Legal

Privacy Policy

Last updated: April 2026

HelmarOps is operated by HelmarOps LLC.

This Privacy Policy describes how HelmarOps ("we," "us," or "our") collects, uses, stores, and shares your personal information when you use our website at helmarops.com and our related services (collectively, the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.

Table of Contents

  1. 1. Information We Collect
  2. 2. How We Use Your Information
  3. 3. Data Storage & Security
  4. 4. Third-Party Services
  5. 5. Data Retention
  6. 6. Your Privacy Rights
  7. 7. Cookies
  8. 8. Children's Privacy
  9. 9. Changes to This Policy
  10. 10. Contact Us

1. Information We Collect

We collect the following categories of information:

Account Information

When you create an account, we collect your name, email address, phone number, business name, business address, and profile information. Authentication is handled through our identity provider (Clerk), and we do not store passwords directly.

Business Data

You may input or import business data into the Service, including customer contact information, job records, estimates, invoices, proposals, contracts, notes, and communications history. This data is owned by you and processed by us solely to deliver the Service.

Customer Contact Information

The Service allows you to store contact information for your customers, including names, phone numbers, email addresses, and physical addresses. You are responsible for ensuring you have appropriate consent to store this information.

Call Recordings & Voice Data

If you use our AI Voice Agent or call recording features, we process and store recordings of telephone calls, voicemails, and call transcripts. Call recordings are encrypted at rest and in transit. You are responsible for complying with applicable call recording consent laws in your jurisdiction.

Payment Information

Payment processing is handled entirely by Stripe. We do not store credit card numbers, bank account numbers, or other financial account information on our servers. We receive only transaction confirmations, subscription status, and billing metadata from Stripe.

Usage Analytics

We automatically collect usage data including pages visited, features used, session duration, browser type, device information, IP address, and referral source. This data is used to improve the Service and is not sold to third parties.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, maintain, and improve the Service, including CRM functionality, AI voice agents, invoicing, scheduling, marketing, and all other platform features.
  • AI Processing: To power AI-driven features such as the AI receptionist, AI-generated estimates, email classification, sentiment analysis, and content generation. Your data is processed in isolated sessions and is not used to train third-party AI models.
  • Analytics: To understand how the Service is used, identify trends, and make improvements. We use aggregated, anonymized data for analytics wherever possible.
  • Communications: To send you transactional emails (account confirmations, billing receipts, security alerts), product updates, and, with your consent, marketing communications. You can opt out of marketing communications at any time.
  • Security & Fraud Prevention: To detect, prevent, and respond to security incidents, fraud, and abuse of the Service.
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes.

3. Data Storage & Security

Your data is stored on cloud infrastructure provided by Amazon Web Services (AWS) in the United States. We implement the following security measures:

  • Encryption at rest: All data is encrypted at rest using AES-256 encryption.
  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3.
  • Access controls: We enforce role-based access controls and the principle of least privilege for all system access.
  • Multi-tenant isolation:Each tenant's data is logically isolated. Every database query is scoped to the authenticated tenant.
  • Audit logging: Administrative and security-relevant actions are logged for audit purposes.

4. Third-Party Services

We use the following third-party services to operate the platform. Each service processes data in accordance with its own privacy policy:

ServicePurposeData Shared
ClerkAuthentication & identity managementEmail, name, profile info
StripePayment processing & subscription billingBilling info, transaction data
Twilio / VapiVoice calls, SMS messaging, AI voice agentPhone numbers, call recordings, SMS content
GoogleCalendar integrationCalendar events, availability
AnthropicAI processing (Claude)Prompts, business context (not used for model training)

We do not sell your personal information to any third party. We share data with third-party services only as necessary to provide the Service.

SMS/Text Messaging. With your consent, HelmarOps may send you text messages such as booking links, appointment confirmations, and reminders. Message frequency varies; message and data rates may apply. You can opt out at any time by replying STOP to any message, and reply HELP for help. We do not share or sell mobile opt-in consent or phone numbers to any third parties or affiliates for marketing purposes.

5. Data Retention

  • Active accounts: We retain your account data and business data for as long as your account is active and as needed to provide the Service.
  • Account closure: Upon account closure or termination, we retain your data for 30 days to allow for reactivation or data export. After 30 days, your data is permanently deleted from our systems, including all backups, within 90 days.
  • Call recordings: Call recordings are retained according to your plan settings. You may delete recordings at any time from your dashboard.
  • Legal obligations: We may retain certain data for longer periods as required by applicable law (e.g., tax records, billing history).

6. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose about you.
  • Request deletion of your personal information.
  • Opt out of the sale or sharing of your personal information (we do not sell personal information).
  • Non-discrimination for exercising your privacy rights.
  • Correct inaccurate personal information.
  • Limit the use of sensitive personal information.

Other State Privacy Laws

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws may have similar rights including access, deletion, correction, portability, and the right to opt out of targeted advertising and profiling.

Exercising Your Rights

To exercise any of these rights, contact us at privacy@helmarops.com. We will respond to your request within 45 days. We may need to verify your identity before processing your request.

7. Cookies

We use cookies as follows:

  • Session cookies: We use essential session cookies to maintain your authentication state and provide core functionality. These cookies are strictly necessary for the Service to operate.
  • Preference cookies: We may use cookies to remember your preferences and settings.
  • No third-party tracking cookies: We do not use third-party tracking cookies, advertising cookies, or cross-site tracking technologies.

8. Children's Privacy

The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at privacy@helmarops.com.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (sent to the address associated with your account) and/or by posting a prominent notice on the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

10. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us: