Privacy Policy
Last Updated & Effective Date: July 7, 2026 · Rarefied Design Limited
This policy explains how Rarefied Design Limited collects, uses, shares, and protects personal information through Affinity Connect and related services. Customer-specific agreements, statements of work, order forms, and data processing addenda may provide additional terms for a specific customer.
Entity & Contact Information
Rarefied Design Limited, 15606 The Gore Rd, Caledon Village, ON L7C 3E5, Canada, operates Affinity Connect and related services.
Google User Data and OAuth Connections
When a user authorizes a Google connection, Affinity Connect uses the approved OAuth scopes and connected-account tokens only to provide the configured workflow, reporting, automation, synchronization, and support features requested by the customer or authorized user. Google-related product surfaces may include Google Analytics, Google Search Console, Google Business Profile, Google Ads, Google Maps/Places, Gmail-related workflows, and related reporting or automation.
For Google Workspace API data, Affinity Connect's use of raw or derived user data adheres to the Google API Services User Data Policy, including the Limited Use requirements. Affinity Connect does not sell this data, use it for advertising or credit decisions, or use or transfer it to create, train, or improve generalized artificial intelligence or machine-learning models.
When an authorized user invokes an AI-assisted feature, Google Workspace API data is processed only as needed to provide that visible, user-requested feature for that user or customer. Human access is limited to the user's explicit consent, security or abuse investigations, legal obligations, or aggregated and anonymized internal operations permitted by Google policy.
Connected credentials, OAuth tokens, API keys, webhook secrets, and connected-account tokens are retained until revoked, replaced, disconnected, expired, or no longer needed to provide the service, and only retained afterward as needed for security, audit, or legal reasons. Users can revoke access from their Google account or by contacting [email protected].
1. Overview
This Privacy Policy explains how Rarefied Design Limited collects, uses, shares, and protects personal information through Affinity Connect and related services.
We primarily process personal information to provide agency software, client portal features, AI voice and messaging agents, websites and forms, billing, reporting, integrations, support, security, and operations.
2. Information We Collect
We may collect or process the following categories of information. We do not intentionally require highly sensitive personal information unless a specific customer workflow is configured for it. Customers should avoid submitting sensitive information unless it is necessary and permitted by their agreement and applicable law.
- Account information: names, emails, usernames, roles, passwords in hashed form, session metadata, IP addresses, user agents, and account preferences.
- Client and business information: company names, contacts, websites, business addresses, phone numbers, locations, services, brand information, assets, knowledge-base content, credentials, settings, and operational notes.
- Communications data: phone numbers, caller/callee metadata, call status, call recordings, transcripts, summaries, messages, SMS content, live chat content, emails, form submissions, webhook payloads, appointment notes, and support messages.
- Customer and lead data: names, phone numbers, email addresses, appointment details, CRM contact fields, opportunity records, attribution data, lead form data, and conversion events.
- Billing and accounting data: billing contacts, invoices, subscriptions, payment status, product and tax-rate identifiers, Stripe customer and invoice IDs, charge/refund metadata, AI credit balances, usage ledgers, QuickBooks sync identifiers, and bank statement import metadata.
- Marketing, ads, and analytics data: campaign records, ad account IDs, insights, conversion uploads, keyword data, SEO audits, rank snapshots, website analytics, Google Business Profile data, reviews, local search metrics, landing page data, attribution events, and research runs.
- Website, asset, and content data: uploaded files, images, documents, website build data, website form submissions, WordPress/plugin records, source-control references, generated content, version history, and deployment logs.
- Technical and diagnostic data: logs, audit events, debug reports, screenshots submitted through debug tools, request metadata, API key metadata, webhook delivery status, provider errors, and usage/cost telemetry.
- Affiliate and referral data: affiliate profile email addresses, referral attribution, payout records, Stripe Connect identifiers, commission entries, and related metadata.
3. Sources of Information
We collect information from:
- You and your authorized users.
