Privacy Policy
We collect what we need to run the product. We keep it tenant-isolated. We don't sell it. We delete it when you ask.
1. Who we are.
Customer Service Pro ("we," "us," "our") is the AI customer-service infrastructure operated by Michael Neubauer, a sole proprietor doing business as Customer Service Pro, based in Syracuse, New York, United States. This Privacy Policy covers personal information collected from visitors to customerserviceprofessional.com and from customers using the service.
Data Protection contact: Michael Neubauer, Founder and acting DPO. Reach him through the contact form (preferred — every legal request is tracked) or directly at michael@customerserviceprofessional.com.
2. What we collect.
From website visitors.
- Cookies: the marketing website sets no analytics or tracking cookies and shows no cookie banner. See section 5.
- Form submissions: when you book a demo, request press materials, or send us email through a contact link, we receive the information you provide.
From customers and their end users.
- Account data: business email, name, role, company, and billing information for the account holder.
- Operational data: messages exchanged through Aria, knowledge base documents you upload, integration credentials you authorize (e.g., HubSpot OAuth tokens), and configuration settings.
- Telemetry: response latency, resolution outcomes, error logs, and audit trails for security and reliability monitoring.
3. How we use information.
- To run Aria on your behalf: route messages, look up knowledge, take actions in connected tools, and produce responses.
- To bill you, support you, and communicate operationally (incident notices, scheduled maintenance, contract changes).
- To detect abuse and protect the platform's integrity (rate limiting, anomaly detection, secret scanning).
- To improve the product in aggregate. We do not train foundation models on your customer messages. Period.
- To follow up with prospective customers: if you voluntarily submit your email through the site (for example, to receive a copy of a configuration you built with the demo), we use it to send what you asked for and to follow up about the product. This is separate from the SMS consent described in Section 6 and does not add you to any marketing sequence.
4. PII handling and redaction.
Customer messages pass through a PII redaction pipeline before any transcript is persisted to a ticket, handed to your team, or written to an audit log. The pipeline matches: US social security numbers written in the usual 3-2-4 grouping, payment card numbers, AWS access keys, Stripe live and test keys, GitHub tokens, and generic high-entropy secrets. Matched values are replaced with [REDACTED]. Redaction runs on the way in, before the message reaches the model or the session transcript, so the original is not retained anywhere — the redacted version is the only one that exists downstream. Emails and phone numbers are kept in tickets so your team can act on them, and stripped from audit logs.
5. Cookies.
The marketing website (customerserviceprofessional.com) sets no analytics or tracking cookies and shows no cookie banner — there is nothing to consent to. The operator app uses a single essential session cookie so signed-in users stay logged in. We use no third-party advertising, analytics, or tracking cookies anywhere.
6. SMS messaging and consent.
When a partner brand deploys Aria with SMS enabled, end customers may receive text messages from the partner's dedicated Twilio number. SMS is used for transactional purposes only: order updates, scheduling confirmations, refund acknowledgments, support follow-ups, and ticket-resolution notifications. We do not send marketing or promotional SMS.
Customer Service Pro's own messaging. Customer Service Pro (Michael Neubauer, a sole proprietor doing business as Customer Service Pro, based in Syracuse, New York) also sends its own text messages. If you contact Customer Service Pro directly — for example, through the live chat or contact form on customerserviceprofessional.com — and you provide your mobile number and check the SMS-consent box, Customer Service Pro may text you to follow up on your specific support or sales request: answering your question, sending an update on an open request, confirming a scheduled call, or checking in when a question was left unresolved. These messages are transactional and conversational; we send no marketing or promotional SMS. We collect your number directly from you at the moment you request follow-up — we never buy, rent, sell, or share your mobile number, and we never text anyone who did not contact us first. The consent, STOP/HELP, frequency, carrier-disclosure, and phone-number-handling terms in the rest of this section apply to these messages in full. The full opt-in record — the exact disclosure shown beside the checkbox, where it appears, and every opt-out keyword — is published at SMS Consent & Opt-In.
Consent. End customers must opt in through the partner brand's signup, support form, or account portal before any SMS is sent. Consent is logged with a timestamp and source in the partner's CRM (HubSpot). No SMS is sent to a phone number that has not affirmatively opted in.
STOP and HELP. Reply STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, or QUIT at any time to opt out. Our system signature-verifies the inbound message and immediately flips the corresponding CRM contact's cs_pro_sms_opt_out flag to true; no further SMS will be sent to that number. Reply HELP to receive help information.
Frequency. Message frequency varies by partner brand and customer-thread activity. Most customers receive between zero and four SMS messages per support thread.
