Privacy Policy
This Privacy Policy explains how QVANTUS CAPITAL LLC, a Delaware limited liability company doing business as CallerSync ("CallerSync," "we," "us"), collects, uses, discloses, and protects personal information when you use our website at callersync.com, the contractor portal, our APIs, our homeowner-facing properties (including hirecontractorstexas.com), and any related services (collectively, the "Service").
1. Who we are
Controller of record: QVANTUS CAPITAL LLC, 8 The Green Ste B, Dover, DE 19901, USA.
Privacy contact: [email protected].
2. Information we collect
From contractors (B2B users)
- Identifiers: name, business name, email, phone, postal address, IP address.
- Account & commercial information: hashed password, ZIP coverage, services offered, business hours, lead Purchase and transaction history, Stripe customer ID.
- Communications: calls placed, calls received, call recordings, AI-assistant transcripts, support emails, in-app messages.
- Device & usage: browser type, operating system, pages visited, timestamps, error logs.
- Session recordings: a replay of how you use the portal and our websites — pages viewed, clicks, scrolling, navigation, and form activity — captured by our own first-party session-replay technology, with the text you type masked.
From homeowners (consumer leads)
- Name, phone number, ZIP code, requested service category, free-text notes.
- TCPA consent record (timestamp, page URL, IP address, checkbox state).
- Audio recording and transcript of any call placed through the Service.
From cookies and similar technologies
We use strictly necessary first-party cookies (an HTTP-only session token named access_token) to keep you signed in. On our marketing pages we also use analytics and advertising technologies — Google Analytics 4, Google Ads, Meta (Facebook) Pixel and TikTok Pixel — which load only after you consent and are disabled when Global Privacy Control is present. See Section 5b below and our Cookie Notice for the full list.
3. How we use the information
- To operate the Service: distributing leads, processing lead Purchases via Stripe, routing calls, displaying analytics, sending transactional email and SMS, provisioning AI assistants.
- To bill, prevent fraud, and resolve disputes (including reviewing call recordings).
- To comply with legal obligations, respond to lawful requests, and enforce our Terms.
- To improve the Service, by tuning our own internal prompts, our routing rules, and our cached "learnings" corpus on de-identified or aggregated call data. We configure our AI providers (OpenAI, Vapi, Deepgram) and our agreements with them so that they are contractually restricted from using your data to train their base models. We do not sell, rent, or transfer call recordings, transcripts, or lead data to any third party for model training.
- To send service announcements; with your separate consent, marketing emails (you can unsubscribe at any time).
4. Legal bases (for users in jurisdictions where this applies)
We process personal information to perform our contract with you, to comply with legal obligations, with your consent (for marketing and call-recording disclosures where opt-in is required), and for our legitimate interests in operating, securing, and improving the Service.
5. How we share information
We share personal information only with the following categories of recipients:
- Matched contractors. When a homeowner submits a lead, we share the homeowner's name, phone, ZIP, requested service, and notes with the matched contractor so they can perform the service. After the match, the contractor acts as an independent controller of that information.
- Service providers (sub-processors) acting under written agreement:
- Twilio, Inc. — voice telephony, SMS, A2P 10DLC.
- Vapi — AI voice-agent orchestration (call routing, turn-taking).
- OpenAI — large-language-model inference for the AI assistant.
- Deepgram — speech-to-text transcription of calls.
- Stripe, Inc. — payment processing for lead Purchases.
- SendGrid (Twilio) — transactional email.
- Hetzner Online GmbH — hosting and infrastructure (Germany / EU).
- Legal & safety. To comply with law, lawful process, or court order; to enforce our Terms; to protect the rights, property, or safety of CallerSync, our users, or the public.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, with successors bound to honor this Policy.
We do not sell personal information for monetary consideration. Sharing a homeowner's contact details with the matched contractor may be considered a "share" for cross-context behavioral advertising under the California CPRA only if used for that purpose; we do not use it for that purpose. See Section 8 for California rights including the right to opt out of any sale or share.
5b. Tracking technologies and advertising
On marketing pages we use a small number of third-party tracking technologies for analytics and conversion measurement. We do not use device fingerprinting or cross-site identity graphs. We honor the Global Privacy Control (GPC) signal as a Do-Not-Sell-or-Share opt-out under the California CPRA and comparable laws.
- Essential — first-party cookies for authentication, security, anti-fraud, and remembering your consent choice. Always on. No tracking purpose.
- Analytics — Google Analytics 4. Pageviews, traffic sources, aggregate behavior. IP anonymized. Loaded only after analytics consent.
- Advertising — Google Ads, Meta (Facebook) Pixel, TikTok Pixel. Conversion measurement and remarketing on marketing pages only (not inside the authenticated contractor portal). Loaded only after advertising consent. Disabled when GPC is present.
