Legal
Privacy Policy
ContentsWho we are
- 01Who we are
- 02Notice at Collection
- 03Information you provide
- 04Information collected automatically
- 05Information from connected platforms
- 06AI Receptionist calls
- 07Information we do NOT collect
- 08How we use your information
- 09Service providers (sub-processors)
- 10We do not sell or share your data
- 11Categories of third parties with whom we share personal information
- 12Automated AI replies
- 13How long we keep data
- 14Your US privacy rights (CCPA/CPRA + state laws)
- 15Global Privacy Control (GPC)
- 16How to submit a request / authorized agents
- 17Data security
- 18International processing
- 19Changes to this policy
- 20Contact
Who we are
This Privacy Policy describes how SMASHONE CORPORATION, a corporation incorporated in Florida, United States, registry number P26000023598 ("SmashOne", "we", "us"), collects, uses, shares, and protects information about users of the SmashOne service at https://smashone.us.
Notice at Collection
At or before the point we collect your personal information, we provide this notice. We collect the categories of information described below to operate, secure, bill, support, and improve the Service. We do not sell your personal information and we do not share it for cross-context behavioral advertising. We retain each category only as long as described in "How long we keep data."
Information you provide
Account details (name, email, business name, optional phone, country of operation); business profile and brand-voice preferences; catalog items and customer content (posts, drafts, images, AI prompts); billing details (processed by Stripe — we store only a tokenized reference and the last 4 digits for display); and support communications you send to info@smashone.us.
Information collected automatically
Usage data (features used, session activity, click patterns); device information (browser, operating system, language); network information (IP address, city/region-level location, referring URL); and activity logs (login timestamps, actions performed, error events). See "Cookies" for cookie-based collection.
Information from connected platforms
When you connect a social account, we receive only what you authorize via OAuth: profile/account identifiers, page and channel IDs, follower counts, and read-only post analytics from Facebook, Instagram, Telegram, WhatsApp Business, and Google Business Profile. For TikTok we receive only what is described in the paragraph below. You can revoke access anytime from your SmashOne dashboard or the platform's own settings.
TikTok. TikTok is not offered or sold to SmashOne customers. The disclosure below applies only to the separately authorized platform-review build. In that build, when a TikTok account is connected, we receive your account identifiers (open ID and union ID), display name, username, and avatar image (user.info.basic) and an access token that lets SmashOne upload and publish videos on your behalf (video.upload, video.publish). We upload only the videos, captions, and post settings you or your AI employee prepare in your workspace; we do not read your TikTok inbox, comments, contacts, or analytics. Access tokens are stored encrypted. Disconnecting the account, or revoking access in TikTok settings, immediately stops SmashOne from posting; the stored credential is erased when you delete your SmashOne account, and account data is removed on the schedule in "How long we keep data" below. The video is streamed to TikTok from your SmashOne media library; the working copy made for the upload is discarded once TikTok reports the publish status. The original file stays in your media library until you delete it.
AI Receptionist calls
When someone calls a line answered by an AI Receptionist, we store the caller's phone number, the telephony provider's call identifier, the written transcript of the conversation, the timestamps of the spoken disclosure and of any consent or opt-out, the call status, the language used, the start time, end time and duration, the reason a call was handed to a person, and per-call cost telemetry (audio-duration, token and stream-minute counters with their USD amounts).
We do not store call audio. The call is transcribed as it happens; the audio is streamed between the caller and our speech provider and is never written to a recording. The duration counters in the cost record measure how long the call ran — they are not audio files.
We use these records to answer the call, to show that the disclosure and any opt-out were given, to pass on the follow-up the caller asked for, to enforce the minutes included with the role, and to reconcile what our providers charge. Written call transcripts are kept for 90 days, then purged; the rest of the call record follows the schedule in "How long we keep data" below. The telephony and speech providers that carry and transcribe these calls are named on the Sub-processors page.
Information we do NOT collect
We do not collect full payment card numbers (handled by Stripe), government IDs, Social Security numbers, biometric data, precise geolocation, or health data. The one category the CCPA calls sensitive that we do hold is account credentials: your hashed password and the tokens you authorize for connected accounts. They are stored encrypted, used only to sign you in and to run the connections you asked for, and never to infer anything about you. The Service is not directed to children under 13, and we do not knowingly collect their data.
SmashOne is not a HIPAA-covered service and we do not sign Business Associate Agreements. Use SmashOne for marketing and customer messaging only — do not store or transmit patient data or other protected health information (PHI) through the Service.
How we use your information
To provide publishing, messaging, the AI assistant, and analytics; to authenticate accounts and process billing; to send transactional and (with opt-in) marketing communications; to secure the Service and prevent fraud and abuse; to improve the product; and to comply with legal and tax obligations.
Service providers (sub-processors)
We share data only with vetted providers acting on our behalf under data-processing terms:
Google LLC (Vertex AI)
AI content generation and live call transcription
United States (global processing)Google LLC (Google Workspace / Gmail)
Transactional and support email
United States (global infrastructure)Telegram FZ-LLC
Messaging channel: customer DMs, AI replies and support conversations
United Arab Emirates, with global message infrastructureTwilio Inc.
Telephony for AI Receptionist calls: inbound call handling and live audio transport
United StatesStripe Inc.
Payments
United StatesSentry
Error tracking and monitoring
United StatesUptime Robot Service Provider Ltd.
External uptime and availability monitoring
MaltaPostHog Inc.
