Skip to content
Back to home

Privacy Policy

Last updated: June 24, 2026

Effective Date: June 24, 2026

Applies to carrtelsolutions.com, dash.carrtelsolutions.com, and all Carrtel automation services.

Plain-language summary (this box is a summary, not the full terms)

Carrtel Solutions Inc. (“Carrtel,” “we,” “us”) is a Calgary, Alberta automation agency. We collect two kinds of personal information: (1) information about you, our client (your name, business, email, phone, billing details), and (2) information about your customers that flows through the automations we run for you (mainly their phone numbers and email addresses, and the content of the messages we send and receive on your behalf). We use a small set of trusted service providers — Twilio, Stripe, Resend, OpenRouter, and Google — to deliver those services. We never sell personal information. You and your customers can ask us what we hold, fix it, or delete it. Anyone can stop our text messages by replying STOP. Questions: support@carrtelsolutions.com.

1. Who we are and what laws apply

Carrtel Solutions Inc. is a corporation based in Calgary, Alberta. This policy is designed to comply with:

  • The federal Personal Information Protection and Electronic Documents Act (PIPEDA);
  • Alberta's Personal Information Protection Act (PIPA); and
  • Canada's Anti-Spam Legislation (CASL).

We act in two different roles, and your rights depend on which applies:

  • As a business in our own right (our website, our marketing, our billing of clients), Carrtel decides why and how your information is used. We are accountable for it directly.
  • As a service provider to our clients (when we run automations for a client and process that client's customers' information), we act on the client's instructions. In that role the client is the organization accountable to its own customers, and we are the processor acting on its behalf. If you are a customer of one of our clients and want your information deleted, the fastest path is usually to contact that business directly, but you may also contact us and we will route your request and honour applicable rights.

2. Information we collect

2.1 — About you, our client (and website visitors)

  • Name, business name, role — collected via contact form, onboarding, and account creation, to identify you and deliver and configure service.
  • Email address — via contact form, onboarding, billing, login, for service delivery, login, billing, and support.
  • Phone number — via contact form and onboarding, for account verification, support, and service alerts.
  • Business & billing address — via onboarding and billing, for invoicing and GST/tax compliance.
  • Payment details — processed by Stripe; we do not store full card numbers.
  • Account credentials / API keys you give us — via onboarding, to connect your systems (calendar, review profiles, etc.) to your automations.
  • Support and communication content — from email, SMS, and calls with us, to provide support, keep records, and resolve disputes.
  • IP address, browser/device, pages viewed, referrer, cookies — collected automatically when you use our sites, for security, fraud prevention, analytics, and site operation.

2.2 — About your customers (processed on your behalf)

When we run automations for you, the following information about your customers passes through our systems so we can deliver the message or action you have configured:

  • Customer phone number (from your CRM, booking tool, missed-call log, or lead form) — for sending SMS (reminders, missed-call text-backs, review requests, follow-ups, invoice reminders) and AI voice handling.
  • Customer email address (from your CRM, booking tool, or lead form) — for sending email (reminders, follow-ups).
  • Customer name and booking/appointment details (from your scheduling/CRM systems) — for personalizing messages and scheduling reminders.
  • Message content and replies (generated by the automation; replies from your customers) — for delivering the service, recording opt-outs, and AI-generating message text.
  • Review/reputation content (from Google / Facebook business profiles) — for review-generation and reputation-defender automations.

We access and process only the minimum customer information needed to run the automations you have configured. We do not use your customers' information for our own marketing, do not build profiles, and do not sell it.

3. How we use information

  • To deliver the service you contracted for (contractual necessity): running automations, sending/receiving SMS, email and voice, configuring integrations, hosting your data, processing payments.
  • To operate and secure our platform (legitimate interest / legal obligation): logging, fraud prevention, debugging, security monitoring, backups, abuse prevention, maintaining the SMS opt-out/suppression list.
  • To communicate with you about your account (service messages — billing, outages, security, support). These are not marketing and are sent on the basis of our service relationship.
  • For our own marketing to you (express consent only): newsletters, tips, case studies. You can opt out at any time. We do not use your customers' data for our marketing.

We never sell personal information, and we do not use automated decision-making that has legal or similarly significant effects on individuals.

4. SMS and electronic-message consent (CASL)

  • Carrtel sends commercial electronic messages on behalf of our clients. The client is responsible for ensuring it has the consent required by CASL from each recipient before that recipient is added to an automation. This is a contractual requirement in our Service Agreement.
  • Every text message we send on a client's behalf identifies the client as the business on whose behalf it is sent and includes a way to opt out, as CASL requires.
  • Opt-out is always available. Any recipient can reply STOP (or UNSUBSCRIBE, CANCEL, END, QUIT) to stop text messages, or HELP for help. Replies are processed automatically: STOP adds the number to our suppression list, and once suppressed, our systems block all further outbound messages to that number across every automation. START re-subscribes. Marketing emails include an unsubscribe link.
  • Service messages required to operate something the recipient asked for (e.g., a booking confirmation they requested) may be sent on the basis of implied consent or an existing business relationship, as permitted by CASL.

5. Service providers (sub-processors) and where data goes

We use the following providers to run the service. We share only the information each provider needs, and we require each to protect it.

