CallButton Privacy Policy
Effective 2026-09-06 · Version 2026-09-06
This Privacy Policy describes how CallButton.AI Inc., a Delaware corporation ("CallButton", "we", "us", "our"), collects, uses, shares, and protects personal data when you use the CallButton mobile applications, the CallButton web ordering experience, the staff tools, and the conversational concierge that connects guests to participating venues (together, the "Service").
This Policy works alongside our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.
In plain language: CallButton is an optional service. To connect you to a venue and serve you, we collect the information described below, we keep it to run, diagnose, maintain, and improve the Service, to investigate disputes, fraud, abuse, and safety or security incidents, and to send you marketing and promotional messages about CallButton and participating venues, which you can opt out of. Messages about your own requests and account are part of the Service and continue regardless. If you do not agree with this Policy, do not use the Service; you can delete your account at any time (§8).
1. Scope and Who We Are
CallButton.AI Inc. is the data controller for personal data processed through the Service, except where this Policy says otherwise (see §6 regarding venues).
This Policy covers:
- the CallButton mobile apps for iOS and Android;
- the CallButton web experience — the browser version of the guest app reached by scanning a venue's QR code or opening a venue link (for example at
demo.callbutton.ai), which lets you browse and order without installing the app; - the staff tools — the tablet and browser dashboards venue staff use to receive and serve requests; and
- the conversational concierge available through each of these;
- the customer portal at callbutton.ai/portal, where venue owners and managers set up and run their venue on CallButton; and
- the callbutton.ai website, including its request-a-demo form.
It applies whether you use the Service as a guest with a phone-verified account, as a web guest who provides only a display name in the browser, as a returning customer, or as a venue staff member signing in to the staff tools. Section 2 includes dedicated parts on web guest sessions, on the data we collect from staff, on venue operators and portal users, and on website visitors.
This Policy does not cover:
- The independent data practices of any participating venue you connect to. Once you connect to a venue, that venue may also collect or use information about you under its own privacy policies — for example, when its staff serve you in person, when you pay at the venue, or when you use the venue's loyalty program. Each venue is an independent data controller for the data it collects from or about you directly.
- Third-party websites, services, or applications that the Service links to or interoperates with.
If you have questions about how a venue handles your data, contact that venue directly.
2. Data We Collect
We collect the following categories of personal data.
Data you provide directly
- Phone number — required, used for SMS verification through our processor Twilio.
- Name — first and last name, optional, used in the app and shown to venue staff when you connect to a venue.
- Email address — optional, used for account communications and (with your opt-in) marketing.
- Profile photo / avatar — optional, uploaded by you.
- Per-venue profile fields — only when you choose to connect to a specific venue and the venue requests them. Examples include room number, member or account number, VIP status, display name, and a per-venue toggle for whether to share your email with that venue.
- Your messages — what you say to the AI concierge and to a venue's staff through the in-app chat.
- Cart and request content — items you add to a cart, requests you submit, modifiers and notes you attach to them.
- Your service location at the venue — the spot, table, cabana, seat, or room code you scan or enter. These are locations the venue has set up for staff to serve, and the code is how staff find you; it is a venue location code, not a GPS reading. Separately, and only with your permission, the app uses your device's GPS location as a convenience to detect that you have arrived at a venue and offer to connect you (see "Location data" below); GPS is never used to decide where an order is delivered.
- Age attestation — if you request an age-restricted item (such as alcohol), a record that you attested to meeting the legal minimum age, and when. We treat this as sensitive and use it to pass your attestation to the venue and to keep a record of it while your account is open.
- Payment information — only where a venue offers card payment in the Service. Your card details go directly to our payment processor, Stripe, which returns a token we use to charge the card; we never receive or store your full card number. We keep the token, the last four digits and card brand for display, and the record of each charge, refund, and dispute. If you save a payment method, Stripe stores it.
- Dietary, allergen, health, or religious notes — anything of this kind that you choose to type or say to the concierge or to staff (for example, "nut allergy" or "no pork"). We treat these as sensitive; we use them only to relay your request to the venue and to keep your conversation history, and we never use them for marketing or profiling.
