Privacy Policy
- Effective
- August 12, 2026
- Last updated
- August 12, 2026
- Version
- v0.1 (working draft)
This policy explains what information Poof collects, why we process it, who we share it with, and how you can control it. Poof does not record or store call audio or video by default.
“Download as PDF” opens your print dialog — choose “Save as PDF”.
01Account and profile information
When you create an account we collect your name, email address, and authentication details. If you sign in with Google, we receive your basic profile and email from that provider; we never receive your password.
You may add optional profile details such as a photo, time zone, and display preferences.
02Provider profile and business information
Providers additionally give us a public profile (display name, headline, bio, avatar, booking slug), service configuration (call lengths, availability, access rules, credit rules), and, where selling is enabled, the business and identity details Stripe requires for payouts.
03Booking and transaction data
We store bookings, their status, the Provider and Client involved, any topic or note you provide, and the credit ledger that records when a Poof was issued, reserved, consumed, returned, or expired. This is what lets balances and history stay accurate.
04Call metadata
For each call we may process technical metadata: who the participants were, the start time, the end time, the duration, how the call ended, and basic connection quality signals.
Poof does not record or store call audio or video by default and does not transcribe calls. Live audio and video pass between participants for the length of the call.
05Device, security, and diagnostic data
We process IP address, browser and device type, operating system, approximate location derived from IP, timestamps, and error or diagnostic logs. We use this to keep accounts secure, prevent abuse, and fix problems.
06Payment information
Stripe processes payment credentials. Card numbers and bank details go directly to Stripe and are not stored on Poof's systems. We keep limited records such as the amount, currency, status, last four digits, and Stripe identifiers so we can show receipts and support your account.
08Why we process each category
- Account and profile data — to create your account, authenticate you, and show you to the people you book with.
- Provider and business data — to publish profiles, run booking rules, and enable payouts.
- Booking, credit, and transaction data — to deliver the service you paid for or were granted, and to keep balances correct.
- Call metadata — to run and end calls on time, show history, and troubleshoot quality issues.
- Device, security, and diagnostic data — to protect accounts, detect abuse, and maintain the platform.
- Payment data — to take payment, issue refunds, and meet financial record-keeping duties.
09Service providers and subprocessors
We share data with vendors who help us run Poof, under contracts that limit what they can do with it. Current categories:
- Cloud hosting and application delivery.
- Database, authentication, and file storage (Supabase infrastructure operated through Lovable Cloud).
- Payment processing (Stripe).
- Email delivery for transactional messages.
- Real-time audio and video transport for the call room.
Current subprocessor list: [SUBPROCESSOR LIST PLACEHOLDER]. We do not sell personal information.
10Data retention
We keep account and booking records for as long as your account is active and afterwards only as long as needed for legal, tax, accounting, dispute, and security purposes. Diagnostic logs are kept for a short period. Specific retention periods: [RETENTION SCHEDULE PLACEHOLDER].
11Account deletion
You can ask us to delete your account by writing to legal@poofcall.com. We will delete or anonymize your personal data except where we must keep records — for example financial transactions — and except for the aggregated data that no longer identifies you. Deleting an account forfeits any remaining Poofs.
12Data security
We use encryption in transit, row-level access controls on our database, scoped credentials, and least-privilege server access. No system can be guaranteed completely secure, so we do not promise absolute security. Tell us immediately if you suspect a problem with your account.
13Health information and HIPAA
Poof is not currently represented as HIPAA compliant.
Do not submit protected health information through Poof and do not use Poof for HIPAA-regulated care unless Poof has expressly entered into the required written agreements with you, including a business associate agreement.
14Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing.
To exercise a right, email legal@poofcall.com. We may need to verify your identity first. You also have the right to complain to your local data-protection authority.
15International data transfers
Poof and its vendors may process data in countries other than your own. Transfer mechanism and safeguards: [INTERNATIONAL TRANSFER MECHANISM PLACEHOLDER].
16Children's privacy
Poof is for adults aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has given us data, contact legal@poofcall.com and we will remove it.
17Changes to this policy
We may update this policy. We will change the “last updated” date and give notice in the product for material changes.
18Contact
Privacy questions and requests: legal@poofcall.com. Data controller: [CONTROLLER ENTITY PLACEHOLDER].
Contact
Questions about this document? Email legal@poofcall.com.
