Parea SMS — Privacy Policy (DRAFT)
This policy explains what Olaes Technology Group Corp, d/b/a Parea SMS ("Parea") collects, why, and your choices. It covers our customers ("Customers" — the businesses using Parea) and the people they message ("Recipients"). For Recipient data, the Customer is the data controller and Parea is a processor acting on their instructions.
1. What we collect
From Customers:
- Account & identity: name, cell number (used for passwordless sign-in), email, SSO identifiers (Google / Microsoft — when you sign in with an identity provider we receive your name and email address from that provider; we never receive or store your password), workspace and member roles.
- Device data for notifications: if you enable notifications in the iOS app, Apple issues a device push token that we store to deliver alerts to your device; it identifies the device installation, not your location or contacts.
- Business/compliance data for carrier registration: legal entity name, EIN, address, authorized representative, website, campaign descriptions, opt-in-flow evidence. This data is shared with our carrier partners, The Campaign Registry (TCR), and downstream carriers as required for A2P sender registration.
- Billing: plan, usage metering; card details are held by our payment processor (Stripe) — Parea never stores full card numbers.
- Product telemetry: feature usage, log and device data, support communications.
From Customers about Recipients (processed on the Customer's behalf):
- Contact records: phone numbers, names, tags, custom fields the Customer adds.
- Message content: SMS/MMS text and media, group-thread membership, delivery metadata, call-forwarding events, opt-in/opt-out records.
2. How we use it
- Provide the Services: transmit messages via carriers, maintain threads and inboxes, provision/port numbers, forward calls, process opt-outs, meter billing.
- AI features: message content and the Customer's approved knowledge base are processed by our AI subprocessor to generate suggested replies, classifications, summaries, and (when the Customer enables it) automated replies. AI outputs are logged with their sources for audit. Our subprocessor agreements do not permit use of this content to train their foundation models [CONFIRM at signing].
- Compliance: register senders (10DLC/toll-free), detect spam/abuse, honor legal obligations.
- Improve and secure the Services (aggregated/de-identified analytics).
We do not sell personal information, and we do not share it for cross-context behavioral advertising. Recipient opt-in data and consent records are used only to provide the Services to the relevant Customer and are not shared with third parties for their own marketing — consistent with carrier registration requirements.
3. Who we share it with (subprocessors)
| Provider | Purpose |
|---|---|
| Twilio (and its carrier network) | Message transmission, numbers, voice forwarding, verification, A2P registration |
| The Campaign Registry & mobile carriers | Sender/campaign registration and vetting |
| Anthropic | AI processing (drafts, classification, summaries) |
| Stripe | Payments |
| Supabase / hosting providers | Database and infrastructure |
| Vercel / error & log tooling | Application delivery, diagnostics |
| Apple (APNs) | Push-notification delivery to iOS devices |
Plus: professional advisors, and authorities where legally required (we notify Customers of legal demands unless prohibited). A current subprocessor list is published at [link]; we provide notice before adding subprocessors that process message content.
4. Retention
- Messages & threads: retained while the workspace is active; deleted [90] days after account closure (export window: 30 days).
- Consent and opt-out records: retained at least [5] years — these are the Customer's legal evidence; suppression lists persist even after contact deletion so opt-outs stay honored.
- Carrier registration records: as required by carrier/TCR rules.
- AI audit logs (
ai_events): retained with message records. - Billing records: per tax law.
5. Security
Encryption in transit (TLS) and at rest; workspace-scoped isolation with row-level security; least-privilege access with audit logging; passwordless authentication; API keys stored hashed; webhook payloads signed.
On-device biometrics. The iOS app offers an optional Face ID / Touch ID lock. Biometric authentication is performed entirely on your device by Apple's operating system; Parea never receives, stores, transmits, or has any access to your biometric data — we only learn that your device reported the unlock succeeded. The setting itself is stored on your device, not on our servers. Incident notification to affected Customers without undue delay [define SLA with counsel]. No method is 100% secure; SMS itself is not an encrypted medium once it leaves our systems for carrier networks and devices.
6. Your rights
- Customers/members: access, correct, export, or delete account data in-app or via support.
- Recipients: your relationship is with the business texting you. Reply STOP to stop messages at any time (or say so in plain language); contact the business for access/deletion; if you contact Parea directly, we will route your request to the relevant Customer and assist them in fulfilling it.
- California (CCPA/CPRA), Virginia, Colorado, and similar state rights; EU/UK GDPR where applicable [attorney: confirm scope + representative requirements]. We honor verified requests within statutory windows and do not discriminate for exercising rights.
7. Other disclosures
- Children: the Services are for business use by adults 18+; we do not knowingly collect children's data.
- Cookies: session and security cookies only in-app; marketing-site analytics are cookieless/aggregate [confirm].
- International transfers: data is processed in the United States [add SCCs/DPF status if EU customers are onboarded].
- Changes: material changes are announced in-app with renewed acknowledgment where required; versions are archived.
Contact: privacy@[domain] · [postal address]