Legal

Privacy policy

How we collect, use, and protect information on the Service Socket platform.

On this page

Effective

1. Introduction and Scope

HelioNova, Inc., doing business as Service Socket ("Company," "we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy ("Policy") explains how we collect, use, disclose, and safeguard information through the Service Socket platform, including our web application, APIs, phone integrations, chat widgets, the Service Socket Voice mobile application, and related features (collectively, the "Service").

This Policy applies to all users, including home service businesses, auto service businesses, their employees and technicians, and end customers who interact with the Service.

2. Information Collection

2.1 Information You Provide

We collect information that you provide directly, including:

  • Business Information: Company name, service type, service area, and contact details
  • Account Information: Names, email addresses, phone numbers, and login credentials
  • AI Configuration: Business hours, service offerings, pricing, scheduling preferences, and custom scripts
  • Financial Information: Payment details, billing addresses, and subscription records
  • Integration Data: API keys and configuration for connected platforms when enabled (for example, Google Calendar, Slack, WhatsApp messaging, Zapier/webhooks, and Salesforce or HubSpot lead/contact push)

2.2 Information Collected via AI Interactions

When Service Socket AI voice and chat features handle calls and chats for your business, the following categories of information may be processed:

  • Telephony data: Phone numbers, call metadata, and live PSTN audio media processed by our telephony provider (Twilio) to connect and stream phone calls
  • AI voice and chat processing: Live voice or chat content, instructions, tool context, generated responses, and transcripts processed by our AI provider (xAI) to operate real-time speech recognition, language understanding, and speech synthesis
  • Stored transcripts and call metadata: Text transcripts and related call metadata for telephony and public web voice sessions, stored in our systems to operate the Service. Service Socket does not currently store call-audio recordings
  • Chat logs: Website chat and messaging conversations between Service Socket AI and end customers
  • Booking and lead information: Appointment details, customer contact info, service requests, and lead details captured during interactions
  • Field documentation: Job-site photos and related metadata captured or attached through Service Socket Voice, which may be linked to jobs or customers and analyzed by AI to support job documentation
  • Opt-in technician location shared with your business for dispatch map visibility and arrival estimates when location sharing is enabled in Service Socket Voice

2.3 Information Collected Automatically

  • Device and browser information, IP addresses, and usage patterns
  • Dashboard access logs, feature usage, and performance analytics
  • Call metadata: duration, timestamps, phone numbers, and outcomes
  • Mobile application data such as app version and usage frequency when using Service Socket Voice
  • Usage metering and billing data, including AI credit consumption, feature usage totals, and related operational metadata

3. Cookies and Analytics

We use necessary cookies and session tokens to authenticate users, maintain secure sessions, and operate the Service. We also collect usage and performance analytics to understand how the Service is used, improve reliability, and support product operations.

  • Authentication and security cookies required for signed-in access
  • Preference and session data needed for dashboard functionality
  • Product analytics and operational metrics related to feature usage and performance

We do not use advertising cookies or sell personal information for third-party advertising based on current practices.

4. Use of Information

4.1 Core Service Delivery

We use collected information to:

  • Power AI voice and chat interactions with your customers
  • Power the internal field Voice assistant for authorized business users and technicians
  • Process and analyze field photos for job documentation
  • Show opt-in technician location on dispatch maps and support arrival estimates
  • Book appointments and sync calendars when Google Calendar or similar scheduling tools are configured
  • Push lead or contact data to Salesforce or HubSpot when those integrations are configured
  • Generate call summaries, lead reports, and analytics
  • Process billing and manage subscriptions
  • Measure AI credit usage, apply included allocations, and support overage billing where applicable
  • Provide customer support and troubleshoot issues

4.2 Service Improvement

  • Monitor quality, reliability, and response relevance
  • Develop new features and integration capabilities
  • Conduct aggregate or de-identified analytics for product improvement
  • Troubleshoot issues and maintain platform security

5. Information Sharing and Disclosure

5.1 Connected Integrations

When you connect Service Socket to third-party platforms (for example, Google Calendar, Slack, WhatsApp messaging, Zapier/webhooks, or Salesforce/HubSpot), we share relevant booking, messaging, and lead data as necessary to operate those integrations per your configuration. Salesforce and HubSpot connections, when enabled, are used for lead or contact push and are not a full bidirectional CRM sync.

5.2 Service Providers

We use trusted third-party providers to operate the Service. These include:

  • Twilio: telephony connectivity, phone numbers, Media Streams, delivery of SMS, and related call or messaging metadata
  • xAI: real-time speech recognition, language model processing, speech synthesis, and related transcript generation for AI voice and chat sessions
  • Infrastructure, payment, and analytics providers that support hosting, billing, and product operations

Providers process personal information only as needed to deliver services on our behalf and may temporarily retain data under their account configuration, contracts, and published policies. Based on current xAI documentation, xAI does not use API inputs or outputs to train models without explicit permission. Temporary provider retention windows are governed by the applicable provider account settings and policies and may change over time.

5.3 Legal Requirements

We may disclose information when required by law, regulation, subpoena, or court order, or when we believe disclosure is necessary to protect rights, safety, or property.

6. Data Security

We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information, including:

  • Encryption in transit (TLS)
  • Provider-managed encryption at rest for hosted infrastructure
  • Role-based access controls and row-level security where implemented
  • Audit logging for sensitive operational access where implemented
  • Dependency scanning and ongoing security review of application code

No method of transmission or storage is completely secure. We continuously work to improve our safeguards, but we cannot guarantee absolute security.

