Security & data

What we hold, who touches it, and how long it stays.

Wepickup answers phone calls, so it necessarily handles what your customers say. This page describes that plainly. It is not a certification claim, and it does not stand in for the contractual documents.

Data categories

What is processed

Business data
Your account and user details, business profile, opening hours, catalog or service list, written rules, staff records and settings.
Call content
Audio of inbound calls where recording is enabled, the transcript of the conversation, and a log of the lookups the assistant performed during it.
Customer records
The caller’s phone number, the name they give, and the orders or bookings associated with them. These are your customers’ personal data, held on your behalf.
Operational data
Usage counts against your plan, delivery logs for webhooks, error and audit logs.
Billing data
Subscription status and invoice history. Card details are handled by Stripe and are never stored by Wepickup.

Retention

How long call recordings and transcripts are kept

Call recordings are retained for 30 days by default and then hard-deleted — both the file held by our telephony provider and the record in our database. The cleanup job runs continuously rather than on request.

Transcripts, orders, bookings and customer records are kept for as long as your account is active, because they are the working record your business runs on. They are removed on a deletion request.

If your operation needs a shorter recording window than 30 days, ask us — the retention period is configurable per deployment.

Processors

Who else touches the data

Telephony
Twilio carries calls and texts, and holds recordings until they are deleted under the policy above.
Voice and language processing
The conversation is processed by our voice runtime and the language models behind it in order to understand the caller and produce a reply.
Database and storage
A managed PostgreSQL database and object storage hold your workspace data and uploaded files.
Payments
Stripe handles subscription billing and, where you connect it, your own customer payment links.
Calendars
Where you connect Google or Microsoft, booking data is written to and read from the calendar you authorise.

The specific processor list, locations and safeguards belong in the data processing addendum. Where this page and the DPA differ, the DPA governs.

Access control

How access is restricted

Workspace isolation
Every request is scoped to one workspace. A user authenticated for one business cannot read another business’s calls, orders, customers or settings.
Authentication
Signed session tokens with password hashing, plus email verification and password reset flows. Credential secrets are held in server-side configuration, never in the browser.
Third-party credentials
Tokens for connected services, such as calendar access, are encrypted at rest before being stored.
Transport
All traffic between your browser, the API and connected services runs over HTTPS.
Webhook integrity
Outbound webhooks are signed with a secret you can rotate, so your receiving endpoint can verify the event came from us.

Your rights

Deleting data and raising an issue

Account owners can request access to, correction of, export of or deletion of the data we hold. The process, including what we can and cannot delete immediately, is on the data deletion page.

To report a suspected security issue, email support@wepickup.app with “Security” in the subject line. Please give us the detail we need to reproduce it, and give us a reasonable window to respond before disclosing it publicly.

We do not hold an ISO 27001, SOC 2 or equivalent certification, and we are not going to imply one. If your procurement process requires evidence beyond this page and the DPA, contact us and we will tell you honestly what we can supply.

Questions before you connect a line?

Ask us anything about data handling before you sign up. We would rather answer it now than in an audit.

Free plan, no card required. 20 AI-answered calls a month.