Privacy notice draft
Privacy notice
This privacy notice explains the current RRCC data posture in plain language. It is draft-only and subject to owner and counsel review before general release.
- Document status
- Draft for legal review
- Effective date
- Not yet effective
Version 2026-07-16 · Legal review required before merge. RRCC is built to tell the owner/operator what to do next before a lead goes cold. Current surfaces are record-only first, customer-facing outbound actions are not enabled yet, and this notice remains draft-only until owner and counsel review is complete.
Data we expect to handle
- Business contact details needed for pilot access, support, and account setup.
- Account-verification and sign-in email events needed to secure applicant access.
- Lead and communication records a participating business chooses to provide or connect.
- Operational metadata used to show queue state, audit history, and safety checks.
- Support messages you send to RRCC at the contact emails listed on this site.
How we use data
- Operate and improve the limited-access workflow for missed-lead review.
- Show owner-facing next actions, draft context, and record-only activity history.
- Maintain security, auditability, abuse prevention, and support workflows.
- Prepare future phase legal, compliance, and operational readiness reviews.
Current boundaries
- RRCC does not sell personal information.
- RRCC may send authentication email to an applicant or account holder. Customer-facing email, SMS, calls, and provider writes remain locked.
- AI runtime is disabled in the current product; a human remains responsible for every customer decision.
- Provider foundations may be record-only or safe form only until explicitly approved.
- Current service categories include hosting through Vercel, database and authentication through Supabase, authentication-email delivery through Resend, and Twilio foundations when used. Final legal-entity, region, and contract details remain subject to legal review.
SMS privacy posture
- SMS-related terms, consent, opt-out, and A2P support language require legal review.
- Future SMS data use must stay tied to a business follow-up purpose and customer-care context.
- STOP/HELP handling, do-not-contact status, and quiet-hours checks must be documented before sending.
- Current RRCC public surfaces do not contact leads or customers. Request Access may send an authentication email to the applicant who submitted the request.
Record-only pilot review links
- Signed-in Provider Readiness separates record-only status from live provider readiness.
- Provider readiness does not claim live provider activity, monitoring evidence, legal approval, or outbound access.
- Signed-in Approvals and Audit are evidence surfaces only; no send starts there.
- SMS terms and compliance support stay draft-only until counsel review.