Legal

Privacy Policy

Wepickup holds two kinds of personal data: yours, as a customer of ours, and your callers', which we process on your behalf.

The two roles we play

For your own account data — your name, email, business details and billing records — Wepickup is the controller. We decide what is collected and why.

For the personal data of people who call your business — their phone number, what they say on the call, and the orders or bookings they make — you are the controller and Wepickup is your processor. We handle that data on your instructions in order to run the service you have configured.

What we collect

The categories of data processed through the platform are:

  • Account data: names, email addresses, hashed passwords, business profile, settings and configuration.
  • Call data: the audio of inbound calls where recording is enabled, transcripts of conversations, and a log of the lookups performed during a call.
  • Customer data: caller phone numbers, names given on a call, and the orders, bookings and history associated with them.
  • Operational data: usage counts against your plan, webhook delivery logs, security and error logs.
  • Billing data: subscription status and invoice history. Card details are handled by Stripe and are never stored by Wepickup.

Why we process it

Account and billing data are processed to provide the service and to meet our contractual and legal obligations to you.

Call, customer and operational data are processed to deliver the functions you have enabled: answering calls, checking your catalog and availability, creating orders and bookings, sending confirmations, and giving you a record of what happened.

Security and error logs are processed on the basis of our legitimate interest in keeping the service reliable and protecting it against abuse.

Call recording and your responsibilities

Where call recording is enabled on your workspace, the audio of inbound calls is recorded. You are responsible for informing callers in accordance with the law applying to your business, including any requirement to give notice at the start of a call.

You control whether recording is enabled. Transcripts are produced in order to operate the assistant and to give you a record of the call.

Google user data

If you connect a Google account so that Wepickup can check therapist or staff availability and place bookings in your calendar, Wepickup's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What we access. Wepickup requests four Google OAuth scopes, and only these four. Each is listed below with the exact purpose it serves. We do not request the full Google Calendar scope, and we do not request permission to read the contents of your calendar events.

  • https://www.googleapis.com/auth/calendar.events — used to create, update and cancel the calendar entries that correspond to bookings made through Wepickup. It is not used to read or modify events created by anyone else.
  • https://www.googleapis.com/auth/calendar.freebusy — used to read busy and free times on the calendars owned by the connected account, so the assistant only offers times that are genuinely open.
  • https://www.googleapis.com/auth/calendar.events.freebusy — used to read busy and free times on calendars that are shared with the connected account, which is how a therapist's or staff member's own calendar is taken into account. This returns busy and free periods only, never event titles, guests or descriptions.
  • https://www.googleapis.com/auth/calendar.calendarlist.readonly — used to read the names of the calendars on the account, so that setup can confirm the connection works and you can choose which calendar a booking belongs to.

How we use, store and share Google user data

How we use it. Free/busy times are used at the moment a caller asks about availability, so the assistant only offers times that are genuinely open. Calendar events are created, updated or cancelled solely to reflect bookings made through Wepickup. That is the entirety of the use.

What we store. Free/busy information is held only in memory for up to sixty seconds while a call is in progress, so that one caller asking about several times does not trigger repeated requests to Google. It is never written to our database. Of your calendar contents we store nothing except the identifier of an event Wepickup itself created, which is what lets us update or cancel that booking later. Your Google access and refresh tokens are encrypted at rest.

Who we share it with. We do not sell Google user data, and we do not transfer or disclose it to third parties. It is not passed to advertising networks, data brokers or information resellers, and it is not used for advertising of any kind.

AI and machine learning. Wepickup is an AI receptionist, so we state this explicitly: Google user data is not used to develop, improve, or train generalised or non-personalised artificial intelligence or machine learning models. Free/busy times are used only to answer the caller in front of us, in that call, and are then discarded.

Retention and removal. Disconnecting Google in your workspace settings deletes the stored tokens and ends our access immediately. You can also revoke access at any time from your Google account's third-party access settings. Events Wepickup created in your calendar remain yours and are unaffected.

How long we keep it

Call recordings are retained for 30 days by default and are then hard-deleted, both from our telephony provider and from our database. This retention period is configurable; ask us if your operation requires a shorter one.

Transcripts, orders, bookings and customer records are retained for as long as your account is active, because they are the working record your business relies on. They are deleted on request in accordance with the data deletion process.

Billing records are retained for as long as required for accounting and tax purposes.

Who else processes the data

We use service providers to deliver the platform. Each is engaged under terms that restrict them to processing data for the purpose of providing their service to us:

  • A telephony provider, which carries calls and text messages and stores recordings until they are deleted under the retention policy above.
  • Voice and language processing services, which turn speech into text and produce the assistant's replies.
  • A managed database and object storage provider, which hosts your workspace data and uploaded files.
  • Stripe, which handles subscription billing and, where you connect it, payment links you send to your own customers.
  • Google or Microsoft, where you choose to connect a calendar.
  • Email delivery services used for account and notification email.

International transfers

Some of these providers operate outside the United Kingdom and the European Economic Area. Where personal data is transferred outside those areas, it is done under the safeguards required by applicable data protection law. The current list of providers and locations is set out in the data processing addendum.

Your rights

Where we are the controller, you may request access to, correction of, a copy of, or deletion of your personal data, and you may object to or restrict certain processing.

Where we act as your processor, requests from your callers should be directed to you as the controller. We will assist you in responding to them.

To exercise any of these rights, email support@wepickup.app from the address associated with your account. Details of the deletion process are on the data deletion page.

Security

Requests are scoped to a single workspace, so one business cannot access another's data. Passwords are hashed, sessions use signed tokens, credentials for connected services are encrypted at rest, and traffic runs over HTTPS. The security page sets out more detail.

No system is immune to compromise. If a breach affects your data we will notify you without undue delay and give you the information you need to meet your own obligations.

Changes and contact

If we change this policy materially we will update the date at the top and notify account owners by email.

Questions about this policy should go to support@wepickup.app.