Product analytics (server-side event tracking)
US Cloud (us.i.posthog.com)DigitalOcean LLC
Cloud infrastructure
United StatesBackblaze, Inc.
Encrypted off-site database backups
United StatesCloudflare Inc.
CDN, WAF, DNS
Global provider networkScrapingBee SAS
Website content retrieval and search results for business profile setup and market data (server-side fetching; no customer personal data is sent)
France (EU)We review this list periodically; the current list is always available on this page.
Categories of third parties with whom we share personal information
When you connect a platform, we disclose the categories of personal information identified below to that independent third party so it can operate the connected account. These recipients process information under their own privacy policies. We do not sell personal information or share it for cross-context behavioral advertising under the CCPA/CPRA. Channel providers receive information only when you connect that channel.
| Category of third party | Categories of personal information | Business purpose | Privacy policy |
|---|---|---|---|
| Facebook Meta Platforms, Inc. | Page and account identifiers, authorized access tokens, published content, comments, messages, and engagement metrics. | To operate the connected Facebook account and provide publishing, messaging, and analytics features. | Privacy policy |
| Instagram Meta Platforms, Inc. | Professional-account identifiers, authorized access tokens, posts, comments, direct messages, and engagement metrics. | To operate the connected Instagram account and provide publishing, messaging, and analytics features. | Privacy policy |
| Telegram Telegram FZ-LLC | Channel and bot identifiers, messages and attachments, usernames, and timestamps. | To operate the connected Telegram channel and provide messaging features. | Privacy policy |
| WhatsApp Business WhatsApp LLC | Business phone-number identifiers, business account metadata, messages, and media exchanged with your audience when the channel is connected. | To operate the connected WhatsApp Business account and provide messaging features. | Privacy policy |
| TikTok TikTok Inc. | Account identifiers (open ID and union ID), display name, username, avatar image, authorized access and refresh tokens, the videos, captions, and post settings you or your AI employee prepare for publishing, and the publish status TikTok returns for those uploads. | To operate the connected TikTok account: upload and publish videos prepared in your workspace (video.upload, video.publish) and show the connected account in your workspace (user.info.basic). | Privacy policy |
| Google Business Profile Google LLC | Business-profile identifiers, authorized access tokens, posts, offers, photos, review replies, and customer questions and answers when the channel is connected. | To operate the connected Google Business Profile and provide publishing and review-management features. | Privacy policy |
These disclosures describe categories of third parties and categories of personal information shared to provide the Service. You can revoke a connected platform's access in its settings or from your SmashOne workspace.
Automated AI replies
The AI assistant generates replies from your catalog, FAQ, and configured brand voice. AI messages are clearly disclosed to your customers as your business's AI assistant. You retain editorial control and may switch any conversation to manual mode at any time. We do not train AI models on your specific content; we may use anonymized, aggregated patterns to improve the Service.
How long we keep data
- Active account datafor the duration of your subscription plus 30 days after cancellation (for reactivation).
- Cancelled accounts with no reactivationdeleted 12 months after cancellation.
- Billing and payment records7 years (US tax law).
- Activity and error logs90 days.
- AI conversation audit logsa compliance record of AI-assistant conversations (with personal data redacted) is kept for 2 years to meet AI-transparency and dispute-resolution obligations, then deleted. This is separate from the conversation text itself, which is deleted within 90 days.
- Support correspondence3 years.
- Marketing preferencesuntil you unsubscribe.
- Anonymized/aggregated dataindefinitely.
Your US privacy rights (CCPA/CPRA + state laws)
If you are a California resident — or a resident of another US state with a comprehensive privacy law (e.g., Virginia, Colorado, Connecticut, Utah, Texas, Oregon) — you may exercise the following rights:
- Right to Know the categories and specific pieces of personal information we collect
- Right to Delete — see our step-by-step Data Deletion Instructions
- Right to Correct inaccurate information
- Right to Opt-Out of any sale or sharing (note: we do neither)
- Right to Limit the use of sensitive personal information (we hold only account credentials, and we use them solely to provide the connections you authorize)
- and the Right to Non-Discrimination for exercising these rights.
If we decline your request. Where your state law gives you an appeal right, email info@smashone.us with "Privacy Appeal" in the subject line. We answer within the period your state law requires — 45 to 60 days depending on the state — and if the appeal is denied we tell you how to bring a complaint to your state attorney general.
Global Privacy Control (GPC)
We honor opt-out preference signals, including the Global Privacy Control (GPC), as a valid request to opt out of the sale or sharing of personal information for browsers on which the signal is enabled. Because we do not sell or share personal information, your experience is unaffected, but the signal is respected.
Global Privacy Control status will be detected by your browser on this page.
How to submit a request / authorized agents
Email info@smashone.us. Please include your account email, full name, and the type of request. We verify your identity (typically by confirming the request matches your account, e.g., the email on file or the last 4 digits of your payment card). We respond within 45 calendar days (extendable by 45 days with notice); opt-out requests are honored within 15 business days. You may designate an authorized agent to submit a request on your behalf with signed written authorization.
Data security
We use TLS encryption in transit, AES-256 encryption at rest, tokenized payment data, role-based access controls, multi-factor authentication, audit logging, backups, and an incident-response plan. In the event of a breach affecting your personal information, we will notify affected users and applicable authorities as required by law.
International processing
The Service is operated from the United States; your information is processed in the United States. By using the Service you consent to this processing.
Changes to this policy
We may update this Privacy Policy. For material changes we will give at least 30 days' notice by email and post the updated version here with a new "Last Updated" date.