- Session recording — our own first-party session-replay technology records how you interact with our sites and the contractor portal (pages viewed, clicks, scrolling, navigation, and form activity, with the text you type masked). We and our staff review these recordings to prevent and investigate fraud, debug problems, resolve billing and lead disputes, and document account activity. Recordings are stored on our own infrastructure and are not sold or shared with advertisers.
We do not use device fingerprinting or cross-site identity graphs. You can change your choice anytime by emailing [email protected] with the subject "Do Not Sell or Share My Personal Information", or by clearing this site's cookies.
6. Call and SMS recording
Inbound and outbound calls placed through the Service may be recorded and transcribed for billing, quality, fraud prevention, dispute resolution, and AI improvement. Where a state or jurisdiction requires two-party (all-party) consent — including California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, and Washington — we play a recording disclosure at the start of the call. By staying on the line you consent to recording. SMS sent through the Service is logged for delivery, opt-out compliance, and audit purposes.
7. Data retention
- Account records: for the life of the account plus seven (7) years for tax and audit.
- Call recordings and transcripts: up to twenty-four (24) months, then deleted or anonymized for AI training.
- Session recordings: retained for a limited period for security, fraud, and dispute purposes, then deleted.
- Stripe transaction metadata: as required by Stripe and applicable financial law.
- TCPA consent records: at least four (4) years from the last consented contact.
8. Your rights — California (CCPA/CPRA)
California residents have the right to:
- Know what personal information we have collected, the sources, the purposes, and the categories of recipients.
- Access a copy of personal information collected in the prior 12 months (or longer on request).
- Delete personal information, subject to legal exceptions (billing, fraud, compliance).
- Correct inaccurate personal information.
- Opt out of sale or sharing of personal information. Use the link below — we treat the request as a global opt-out.
- Limit the use of sensitive personal information to that necessary to provide the Service.
- Non-discrimination — we will not deny service, raise prices, or lower quality because you exercised a right.
To exercise these rights, email [email protected]with the subject "CCPA Request" and the request type. We will verify your identity (we may request enough information to match you to an account) and respond within 45 days. Authorized agents may submit requests with written permission.
→ Do Not Sell or Share My Personal Information
9. Texas residents — SB 140 telemarketing protections
Texas treats most outbound calls and text messages from a business to a consumer as regulated telemarketing under Texas Business & Commerce Code §305 and the 2025 amendments commonly referred to as SB 140. CallerSync operates an inbound, consent-based model: we contact you only after you submit a service request, and we gate every outbound attempt on a multi-layer compliance check.
- Calling-window enforcement. Texas calls and SMS are placed only Monday–Saturday 09:00–21:00 and Sunday 12:00–21:00 local time. Federal default (08:00–21:00) applies in non-Texas states. The window is enforced in code, not policy.
- Multi-layer Do-Not-Call scrubbing. Before any call or SMS, we check the recipient against (a) our internal STOP list, (b) the federal DNC registry, and (c) the Texas state DNC list. A match in any list blocks the attempt. State-DNC scrubs are refreshed on a weekly schedule; federal daily.
- Reassigned-number protection. When a consent record is older than a typical service window, we query Twilio Lookup's reassigned-number package before contacting the number, and fall back to a 6-month/90-day inactivity heuristic if the API is unavailable.
- Opt-out (STOP). Replying STOP to any CallerSync SMS revokes every active consent record for the number, suppresses the number from all future contact, and is confirmed by a single reply. No marketing add-ons.
- Recording disclosure. Inbound and outbound calls placed through CallerSync include an audible recording disclosure on the caller leg before any conversation, satisfying two-party-consent state laws.
To exercise Texas-specific rights — including a copy of the consent we hold for your number — email [email protected] with subject "Texas Privacy Request."
10. Your rights — other US states
Residents of states with comparable privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Delaware) have similar rights of access, deletion, correction, portability, and opt-out of targeted advertising. The same email address above is the point of contact.
11. Children
The Service is not directed to children under 16. We do not knowingly collect information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
12. Security
We use industry-standard safeguards: TLS in transit, encrypted database storage at rest at the host level, hashed passwords, HTTP-only authentication cookies, role-based access control, principle-of-least-privilege for staff, and a hardened ingress (Caddy) with Let's Encrypt certificates. No system is 100% secure; you use the Service at your own risk and should keep your credentials confidential.
13. International transfers
Our infrastructure is hosted in Germany (Hetzner). If you access the Service from outside the EU/EEA, your information will be transferred to and processed in the EU and the United States. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.
14. Third-party links
The Service may link to third-party sites (Stripe checkout, etc.). We are not responsible for the privacy practices of those sites; review their policies separately.
15. Changes
We may update this Policy from time to time. We will post the revised version with a new effective date and, for material changes, notify you by email or in-app banner.
16. Contact
QVANTUS CAPITAL LLC
8 The Green Ste B, Dover, DE 19901, USA
Privacy: [email protected]
Legal: [email protected]