SUBLAKE Holdings LLC ("SUBLAKE", "we", "us", or "our") is committed to protecting your privacy and handling your information responsibly. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered business automation platform.
1. Introduction
This Privacy Policy applies to all information collected through our website (sublake.com), our application platform, and any related services, sales, marketing, or events (collectively, the "Service").
By using our Service, you consent to the collection and use of information in accordance with this Privacy Policy. We will not use or share your information with anyone except as described in this policy.
This Privacy Policy is governed by the laws of the State of Delaware, United States. Our registered mailing address is available on written request to contact@sublake.com.
3. Google User Data
Google API Services Disclosure
SUBLAKE's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect your Google account to SUBLAKE, we access the following data:
- Google Calendar: Calendar events for scheduling, appointment management, and availability detection
- Business Profile: Publicly listed business details (such as address and hours) used to set up and personalize your account
How we use Google data: We use Google data solely to provide our AI automation services to you. We do not sell, share, or use Google user data for advertising purposes. We do not use Google user data to train general-purpose AI models.
Data retention: Google user data is retained only as long as necessary to provide our services or as required by applicable law. You can revoke access and request deletion at any time.
4. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process transactions and manage your subscription
- Power AI features including automated responses, contact enrichment, scheduling, and business communications
- Personalize your experience and improve our platform
- Communicate with you about your account, updates, and promotions (with consent)
- Respond to your support requests and inquiries
- Monitor and analyze usage patterns to improve performance and security
- Detect, investigate, and prevent fraudulent or unauthorized activities
- Comply with legal obligations and enforce our Terms of Service
SMS & Text Messaging
When you provide your mobile number — by booking an appointment on a business's booking page, or by adding it to your SUBLAKE account — we use it to send transactional text messages (SMS): appointment confirmations and reminders to a business's customers, and account and payment alerts to business owners. These are not marketing messages. Message frequency varies, and message and data rates may apply. You can opt out at any time by replying STOP, or get help by replying HELP.
We do not sell or share your mobile number or SMS opt-in with third parties for their marketing. Mobile information collected for text messaging is used only to deliver the messages you signed up for. See our Messaging (SMS) Terms for full details.
5. AI Data Processing
SUBLAKE uses artificial intelligence to process your business communications and data. This includes:
- Contact Extraction: AI analyzes incoming messages to identify and create contact records
- Sentiment Analysis: Messages are analyzed for tone and urgency to prioritize responses
- Response Generation: AI generates suggested replies based on conversation context and your business information
- Engagement Scoring: Customer interactions are scored to identify high-value relationships and churn risk
Automated Decision-Making
Our AI answers inquiries and records each customer request automatically, without a person reviewing every interaction in advance. A human can review and override the AI's actions, and businesses control how the AI behaves in their account. If you have questions about how your data is handled by our automated systems, or you would like a person to review a specific decision, contact us at contact@sublake.com.
AI Data Use Commitment
Your data is never used to train general-purpose AI models. AI processing is performed exclusively within your account context to provide personalized services to you.
6. Information Sharing
We do not sell your personal information. We may share your information only in these limited circumstances:
- Sub-Processors: With a set of vetted service providers who process data on our behalf to run the Service — covering payments, telephony and SMS, voice call handling, AI processing, hosting, and email. Each is bound by a data processing agreement and may use your data only to provide services to us.
- Public Map Services: To place an address on a map, draw the map and plan a route, we use a few public services that are not sub-processors and work under their own published terms. Each receives only what the task needs — an address line, the text being typed, the part of the map being viewed, or the two ends of a route — never a customer's name, phone number or messages. They are listed below.
- Legal Requirements: When required by law, subpoena, or government request
- Safety: To protect the rights, property, or safety of SUBLAKE, our users, or the public
- Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified)
- With Your Consent: In any other circumstance where you provide explicit consent
We maintain a complete, current list of our sub-processors — including what each one processes and where — on our Sub-processors page. Our current sub-processors include:
- Supabase, Inc.: Database and file storage hosting
- Vercel, Inc.: Website and application hosting / content delivery
- Railway Corp.: Application (backend) hosting
- Anthropic, PBC: AI processing — understanding messages and drafting responses
- Vapi, Inc.: Real-time voice call handling for the AI Receptionist
- Twilio Inc.: Telephony and SMS delivery (phone numbers, calls, texts)
- Stripe, Inc.: Payment processing and payouts
- Resend (Plus Five Five, Inc.): Transactional email delivery
- Loops (Loops Software, Inc.): Product and lifecycle email
- Functional Software, Inc. (Sentry): Application error monitoring
- Google LLC: Address suggestions while an address is typed (including on your booking page) and finding your business and its time zone when you sign up; plus calendar sync and sign-in when you connect a Google account
- Meta Platforms, Inc.: WhatsApp, Instagram, and Messenger messaging (only when you connect it)
The public map services are:
- U.S. Census Bureau (Census Geocoder): Placing a U.S. address on the map — our server sends the address line only
- OpenStreetMap Foundation (Nominatim): Placing an address on the map outside the U.S., or one the Census Geocoder cannot find — our server sends the address line only
- komoot GmbH (Photon): Address suggestions while an address is typed, only when Google address suggestions are switched off — our server sends the typed text only
- OpenFreeMap: Background map imagery for the map views — your browser requests the squares of map being viewed
Your data is never used to train general-purpose AI models. Our AI provider processes your data only to deliver responses for your account, under terms that prohibit training on your data.