  • Twilio — SMS, MMS and voice delivery. Handles phone numbers, message and call content, and opt-out status. United States. (twilio.com/legal/privacy)
  • Stripe — payment processing (client billing). Handles client name, email, billing details, and card data. United States. (stripe.com/privacy)
  • Resend — transactional and notification email delivery. Handles email addresses and email content. United States. (resend.com/legal/privacy)
  • OpenRouter — AI text generation (composing/handling message and voice content). Handles message prompts/snippets — minimized; not used to train models on your data where avoidable. United States. (openrouter.ai/privacy)
  • Google — Places / Business Profile / Calendar APIs (reviews, booking, reputation). Handles business and review data and appointment data. United States. (policies.google.com/privacy)
  • Carrtel-hosted infrastructure (n8n, PostgreSQL, and a local Ollama AI model on our own server) — workflow execution, data storage, and a fallback AI model. Handles all data passing through automations. Hosted on our dedicated server (Vultr; primary processing in Canada/North America).

About AI processing: Most automated message text is generated by an AI model. Our primary AI provider is OpenRouter (United States); when it is unavailable we fall back to a self-hosted Ollama model running on Carrtel's own server, which keeps that processing on infrastructure we control. We send AI providers only the minimum content needed to generate a message and do not send them more of your customers' data than necessary.

Cross-border transfers. Several providers operate in the United States, so some personal information is processed there and is subject to US law, which differs from Canadian law and may permit lawful access by US authorities. We reduce this risk by (a) choosing providers with recognized security practices, (b) requiring data-protection commitments in our contracts, and (c) transferring only the minimum necessary data.

We may also disclose information where required by law, to enforce our agreements, to prevent fraud or harm, or in connection with a sale or reorganization of our business (subject to confidentiality).

6. How we protect information

  • Encryption in transit (TLS) and at rest where supported; secrets and API keys held in protected server environment variables, not in source code.
  • Access on a least-privilege basis; authentication on administrative systems; access logging and audit trails.
  • A maintained SMS suppression list that blocks messages to anyone who has opted out.
  • Encrypted backups and documented incident-response procedures.
  • No security is perfect; we cannot guarantee absolute security, but we take commercially reasonable measures appropriate to the sensitivity of the data.

7. Data retention

  • Client account information — term of contract + 1 year (service, support, dispute resolution).
  • Financial / payment records — 6 years (Canada Revenue Agency / Excise Tax Act).
  • Your customers' data processed for automations — term of contract; deleted within 30 days of termination unless you ask for earlier deletion or we must retain it by law.
  • Opt-out / suppression records — retained indefinitely while the number/email is active in our system, so we can keep honouring the opt-out (we must remember who said STOP).
  • Communication / support records — 2 years after last contact.
  • Marketing-consent records (our own marketing) — until consent withdrawn + 2 years (proof of consent under CASL).
  • Server, security and automation logs — up to 12 months.

We securely delete information when it is no longer needed, and can provide a certificate of destruction on client offboarding.

8. Your rights

Subject to legal limits and identity verification, you (and, where applicable, your customers) may:

  • Access the personal information we hold about you;
  • Correct inaccurate or incomplete information;
  • Withdraw consent or request deletion (we may be unable to delete information we must keep by law, e.g., tax records, or opt-out records we must retain to keep honouring a STOP request); and
  • Complain to a regulator (below).

We respond within 30 days. To exercise a right, email support@carrtelsolutions.com with the subject line “Privacy Request.” If you are a customer of one of our clients, we may need to forward your request to that business, since they control that data.

9. Opt-out and unsubscribe (quick reference)

  • Stop our marketing email to you: click unsubscribe in any marketing email.
  • Stop text messages (you or your customers): reply STOP. For help, reply HELP.
  • All other requests: email support@carrtelsolutions.com.

10. Cookies and analytics

Our website uses essential cookies (site function, security) and Google Analytics 4 to understand how visitors use the site (pages viewed, general location, device and referral source). We also use Microsoft Clarity to understand how visitors interact with pages (aggregated heatmaps and anonymized session replays; keystrokes and sensitive inputs are masked by default). Both tools set their own cookies and process this data as our service providers; we do not sell it, and we do not use it to identify you personally. IP addresses are truncated and are not stored by us.

To opt out, you can install Google's official Analytics opt-out browser add-on, block or clear cookies through your browser settings, or use a browser that sends a Global Privacy Control / Do Not Track signal. Blocking analytics cookies does not affect your ability to use the site.

11. Children

Our services are intended for businesses and are not directed to individuals under 18. We do not knowingly collect children's information.

12. Changes

We may update this policy; we will post the revised version with a new “Last Updated” date and, for material changes, notify active clients by email.

13. Complaints / regulators

  • Office of the Privacy Commissioner of Canada — 1-800-282-1376, priv.gc.ca
  • Office of the Information and Privacy Commissioner of Alberta — 1-888-878-4044, oipc.ab.ca

14. Contact us / Privacy Officer

Carrtel Solutions Inc. — Privacy Officer

Email: support@carrtelsolutions.com

Location: Calgary, Alberta, Canada

[Registered office address — to be added]

We aim to acknowledge privacy inquiries within 5 business days.