- Voice input — if you speak to the concierge, your device's operating system converts speech to text on the device (or through the OS vendor's speech service, under that vendor's terms). We receive only the text. We do not receive, store, or process audio.
Web guest sessions (no account)
If you use the web experience and place a request by entering a display name instead of verifying a phone number, we create a limited web guest session:
- we store the display name you enter, the venue and location you are at, and the requests and messages you send, exactly as for an account holder — venue staff see the name you entered;
- the session is identified by a random session token kept in your browser's local storage (not a tracking cookie). Clearing browser storage ends the session on that device; the data already sent to the venue remains with the venue and in our records under the retention schedule in §8;
- no phone number, email, or password is collected, so we cannot verify who you are; if you later verify a phone number, we may link the web session to your account so your history is in one place;
- to have a web guest session's data deleted, email support@callbutton.ai with the venue, date, and display name used.
Data collected automatically by the app
- Device push token — a per-install Expo push token used to send you push notifications; Expo relays notifications to Apple and Google for delivery.
- App and device diagnostics — app version, operating system, device model, language, time zone, and similar technical details, used to render the right UI and to investigate bugs.
- Location data — approximate and precise location only while you are using the app and only when you grant the permission. Location is used for venue discovery (showing you venues near you) and for arrival detection at venues you have used (checking, while the app is open, whether you are inside a venue's geofence so we can offer to connect you). Location is handled by the Radar SDK inside the app: while the app is open, the SDK sends your device's location to Radar together with your CallButton account identifier and the phone number on your account, so that arrival events can be attributed to you. Radar stores location data under its own retention policies as our processor (§6). We do not request background location; our own database keeps the venues you connected to, not a history of your movements.
- Camera and NFC — the camera is used to scan venue QR codes and, optionally, to take a profile photo; NFC is used to read CallButton location tags. QR frames are decoded on your device and are not stored or sent to us — only the decoded venue and location code is.
- Biometric unlock — if you enable Face ID, Touch ID, or your device's biometric unlock for the app, the check is performed entirely by your device's operating system. Biometric data never leaves your device and is never sent to CallButton. A yes/no flag that you turned the feature on is stored on your device, not by CallButton. This feature may not be available in every version of the app.
- Photo library — accessed only when you choose a profile photo; we receive the photo you pick, nothing else.
- Product usage analytics — how you use the Service: which screens you open, when you connect to a venue, open a menu, add an item, place an order, or message the concierge or staff, how long things took, and similar interaction events. We collect this through our analytics processor Mixpanel (see §6). Each event is keyed on a random identifier we generate for your account when it is created. It is not your phone number, name, or email, nor a hash of them, and Mixpanel never receives those. Because the identifier belongs to your phone-verified account, your activity stays associated with you across devices and reinstalls. Events carry the venue you are at, the kind of item or event, counts and amounts, and technical details such as app version and device type. Events for concierge and staff-chat turns also carry what you said, after phone numbers, email addresses, and long digit strings are replaced with placeholders and the text is truncated; the full text stays in our own database. The Mixpanel profile for that identifier holds our internal account number for you, the venues you have visited, and counts and totals of your activity. We use analytics to diagnose, maintain, and improve the Service, to tell venues how the Service performs at their property, and to decide which CallButton or venue communications to send you (§5). We do not derive your location from analytics — IP-based location is switched off in our analytics configuration. As of the effective date, the Service contains no third-party advertising SDKs and we do not "track" you across other companies' apps or websites as that term is used by Apple's App Tracking Transparency framework. If we add advertising, partner offers, or cross-app tracking in the future, we will update this Policy and ask for any permission the platform or the law requires.
Fraud- and abuse-prevention data
To protect the Service and the venues from abuse (for example, automated attempts to trigger paid SMS verification, or to mint web guest sessions in bulk), we record for each attempt to request a verification code or start a web guest session: the phone number (for SMS), the IP address, the time, and whether the attempt was allowed or blocked and why. These records are used only to enforce rate limits and investigate abuse, and are retained for up to 30 days (see §8). Session records that identify a device or browser (a random per-install or per-tablet identifier) are kept so a venue can tell its devices apart and so we can investigate a disputed order.