7. Data Security
We protect your information with the following measures:
- Encryption in transit: Data moving between you and the Service is encrypted using TLS 1.2 or higher
- Encryption at rest: Stored data is encrypted using AES-256 encryption
- Tenant isolation: Each workspace's data is logically isolated from every other customer's
- Least-privilege access: Internal access to data is limited to what each role needs to do its job
- Encrypted connection tokens: The access tokens for services you connect (such as Google) are encrypted before storage
- Verified webhooks: Incoming automated messages are cryptographically signed and verified before they are processed
- Audit logging: Security-relevant events are recorded in audit logs
- Backups & recovery: We take regular backups with point-in-time recovery
- Incident response: We maintain a documented incident-response process with internal escalation procedures
- Availability: The Service is designed for high availability with redundant systems
- Card data: We never store your or your customers' card numbers — card payments are handled by our payment processor, which is PCI-DSS Level 1 certified
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA"), gives you specific rights regarding your personal information. This section is our notice at collection and describes those rights.
Categories of Personal Information We Collect
In the twelve months before the effective date of this policy, we collect the following categories of personal information, for the purposes described in "How We Use Your Information" above — to provide, operate, secure, and improve the Service, process payments, and communicate with you:
- Identifiers: Name, email address, phone number, account credentials, IP address, and device identifiers
- Customer communications content: The content of messages and calls handled through the Service, and of the transactional emails the Service sends on your behalf, including call audio recordings and transcripts
- Commercial and appointment information: Subscription and billing records; appointments, bookings, and related CRM records; and, for businesses that accept payments through SUBLAKE, payment and transaction records of their customers
- Financial information: For businesses using SUBLAKE Payments, the bank or debit-card payout account and identity/tax details needed to send payouts (collected and stored by our payment processor; SUBLAKE does not store full account numbers)
- Partner Program information: For partners, referral identifiers, referral activity, and payout/tax details
- Internet and network activity: Usage data, pages viewed, features used, and log data
- Professional information: Company name and job title
Sensitive Personal Information
The only categories of sensitive personal information we collect are your account log-in credentials and, for businesses that use SUBLAKE Payments, financial-account information. We use this information solely to operate and secure the Service and to send payouts. We do not sell or share it, and we do not use or disclose it to infer characteristics about you.
Your California Rights
- Right to know / access: Request the categories and specific pieces of personal information we have collected about you
- Right to delete: Request deletion of personal information we have collected from you
- Right to correct: Request correction of inaccurate personal information
- Right to opt out of sale or sharing: Direct us not to sell or share your personal information
- Right to limit: Limit the use and disclosure of sensitive personal information
- Right to non-discrimination: Exercise your rights without receiving discriminatory treatment
We Do Not Sell or Share Your Personal Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
How to Exercise Your Rights
To exercise any of these rights, email us at contact@sublake.com or visit our Do Not Sell or Share My Personal Information page. We honor Global Privacy Control (GPC) browser signals as a valid request to opt out of sale or sharing. You may also use an authorized agent to submit a request on your behalf; we may ask the agent for proof of authorization and may ask you to verify your identity directly. We will not discriminate against you for exercising any of your rights.
9. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Specific retention periods:
- Account data: Retained while your account is active. If you delete your workspace, there is a 30-day recovery grace period, after which the data is permanently deleted; residual encrypted backups are overwritten on a rolling basis within 90 days
- Business data (CRM, messages, recordings): Retained while your account is active and exportable at any time; permanently deleted within 30 days of workspace deletion (residual backups within 90 days), except records we must keep by law
- Usage analytics: Aggregated and anonymized after 24 months
- Server logs: Retained for 90 days for security and debugging
- Billing and financial records: Retained as required by tax and accounting law (typically 7 years)
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of your personal data in a portable format
- Correction: Update or correct inaccurate personal information
- Deletion: Request permanent deletion of your personal data
- Restriction: Limit how we process your data in certain circumstances
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests or direct marketing
- Withdraw Consent: Revoke consent for optional data processing at any time
- Non-Discrimination: Exercise your rights without penalty or reduced service quality
To exercise any of these rights, contact us at contact@sublake.com. We will respond within 30 days (or sooner where required by law).
11. International Data Transfers
Our servers are located in the United States. If you are accessing the Service from outside the US, your information may be transferred to, stored, and processed in the US. The public map services named in section 6 are in the countries shown on our Sub-processors page. We protect international transfers through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The UK International Data Transfer Addendum for transfers subject to UK GDPR
- Equivalent safeguards for transfers subject to the Swiss FADP
- Data Processing Agreements (DPAs) with all sub-processors
Data breach notification. If a breach affects your personal data, we will notify you and any applicable authorities without undue delay and consistent with applicable law.
12. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly.
13. Policy Changes
We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of material changes by email and by posting the updated policy on our website at least 30 days before the changes take effect.