Tellem Privacy Policy
Effective date: June 4, 2026 · Last updated: July 19, 2026
1. Overview
This Privacy Policy explains how Tellem.ai LLC, a New Hampshire limited liability company (“Tellem,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects information in connection with the Tellem back-office automation and customer communication service, including our website, dashboard, APIs, integrations, SMS and email workflows, location-enabled ETA features, support, and related services (collectively, the “Service”).
Tellem helps small service businesses coordinate appointments, route and dispatch field workers, send appointment-related customer updates, manage communication preferences, interpret calendar and job activity, and support related administrative workflows.
This Privacy Policy applies to information about account owners, administrators, and authorized users; end customers of Business Customers; field workers, employees, contractors, and agents whose work-related information may be processed through the Service; and visitors to Tellem websites or dashboards.
2. Our role
For account registration, authentication, support, billing if introduced, service administration, security, legal compliance, website operation, and product improvement, Tellem generally acts as a controller of personal information.
For end-customer data, appointment data, field-worker data, operational communications, calendar data, customer lists, service addresses, job notes, message logs, location pings, and other data submitted, connected, configured, or controlled by a Business Customer (“Customer Data”), Tellem generally acts as a processor or service provider. In that role, we process Customer Data for, and under the instructions of, the Business Customer.
Business Customers are responsible for providing required notices, obtaining required consents or acknowledgments, honoring communication preferences, maintaining lawful contact lists, and ensuring they have the right to submit or connect Customer Data to the Service.
Where a privacy law uses different terms, such as “business,” “service provider,” “controller,” or “processor,” those terms apply as defined by that law.
For Tellem.ai Service Alerts, Tellem separately operates and controls the SMS messaging program. Tellem controls the approved consent language, standardized message templates, sending rules, messaging-hour controls, HELP and STOP processing, and suppression records. Participating Business Customers provide factual appointment and service-status information and present Tellem’s approved consent request. Business Customers do not create, edit, append, or send free-form messages through Tellem.ai Service Alerts.
3. Information we collect and process
3.1. Account, admin, and operator information
We may collect name, email address, phone number, business role, login credentials or authentication identifiers, account identifiers, multi-factor or security information, and related profile information.
We may collect Google OAuth identity and authorization metadata when an authorized user connects Google Calendar or uses Google sign-in.
We may collect business name, business phone number, business address, mailing address, time zone, service areas, messaging hours, service categories, notification settings, trigger configurations, dashboard preferences, subscription or order-form information, and support details.
We may collect consent and acceptance records, including document version, timestamp, IP address, user agent, and related audit information.
3.2. Business configuration and integration information
We may collect calendar connection settings, email configuration, phone-number assignment, messaging provider configuration, OwnTracks or similar tracker configuration, mapping and geocoding settings, workflow rules, trigger logic, webhooks, API tokens, encrypted OAuth tokens, and other settings needed to operate the Service.
We store integration credentials only as needed to operate connected features and apply access controls and encryption where appropriate.
3.3. End-customer information processed for Business Customers
We may process end-customer name, phone number, email address, service address, billing or mailing address if provided, communication preferences, opt-in or opt-out status, appointment date and time, arrival windows, service type, assigned worker, job status, notes, custom fields, SMS and email message content, replies, delivery status, timestamps, and other information the Business Customer chooses to submit or connect to Tellem.
End-customer information is processed to provide the Service to the Business Customer and not for Tellem advertising or sale.
3.4. Field-worker and work-related location information
We may process field-worker name, phone number, role, worker identifier, assigned jobs, route status, work-related messages, and per-worker tracker token or device/app identifier.
When enabled by a Business Customer, we may process GPS or similar location pings, including latitude, longitude, accuracy, battery level, timestamp, and related route or ETA metadata reported by a configured tracking app or device.
The Service is designed to support location processing for the Business Customer’s configured work-related tracking windows and service purposes. Business Customers must configure tracking responsibly, provide clear notice to workers, and obtain consent or acknowledgment where required. Pings outside configured windows should be dropped or excluded where the technical configuration supports that behavior.
Precise geolocation may be treated as sensitive information under certain privacy laws. We process it only for Service-related purposes such as dispatch, ETA support, routing, delay detection, customer updates, safety, fraud prevention, and troubleshooting.
3.5. Messages and communications
We may process SMS, MMS, email, in-app, support, and administrative communications, including message text, sender and recipient information, timestamps, delivery status, failure codes, replies, HELP and STOP requests, suppression records, and related compliance logs.
Messages sent through Tellem.ai Service Alerts are generated from standardized templates created and controlled by Tellem. Business Customers may provide approved factual variables, including the business name, appointment date and time, assigned field worker, job status, arrival window, delay duration, and estimated arrival time. Business Customers may not create, edit, append, or send free-form, marketing, promotional, or unrelated SMS content through Tellem.ai Service Alerts.
3.6. Automatically collected information
We may collect server logs, IP address, browser and device information, user agent, request path, referring page, session information, error logs, diagnostic information, security and abuse-prevention logs, usage events, feature interactions, performance metrics, and cookie or similar technology data if used in the dashboard or website.