Data we collect from venue staff
If you use the staff tools on behalf of a venue, we collect:
- Your name and staff record — provided by your venue when it sets up your access, and shown on requests you handle.
- Sign-in attempts — when someone attempts to sign in to a venue's staff tools, we record the venue name entered and the IP address of the device, so we can lock out repeated failed attempts. Records of failed attempts are cleared when a sign-in succeeds; the lockout window is 15 minutes.
- Station and device — which service station you are working, and a random identifier we assign to the tablet so a venue can tell its devices apart. This identifier is not tied to you personally and does not survive a reinstall.
- Staff usage analytics — the same kind of interaction events described above for guests (dashboard opened, order handled, message sent), keyed on the station rather than on you. Analytics events carry your staff record's numeric ID and the tablet identifier; they do not carry your name.
- Your messages to guests — what you send through the staff chat, stored with the conversation.
Your venue is an independent controller for your employment relationship and for how it configures and uses the staff tools; see §1.
Data from third parties
- SMS verification status from Twilio — whether your phone number successfully verified.
- Geofence events from Radar — Radar evaluates the location the app sends it (see "Location data" above) against venue geofences and returns arrival events to the app, which we use to offer to connect you to that venue.
Venue operators and portal users
If you use the customer portal on behalf of a venue, we collect your name and email address, records of the sign-in links we email you (through our email processor, Resend) and when they were used, your role at the venue (owner or manager) and any invitations you send, and the venue information you enter — including staff names and PINs (PINs are stored hashed and never shown back), hours, areas, photos, announcements, and menus. Menus you upload for AI import are sent to Anthropic for parsing (§4). Portal activity is not included in guest product analytics.
Website visitors and demo requests
When you visit callbutton.ai, our host Vercel receives standard web-server request logs (IP address, browser type, pages requested). The website sets no analytics or advertising cookies. If you submit the request-a-demo form, we store the name, email, company, role, and message you provide and email them to our team so we can contact you about CallButton. We may follow up with you about our services; you can ask us to stop at any time.
Consent records
We keep a record of:
- which version of our Terms of Service and which version of this Privacy Policy you accepted, and when you accepted them;
- your marketing-email opt-in preference and any changes you make to it.
These records are stored in an append-only audit table called consent_log so we can demonstrate your consent. The consent_log is treated as personal data and is included in the deletion described in §8.
3. How We Use Data
We process personal data for the following purposes.
- Provide and operate the Service. Route your requests to the right venue, render menus, place orders, manage your cart, process card payments where a venue offers them, deliver in-app and push notifications, and keep your account working across devices.
- Authenticate you. Verify your phone number through Twilio SMS, then issue you a session token from our backend. We also mint a Firebase Realtime Database custom token that is used solely as an identity stamp for the real-time presence system. Firebase is not our authoritative auth provider — our backend (Xano) is.
- Real-time signaling. Firebase Realtime Database delivers low-latency "bell" notifications — small in-app signals that something has changed for you or for a venue. Firebase Cloud Messaging delivers push notifications when the app is backgrounded or closed.
- AI concierge. Your messages and the session's conversation context are sent to Anthropic through our backend so the AI can produce a response. See §4 for the full AI processing detail.
- Diagnose, maintain, and improve the Service. Use everything we collect — including your messages with venue staff, your concierge transcripts, order and request records, device diagnostics, and product usage analytics (§2) — to understand how the Service is used, reproduce and fix problems, keep the concierge and ordering reliable, measure whether features work, prioritize what to build, and investigate disputes, fraud, abuse, and safety or security incidents (see also purpose 7). We also use it to report to venues on how the Service performs at their property — for example, how many orders were placed through the concierge versus the menu, or how quickly requests were served. Reporting to venues is at the level of the venue's activity; it does not identify individual guests.
