This Privacy Policy explains what personal information ThreeDay Digital collects, why, who we share it with and the choices you have. It covers threedaydigital.com, app.threedaydigital.com, the ThreeDay Digital iPhone app, ThreeDay Social (threedaysocial.com) and our support channels. It is written to meet Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and the substantially similar provincial laws, and it also describes the rights that US state privacy laws and the EU/UK GDPR give you where they apply.
- We collect what we need to run your account, your receptionist and your back office — and nothing for advertising.
- Calls, texts and contacts that flow through your receptionist belong to your business. We process them for you, and we never sell them.
- We do not use your content or your customers’ communications to train AI models — ours or anyone else’s.
- You can access, correct, export or delete your data, and take your number with you, at any time.
A shorter policy, with extra detail about the Google data our integrations can access, is published inside the app at app.threedaydigital.com/privacy. The two are meant to be read together; this page is the complete policy.
1. Who we are
ThreeDay Digital (“ThreeDay”, “we”, “us”) is a software company based in Ontario, Canada. We make an AI receptionist that answers and places calls, texts and books appointments for businesses, together with a business back office, an iPhone app and ThreeDay Social, our social-media studio. We have appointed a Privacy Officer who is accountable for our compliance with this policy and with privacy law. You can reach them at privacy@threedaydigital.com.
2. Two roles: your data and your customers’ data
We handle personal information in two different capacities, and it matters which one applies:
- Information about you and your team (we are responsible). When you visit our website, sign up, pay, use the app or contact support, we decide how your account, billing, usage and support information is handled. For this information we are the organization responsible (the “controller” in GDPR terms), and this policy describes what we do.
- Information about your customers (you are responsible; we process it for you). When your receptionist answers a call, records it, sends a text or books an appointment, the caller’s name, number, recording, transcript and details are collected on your behalf. The same is true of contacts you import and invoices you issue. For this information your business is the organization responsible and we act as your service provider (“processor”): we only use it to provide the Services to you, on your instructions, as our Terms of Service describe. You are responsible for giving your customers appropriate notice, obtaining any consent the law requires (for example for call recording or text messages) and answering their requests. Section 10 explains what a caller or customer can do.
3. What we collect
3.1 Account and business information
Your name, email address, phone number, password (stored only as a secure hash), business name, address, website, industry and time zone, optional profile photo, team members you invite and their roles, and your preferences. If you sign in with Google, we receive your name, email address and profile picture from Google.
3.2 Communications handled by your receptionist
For each call the receptionist answers or places: the caller’s phone number, the time, duration and outcome, the audio recording (when recording is on), the transcript, an AI-written summary, and anything the caller volunteers — such as a name, email address, appointment preference or reason for calling. For text messages and emails sent or received through the Services: the message content, sender and recipient details, and delivery status. Outbound calls and campaigns you run are logged the same way.
3.3 Business and customer records
Contacts, conversations, appointments, invoices and payments, documents, notes, reviews, intake-form submissions, imported lists and anything else you or your team store in the app. In ThreeDay Social: the brand details, media, captions and posts you create, and the accounts you connect.
3.4 Your receptionist’s configuration
Greetings, scripts, call flows, the knowledge base you train it with (services, prices, hours, FAQs), voice and model settings.
3.5 Payment information
Payments are processed by Stripe. We never see or store your full card number. We keep your Stripe customer ID, the card brand, its last four digits and expiry month and year so you can see which card is on file, plus your invoices and billing history.
3.6 Usage, device and log data
When you use the website or the apps we record technical data such as IP address, browser and device type, operating system, app version, language, pages and features used, timestamps, and error or crash reports. The iPhone app may store a push-notification token so we can alert you when a call is booked, if you allow notifications.
3.7 Integrations and connected accounts
When you connect a third-party account we store the access tokens needed to act on your behalf and the data the integration returns. Within the ThreeDay Digital app, the Google data we access is limited to your Google Business Profile (profile details and reviews, including the ability to post your replies) and read-only Google Search Console performance data; we do not request access to Gmail, Google Drive, Contacts, Photos or Calendar through those integrations. ThreeDay Social asks for the permissions needed to publish to each social platform you connect, and each is shown on that platform’s consent screen. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect any integration from the app at any time.
3.8 Support and marketing contact
Messages you send us by email, WhatsApp, the contact form or the app, and notes of calls with our team. Calls to our own business line are answered by our AI receptionist and may be recorded and transcribed in the same way we describe for yours.
3.9 Website visitors
On threedaydigital.com we record page views and, on some pages, how the page is used (see section 13). If you book a call or submit a form, we collect what you enter.
