Privacy Policy
Version: v1.0 β 2026-07-23 Effective date: 2026-07-23
This Privacy Policy explains how Vestibo
("Vestibo", "we", "us", "our") collects, uses, and
shares personal information when you (a) visit our website at
https://vestibo.com, (b) use the Vestibo
dashboard as a customer, (c) interact with an AI agent built on the
Vestibo platform as an end-user, or (d) communicate with us. It is
written to satisfy our obligations under the EU GDPR, the UK GDPR,
the Swiss FADP, the California Consumer Privacy Act ("CCPA") as
amended by the CPRA, Canada's PIPEDA, and Australia's Privacy Act.
Counsel must localise the language for every jurisdiction where the
Service is offered.
If you are an end-user interacting with an AI agent built on Vestibo on behalf of one of our customers, the customer is the data controller for that interaction. Refer to that customer's privacy notice. We act as a processor on the customer's behalf β see the Data Processing Addendum.
1. Who we are
Vestibo is based in the United States and its infrastructure runs in the United States. Our full registered company details and postal address are available on request at legal@vestibo.com. For privacy questions, contact:
- Privacy / data subject requests: privacy@vestibo.com
- EU / UK representative (Art. 27 GDPR / UK GDPR): not currently appointed. We do not target the Service to individuals in the EEA or the UK; if and when Art. 27 applies to us, we will appoint representatives and update this notice.
- Data Protection Officer: not appointed β our processing does not meet the Art. 37 GDPR thresholds that require one. Privacy questions go to privacy@vestibo.com.
2. What we collect, why, and on what legal basis
2.1 If you are a website visitor
| Category | Examples | Why | Legal basis (GDPR) | Retention |
|---|---|---|---|---|
| Device & log data | IP address, user-agent, pages viewed, referring URL | Operate the website, detect abuse, debug | Legitimate interests (Art. 6(1)(f)) | 90 days |
| Cookies | Strictly-necessary cookies plus a consent-exempt language-preference cookie (see Cookie Policy); no analytics or advertising cookies β aggregate usage is measured server-side | Run the site | Legitimate interests (Art. 6(1)(f)) | per Cookie Policy |
| Communications | Email content you send to us, support tickets | Respond to you | Legitimate interests / contract | 3 years |
2.2 If you are a customer (account holder)
| Category | Examples | Why | Legal basis | Retention |
|---|---|---|---|---|
| Identity | Name, email, password hash, time-zone, locale | Provide the Service, account security | Contract (Art. 6(1)(b)) | account life + 30 days |
| Billing | Stripe customer ID, last 4 digits of card, billing address, VAT/GST ID | Charge for the Service | Contract / legal obligation | 7 years (tax) |
| Configuration | Agent name, industry, persona, guardrails, knowledge base text | Run your agent | Contract | account life + 30 days |
| Telemetry | Login times and product-usage milestones (e.g. onboarding/funnel steps reached) | Detect abuse, measure adoption, improve | Legitimate interests | 12 months |
| Support | Email + chat content with our team | Help you | Contract | 3 years |
| OAuth tokens | Tokens for the integrations you choose to connect (e.g. Google, Acuity, HubSpot, Salesforce), stored encrypted at rest | Integrations you turn on | Contract (your consent) | until revoked |
2.3 If you are an end-user reaching an agent built on Vestibo
For end-users (people who text, call, or email an agent built on Vestibo by one of our customers), the customer is the data controller, and Vestibo processes the data on the customer's behalf under the DPA. Categories we may process on the customer's behalf include:
- Identity: name, phone number, email address, postal address (where the caller provides it).
- Conversation content: transcripts of the call/text/email/chat, voicemail recordings (where a caller leaves a voicemail β full live call audio is not recorded by default, so the stored record of a live call is its text transcript), and the structured fields the agent extracts (appointment time, reason for contact, etc.).
- Health information ("PHI"): only if the customer is on the HIPAA-eligible tier and has signed a BAA with us. Otherwise you must not transmit PHI to the agent.
- Sensitive special-category data (Art. 9 GDPR): we do not intentionally process it unless the customer has lawful basis and has configured the agent to handle it (e.g. a healthcare customer with a BAA).
2.4 Cookies and tracking technologies
See the dedicated Cookie Policy.
2.5 We do not knowingly collect data about children under 16
If you are under sixteen (16), please do not use the Service. If we become aware that we have collected personal information from a child under sixteen without verifiable parental consent, we will delete it.
3. How we use personal information
We use personal information to:
- provide, secure, and improve the Service;
- authenticate accounts (including via magic link and TOTP);
- communicate with you about your account (transactional);
- send marketing communications to customers who have opted in (you can unsubscribe at any time via the link in every marketing email);
- bill you for paid plans and recover unpaid invoices;
- detect, investigate, and prevent fraud, security incidents, and abuse;
- comply with legal obligations (tax, accounting, lawful requests);
- produce aggregated, de-identified usage statistics for our own product analytics.
We do not:
- sell personal information (and have not in the prior twelve months) within the meaning of CCPA / CPRA;
- share personal information for cross-context behavioural advertising;
- use Customer Data, conversation transcripts, or end-user voice recordings to train any third-party foundation model.
