Legal
Privacy Policy
This policy explains what Opps Cloud (“Opps Cloud”, “we”, “us”) collects, why, how long we keep it, and what you can ask us to do with it. It covers:
- the website at opps.cloud, including its contact form, chat and voice assistant;
- the Opps Cloud platform — hosted AI back-office agents and the customer portal we run for businesses that subscribe to us; and
- Opps Cloud Desk, our help-desk application for HighLevel (GoHighLevel) sub-accounts.
The short version
- We do not sell personal information, and we do not share it with advertisers.
- We do not run third-party advertising trackers on opps.cloud.
- We collect what you give us (forms, chat, tickets, email) and what our customers connect to us (their CRM data) in order to provide the service — nothing else.
- Customer data belongs to the customer. We process it on their instructions and delete it when they ask or when they leave.
- Ask us anything about your data at hello@opps.cloud.
1. Website visitors
Contact and demo forms. We store what you type: name, email, phone, company, and your message, plus the page and time of submission. It is delivered to our team through our own automation server and stored in our CRM so we can reply.
Chat and voice assistant. Conversations with the assistant on opps.cloud are transcribed and stored so we can follow up and improve the assistant. Voice calls are processed by our voice provider; text is processed by our AI provider (see “Who processes data”). Do not share payment card numbers or passwords with the assistant.
Server logs. Our web server records IP address, user agent, requested page and time, kept for up to 30 days for security and troubleshooting.
Cookies. opps.cloud sets no marketing or analytics cookies. The platform and Desk use strictly necessary cookies for sign-in and session security only.
2. Platform customers and their data
When a business subscribes to Opps Cloud, we create an account for its staff (name, email, role) and run one or more AI agents on its behalf. Those agents may be connected, at the customer’s request, to the customer’s email, calendar, phone system, CRM, help desk, or other tools. Data that flows through those connections — messages, contacts, appointments, tickets, documents — is customer data. We process it only to provide the service the customer configured, and we treat the customer as the controller of that data.
Agent memory: agents keep a working memory of the customer’s business (preferences, prior conversations, facts the customer tells them) so they can act consistently. This memory is per-customer, isolated from other customers, and deleted with the account.
3. Opps Cloud Desk for HighLevel
When a HighLevel sub-account installs Opps Cloud Desk, HighLevel grants us an access token scoped to that sub-account. Using it we access, in order to run the help desk:
- Contacts and companies — name, email, phone, company, tags, custom fields — so tickets can be linked to the right person. We keep a synchronized copy of these records for the installed sub-account.
- Users — staff name, email and role — to sign staff into the Desk and assign tickets. Staff are signed in through HighLevel’s own single sign-on; we do not store HighLevel passwords.
- Conversations, opportunities, custom fields and tags — read and written only to link ticket activity back to the contact (for example adding a note or a
desk:opentag), so the customer’s own HighLevel automations can react.
We do not use HighLevel data for any purpose other than operating the Desk for that sub-account. We do not sell it, share it across customers, or use it to train AI models. Uninstalling the app revokes our token immediately; the sub-account’s tickets and synchronized records are deleted within 30 days of a written request, or automatically 90 days after uninstall.
Ticket content. Tickets contain whatever end-customers and staff write, including emails forwarded to a support address, web-form submissions, chat transcripts, attachments and internal notes. That content is stored in our database and file storage, encrypted at rest, and is visible only to the installing sub-account’s staff and to the end-customer it belongs to (through the customer portal).
4. AI processing
Parts of the service use large language models (for example to draft replies, summarize tickets, or power the assistant). Content sent to an AI provider is used only to produce the response and is subject to that provider’s terms, which prohibit training on our API traffic. We do not train our own models on customer data.
5. Who processes data (subprocessors)
| Provider | Purpose | Location |
|---|---|---|
| Hostinger | Virtual servers that run the platform, agents and automation | United States |
| Supabase | Database, authentication and file storage for the Desk and portal | United States (us-east-1) |
| Cloudflare | DNS, TLS and edge protection | Global |
| HighLevel (GoHighLevel) | CRM platform the Desk integrates with, on the customer’s instruction | United States |
| Anthropic / OpenAI | AI language models | United States |
| Vapi | Voice assistant on opps.cloud | United States |
| Zoho Mail / customer mail providers | Sending and receiving support email on the customer’s domain | United States |
| Stripe | Subscription billing (card details never touch our servers) | United States |
6. Retention
- Website form and chat submissions: until you ask us to delete them, or 24 months after last contact.
- Customer accounts and customer data: for the life of the subscription, then deleted within 30 days of a written request or automatically 90 days after termination. Backups roll off within a further 30 days.
- Server and security logs: up to 30 days.
- Billing records: as long as tax law requires.
7. Your rights
You can ask us to tell you what we hold about you, correct it, export it, or delete it. If your data is held because you are a customer of one of our customers (for example you emailed their support desk), we will pass your request to them and help them fulfil it. California residents have these rights under the CCPA/CPRA; we do not sell or share personal information as those laws define it. Write to hello@opps.cloud and we will respond within 30 days.
8. Security
Data is encrypted in transit (TLS) and at rest. Access tokens and credentials are stored encrypted and never exposed to browsers. Each customer’s data is isolated by tenant at the database level. Staff access to production is limited to the people who operate the service and is logged. If we become aware of a breach affecting your data we will notify affected customers without undue delay.
9. Children
Our services are for businesses and are not directed at children under 16. We do not knowingly collect their data.
10. Changes
We will post changes here with a new “last updated” date and, for material changes affecting customers, notify account owners by email.
11. Contact
Opps Cloud · Lincoln, California, USA · hello@opps.cloud