4. How we use information
We use personal information to:
- Provide the Services — create and secure your account, provision your number, answer and place calls, send texts and confirmations, transcribe and summarise conversations, book appointments, issue invoices, publish posts you schedule, sync integrations and show everything in your dashboard and the iPhone app.
- Bill you — process payments, meter minutes and premium-model usage, send invoices and receipts, and prevent fraud.
- Support you — respond to questions, troubleshoot problems (which may involve our staff viewing your account data), and deliver setup services such as the White-Glove Launch.
- Keep the Services safe — detect and prevent abuse, spam, fraud and security incidents, and enforce our Acceptable Use Policy.
- Improve the product — understand how features are used and tune the receptionist using aggregated, non-identifying metrics such as average call length or the share of calls that end in a booking. Individual recordings and transcripts are never used for this outside your own account.
- Communicate with you — send service notices (renewals, security, changes to terms), and, if you are a customer or asked to hear from us, product news you can opt out of at any time.
- Meet legal obligations — tax and accounting records, carrier and regulatory registrations, and lawful requests from authorities.
Where the GDPR applies, our legal bases are performance of our contract with you, our legitimate interests in running, securing and improving the Services, your consent where we ask for it, and compliance with legal obligations. We do not use personal information for automated decisions that have legal or similarly significant effects on you.
5. AI processing
The receptionist and other AI features work by sending audio, text and images to AI providers to transcribe speech, understand and respond to a caller in real time, summarise conversations, draft messages and documents, generate voices, and create images and videos. Our current AI providers are Retell AI, OpenAI, Anthropic, Google, ElevenLabs, Deepgram and Replicate (see section 6).
- No selling. We do not sell personal information, yours or your customers’, and we do not share it for advertising.
- No model training. We do not use your content or your customers’ communications to train AI models, and we do not allow our AI providers to use them to train theirs. Our providers process this data under business terms that prohibit training on it; where a provider offers a zero-retention configuration (as Anthropic does), we use it.
- Human review is limited. Recordings and transcripts are available to you and your team in your account. Our staff view them only to support you at your request, to investigate abuse or security issues, or when the law requires.
- AI can be wrong. Transcripts, summaries and answers are generated automatically and may contain errors. You should review anything you rely on.
6. Who we share information with
We share personal information only as described here. We use a small set of service providers (“subprocessors”) to run the Services. Each is bound by contract to use the data only to provide its service to us and to protect it.
| Provider | What it does for the Services | Where data is processed |
|---|---|---|
| Supabase | Database, authentication and file storage for the apps | United States |
| Netlify | Hosting for our websites and apps, and the server functions behind them | United States |
| Cloudflare | DNS, edge delivery, security and some file storage | United States and global edge network |
| Twilio | Phone numbers, calls and SMS | United States |
| Retell AI | Real-time voice conversation engine for the receptionist | United States |
| OpenAI | Language and real-time voice models | United States |
| Anthropic | Language models for summaries, drafting and the in-app assistant | United States |
| Sign-in, AI models, Business Profile and Search Console integrations, app distribution | United States | |
| ElevenLabs | Voice synthesis | United States |
| Deepgram | Speech recognition and transcription | United States |
| Replicate | Image and video generation | United States |
| Stripe | Payments, invoicing and card storage | United States |
| Resend | Transactional email delivery | United States |
| Apple | iPhone app distribution and push notifications | United States |
We also share personal information:
- With integrations you connect — calendars, Google Business Profile, Stripe, social-media platforms and others — as needed to do what you asked, under that platform’s own terms.
- With the scheduling tool on our Book-a-call page, which is provided by a third-party scheduling service and processes the details you enter when you book.
- With a reseller, if you signed up through one of our reseller partners, to the extent needed to manage your account and billing.
- With professional advisers such as accountants, lawyers and insurers, under confidentiality.
- For legal reasons — to comply with law, a court order or a lawful request from a regulator or carrier, to enforce our terms, or to protect the rights, safety and property of ThreeDay, our customers or the public.
- In a business transaction — if we merge with, are acquired by or sell assets to another company, personal information may be transferred as part of that transaction; we will notify you before it becomes subject to a different privacy policy.
We will update this list when we add or replace a subprocessor. If a change is material, we will tell active customers by email or in the app.
7. How long we keep it
- While your account is active we keep your account data, communications, records and configuration so the Services work and your history is available to you. You can delete individual records in the app where the feature is offered, or ask us to.
- After your subscription ends we keep your data for 90 days so you can reactivate or export it, then delete it. Your phone number stays reserved for you during the same 90 days.