- Marketing. Tell you about CallButton, participating venues, offers, and new features, through push notifications, in-app messages, and — where you have opted in — email. We use your product usage data (§2) — for example, the venues you have visited and the kinds of things you order — to choose what to send you. If you turn off marketing email or notifications, we stop using your data for that channel. See §5 for how each channel works and how to stop it.
- Fraud prevention, safety, and enforcement. Enforce rate limits, detect and investigate suspected fraud or abuse (including unauthorized, duplicate, or misdirected orders), help a venue resolve a disputed order, protect the safety of staff and guests, and enforce our Terms.
- Legal compliance. Respond to lawful requests and legal process and meet our legal obligations.
Automated decision-making. The AI concierge and our fraud controls are automated, but we do not make decisions about you that have legal or similarly significant effects solely by automated means. The concierge suggests and drafts; a venue's staff decide whether to accept your order. A rate limit may temporarily block a verification code or a web session, and you can contact support to have a person review it.
Advertising and partner offers. As of the effective date we do not sell personal data and do not share it for cross-context behavioral advertising. We may in the future show offers from participating venues or partners, or introduce advertising, and we may share limited information with venues or partners for that purpose. If we do, we will update this Policy first and provide any opt-out that applicable law requires (§7). Using CallButton is optional; if you do not agree with how we use data, you may stop using the Service and delete your account at any time.
4. AI Processing
The Service's AI concierge is powered by large language models from Anthropic (currently Anthropic's Claude family), accessed through our backend over a server-to-server API.
- When you message the concierge, our backend sends Anthropic the recent conversation context for that thread, the venue context where applicable, and your most recent message. Anthropic returns a generated reply, which our backend streams back to you.
- We do not allow Anthropic — or any third-party AI provider — to train on your conversation content. As of the effective date of this Policy, the Anthropic API does not train on API inputs by default, and we operate on that basis. Anthropic acts as our processor under industry-standard data-protection terms.
- We use Anthropic's prompt caching to lower latency and cost. Prompt caching temporarily stores the repeated parts of a request (our instructions, the venue's menu, and the conversation context) on Anthropic's infrastructure for a short window — currently up to one hour after the last use — so the next turn can reuse them. Cached content expires automatically, is not retained beyond that window, and is not used to train models.
- Anthropic may retain API inputs and outputs for a limited period for trust-and-safety purposes under its own policies; we have no control over that retention beyond the contractual terms under which Anthropic acts as our processor.
- Concierge conversations are also stored in our database so you can see your past requests in the app. They follow the same deletion rules described in §8.
5. Marketing
Email. We send marketing email only if you have opted in.
- The marketing opt-in is off by default when you create your account.
- You can opt in at the phone-entry screen during signup, or later in Settings → Preferences → Marketing.
- You can withdraw consent at any time by switching the same toggle off, by emailing support@callbutton.ai, or by replying STOP / using the unsubscribe link in any marketing email.
- Every change to your marketing preference is recorded in our
consent_logaudit table.
Push and in-app messages. If you allow notifications, we may also send push notifications and in-app messages about participating venues, offers, and CallButton features, in addition to messages about your requests. You can turn notifications off in your device settings at any time.
Text messages. As of the effective date we send SMS only for verification codes and account security. If we ever send marketing SMS, we will ask for your separate express consent first.
Withdrawing marketing consent stops marketing email. It does not stop necessary transactional messages — for example, account-deletion confirmations, security alerts, or notifications about a request you submitted to a venue.
6. Sharing and Disclosure
As of the effective date we do not sell personal data and do not share it with third parties for their own direct marketing or for cross-context behavioral advertising. If that changes, we will update this Policy and provide the opt-outs described in §7.
We share personal data in the following ways.
With venues you connect to
When you choose to connect to a venue, we share only what is reasonably necessary for that connection:
- your name (if you provided one);
- the per-venue profile fields you supplied for that venue (for example, room number, member number, and the per-venue email-sharing toggle if you turned it on);
- your real-time chat content with that venue's staff and the content of any requests or orders you submit to that venue.
We do not share your phone number, your verification codes, your precise GPS location, or your conversations with other venues.