- Your clients, customers, leads, callers, form submitters, website visitors, and portal users.
- Connected third-party services and APIs.
- Webhooks, imports, uploads, websites, forms, calls, messages, and automations.
- Service providers that help operate, secure, bill, analyze, or support the service.
4. How We Use Information
We use information to:
- Provide, operate, secure, monitor, and improve the service.
- Authenticate users, manage accounts, permissions, API access, and sessions.
- Run AI voice agents, call flows, SMS workflows, transcriptions, summaries, analysis, and routing.
- Manage CRM, calendar, booking, email, and communication workflows.
- Provide client portals, reports, dashboards, websites, forms, asset libraries, and knowledge bases.
- Operate billing, subscriptions, invoices, AI credits, accounting sync, affiliate payouts, and cost reporting.
- Connect and manage third-party integrations at your direction.
- Generate, review, and assist with ad, SEO, social, GBP, website, and content workflows.
- Detect abuse, debug errors, investigate security issues, maintain audit logs, and enforce terms.
- Communicate with you about service updates, support, billing, security, and operations.
- Comply with legal, tax, accounting, regulatory, dispute, and contractual obligations.
5. AI Processing
AI features may send prompts, call audio, transcripts, summaries, instructions, website content, client settings, brand materials, reports, or other Customer Data to AI, speech-to-text, text-to-speech, image generation, and model-routing providers as needed to provide configured features.
Depending on configuration, providers may include Google Gemini, xAI, OpenAI, Deepgram, Groq, Inworld, Replicate, Cloudflare AI Gateway, or other approved providers. Provider availability and routing may vary by feature, customer configuration, and environment.
Customers are responsible for deciding what Customer Data may be used with AI features and for providing required notices, consents, and opt-outs.
6. Cookies and Similar Technologies
The web application may use cookies, local storage, session storage, tokens, and similar technologies for login sessions, security, preferences, portal state, and application functionality. Connected websites or landing pages may also use analytics, advertising, anti-spam, attribution, or consent tools depending on customer configuration.
Customers are responsible for cookie notices and consent banners on their own websites where required.
7. Sharing and Disclosure
We may share information with:
We do not sell personal information for money. Some advertising, analytics, attribution, or conversion-upload workflows may involve disclosures that privacy laws can define as sharing or targeted advertising when customers configure those features.
- Service providers and subprocessors that host, store, secure, process, analyze, transmit, or support the service.
- Connected third-party integrations that you authorize, such as CRM, telephony, calendar, payment, accounting, email, ads, analytics, hosting, storage, AI, speech, website, and source-control providers.
- Your authorized users, client users, admins, contractors, and team members according to permissions.
- Professional advisors, auditors, insurers, banks, payment processors, and legal representatives.
- Law enforcement, regulators, courts, or other parties where required by law or necessary to protect rights, safety, security, or service integrity.
- A successor in connection with a merger, acquisition, financing, reorganization, or sale of assets.
8. Third-Party Providers
The service may use or connect to providers such as MongoDB, Railway, Cloudflare, Cloudflare R2, Cloudflare AI Gateway, AWS S3-compatible storage, Twilio, GoHighLevel, Google, Google Ads, Google Analytics, Google Search Console, Google Business Profile, Google Maps/Places, Meta/Facebook, Reddit Ads, Stripe, Stripe Connect, QuickBooks Online, Cal.com, SendGrid, GitHub, Firecrawl, Deepgram, Google Gemini, xAI, OpenAI, Groq, Replicate, Inworld, Vercel, and WordPress-related services.
These providers process information under their own terms, privacy policies, data processing terms, and customer configurations.
9. Data Retention
We retain information for as long as needed to provide the service, maintain business records, comply with legal and tax obligations, resolve disputes, enforce agreements, preserve security/audit logs, operate backups, and support legitimate operational needs.
