Privacy Policy
Last updated: August 25, 2026
This policy describes how Verata Group, LLC (“Verata,” “we,” “us”) collects and uses information through our website (veratagroup.com) and our AI receptionist service.
Information we collect
- Website leads. When you submit our demo or contact form, we collect the details you provide: name, company, email, phone number, trade, and your message.
- Calls and chats handled by the Service. When our AI receptionist answers on behalf of a client business, it may collect the caller's name, contact details, service address, a description of the requested work, and recordings/transcripts of the conversation. This information is collected for, and shared with, the business the caller contacted.
- Website usage. Basic analytics (pages visited, device type, approximate location) collected via cookies or similar technologies when analytics are enabled.
How we use it
- To respond to demo requests and operate the sales process you initiated.
- To provide the receptionist service: answering, booking appointments, taking messages, and delivering leads to the client business.
- To improve service quality, including reviewing recordings and transcripts for accuracy.
- To meet legal obligations.
We do not sell personal information.
AI interactions
Conversations with our receptionists are processed by artificial intelligence. Receptionists identify themselves as automated. See our AI & Call Recording Disclosure for how recording notice and consent are handled.
Google Calendar data
A client business may connect its Google Calendar so the receptionist can place appointment holds. This is optional, and it only ever happens after the business owner grants access on Google's own consent screen. We request two scopes and use them narrowly:
- Availability (
calendar.freebusy). Before proposing a time, we ask Google whether one specific window is free on the business's primary calendar. We receive busy/free time blocks only — never event titles, descriptions, guests, locations, or attachments. - Events (
calendar.events.owned). If the window is free, we create one provisional event titled “HOLD — …” for the team to confirm. We never edit, move, or delete an event we did not create, and a busy window is always a refusal to book, never something written over. This scope is limited to calendars the business owns; we do not request access to calendars merely shared with them.
What we store. Only the access credential Google issues, so the receptionist can place a hold later without asking the owner to sign in again. We do not store the contents of anyone's calendar: availability answers are used in the moment and discarded, and we keep no copy of the holds we create.
What we never do. Google Calendar data is not sold, not shared with anyone other than the business whose calendar it is, not used for advertising, and never sent to an AI or machine-learning model — we do not use it to develop, improve, or train generalized AI/ML models. No person at Verata reads it except where required for security or by law, or with the business's explicit permission.
Disconnecting. A business can revoke access at any time from its Google Account permissions page, or by emailing support@veratagroup.com. We delete the stored credential on request, and the receptionist stops placing holds.
Verata's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Text messages (SMS)
Verata sends text messages from its own registered business number. We text only numbers given to us for that purpose — we never message numbers obtained from purchased, rented, or scraped lists. There are two cases, and consent for each is obtained separately:
- Operational alerts to a client business. Optional, and separate from signing up. A business that wants them opts in itself — at veratagroup.com/sms-alerts, or through the optional SMS field at checkout — and gives us the mobile number it wants alerts sent to. Consent to receive texts is never required to buy or use the Service, and declining changes nothing else about it. The alerts are transactional notices about activity on the business's own lines, for example that its receptionist flagged a possible emergency on a call or chat. They are never marketing.
- Messages to a client's customers. Where a client has enabled follow-up messaging, we send appointment and follow-up texts on that client's behalf, relating only to the service request the person initiated with that business. The client is responsible for obtaining prior express consent from its customers before those numbers are messaged.
We do not sell or share mobile information. Mobile phone numbers, SMS opt-in information, and consent are not sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Mobile information is disclosed only to the service providers who help us deliver the messages (for example our telephony provider), which may not use it for their own purposes, and to the client business a message was sent on behalf of.
Opting out. Reply STOP to any message to stop receiving texts from us. We also honor plain-language requests such as “please stop texting me.” Reply HELP, or email support@veratagroup.com, for help. Message frequency varies. Message and data rates may apply.
Opt-outs are permanent and are checked before every message we send. We do not operate an automatic re-subscribe keyword: if you opt out and later want messages again, contact us at support@veratagroup.com.
Sharing
Caller information collected by a receptionist is shared with the client business it serves — that's the product. We also use service providers (hosting, telephony, scheduling, CRM) that process data on our behalf under contractual confidentiality obligations. We may disclose information if required by law.
Security
We protect the information described above with technical and organizational safeguards matched to how sensitive it is. In plain terms: it travels encrypted, the credentials we hold are encrypted where they are stored, and we try not to hold anything we do not need.
In transit. Every connection to our website and to our service endpoints is encrypted with TLS (HTTPS), on certificates that are issued and renewed automatically. The calls we make to the providers who process data on our behalf are encrypted in the same way.
At rest. Credentials are encrypted before they are written to storage. In particular, the Google OAuth token a business gives us when it connects its calendar — the only Google artifact we store at all — is encrypted using authenticated symmetric encryption (AES with an integrity check, so a tampered value fails rather than being used). The encryption key is held in the service's environment configuration, separately from the database, and is never committed to source control. If that key is unavailable the application refuses to store the credential at all rather than falling back to storing it unprotected.
Access. The service runs on a dedicated server under an isolated system account, and the datastore is readable only by that account. It is not exposed through any public interface. Access by a person is limited to authorized Verata personnel and happens only where required to operate or secure the service, where required by law, or with the client business's explicit permission.
Holding less. The most reliable protection is not keeping the data. We store no Google Calendar content of any kind — availability answers are used in the moment and discarded, and we keep no copy of the holds we create. Web chat conversations are held only until the summary has been delivered to the business, and the record is then deleted. We do not retain the caller's side of a phone conversation, except for a short, length-limited excerpt kept only when the receptionist flagged a possible emergency, so that those detections can be reviewed for accuracy.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a security problem affecting this service, please tell us at support@veratagroup.com and we will investigate.
Retention
Website lead information is kept for as long as needed to manage the relationship. Call recordings and transcripts are retained according to each client's configuration and applicable law, and are deleted or returned when a client relationship ends. Client businesses own their data.
Your choices and rights
You may request access to, correction of, or deletion of your personal information by emailing support@veratagroup.com. If you are a caller whose conversation was handled by our receptionist on behalf of a business, we may direct your request to that business, which controls the data. Depending on your state, you may have additional rights under state privacy law.
Contact
Verata Group, LLC · support@veratagroup.com · 212 N 2nd Street, STE 100, Richmond, KY 40475