Disputed or suspected-fraudulent orders. If a venue or you report an order as unauthorized, mistaken, or fraudulent, we may provide the venue with the records of that session — timestamps, the location code used, the order and message content, and the random device, browser, or session identifier involved — so the venue can resolve it. We do not provide your phone number to the venue for this purpose without your consent or legal process.
Each venue is an independent data controller for the data we share with it. Once data reaches a venue, that venue's privacy practices govern what it does with that data. See §1.
With service providers (processors)
We rely on third-party providers to operate the Service. They process personal data only on our behalf and under industry-standard contracts that prohibit them from using it for their own purposes.
| Provider | What it does |
|---|---|
| Anthropic | AI processing for the concierge (see §4). |
| Firebase (Google) | Realtime Database for in-app "bell" signals, Cloud Messaging for push, Remote Config for app configuration, and the custom token used as an identity stamp for real-time presence. |
| Twilio | SMS verification of your phone number. |
| Radar | Location and geofence evaluation while the app is open. Receives your device location together with your account identifier and phone number so arrival events can be attributed to your account. |
| Xano | Our backend host, where account data, profiles, conversations, and orders are stored. |
| Mixpanel | Product usage analytics (§2). Receives interaction events keyed on a random account identifier — never your phone number, name, or email — including redacted concierge and staff-chat text as described in §2. Session recording and automatic event capture are switched off. |
| Expo | Delivers app updates to your device and relays push notifications to Apple and Google; receives your push token and app version. |
| Apple / Google | Deliver push notifications to your device and, for voice input, may perform speech-to-text under their own terms. |
| Stripe | Card payments, where a venue offers them. Receives your card details directly (we never see the full number), the amount, and the venue being paid; acts as the venue's payment processor and under its own privacy policy for fraud screening. |
| Resend | Delivers our email: portal sign-in links, account-deletion notices, marketing email you opted into, and internal alerts to our team (for example a demo request, or a suggestion the concierge passes along that may include your display name and what you asked for). |
| Vercel | Hosts the web experience, the portal, and this website; receives standard web-server request logs (IP address, browser type, pages requested). |
Each provider is bound by its contract with us to use your data only to provide its service to us.
App-store disclosures. The data-collection summaries we publish in the Apple App Store ("App Privacy" label) and Google Play ("Data safety" section) are derived from this Policy and are kept consistent with it. Where they appear to differ, this Policy is the more detailed statement.
Venue reporting and aggregated insights
We share with each venue statistics about activity at that venue — for example, weekly request volume, how quickly requests were served, or the share of orders placed through the concierge. These reports describe the venue's activity, not you, and cannot reasonably be used to identify you. We may also share aggregated statistics across venues, which are likewise de-identified.
Separately, the venue already holds its own record of everything you ordered and said to its staff through the Service (see "With venues you connect to" above). What the venue does with that — for example, combining it with its point-of-sale, membership, loyalty, or folio systems to report on you individually — is the venue's own activity under its own privacy policy and is outside CallButton's control.
Legal disclosure and corporate transactions
We may disclose personal data:
- to comply with valid legal process (such as a subpoena, court order, or government request);
- to protect the rights, property, or safety of CallButton, our users, venues, or others, including investigating suspected fraud or abuse;
- in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case your personal data may be transferred to the acquiring or successor entity. We will give notice in-app or by email if a change of control materially changes how your data is handled.
7. Your Rights and Choices
You have the following rights with respect to your personal data. You can exercise any of them by emailing support@callbutton.ai. We may need to verify your identity (typically by confirming control of the phone number on your account) before acting on a request.
Available to everyone
- Access — request a copy of the personal data we hold about you. We fulfill access requests manually and respond within the time applicable law allows; we do not currently offer an automated in-app download.
- Correction — your name and email are editable in Profile → Account Details. For other corrections, contact support.
- Deletion — delete your account in-app through Profile → Settings → Delete account. See §8 for the timeline and what is removed versus retained.
- Marketing withdrawal — toggle off in Settings, reply STOP, or use the unsubscribe link in a marketing email. See §5.
