Privacy Policy
Last updated: May 19, 2026
Owlvox (“we”, “us”) operates a lead-response platform that real-estate agencies subscribe to. This policy explains what personal data flows through our system, how we use it, and the rights you have over your information.
1. Who is the data controller?
For the prospect's personal data (name, phone number, email, message content): the real-estate agency that operates the Instagram, Facebook, or WhatsApp account the prospect contacted. The agency is the data controller; Owlvox is the data processor acting on their behalf.
For account holders at agencies (their login email, billing info): we are the data controller for that limited operational data.
2. What we collect
- Prospect data: name, phone, email, and the text of DMs/messages they send to the agency's Meta or WhatsApp accounts. Delivered to us via Meta's official webhook APIs.
- Call transcripts: text transcripts of AI calls placed to qualify the prospect. Audio recordings are stored by our voice provider (Vapi); we only persist the transcript.
- Agency account data: login email, hashed password, billing identifiers from Lemon Squeezy.
- Technical logs: timestamps, IP addresses on authentication, and error logs for debugging.
3. How we use it
Strictly to deliver the service the agency has subscribed to: reply to the prospect on the agency's behalf, place a follow-up AI call, book viewings, and surface the activity in the agency's dashboard. We do not sell or share personal data with third parties for marketing.
4. Sub-processors we rely on
- Meta Platforms: Instagram, Facebook, and WhatsApp message delivery.
- OpenAI: generating reply text. We do not send personally identifying details beyond what's required to compose the reply.
- Vapi: placing the outbound AI phone call.
- Twilio: telephony.
- Lemon Squeezy: payment processing.
- Google: Calendar synchronization (with explicit OAuth consent from the agency owner).
- Resend: transactional email.
5. Where the data lives
Our application database is hosted on Railway (PostgreSQL). Per-agency Meta access tokens are encrypted at rest using AES-256-GCM. Backups are retained for 14 days.
6. How long we keep data
- Prospect records: as long as the agency's account is active, then deleted within 90 days of account closure.
- Account data: as long as the account is active, plus 12 months for billing/tax records.
- Technical logs: 30 days.
7. Your rights (GDPR / equivalent)
If you are a prospect whose data we hold on behalf of an agency, you can request:
- A copy of the data we hold about you.
- Correction of inaccurate data.
- Deletion (we will forward the request to the agency that owns the record and delete from our systems within 30 days).
- Opt-out of automated calls, see our Call Consent page.
Requests: email [email protected] with the phone number or email you used.
8. Cookies
Our dashboard uses a single session cookie for authentication. The public landing page does not currently set tracking cookies.
9. Changes
Material changes will be announced 14 days before they take effect.
10. Contact
Owlvox, Tunis, Tunisia. Email: [email protected].