Privacy Policy

Last updated: 2026-06-29 · Version v2.0

1. Introduction

AI Business Review (“we,” “our,” “us”) is an SMB automation assessment service. This Privacy Policy explains what information we collect, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to our website (theaibusinessreview.com), the intake form, the assessment call system, and the report-delivery email flow.

Controller: AI Business Review acts as the data controller for the information described below. Our privacy contact is hello@theaibusinessreview.com.

2. Information We Collect

We collect the following categories of information:

  • Intake data: Your name, email address, business name, industry, website URL, and optional context such as company size, revenue range, and primary challenge. This is information you provide directly when purchasing an assessment.
  • Call recordings and transcripts: Your assessment call is recorded and transcribed in full. The recording is the primary input for your findings report. Recording requires your explicit consent at intake and again at the start of each call.
  • AI-generated analysis: After the call, we use AI to generate structured findings from your transcript, including a sentiment score and a conversion-likelihood score used only to prioritise our own internal follow-up queue. We do not use these scores to set your price, deny service, or refuse a refund. You have the right to ask for human review of any automated decision affecting you (see §7).
  • Payment metadata: Payment is processed by Stripe. We receive a confirmation token and the last four digits of your card for receipt purposes. We do not store your full card number, CVV, or billing address.
  • Analytics data: Vercel Analytics collects aggregated page-view counts and Web Vitals metrics. It does not set cookies and does not collect personally identifiable information.
  • Security telemetry: We log IP addresses, user agents, and authentication events on our internal operator dashboard to detect abuse and brute-force attempts.

3. How We Use Your Information (Lawful Basis)

  • Delivering your assessment — generating your findings report from your call transcript and intake data. Lawful basis: contract (GDPR Art. 6(1)(b)).
  • Recording your call — we record only with your explicit consent. Lawful basis: consent (GDPR Art. 6(1)(a) and Art. 7). You can withdraw this consent at any time, though doing so before the call means we cannot produce your report.
  • Communicating with you about your order, your passcode, report delivery, and follow-up scheduling via email. Lawful basis: contract.
  • Scheduling and conducting your Pro follow-up consultation — the human consultant reviews your report before the session. Lawful basis: contract.
  • Improving our service — we review anonymised patterns to improve agent question quality and report accuracy. Lawful basis: legitimate interest, balanced against minimal data use.
  • Detecting abuse — security telemetry on authentication and rate-limit events. Lawful basis: legitimate interest.

We do not use your data for advertising and we do not sell it.

4. Subprocessors and International Transfers

We rely on the following subprocessors to operate. Each receives only the data necessary for its function. All listed providers are based in the United States; transfers from outside the US are covered by Standard Contractual Clauses (SCCs) or the EU–US Data Privacy Framework (DPF) where the provider has self-certified.

ProviderPurposeData sharedTransfer mechanism
SupabaseDatabase + file storageIntake, transcripts, recordings, PDFsSCCs (DPA)
VercelHosting + CDN + aggregated analyticsRequest metadata (no PII)SCCs + DPF
VAPIVoice AI infrastructurePhone number, voice content, transcriptSCCs
Anthropic (Claude)AI synthesisTranscript content, intake fieldsSCCs + DPF + zero-data-retention
StripePayment processingEmail, name, payment metadataSCCs + DPF
ResendTransactional emailEmail address, message contentSCCs

We notify customers by email at least 14 days before adding or replacing any subprocessor that processes personal data. The current register is mirrored internally at .planning/security/SUBPROCESSORS.md.