- Other requests — email support@callbutton.ai. We honor the requests applicable law gives you; deleting your account (§8) removes your product usage analytics as well.
Additional rights — California residents (CCPA / CPRA)
If you are a California resident, you have the right to:
- know what personal information we collect, use, disclose, and (if applicable) sell or share;
- delete the personal information we have collected from you, subject to legal exceptions;
- correct inaccurate personal information;
- opt out of "sale" or "sharing" of personal information. As of the effective date we do not sell personal information or share it for cross-context behavioral advertising; if we begin to, we will provide a "Do Not Sell or Share" mechanism, and you may exercise the right at any time by contacting us;
- limit the use of sensitive personal information to what is necessary to perform the Service;
- non-discrimination for exercising any of these rights.
You can also designate an authorized agent to make a request on your behalf. We will require the agent to provide proof of authorization and may verify the request with you directly.
To exercise any of these rights, email support@callbutton.ai.
Additional rights — other U.S. states
If you live in a state with a comprehensive consumer-privacy law (including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia), you have rights of access, correction, deletion, and portability, and the right to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. As of the effective date we do not sell personal data, do not engage in targeted advertising, and do not engage in such profiling; if we begin to, we will provide the required opt-out. You may exercise any of these rights by emailing support@callbutton.ai.
Sensitive data. Precise geolocation and the age attestation described in §2 are treated as sensitive personal data. We process them only with your permission (for location) or at your request (for an age-restricted order), and only for the purposes described in §3.
Global Privacy Control. As of the effective date we do not sell or share personal data for advertising, so a browser-level Global Privacy Control (GPC) signal does not change how we handle your data. If that changes, we will treat GPC signals as an opt-out request on the web experience where the law requires.
Appeals. If we decline a request, we will tell you why and how to appeal. To appeal, reply to our decision or email support@callbutton.ai with "Privacy appeal" in the subject line; we will respond within the period required by your state's law. If we deny your appeal, you may contact your state Attorney General.
8. Data Retention and Deletion
We retain personal data only for as long as we need it to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements.
Account deletion timeline
You can delete your account in the app at Profile → Settings → Delete account.
- Account closure is immediate. As soon as you confirm deletion, your account is locked and you are signed out of every device. You cannot sign back in.
- Permanent deletion runs after 14 days. During that window, your data remains intact so that you — or anyone investigating an abuse report or dispute — can resolve the situation. To cancel deletion within the 14-day window, email support@callbutton.ai from the email on file or include the phone number on your account.
- On day 14, an automated task permanently deletes the data described below.
What we permanently delete
- your profile — name, email, phone number, and avatar image;
- the per-venue profiles you created (room numbers, member numbers, preferences, and per-venue sharing settings);
- your chat conversations — both with venue staff and with the AI concierge — including their message contents and thread metadata;
- your favorites and venue history;
- your device push tokens;
- your cart and any in-progress order session;
- your biometric unlock state and saved venue connections;
- your phone-verification records;
- your entries in the
consent_logaudit table; and - your product usage analytics — on permanent deletion we submit a deletion request to Mixpanel for your account's analytics identifier, which removes the events and profile associated with it. Mixpanel completes such requests within its published processing window (currently up to 30 days).
We make a best-effort attempt to delete your avatar file from object storage at the same time.
What we retain after deletion, and why
- Past order records are kept as the venue's business record. Each order keeps a snapshot, taken when you submitted it, of the name, member or account number, room number, and member status you had on file with that venue, together with what was ordered, when, where it was delivered, and the amounts. When your account is deleted the order is unlinked from your account and your phone number and email are not part of it, but the snapshot fields remain so the venue's business and tax records stay intact.
- Aggregated statistics that have already been computed (for example, weekly active counts or popular items by category) persist; they cannot identify you.
- Security, abuse-prevention, and infrastructure records (verification and web-session attempts with phone number and IP address, staff sign-in attempts, request logs, and error events) are kept for as long as we need them to enforce rate limits, investigate abuse or a disputed order, and secure the Service, or longer under a legal hold.