We use this information to operate, secure, debug, improve, and protect the Service.
3.7. Information we do not want submitted
The Service is not intended to process protected health information under HIPAA, payment card data, financial account credentials, government identification numbers, biometric identifiers, children’s personal information, criminal-history information, immigration status, or other highly sensitive information unless Tellem has expressly agreed in writing and any legally required supplemental agreement is in place.
Business Customers should not submit sensitive information in free-text notes, message content, calendar titles, or custom fields unless legally authorized and necessary for the Service.
4. How we use information
We use information to provide, operate, maintain, and secure the Service; create and manage accounts; authenticate users; import and interpret calendar, appointment, route, and job activity; send or support appointment-related SMS, MMS, email, or other notifications; calculate, display, or support ETA-related workflows; manage opt-outs, communication preferences, suppression lists, rate limits, and safety controls; provide support and troubleshoot issues; monitor performance; prevent fraud, abuse, and security incidents; maintain records of consent, policy acceptance, communication preferences, and compliance activity; comply with legal obligations and lawful requests; enforce our Terms; and improve the Service using aggregated, de-identified, or business-account usage information.
We do not sell Customer Data. We do not use Customer Data for targeted advertising. We do not use end-customer or field-worker data to train generalized or third-party AI models. If Tellem later offers AI-assisted features, Customer Data will be used only to provide those features to the relevant Business Customer unless we obtain the rights and consents required for any broader use.
5. Tellem.ai Service Alerts
Tellem.ai LLC operates Tellem.ai Service Alerts, an informational SMS program for scheduled service appointments. Messages are sent through a Tellem-controlled toll-free number. The service business associated with an appointment is identified to provide context for the recipient’s scheduled service visit.
Messages are limited to appointment confirmations, reminders, schedule changes, arrival windows, estimated-arrival updates, running-late notices, on-the-way alerts, arrival notices, job-complete notices, and directly related customer-care communications.
Tellem.ai Service Alerts is not used for marketing, advertising, promotional offers, solicitations, fundraising, lead generation, cross-selling, or upselling.
Before messaging begins, the recipient must affirmatively consent to receive Tellem.ai Service Alerts concerning a scheduled appointment. Tellem defines and manages the approved consent methods and disclosures and maintains the resulting consent and suppression records. Providing a mobile number, booking an appointment, or agreeing to receive general service communications does not by itself constitute consent to receive SMS messages from Tellem.
Recipients may reply STOP to opt out of all messages from the toll-free number that sent the message. Tellem prevents further messages from that number unless the recipient subsequently completes a supported opt-in process.
Text messaging originator opt-in data and consent will not be shared with any third parties. Tellem does not sell, rent, or use mobile numbers, SMS opt-in data, or SMS consent records for marketing or promotional purposes.
6. Google Calendar and Google API data
If a Business Customer or authorized user connects Google Calendar or another Google API, Tellem accesses and processes Google user data only as necessary to provide the requested integration and Service functionality, such as importing calendar events, interpreting appointment information, detecting schedule changes, and supporting customer communication workflows.
Tellem’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data, use it for targeted advertising, use it to train generalized AI models, or transfer it except as needed to provide or secure the Service, comply with law, or as otherwise permitted by Google’s policies and authorized by the Business Customer or user.
7. Field-worker location data
Tellem may process field-worker location data to support dispatch coordination, route awareness, arrival estimates, delay detection, customer notifications, worker safety, fraud prevention, troubleshooting, and related operational workflows.
Business Customers are responsible for providing clear written notice to field workers before location tracking is used; explaining what location data is collected, when tracking occurs, why tracking is used, who can access location information, how long it is retained, and how tracking can be disabled or limited when off duty where applicable; obtaining consent, acknowledgment, or authorization where required; limiting tracking to legitimate business purposes; configuring reasonable tracking windows; avoiding unnecessary collection outside working time; responding to worker questions and requests; and complying with employment, contractor, privacy, consumer-protection, and location-tracking laws.
Field workers may be able to disable tracking through their device or tracking app. Disabling tracking may affect the Business Customer’s ability to use ETA, dispatch, or customer update features.
8. How we disclose information
We disclose information to service providers, subprocessors, and integration providers that help us operate the Service. These providers may process information only as needed to provide services to us or to the Business Customer and are expected to protect information under written terms.
Current or expected subprocessors and infrastructure providers include:
Notwithstanding any other provision of this Privacy Policy, text messaging originator opt-in data and consent are excluded from the disclosures described in this section and will not be shared with any third parties.
| Sub-processor | Purpose |
|---|---|
| Supabase | Database, authentication, and storage hosting |
| SMS messaging providers | Toll-free-number services, SMS delivery, inbound-message processing, delivery status, and messaging-compliance support |
| Resend | Transactional email delivery |
| Mapbox | Address autocomplete, mapping, geocoding, and ETA-related services |
| Calendar import when a Business Customer connects Google Calendar | |
| Vercel | Web dashboard hosting |
| Railway | API and background worker hosting |
We may also disclose information to comply with law, legal process, subpoenas, court orders, or government requests; investigate fraud, abuse, security incidents, or illegal activity; protect the rights, safety, and property of Tellem, users, customers, workers, or others; professional advisors such as attorneys, accountants, auditors, insurers, or consultants; in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets; with the Business Customer’s direction or consent; or as otherwise described in this Privacy Policy.