Carrier disclosures. Msg & data rates may apply. Message and data charges from your wireless carrier are your responsibility. We are not liable for delays, undelivered messages, or carrier-side throttling.
Phone number handling. Phone numbers are stored under partner-tenant isolation (see Security Overview) and used only within the conversation thread that originated the contact. Phone numbers are never sold, never shared with third-party marketers, and never reused across partner tenants.
7. Third-party processors.
To deliver the service, we share data with the following processors. Each is used under the data-processing terms published in its own standard customer agreement. We have not yet executed separate negotiated Data Processing Agreements with these providers, and we will do so before processing any customer data on behalf of a business that requires one — ask us for the current status before you sign.
- Anthropic — AI model inference and prompt caching.
- OpenAI — tenant-isolated vector stores for knowledge-base retrieval, and provider health checks. Model inference no longer runs on this provider.
- Fly.io — application compute. Tenants share one application; isolation is logical, enforced in the data layer.
- Supabase — managed Postgres database for tenant data, with at-rest encryption and row-level security scoping every query to the authenticated tenant.
- Redis — rate-limit counters, session locks, and delivery idempotency keys. Holds IP addresses and session identifiers, not conversation content.
- Sentry — application error monitoring. Receives error stack traces; customer conversation content is not sent.
- Twilio, Stripe, HubSpot, Slack, Gmail, Google Sheets, Calendly, Zendesk — invoked only on your behalf, only with credentials you explicitly authorize. This also covers any additional helpdesk/CRM integration you connect through the operator dashboard (Front, Gorgias, Salesforce, Kustomer, Jira Service Management, ServiceNow, Help Scout, Intercom, Freshdesk, Zoho, Pipedrive) — each is invoked only with the credentials you provide for that connection.
- Cloudflare — edge/CDN, Workers, and marketing website delivery, plus contact-form intake via a Worker that forwards to Resend for transactional email. No customer-deployment data passes through Cloudflare; only the marketing site and inbound contact-form submissions.
- Resend — transactional email delivery for contact-form and configurator-capture intake. Receives the submitted payload (name/email/company/topic/message for the contact form; email/agent name/company/industry/tone for the configurator capture) and our team's recipient address only.
Full processor list with subprocessors available on request. We will give you 30 days' notice before adding a new subprocessor.
8. Data retention.
Conversation history is retained for the window your plan includes, then permanently deleted: 30 days on trial, 180 on Starter, 365 on Growth, three years on Scale, seven years on Enterprise. Your current window is shown in the operator app under Settings → Account. Deletion is enforced nightly rather than on request — transcripts past the window are removed along with everything mirrored off them. Knowledge base documents are retained until you delete them through the admin UI or API. Audit logs are retained 12 months for security investigations. Their contents are redacted when the record is written, not a year later — emails, phone numbers, card numbers, government identifiers, and secrets are stripped before the row is stored. The records are then append-only and hash-chained, so they cannot be rewritten afterwards without breaking the chain that makes them worth keeping. On contract termination you can export everything in standard formats (JSON, CSV) within the 90-day window.
9. Your rights.
- Access: request a copy of personal data we hold about you.
- Correction: ask us to fix inaccurate information.
- Deletion: request erasure, subject to legal obligations that may require retention.
- Portability: receive your data in a machine-readable format.
- Objection / restriction: ask us to limit how we process your data.
- Withdrawal of consent: for processing based on consent, withdraw at any time without affecting the legality of prior processing.
Send rights requests through our contact form. We respond within 30 days.
Your California privacy rights (CCPA/CPRA).
If you are a California resident, you may request to access the personal information we hold about you, request its deletion, or opt out of the "sale" or "sharing" of personal information. Customer Service Pro does not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use personal information for cross-context behavioral advertising. To exercise any of these rights, email hello@customerserviceprofessional.com or michael@customerserviceprofessional.com. Verified deletion requests are honored through our data-subject erasure process, and we will not discriminate against you for exercising these rights.
10. Security.
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Tenant isolation is structural: each tenant's knowledge base, configuration, and messages are namespaced and verified at the file resolution layer. Detailed security posture is in our Security Overview.
11. International transfers.
Today our infrastructure runs in the United States (Fly.io application compute and Supabase Postgres). If you require EU residency or other regional pinning under GDPR Article 28, we add it on contract (enterprise setup, approximately two weeks). Standard Contractual Clauses apply to transfers outside the originating region.
12. Changes to this policy.
Material changes are emailed to account holders 30 days before they take effect. The current version and effective date are always shown at the top of this page.
13. Contact.
Questions about this policy or how we handle your data: reach us through the contact form.