Where we use an AI sub-processor (such as Anthropic β our default
model provider β and, where enabled for a tenant, OpenAI, Deepgram, or
ElevenLabs) we have contracted for the same restrictions β see
SUBPROCESSORS.md.
4. Who we share data with
We share personal information only with:
- Sub-processors β the third-party service providers listed in
SUBPROCESSORS.md, each under a written contract that satisfies Art. 28 GDPR / SCC obligations and prohibits use of the data outside the Service. - Our customers β when you interact with an agent built on Vestibo, we share the conversation with the customer that configured the agent. That customer is the controller of that conversation under their privacy notice.
- Authorities β where required by law (subpoena, warrant, court order). We challenge over-broad requests where possible and aim to publish an annual transparency report.
- Acquirers β in a merger, acquisition, financing, or asset sale, personal information may be transferred to the acquirer subject to this Privacy Policy (or a more protective successor). We will notify customers and end-user controllers in advance.
We do not share personal information with data brokers, advertisers, or any third party for targeted advertising.
5. International transfers
We are headquartered in the United States. Our primary infrastructure
runs in us-east-1.
Where personal data of EU/EEA, UK, or Swiss residents is transferred
to a country that has not been deemed by the European Commission to
provide an adequate level of protection, we rely on:
- the EU Standard Contractual Clauses (Module 2 β Controller to Processor) as adopted in Commission Implementing Decision (EU) 2021/914 of 4 June 2021;
- the UK International Data Transfer Addendum issued by the ICO on 21 March 2022, where the transfer is from the UK;
- the Swiss FDPIC's addendum to the SCCs, where the transfer is from Switzerland.
We maintain a Transfer Impact Assessment (TIA) process for onward transfers to US-based sub-processors under the Schrems II framework, and make our current assessment available to customers on request.
EU/UK customers can also rely on the EU-US Data Privacy Framework ("DPF") or its UK extension where the sub-processor is DPF-certified; the Sub-processors list flags this for each.
6. Security
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorised access, disclosure, alteration, and destruction. These are described in the public Security Overview. No method of electronic transmission or storage is one-hundred-percent secure; we cannot guarantee absolute security.
In the event of a personal data breach affecting personal data processed on a customer's behalf, we notify the customer without undue delay and in any event within forty-eight (48) hours of becoming aware, in accordance with Art. 33 GDPR and the DPA.
7. Retention
We retain personal information only as long as needed to provide the Service and meet the legal, accounting, and reporting obligations in Β§ 2 above. See the Retention column there for the relevant period.
After the retention period:
- account data is deleted within thirty (30) days of account closure;
- the data is purged from rolling backups within ninety (90) days;
- aggregated, de-identified statistics may be retained indefinitely for internal analytics.
Customers can request earlier deletion under Β§ 8 (Your rights).
8. Your rights
Depending on where you live, you have some or all of the following rights regarding the personal information we hold about you:
- Access β receive a copy of the personal information we hold about you.
- Rectification β correct inaccurate personal information.
- Erasure ("right to be forgotten") β request deletion, subject to legal exceptions.
- Restriction β restrict our processing pending verification.
- Portability β receive your data in a structured, commonly used machine-readable format.
- Objection β object to processing based on legitimate interests, including profiling and direct marketing.
- Withdraw consent β where processing is based on consent, at any time without affecting prior lawful processing.
- Not be subject to a decision based solely on automated processing β we do not make legally significant or similarly significant decisions about you solely by automated means.
- Lodge a complaint with your local supervisory authority (in the EU/EEA), the ICO (UK), the FDPIC (Switzerland), the OPC (Canada), the OAIC (Australia), or the California Privacy Protection Agency (CPPA).
California residents have additional rights under the CCPA / CPRA (right to know, right to delete, right to correct, right to opt out of sale or sharing β N/A as we do not sell or share for behavioural advertising β right to limit use of sensitive personal information, and the right to non-discrimination for exercising these rights).
To exercise any right, email privacy@vestibo.com or use the dashboard's privacy centre. We respond within thirty (30) days of verifying your identity (extendable to sixty (60) days for complex requests, with notice).
If you are an end-user reaching a Vestibo-powered agent, please contact the relevant customer first; we will forward your request to them as a processor.
9. Marketing
We send marketing emails only to customers who have opted in. Every marketing email contains an unsubscribe link. We do not send marketing SMS or calls. The transactional emails our customers' agents send through the Service are governed by the customer's relationship with the recipient, not by this Privacy Policy.
10. Children
The Service is not directed to children under sixteen (16). See Β§ 2.5.
11. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Effective date" and, for material changes, notify customers by email and an in-product banner at least thirty (30) days before the change takes effect.
12. How to contact us
| Topic | Channel |
|---|---|
| Privacy / data subject requests | privacy@vestibo.com |
| Security disclosures | security@vestibo.com β see Vulnerability Disclosure |
| Legal notices | legal@vestibo.com |
| General contact | hello@vestibo.com |
Postal address: available on request at legal@vestibo.com.
Changelog
- v1.0 (2026-07-23) β first published version; rebranded to Vestibo and reconciled to the current product.
- v0.1 (2026-05-16) β initial internal draft.