5. Data Retention

We retain personal data only as long as necessary for the purpose collected. Concrete schedules:

  • Intake & contact data — 36 months from your last activity with us.
  • Call recordings — 90 days after the call ends. The recording is destroyed after that period; the transcript remains as the working record.
  • Call transcripts — 24 months from the last call leg.
  • Findings analysis and PDF reports — 7 years (business-records norm, supports outcome tracking and any tax / contract defense).
  • Operator audit log — 7 years (security and compliance evidence).
  • Processing-error logs — 90 days (diagnostics window; personal data is stripped before storage).
  • Consent records — for the life of the consent plus 6 years after withdrawal (proof of consent).
  • Payment references— 7 years (tax and Stripe reconciliation). These survive an erasure request under the “legal obligation” lawful basis with the customer reference replaced by a pseudonymous ID.

You can request deletion of your data at any time (see §7). We will process the request within 30 days.

6. Cookies and tracking

We use only essential cookies set by Stripe Checkout during payment. We do not use advertising cookies or cross-site trackers. Vercel Analytics is cookieless. We will display a cookie notice if we ever add non-essential cookies.

7. Your Rights

Depending on where you live, you have some or all of the following rights. We honour each of them with no charge and within 30 days of a verified request.

  • Access(GDPR Art. 15; CCPA § 1798.110) — request a copy of the data we hold about you.
  • Rectification (GDPR Art. 16) — ask us to correct inaccurate information.
  • Erasure(GDPR Art. 17; CCPA § 1798.105) — request deletion of your data. We will anonymise fields we must retain for legal reasons (e.g. payment records).
  • Restriction (GDPR Art. 18) — request that we pause processing while a dispute is resolved.
  • Portability (GDPR Art. 20) — receive your data in a portable format.
  • Objection (GDPR Art. 21) — object to processing based on legitimate interest.
  • No-sale / no-share (CCPA / CPRA) — we do not sell or share your data, so this right is satisfied by default.
  • Human review of automated decisions (GDPR Art. 22) — ask for human review of any decision based solely on the AI-generated sentiment or conversion scores.
  • Withdraw consent (GDPR Art. 7) — withdraw your call-recording consent. This does not affect processing before withdrawal.
  • Lodge a complaint with your local supervisory authority (EU/UK) or the California Attorney General (US).

To exercise any right, email hello@theaibusinessreview.com from the address you used at checkout. We will verify the request and respond within 30 days.

8. AI transparency

Your assessment is conducted by an AI voice agent, and your transcript is analysed by an AI model (Anthropic Claude) to produce the findings in your report. We disclose this here, on the pricing and intake pages, and at the start of each call. The AI does not make consequential decisions about you — the sentiment and conversion scores are used only to prioritise our internal follow-up queue and never to set price, deny service, or refuse a refund.

9. Sensitive topics

The assessment is structured around your business operations. Please do not discuss protected health information (PHI), customer financial-account details (SSNs, full account numbers), or other sensitive personal data on the call. Our synthesis pipeline is instructed to drop any incidental sensitive content from the report; if you operate in healthcare or financial services, please email us before scheduling so we can apply the right safeguards.

10. Security

We implement industry-standard security practices. Data is stored in Supabase (SOC 2 Type II compliant), hosted on Vercel (ISO 27001 certified), and transmitted over HTTPS with HSTS preload. Internal controls include row-level security on every database table, multi-factor authentication for operator accounts, signed-URL access to recordings, and append-only audit logging.

No system is completely secure. Please report any security issue to security@theaibusinessreview.com. If we determine that a personal-data breach has occurred, we will notify the relevant supervisory authority within 72 hours and notify affected users without undue delay where the risk to you is high.

11. Children

This service is not intended for users under 18 years of age. We do not knowingly collect information from minors. If you believe a minor has submitted data to us, please contact us immediately so we can delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date and version number above will reflect the most recent revision. For material changes, we will notify you by email if we have your contact information.

13. Contact

Questions about this Privacy Policy? Email hello@theaibusinessreview.com. For security disclosures, please use security@theaibusinessreview.com.

This policy is the binding language for our handling of your personal data. It is not legal advice. It will be reviewed by qualified counsel before the first paying customer as part of our launch checklist (POL-06).