7. Voice Processing and Transcripts

Live AI processing is part of normal Service Socket voice operations. How audio and transcripts are handled depends on the channel:

7.1 Customer-facing telephony and public web voice

When a call or public web voice session is handled by Service Socket AI for your customers:

  • Live audio is streamed through Twilio for PSTN telephony and processed by xAI in real time to understand speech, generate responses, and synthesize speech
  • Text transcripts and call metadata are stored so you can review conversations, operate workflows, and support your customers
  • Service Socket does not currently store call-audio recordings. If stored audio recording becomes available later, we will update this Policy and describe any related notices or controls

7.2 Internal field Voice app (Service Socket Voice)

When authorized business users or technicians use Service Socket Voice (the native mobile field assistant):

  • Live microphone audio is streamed through our voice infrastructure and processed by xAI in real time for push-to-talk AI assistance and tool use. Audio is not recorded or stored on the device
  • Session transcripts shown in the app are ephemeral and are not persisted server-side in the current product version
  • Field photos may be uploaded, analyzed by AI, and retained as job or customer documentation

You are responsible for providing any notices and obtaining any permissions required by applicable law for AI-assisted calling, transcript storage, field photo capture, and related processing in your jurisdiction.

8. Mobile Applications (Service Socket Voice)

Service Socket Voice is our native mobile application for authorized business users and field technicians. It is distinct from customer-facing telephony and public web voice. The app may request device permissions necessary for field operations. Permissions are requested with system prompts, and you can deny or revoke them in device settings (some features will not work without the related permission):

  • Microphone: push-to-talk with the AI assistant. Audio is streamed for real-time AI assistance and is not recorded or stored on the device. During an active voice session, audio may continue while the app is backgrounded so the session can remain usable; this is not always-on recording when you are not in a session.
  • Camera and photo library: capture or attach job-site photos for AI analysis and job documentation. Photos may be uploaded and retained as part of your business records.
  • Location: opt-in location sharing so dispatch can see where technicians are and estimate arrival times. When you enable sharing, location may continue in the background while sharing remains on. You can turn sharing off in the app.

Authentication tokens and certain preferences (for example, UI mode) are stored securely on the device. We do not use biometrics or push notifications in the current Service Socket Voice product version.

9. SMS and Text Messaging

Service Socket provides messaging infrastructure that subscriber businesses may use to send transactional and service-related SMS through Twilio. HelioNova, Inc., doing business as Service Socket, operates the platform. Each subscriber business is responsible for obtaining and retaining each recipient's consent under applicable law before enabling SMS for that customer. Service Socket does not maintain a separate end-user consent ledger or application-owned opt-out list for subscriber SMS programs.

Message types. Supported messages include payment confirmations and transactional or service-request follow-ups enabled by the subscriber business. We do not use this program for affiliate or third-party marketing.

Frequency. Message frequency varies based on service events and subscriber settings.

Rates.Message and data rates may apply based on the recipient's wireless plan. Service Socket does not charge end users to receive program messages.

Opt-out. Recipients may reply STOP to unsubscribe. Where SMS is routed through a configured Twilio Messaging Service with Advanced Opt-Out enabled, Twilio processes standard opt-out and help keywords. Recipients may reply HELP for customer care contact information or email support@servicesocket.ai. An SMS opt-out stops future messaging from the applicable sending path; it is not itself a request to delete transcripts, customer records, or activity logs.

No sale or sharing for marketing. Mobile numbers and SMS consent information collected under this program are not sold, rented, or shared with unaffiliated third parties for their marketing purposes. Mobile numbers are shared with Twilio and wireless carriers only to the extent necessary to deliver the messages.

Full program disclosures. For the complete SMS program description and subscriber business obligations, see our SMS Terms and Consent Disclosures.

10. Data Retention

We retain information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type, account status, operational needs, provider configuration, and applicable law. Transcripts and call metadata for telephony and public web voice are retained for operational needs unless deleted in response to a valid request or other retention rule. Field photos may be retained as job or customer documentation. Mobile Voice app session transcripts are not persisted server-side in the current product version. Providers such as Twilio and xAI may temporarily retain related data under their own account settings and published policies. You may request deletion of your data by contacting us; requests are subject to legal and operational exceptions. An SMS STOP request is not itself a deletion request.

11. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access and receive a copy of your data
  • Correct or update inaccurate information
  • Request deletion of your data
  • Restrict or object to certain processing
  • Export your data in a portable format
  • Withdraw consent at any time where processing is based on consent

To exercise these rights, contact us using the details in Section 16. For SMS opt-out, reply STOP or see our SMS Terms. Opting out of SMS does not automatically delete transcripts, customer records, or activity logs; use the privacy contact path for deletion requests.

12. California Privacy Rights

If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA), as amended, including the right to know, access, correct, delete, and receive a portable copy of certain personal information. Based on current practices, Service Socket does not sell personal information for cross-context behavioral advertising. To exercise California privacy rights, email privacy@servicesocket.ai. We will verify requests as required by applicable law and will not discriminate against you for exercising your privacy rights.

13. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact privacy@servicesocket.ai and we will take appropriate steps to delete the information.

14. International Data Transfers

Your data may be processed in the United States or other countries where Service Socket and our service providers operate. Where required by applicable law, we use appropriate safeguards for cross-border transfers.

15. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated via email, in-app notifications, or dashboard alerts. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

16. Contact Information

For privacy-related questions or to exercise your rights, contact us at privacy@servicesocket.ai or visit our contact page.

Last updated .