Feature-specific retention periods are listed in the Operational Data Retention Schedule below. Some records may be kept longer where required for legal, tax, accounting, security, fraud prevention, dispute resolution, contractual, provider, backup, or audit purposes.
When deletion is requested and legally permitted, we will delete or de-identify applicable records within a reasonable period, subject to backups, audit logs, billing records, legal holds, security records, and third-party provider retention.
10. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These may include authentication, hashed passwords, role-based access controls, credential storage controls, audit logs, signed webhooks, provider tokens, and operational monitoring.
No method of transmission or storage is completely secure. Customers must protect their own users, devices, credentials, connected accounts, API keys, and third-party permissions.
11. International Transfers
Information may be processed in Canada, the United States, and other countries where we or our service providers operate. These countries may have data protection laws different from those in your jurisdiction. Where required, appropriate contractual or legal transfer mechanisms should be used.
12. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. You may also have the right to withdraw consent where processing is based on consent.
To exercise rights, contact [email protected]. We may need to verify your identity and may refer requests involving customer-controlled data to the customer that controls the account or workflow.
13. Customer-Controlled Data
For many workflows, our customer is the controller or business that decides why and how personal information is processed, and we act as a processor or service provider. If your information was submitted through one of our customers' websites, forms, calls, messages, ads, CRMs, or portals, you may need to contact that customer directly to exercise privacy rights.
14. Children's Privacy
The service is not intended for children under 16. Do not knowingly submit children's personal information unless your agreement expressly permits it and you have all required legal authority and safeguards.
15. Marketing Communications
We may send service, security, billing, and administrative communications. Where permitted, we may send marketing communications. You can opt out of marketing emails, but we may still send non-marketing service messages.
Customers using the service to send marketing communications are responsible for their own consent, unsubscribe, and suppression obligations.
16. Regional Notices
Additional rights may apply under laws such as Canadian privacy laws, U.S. state privacy laws, GDPR/UK GDPR, ePrivacy rules, anti-spam laws, telecom rules, and advertising platform policies. Add jurisdiction-specific notices before publication if the service targets or monitors people in those regions.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted or otherwise communicated as required. The effective date will show when the latest version applies.
18. Contact
Privacy questions or requests can be sent to [email protected].
Operational Data Retention Schedule
| Data Category | Default Retention |
|---|---|
| Account, admin, portal, client, agency, user, permission, and configuration records | For the active relationship, then up to 7 years where needed for legal, tax, audit, security, dispute, or business record purposes. |
| Call records, call metadata, call recordings, transcripts, summaries, AI analysis, SMS records, live chat records, form submissions, lead records, and opportunity records | 24 months after collection or last activity, unless the customer asks for earlier deletion and deletion is legally and technically available. |
| Uploaded assets, knowledge-base documents, website build data, website form records, generated content, reports, SEO records, GBP records, ads records, campaign records, and integration history | For the active relationship, then 90 days after offboarding or deletion request, unless needed for an active project, legal hold, dispute, audit trail, or signed agreement. |
| Debug screenshots and client debug reports | 90 days by default. |
| Webhook events, delivery records, audit logs, API/MCP key metadata, security logs, provider errors, and operational telemetry | 24 months by default; security-relevant records may be kept longer if needed to investigate abuse, fraud, or system integrity issues. |
| Billing, subscription, invoice, payment, receipt, tax, accounting, QuickBooks, Stripe, AI credit ledger, affiliate, payout, and cost records | 7 years after the end of the relevant tax, accounting, or contractual period. |
| Credentials, OAuth tokens, API keys, webhook secrets, and connected-account tokens | Until revoked, replaced, disconnected, expired, or no longer needed to provide the service; retained only as needed for security, audit, or legal reasons after disconnection. |
| Backups | Deleted or overwritten on the normal backup rotation schedule. Some deleted records may remain in backups until that cycle completes. |
Provider Coverage
Current product coverage includes the following provider and integration surfaces: