Create Telecom LLC · d/b/a Ready Freddy
Privacy Policy
Create Telecom LLC ("Company," "we," "us," or "our") is committed to the highest standards of data integrity and privacy compliance. This Privacy Policy is an independent public disclosure document, separate from our Terms of Service, describing how we collect, process, store, and protect personal information generated through the Ready Freddy multi-channel conversational widget, SMS/voice qualification engines, CRM lead capture, Google Calendar scheduling sync, and Generative Engine Optimization (GEO) portal suite.
Under applicable privacy statutes including the California Consumer Privacy Act (CCPA/CPRA) and General Data Protection Regulation (GDPR), Create Telecom LLC acts as a Data Processor when managing data on behalf of our subscribers, who retain absolute status as the primary Data Controllers of their localized client ledgers and dashboard data.
Google API Data Access & Limited Use
Subscribers may optionally connect a Google account so Ready Freddy can read calendar availability, list calendars, and create or update booking events on their behalf. OAuth tokens are stored encrypted at rest, scoped to the authenticated tenant, and used only to operate scheduling features the subscriber enables. We do not use Google user data for advertising, sell it, or transfer it to unrelated apps except as required to provide the connected scheduling service or as required by law.
Create Telecom's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google Calendar scopes are requested only after an explicit OAuth consent (including access_type=offline and prompt=consent on reconnect). Subscribers may revoke access at any time in their Google Account security settings or by disconnecting Calendar inside the Ready Freddy Scheduling module.
1. Data We Collect
Our infrastructure collects information across the following primary categories:
1.1 Subscriber Profile Data
During account onboarding or Stripe checkout, we collect: legal company name, business phone number, main domain URL, payment processing email, selected subscription tier, and target service area keywords. We do not collect, store, or process Social Security Numbers (SSNs) or Employer Identification Numbers (EINs). All financial onboarding runs exclusively through Stripe Connect Express using bank-grade encryption.
1.2 Automated Onboarding Web Scraper
When a new subscriber inputs their homepage URL into the setup dashboard, our automated background function performs a single-shot scrape of publicly visible page text. This function dynamically extracts trade niche, existing phone patterns, and regional tags to pre-populate the subscriber's AI Bait Schema JSON-LD catalog. No personal consumer data is collected during this process.
1.3 Voice Services & Conversational Telemetry
When an End User interacts with our embedded website chat widget, triggers an SMS automation lane, or speaks with the voice qualification assistant (telephony / Vapi-orchestrated voice streams), our systems may process: complete text transcript strings, call/session metadata, timestamps, IP-related location signals, and carrier-grade communication delivery status logs. All such data is collected under and subject to the subscriber's TCPA-compliant consent disclosure. Voice audio is offloaded to specialized telephony orchestrators; we do not operate custom in-app audio chunk buffers as the system of record.
1.4 CRM Lead Capture
Qualified conversations may create or update CRM lead records for the subscriber who owns the workspace, including name, phone, email, service intent, booking preferences, channel tags (e.g., voice agent vs. website chat), and related timeline notes. Lead data is tenant-isolated: each authenticated workspace may only access its own customerId / tenantId-bound records.
1.5 Google Calendar Integration
When a subscriber connects Google Calendar, we may process calendar identifiers, event summaries/times needed for availability and booking sync, OAuth access and refresh tokens (encrypted), and the Google account email associated with the grant. Calendar data is used solely to display busy/free state, merge scheduling lanes, and write confirmed appointments back to the connected calendars.
1.6 Ephemeral Audio & Stored PII
Raw audio streams used for real-time speech-to-text are processed in ephemeral memory (and/or by authorized telephony / STT subprocessors) for conversion during the live session and are not retained as durable raw audio objects in Create Telecom application databases. Durable CRM persistence is limited to text transcripts, lead contact fields, booking metadata, and related operational records. Transcripts and lead metadata are stored using industry-standard encryption in transit (TLS) and encryption at rest consistent with AES-256-class controls on our cloud data stores.
1.7 SMS / TCPA Messaging
SMS may be sent for scheduling, confirmations, and follow-up after user-initiated calls or form submissions (or other affirmative opt-ins captured by the subscriber). Message frequency varies. Message and data rates may apply. Inbound keywords such as STOP, UNSUBSCRIBE, QUIT, or CANCEL revoke SMS consent and suppress further automated texts to that number. Automated booking and campaign SMS respect quiet-hour windows (typically 9:00 PM–8:00 AM local time) where configured.
2. Data Visibility and Access — Principle of Least Privilege
We apply a strict Principle of Least Privilege to all internal data access:
- Master Database Access. As system operators, our database administrators and server engineers possess root query capacity across our multi-tenant database infrastructure. This access is technically mandatory for server patches, real-time routing maintenance, data hygiene, and secure cloud backups.
- Support Isolation Guard. Despite possessing root access, no internal support operator, sales agent, or executive is permitted to browse, read, or export any subscriber's lead records, conversation transcripts, or task boards. Access to an active subscriber ledger is strictly gated and will only occur if: (a) the subscriber explicitly files a technical support ticket requesting database troubleshooting; or (b) our automated system triggers a critical stability alert.
