Security at Ride N Repair OS

Your customers' calls, addresses and payment records pass through our system. This page says plainly how we protect them, and what we have not done yet.

Last updated

Summary

  • We never train AI models on your calls, transcripts or customer data, for ourselves or anyone else.
  • Every AI call opens with a disclosure that the caller is speaking to an AI and that the call is recorded. You cannot turn it off.
  • Each customer's data is isolated per account. Staff access is role-based, logged and limited to support you asked for.
  • Data is encrypted in transit and at rest.
  • Recordings are kept 90 days by default; you can set 30 to 365 days. Everything is deleted within 30 days of termination, after you export what you need.
  • We do not have a SOC 2 report yet. We answer security questionnaires honestly and will tell you what is and is not in place.

Calls, recordings and AI

The AI Receptionist answers calls forwarded from your business number. Audio is transcribed, the model decides the next step (answer a question, quote from your price list, book a slot, hand off to your team), and the call is recorded and summarized so your team can review it.

  • Disclosure first. The greeting states that the caller is talking to an AI assistant and that the call is recorded. Continuing the call is the caller's consent, which matters in the eleven all-party-consent states. We log that the disclosure played on every call.
  • No training, no self-benefit. Speech, language and voice vendors are used under terms that prohibit training on your data and limit their retention. We act only as your service provider and processor.
  • No voice biometrics. We do not create voiceprints or identify callers by their voice.
  • Inbound only by default. We do not place outbound AI marketing calls or texts. Follow-ups go only to people who asked to be contacted, as described in our acceptable use policy.

Hosting and data location

The website is static and served from our own servers. US customer call audio and transcripts are hosted in a US region before any US customer goes live. Rolling out US-region hosting for operational data is being completed for the first customers; ask us for the current status before you sign.

Some engineering and support staff work for our affiliate outside the US. They reach customer systems only through logged, role-based access for support and operations, under an intercompany data processing agreement.

Encryption

  • All traffic to the app, the API and this website uses TLS (HTTPS). Plain HTTP is redirected.
  • Databases, backups and stored recordings are encrypted at rest.
  • Card data never touches our servers; payments are handled by Stripe.
  • Secrets such as API keys are kept out of source code and rotated when staff change.

Access control

  • Your team signs in with individual accounts. Roles decide who sees recordings, prices, payouts and reports.
  • Lead Desk masks customer numbers so reps call from your business line and never see or store personal numbers.
  • Our staff access is least-privilege, tied to named accounts, logged, and removed on the day someone leaves.
  • Single sign-on is included in the Command Center plan. Rolling out

Retention and deletion

DataDefault retention
Call recordings90 days (configurable 30–365)
Call transcripts and summaries12 months
Jobs, invoices, service historyWhile your account is active
All customer data after terminationDeleted within 30 days, after export

Subprocessors

We use a small number of vendors, each under a written agreement with confidentiality, security and no-training terms where relevant:

  • Payments: Stripe.
  • Telephony: a US phone carrier (Telnyx) for numbers, call routing and texts.
  • Speech and language: speech-to-text, language-model and text-to-speech providers, on no-training, limited-retention terms.
  • Infrastructure: cloud hosting and email delivery.

The current named list is available on request and is attached to our data processing agreement. We give notice before adding a subprocessor that handles customer data.

Payments

Card payments and pay links run on Stripe's hosted checkout and payment pages. We store payment status, amounts and the last four digits for reconciliation, never full card numbers.

This website

This site loads nothing from third parties: no external fonts, analytics, ad pixels, session recording, chat widgets or embeds. We count page events with our own first-party logging. Forms send only what you type, to our own API.

Compliance status

  • SOC 2: not started. We will begin a Type I audit when a customer requires it and will state the timeline here only when it is real.
  • Data processing agreement: available on request, covering our role as your service provider and processor.
  • Privacy: see our privacy policy. We do not sell or share personal information.

Incidents

If we confirm a security incident that affects your data, we notify your account owner without undue delay, tell you what happened, what data was involved and what we are doing, and follow up with a written report.

Reporting a vulnerability

Email ceo@ridenrepair.ai with "Security report" in the subject. Include steps to reproduce. Please do not access other customers' data, run load or denial-of-service tests, or use social engineering. We will acknowledge within three business days and keep you updated until it is fixed.