Afterping · Legal document
Draft – Pending Legal Review
Privacy Policy
Afterping is an online lead-recovery product for HVAC and plumbing contractors. This draft describes information categories and application behavior visible in the checked-in code; deployment and legal details remain to be confirmed.
Bracketed owner and counsel notes are unresolved placeholders. Confirm them before publishing a final document.
1. Scope, provider, and roles
[OWNER AND COUNSEL INPUT: Identify the legal entity operating Afterping, the people and services covered by this notice, and whether Afterping acts as a controller, processor, service provider, or another role for each category of information. Confirm whether a separate customer-facing data-processing agreement is needed.]
2. Information represented in the application
Account and authentication information. The authentication schema includes a user name, email address, email-verification state, account and session records, and email-verification records. Session records can include an expiry time, IP address, and browser user-agent. The schema includes credential fields; confirm which credential data is actually retained and how it is protected before this description is finalized.
Lead records entered by contractors. The lead model includes name, optional email and phone, source, lead type, consent status, opt-out status, a manual send-block flag, recovery status, notes, assigned workflow, follow-up date, booking outcome, and creation and update times.
Activity history and templates. Lead activity records contain an activity type, summary, and timestamp. Saved recovery message templates contain a channel (SMS or voice), category, name, content, and creation and update times.
[OWNER INPUT: Confirm whether production stores additional information through integrations, support operations, logs, or separate systems that are not represented by these application models.]
3. How information is collected
- A person provides account details when registering and verifying an Afterping account.
- A contractor or authorized account user enters and updates lead records and message templates in the app.
- The app records lead creation and update activity in its lead history.
- The authentication setup sends an account-verification email through the Polsia email proxy.
- If analytics is enabled for a deployment, the site code creates a browser visitor ID in local storage and sends an analytics beacon. See the analytics section below.
[OWNER INPUT: Confirm all production collection points, including imports, integrations, support, call or message systems, and any third-party sources. The inspected app does not establish that such sources are connected.]
4. How information is used in the checked-in app
The app uses account information for account registration, email verification, and role-based access. Admin-facing tools let an authorized admin manage lead records, review their status and activity, manage saved templates, and filter an audience preview.
The audience endpoint returns a filtered count only. Its filters include lead type, source, recovery status, consent eligibility, and whether a booking outcome exists. The inspected endpoint does not return the matching lead list or send or queue a message.
The checked-in API routes for lead records, templates, and audience counts require an admin role. This statement describes those routes in the inspected code and is not a broader claim about every production system or access path.
[OWNER INPUT: Confirm additional business purposes, analytics purposes, support access, and any processing outside these app features.]
5. Messaging and AI: implementation status
Afterping’s website advertises AI voice and SMS recovery. In the checked-in application, SMS and voice templates can be stored and edited, and an audience count can be previewed; the inspected app routes do not send or queue those messages. The repository does not establish whether a separate production system enables messaging, voice calls, AI, call recording, transcription, or related integrations.
[OWNER INPUT: Verify deployed behavior and list any data used by message or voice providers, AI systems, integrations, or human review. Include their purposes, recipients, and opt-out and consent handling only after verification.]
8. Retention and deletion
[OWNER INPUT: Set and verify retention periods and deletion procedures for account, lead, activity, template, session, verification, analytics, support, and provider-held data. Describe export, backup, and post-termination handling only after confirming how they work.]
9. Security
[OWNER AND COUNSEL INPUT: Confirm the security measures and incident-response process that are in place and approve any description for publication. This draft does not promise a particular safeguard, certification, or security outcome.]
10. Storage location and transfers
[OWNER INPUT: Identify production storage locations and any cross-border processing or transfer, including provider locations and safeguards used where applicable. These details are not established by the inspected repository.]
11. Privacy choices and requests
[COUNSEL INPUT: Describe the rights and choices that apply by location, how an individual can make a request, how identity and authority are checked, response timelines, and any applicable limits or appeals. Confirm how a contractor customer should handle requests about lead records it provided.]
12. Children’s information
[OWNER AND COUNSEL INPUT: Confirm whether the service is intended for or available to children, any age threshold, and the steps to take if information about a child is submitted. No age rule is established by the repository.]
13. Changes to this notice
[OWNER AND COUNSEL INPUT: Set how changes will be approved, the notice method, and when an updated notice takes effect. Confirm whether a version or effective date should be displayed on this page.]
14. Contact for privacy matters
The company contact email provided for this app is afterping-7@polsia.app.
[OWNER INPUT: Confirm that this inbox is authorized and monitored for privacy requests, or provide the correct privacy contact and mailing address. Counsel should approve the final contact and request process.]