- No PII Plaintext Logging. All raw exception errors and server debug traces are automatically scrubbed. Deep stack faults write exclusively to secure internal encrypted logs, while user-facing browser displays receive only generic standardized tracking strings.
3. Third-Party API Integrations
Create Telecom LLC does not sell, lease, rent, or trade your private information or consumer leads to third-party data brokers or advertising networks. To execute multi-channel delivery, data is securely streamed through our authorized core API integrations:
| Integration Partner | Data Shared | Operational Purpose |
|---|---|---|
| Stripe / Stripe Connect | Billing tokens, email strings, affiliate attribution keys | Recurring subscription processing and partner commission payouts |
| Twilio / Carrier Networks | Outbound SMS text content, voice streams, subscriber phone numbers | Carrier-grade SMS conversations and voice routing |
| Resend / Mail Matrix | Transactional email headers, follow-up content, contract copies | Dashboard email composer, marketing alerts, signed agreement dispatch |
| Cloudflare | Edge request metadata, AI inference payloads | Edge networking, security, and AI inference routing |
| ElevenLabs | Conversation text payloads for voice synthesis | Text-to-speech and synthetic voice generation |
| Google Calendar APIs | OAuth tokens, calendar IDs, event times/summaries needed for sync | Availability lookup and appointment write-back under Limited Use |
| Vapi / telephony orchestrators | Call metadata, transcripts, routing tokens | Real-time voice qualification and booking handoff |
4. Affiliate and Agent Data Protections
For independent contractors and sales representatives accessing the Partner Portal and Sales Cockpit, we enforce the following data boundaries:
- No SSN/EIN Storage. The platform does not collect, type, or store agents' Social Security Numbers or Employer Identification Numbers. All financial onboarding flows directly through Stripe Connect Express using bank-grade encryption. Create Telecom LLC never views or possesses agent tax identification numbers.
- Affiliate Tracking Scope. When a prospect clicks an agent's unique tracking URL (?ref=PARTNER-XXXX), we set an internal attribution cookie to log referral credit in our backend partner ledger. This tracking compiles only transaction totals and timestamp values. The customer's wider CRM profile remains entirely hidden from the agent.
- W-9 Handling. Agents are required to submit IRS Form W-9 information directly through Stripe Connect's encrypted onboarding interface prior to receiving any commission payment. This information is held exclusively by Stripe and is not accessible to Create Telecom LLC's database.
5. Data Retention and Deletion
We believe in absolute data minimization:
- Active Accounts. Subscriber information and customer conversation records remain active within our secure cloud network for as long as the account subscription is in good standing.
- Cancellation or Lapse. If a subscriber cancels their account or a trial subscription lapses, all corresponding lead lists, conversational text records, and metadata vectors are scheduled for a permanent, non-recoverable system wipe within thirty (30) days to eliminate the risk of ghost data leakage.
- Inline Deletion Controls. If an End User requests deletion of their contact information from a subscriber's dashboard, the platform enables immediate inline deletion controls. Because we act as the Data Processor, direct erasure requests sent to Create Telecom LLC will be immediately forwarded to the primary subscriber for verification and execution.
6. Your Rights Under Applicable Privacy Laws
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Right to Know / Access: The right to know what personal information we collect and how it is used.
- Right to Delete: The right to request deletion of personal information we hold about you.
- Right to Correct: The right to request correction of inaccurate personal information.
- Right to Opt Out of Sale: We do not sell personal information. However, you may contact us to confirm this.
- Right to Non-Discrimination: We will not discriminate against you for exercising any privacy rights.
To exercise any of these rights, please contact us at the address below. We will respond within the timeframe required by applicable law.
7. Security Measures
We implement industry-standard security measures to protect your data, including:
- Encryption in transit (TLS) and encryption at rest (AES-256-class controls) for stored transcripts and lead metadata;
- Role-based access controls enforcing the Principle of Least Privilege;
- Automated scrubbing of raw exception errors and server debug traces;
- Secure, encrypted internal logs for all deep stack faults;
- Regular security patches and infrastructure monitoring.
No system is perfectly secure and Company makes no warranty of absolute data security. In the event of a confirmed security incident involving unauthorized access to your data, we will notify affected parties as required by applicable law.
8. Regulatory Compliance
Our processing networks maintain strict compliance with applicable federal and state data laws, including:
- California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA);
- Oregon Consumer Privacy Act (OCPA);
- General Data Protection Regulation (GDPR) frameworks for international data flows;
- E-SIGN Act (15 U.S.C. § 7001) for electronic signature audit trails;
- TCPA opt-out enforcement ensuring carrier opt-outs permanently freeze outbound workflows.
9. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy at any time. We will provide notice of material changes via email or in-Platform notification at least thirty (30) days before the changes take effect. Continued use of the Platform after the effective date of any modification constitutes acceptance of the revised policy.
10. Contact Us
If you have any specific inquiries, data correction requests, deletion requests, or security audit questions regarding our compliance architecture, please contact us:
Create Telecom LLC | d/b/a Ready Freddy
961 Almaden Street, Eugene, OR 97402
Attn: Data Privacy & Compliance Team
[email protected] | https://createtelecom.net