- On request we delete your account and everything in it sooner. Email privacy@threedaydigital.com with the subject line “Delete my account” and we will confirm completion within 7 business days.
- Exceptions. We keep invoices and payment records for as long as tax and accounting law requires, keep records needed to resolve disputes or enforce our terms, and retain de-identified aggregated statistics. Residual copies in encrypted backups are overwritten on our normal backup cycle.
- Website and log data is kept for a limited period for security and analytics and then deleted or aggregated.
8. How we protect it
We use physical, technical and organizational safeguards appropriate to the sensitivity of the information: encryption in transit (TLS) and at rest, database rules that isolate each customer’s data so it can only be read by sessions belonging to that account, server-side secrets that are never exposed to the browser, role-based access for your team, access logging, and staff access limited to what support and security require. Integration tokens are stored encrypted. No system is perfectly secure; if we learn of a breach affecting your personal information that creates a real risk of significant harm, we will notify you and the relevant authorities as the law requires. Please use a strong, unique password and remove team members who leave.
9. Your rights and choices
Subject to the law that applies to you, you can:
- Access the personal information we hold about you and learn how it has been used and shared.
- Correct information that is inaccurate or incomplete (most account details can be edited in the app).
- Export your data. Contacts and history export from the app; ask us for anything else in a commonly used format.
- Delete your account and data (section 7).
- Withdraw consent where processing is based on consent — for example by disconnecting an integration, turning off notifications or unsubscribing from product emails. Withdrawing consent may mean some features stop working.
- Object to or restrict certain processing, and, where the GDPR applies, exercise the rights of data portability and to lodge a complaint with a supervisory authority.
- US state rights. If you are a resident of California or another US state with a privacy law, you may have the right to know, correct and delete personal information, to opt out of the sale or sharing of personal information (we do not sell or share it for advertising) and not to be discriminated against for exercising your rights. We treat Global Privacy Control signals as an opt-out request where the law requires.
To exercise a right, email privacy@threedaydigital.com. We will verify that the request comes from you (or from someone authorized to act for you), and respond within 30 days, or sooner if the law requires. We do not charge for reasonable requests.
10. If you are a caller or customer of a ThreeDay business
If you called, texted, booked with or paid a business that uses ThreeDay, that business is responsible for your personal information and for answering your questions about it. Please contact the business directly — it can see and manage your records in its account. If you contact us instead, we will pass your request to the business and help it respond; we will not otherwise use your information for our own purposes. To stop receiving text messages from a business, reply STOP to any message.
11. Children
The Services are business tools for people 18 and over. We do not knowingly collect personal information from children, and our customers may not use the Services to do so. If you believe a child has provided us with personal information, contact us and we will delete it.
12. International transfers
We are based in Canada, and most of our service providers are in the United States, so your information will be stored and processed in both countries. Personal information held in Canada or the United States may be accessed by the courts, law-enforcement and national-security authorities of those countries under their laws. Where the GDPR or UK law applies, we transfer personal information under standard contractual clauses or another lawful mechanism. By using the Services you acknowledge that your information will be processed in Canada and the United States under the safeguards described in this policy.
13. Cookies, local storage and website analytics
Our marketing website (threedaydigital.com) does not use advertising cookies or third-party analytics trackers. It stores a small amount of data in your browser: your chosen colour theme (local storage) and a random session identifier (session storage) used for the visitor analytics below. Both stay in your browser until you clear it.
To understand how the site is used, our own first-party analytics record the pages you view, the referring site and, on some pages, how the page is used — clicks, scrolling and mouse movement — so we can replay a visit and see what worked and what confused people. Anything you type into a form is masked at the point of capture and never transmitted by this tool. The data is sent to our own servers, not to an advertising network.
The apps use cookies and similar storage that are strictly necessary to keep you signed in, remember your preferences and protect your account.
Embedded content such as the scheduling calendar on our Book-a-call page or a video player may set its own cookies under the provider’s policy. You can block or clear cookies in your browser settings; some features may then stop working.
14. Changes to this policy
We will post any changes to this policy on this page and update the effective date at the top. If a change materially affects how we handle your personal information, we will email active customers at least 30 days before it takes effect.
15. Contact and complaints
Questions, requests and complaints go to our Privacy Officer:
We will acknowledge a complaint promptly and investigate it. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (1-800-282-1376), to your provincial privacy commissioner where a provincial law applies, or, if you are in the EU or UK, to your local data-protection authority.
Questions about this document? Email privacy@threedaydigital.com or call +1 (289) 904-1677. Our legal documents: