This document has not been reviewed by a lawyer. It is a good-faith starting template prepared for the operator's review, written to describe this product's actual data practices accurately. It is not a substitute for legal advice, and the operator should have qualified counsel review it before relying on it commercially.
Privacy Policy
Last updated: September 6, 2026 · Version 2026-09-06
1. What ConverStruct Is
ConverStruct is a voice-to-CRM tool for construction contractors. You speak to it (by recorded audio or typed text); it transcribes what you said, extracts the CRM action you meant (create a contact, book an appointment, send an estimate, and so on), and executes that action against your own GoHighLevel account. This policy explains what we collect while doing that, why, who else touches it, and what your rights are.
2. Voice Recordings and Transcripts
When you use the voice features, we capture the audio you record and the text transcript produced from it, along with the CRM action our system extracted from that transcript. We retain this so you have a history of what you asked for and what was done, so failed actions can be retried, and so we can improve transcription accuracy.
Recordings and transcripts routinely contain personal data about third parties — your customers.
Because you use ConverStruct to talk about your customers, a typical recording or transcript will contain a customer's name, phone number, address, and job details. Those individuals have not spoken to ConverStruct and have not agreed to anything with us. You, the contractor, are responsible for having a lawful basis to record and process that information — for example, your own customer relationship, applicable consent or notice requirements in your jurisdiction, and any two-party consent-to-record laws that apply where you operate. ConverStruct processes this data on your behalf as a data processor; you remain the data controller for your customers' information.
3. What We Collect
- Account data: your name, email, timezone, language, and password (held by Supabase Auth, never by us in plaintext).
- Voice data: recorded audio, transcripts, and the structured actions extracted from them.
- CRM data: a local cache of contacts, appointments, invoices, and estimates synced from your connected GoHighLevel account, used for duplicate detection and faster lookups.
- Connection credentials: your GoHighLevel Private Integration Token, encrypted at rest, used only to act on your behalf against your own GHL account.
- Billing data: subscription status and identifiers from Stripe. Card numbers are never sent to or stored by us; Stripe handles payment details directly.
- Usage data: counts of transcriptions, messages, and similar actions, used for plan limits and billing.
- Conversation history: a durable log of your chat turns with the assistant, so you can review past sessions across devices.
4. Sub-processors: Who Else Sees Your Data
We use the following third-party services to operate ConverStruct. Each receives only the data it needs to perform its function, under its own data processing terms.
- OpenAI — primary voice transcription and the language model that extracts CRM actions from your transcript.
- ElevenLabs — fallback voice transcription, used when OpenAI's transcription is unavailable or fails.
- Supabase — authentication (login, password storage) and our primary database, where your account and CRM cache data are stored.
- Stripe — subscription billing and payment processing.
- Resend — transactional email (password resets, notifications, invoice-approval links).
- GoHighLevel (GHL) — your own CRM account, which is the system of record we create and update contacts, appointments, invoices, and messages in on your instruction.
- Vercel — application hosting and infrastructure.
5. Data Retention
We keep account data, action history, conversation history, and cached CRM data for as long as your account is active, so your history stays useful and your dashboard stays accurate. Raw voice recordings are retained to support transcript review and dispute resolution; if you need a shorter retention window for recordings specifically, contact us and we will accommodate that on request.
If you delete your account (Section 7 below), we delete your account record and the CRM-related rows that identify you or your customers within our systems immediately, as part of that deletion. Data already synced into your own GoHighLevel account is not ours to delete; it is managed there under your GHL account and its own retention settings.
6. Security
Credentials such as your GoHighLevel token and two-factor secret are encrypted at the application level before storage. Passwords are managed entirely by Supabase Auth and are never visible to us in plaintext. Administrative access to the platform requires two-factor authentication. No system is perfectly secure, and we cannot guarantee absolute security, but we take reasonable technical measures to protect the data described in this policy.
7. Your Rights
As a ConverStruct account holder, you have the right to:
- Access the data we hold about you.
- Export a machine-readable copy of that data.
- Delete your account and the associated data we hold.
You can exercise access and export rights yourself at any time from Settings → Profile, which has a "Download my data" button. Account deletion is available from the same page, in the Danger Zone section, and requires you to type a confirmation phrase so it cannot happen by accident. If you cannot access your account, email us and we will handle the request manually. Because a recording or transcript may name one of your customers rather than you, a request from a third party about their own data captured in your recordings should be directed to you, the contractor who made that recording, as the data controller for that information; we will assist you in responding to it.
8. Changes to This Policy
If we make a material change to this policy, we will update the version string and effective date at the top of this page, and, where required, ask you to accept the new version. The version accepted at signup or onboarding is recorded on your account.
9. Contact
Questions about this policy, or requests to access, export, or delete your data, can be sent to the ConverStruct operator through the contact channel provided at signup.