If we add material new subprocessors that process personal information, we will update this Privacy Policy or provide notice through another appropriate mechanism where required.
9. Cookies and similar technologies
Tellem websites or dashboards may use cookies, local storage, pixels, or similar technologies for authentication, session management, security, preferences, analytics, performance, and debugging.
If Tellem later uses non-essential cookies for advertising or cross-context tracking, we will update this Privacy Policy and provide any required choices before doing so.
10. Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, contract, security needs, backup practices, dispute resolution, audit, fraud prevention, or compliance obligations.
Current retention practices are expected to include:
- Account profile, business configuration, and message logs: for the life of the account plus approximately 30 days after deletion unless a longer period is required.
- Field-worker GPS pings: for the number of days configured by the Business Customer, with a default of 30 days and configurable limits from 1 to 365 days.
- Consent, policy acceptance, communication preference, suppression, and opt-out records: for the life of the account and for a reasonable audit/compliance period afterward.
- Server and security logs: for up to 90 days unless needed longer for security, fraud prevention, debugging, or legal purposes.
- Backups: deleted or overwritten according to ordinary backup cycles.
Business Customers may request account deletion or export by contacting support@tellem.ai. Deletion from backups may occur on the ordinary backup lifecycle.
11. Privacy rights and requests
Depending on where an individual lives and the role in which the individual interacts with Tellem, privacy rights may include the right to confirm whether personal information is being processed; access personal information; correct inaccurate personal information; delete personal information; obtain a portable copy of personal information; opt out of sale, targeted advertising, or certain profiling; revoke consent; and appeal a denied privacy request.
Tellem does not sell personal information or process personal information for targeted advertising. If that changes, we will update this Privacy Policy and provide any legally required opt-out mechanism before such processing begins.
Account owners and administrators may contact support@tellem.ai to exercise applicable rights. End customers and field workers should generally contact the Business Customer that scheduled the service, employed or contracted the worker, or configured the Tellem account. If an end customer or field worker contacts Tellem directly, we may refer the request to the relevant Business Customer or assist the Business Customer in responding.
When Tellem acts as a controller and a privacy law applies, we will respond to verified privacy requests as required by law. For New Hampshire consumers, when the New Hampshire Data Privacy Act applies, controllers generally must respond without undue delay and not later than 45 days after receipt, subject to a 45-day extension when reasonably necessary, and must provide appeal instructions when declining a request. We will provide an appeal process where required and respond to appeals within the legally required period.
We may need to authenticate the requester before fulfilling access, correction, deletion, or portability requests. We will not require a consumer to create a new account solely to exercise privacy rights, but we may require use of an existing account where permitted by law.
12. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information. These measures may include encryption in transit using TLS; database encryption at rest through hosting providers; additional encryption for certain sensitive integration tokens; access controls and role-based restrictions; account-isolation controls; production access limited to authorized personnel; logging, monitoring, rate limiting, and abuse-prevention controls; secure development and deployment practices; and periodic review of security controls.
No system is perfectly secure. We cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur. Business Customers are responsible for maintaining appropriate security controls for their own systems, devices, user accounts, passwords, integrations, employee access, and business processes.
13. Security incidents and breach notification
If Tellem becomes aware of a security incident involving personal information, we will investigate and take steps we determine appropriate under the circumstances.
If a security incident affects Customer Data that we process on behalf of a Business Customer, we will notify and cooperate with the Business Customer as required by law and contract. If Tellem is legally responsible for notifying individuals, regulators, attorneys general, consumer reporting agencies, or other parties, we will provide required notices in accordance with applicable law.
Business Customers remain responsible for determining and making legally required notices for incidents involving Customer Data unless law places that obligation directly on Tellem.
14. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Business Customers should not submit children’s personal information to the Service unless they have the legal right to do so and have obtained any required parental consent.
If we learn that we have collected personal information from a child under 13 without required consent, we will take appropriate steps to delete or restrict that information.
15. De-identified and aggregated information
We may use aggregated or de-identified information to operate, analyze, and improve the Service. We will not attempt to re-identify de-identified information except as permitted by law, such as to test whether de-identification measures are effective.
Where required, we will take reasonable measures to ensure de-identified data cannot reasonably be associated with an individual and will contractually require recipients to maintain the data in de-identified form.
16. International processing
Tellem and its service providers may process information in the United States and other locations where our service providers operate. By using the Service, Business Customers understand that information may be processed outside the state, province, or country where it was collected.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will provide notice through the Service, by email, by posting an updated policy, or by another reasonable method. We may require account owners or administrators to accept the updated policy before continuing to use the Service.
The “Last updated” date identifies the most recent update.
18. Contact
Questions or privacy requests may be sent to:
Tellem Privacy TeamTellem.ai LLC
14 Littleworth Rd
Dover, NH 03820
Email: support@tellem.ai
Phone: (845) 377-6588