If you don't have the app installed
You can still request deletion by emailing support@callbutton.ai from the email on file or by including the phone number on your account. We will process the deletion the same way — immediate closure, 14-day window, permanent deletion on day 14.
Analytics retention
Product usage analytics are retained in Mixpanel for up to 5 years from the date of the event, after which they are automatically deleted. They are deleted sooner if you delete your account (§7, §8).
Retention schedule
| Data | Retained | Then |
|---|---|---|
| Account profile (name, phone, email, avatar, per-venue fields) | While your account is open | Deleted 14 days after you request deletion |
| Chat with venue staff and with the concierge | While your account is open | Deleted with the account; concierge history older than 30 days is purged on a rolling basis before that |
| Orders and requests | Indefinitely, as the venue's business record | Unlinked from your account 14 days after deletion; the name/member/room snapshot on each order remains (see above) |
| Web guest session (display name, requests, messages) | While the session and its venue connection are live, then as above | Deleted on request through support; orders remain as the venue's record |
| Device push tokens | While the app is installed and signed in | Deleted on sign-out, uninstall cleanup, or account deletion |
Consent and age-attestation records (consent_log) | While your account is open | Deleted with the account |
| Product usage analytics (Mixpanel) | Up to 5 years from the event | Deleted sooner on account deletion |
| Verification, web-session, and staff sign-in attempt records (phone, venue name, IP) | As long as needed for rate limiting and abuse investigation | Deleted when no longer needed |
| Infrastructure and security logs | As long as needed for security and operations | Deleted unless under legal hold |
Other retention drivers
Where law requires us to keep certain data for longer (for example, in connection with a legal hold or a regulatory investigation), we will retain only what is necessary to meet that requirement and will delete it as soon as the requirement no longer applies.
9. Security
We use commercially reasonable administrative, technical, and physical safeguards to protect personal data. These include:
- TLS encryption in transit for connections to our backend and to third-party processors;
- encryption at rest where our service providers support it;
- access controls restricting production data access to authorized personnel on a need-to-know basis;
- periodic review of access and credentials; and
- monitoring and logging of suspicious activity.
No security program is perfect, and we do not promise that the Service will be free from intrusion or attack. If a security incident affects your personal data, we will notify you as required by applicable law, through the Service, by email, or by SMS to the number on your account.
If you believe you have found a security vulnerability, please report it to support@callbutton.ai with "Security report" in the subject.
10. Children
The Service is for adults. You must be 18 or older to use it (Terms of Service, §1), and age-restricted items such as alcohol require the legal minimum age in the venue's jurisdiction (21 in the United States). We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided personal data to us, contact support@callbutton.ai and we will delete it.
11. Where Data Is Processed
The Service is offered in the United States. Our infrastructure and our service providers are located in the United States, and your personal data is stored and processed there. If you use the Service from outside the United States, you understand that your data will be transferred to and processed in the United States, where data-protection laws may differ from those in your country.
12. Changes to This Policy
We may update this Policy from time to time. The Version stamp at the top reflects the current effective date.
For material changes, we will present the updated Policy to you in-app and require renewed acceptance through our consent-update prompt. We will record the new acceptance in our consent_log. For non-material changes (such as clarifying wording or adding a new sub-processor in the same category), the updated Policy takes effect when it is posted at the URL above.
Your continued use of the Service after the effective date of an updated Policy means you accept the update. If you do not agree, your option is to stop using the Service and, if you wish, delete your account (see §8).
13. Do Not Track
Some browsers send a "Do Not Track" signal. There is no common standard for responding to it, and the web experience does not respond to DNT signals; because we do not track you across other sites, no tracking occurs regardless of the signal.
14. Contact
For questions about this Policy, to exercise any of the rights described in §7, or to lodge a privacy complaint:
Postal address:
CallButton.AI Inc. c/o Corporation Service Company d/b/a CSC-Lawyers Incorporating Service Company 211 E. 7th Street, Suite 620 Austin, TX 78701-3218
Terms of Service: https://callbutton.ai/terms · Account deletion: https://callbutton.ai/account/delete