Spurwise Privacy Policy
Last updated: 28 July 2026
Spurwise ("we", "us", "our") provides an AI receptionist service for small businesses, including AI-answered phone calls, SMS messaging, call summarisation, and calendar-based appointment booking. This policy explains what data we collect, why, and how it's handled.
1. Who this applies to
This policy covers two groups:
- Business customers — the businesses (e.g. garages, clinics) who sign up for Spurwise and use the dashboard.
- Callers/end customers — the people who call, text, or book appointments with a business using Spurwise.
2. What we collect
From business customers:
- Account details (name, email, business name, phone number)
- Business information (services, hours, pricing) — entered manually or extracted from your website
- Calendar connection data (see Section 4)
- Billing information, processed by our payment provider (Stripe) — we do not store card details ourselves
From callers, via the AI receptionist:
- Call recordings and transcripts
- Caller name, phone number, and any details volunteered during the call (e.g. vehicle registration, reason for calling)
- SMS message content, for businesses using SMS features
3. How we use this data
- To operate the AI receptionist: answering calls, summarising them, and taking messages
- To book, reschedule, or cancel appointments on your connected calendar
- To send SMS confirmations, reminders, and follow-ups on your behalf
- To generate performance analytics shown in your dashboard (call volume, lead scores, review tracking)
- To improve and troubleshoot the service
4. Calendar access (Google Calendar / Microsoft Outlook)
If you connect a Google or Microsoft calendar, we request access to:
- Read your calendar's free/busy availability, so the AI only offers real open slots
- Create and delete events for bookings made through Spurwise, and remove them if a booking is cancelled
We only access the specific calendar you select during setup. We do not read, modify, or delete any event Spurwise did not create, other than checking availability. Calendar access can be revoked at any time from the Integrations page in your dashboard, which immediately deletes our stored access token.
We do not sell, share, or use your calendar data for advertising, and we do not use it to train AI models.
Limited Use compliance statement: Spurwise's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Raw or derived data from your Google Calendar is never transferred to, or used to train, any third-party AI or machine learning model — including the AI (Anthropic's Claude, see below) used elsewhere in the product to draft suggested replies to customer messages. That drafting feature only ever sees the customer's own message text; it is never given calendar event details, free/busy data, or any other content read from your connected calendar.
5. How we protect sensitive data
Calendar data (see Section 4) and caller information (Section 2) are treated as sensitive. We protect them using the following mechanisms:
- Encryption in transit: all data, including calendar API traffic, is transmitted over TLS (HTTPS). We never send sensitive data over unencrypted connections.
- Encryption at rest: all stored data, including calendar access tokens, call transcripts, and caller records, is encrypted at rest in our database provider (Supabase, running on encrypted PostgreSQL storage).
- Access controls: production data is accessible only to authorised Spurwise personnel who need it to operate or support the service, via role-based, authenticated access. Business customers can only see their own account's data — calendar tokens, calls, and customer records are isolated per business at the database level.
- Token security: OAuth access and refresh tokens for connected calendars are stored encrypted, are never exposed to the browser or to any third party, and can be permanently deleted on demand — disconnecting a calendar from the Integrations page immediately revokes and deletes the stored token (see Section 4).
- No AI training on sensitive data: calendar data and caller data are never used to train any AI or machine learning model, ours or a third party's (see the Limited Use statement in Section 4).
- Minimal retention: sensitive data is retained only as long as your account is active, and deleted on request — see Section 7.
6. Third-party services we use
- Google Calendar API / Microsoft Graph API — calendar booking (only if you connect a calendar)
- Retell AI — powers the AI voice agent
- Anthropic (Claude) — drafts suggested replies to customer email/SMS/WhatsApp messages for you to review and edit before sending; never receives calendar data (see Limited Use statement above)
- Twilio — SMS and phone call delivery
- Supabase — database and backend hosting
- Stripe — payment processing
- Resend — transactional email delivery
Each of these providers processes data only as needed to deliver that part of the service, under their own privacy and security commitments.
7. Data retention
- Call recordings, transcripts, and customer records are retained for as long as your account is active, so you can review call history and manage returning customers.
- Calendar access tokens are deleted immediately when you disconnect a calendar.
- On account deletion, we delete your business data and associated call/customer records — contact team@spurwise.co.uk to request deletion.
8. Your rights
Business customers and callers based in the UK/EU can request access to, correction of, or deletion of their personal data by contacting team@spurwise.co.uk.
9. Contact
Questions about this policy: team@spurwise.co.uk