Back to Home

Privacy Policy

Effective Date: April 1, 2026 ยท Last Updated: July 8, 2026

1. Who We Are

Ironclad Solutions LLC ("Ironclad," "we," "us," or "our") is a limited liability company organized under the laws of the Commonwealth of Puerto Rico, with its principal place of business in San Juan, PR. We provide artificial-intelligence-powered workforce automation services to home-service contractors across all trades.

This Privacy Policy describes how we collect, use, store, share, and protect information when you visit ironcladsolutions.ai (the "Website"), use our client portal at app.ironcladsolutions.ai (the "Portal"), interact with our AI voice or messaging systems, or otherwise engage with our services (collectively, the "Services").

By using our Services, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of our Services immediately.

2. Information We Collect

2.1 Information You Provide Directly

  • Contact & Lead Information: Name, email address, phone number, trade or industry, and company name submitted through our website forms, phone calls, or other intake methods.
  • Account Information: Credentials, business details, service preferences, and onboarding data provided when you create a Portal account.
  • Payment Information: Billing details processed through our PCI-compliant payment processor. We do not store full credit card numbers on our servers.
  • Communications: Emails, support messages, and any other correspondence you send us.

2.2 Information Collected Through Our AI Services

  • Voice Call Data: When our AI receptionist handles calls on your behalf, we collect call recordings, transcripts, call duration, caller phone number, call disposition, and scheduling data. Callers are informed at the beginning of each call that the call is handled by an AI assistant and may be recorded.
  • SMS & Messaging Data: Message content, phone numbers, timestamps, delivery status, and opt-out requests for automated text messages including appointment reminders, follow-ups, and review requests.
  • Scheduling Data: Appointment details, technician assignments, calendar availability, and job records processed through our scheduling engine.
  • Review & Reputation Data: Publicly available business reviews collected from third-party review platforms, along with AI-generated review responses and review request tracking.
  • Job & Revenue Data: Job outcomes, revenue figures, service types, and technician performance data reported by your team for analytics and reporting purposes.

2.3 Information Collected Automatically

  • Server & Security Logs: Standard web-server logs (IP address, browser type, request URL, and timestamps) kept by us and by our hosting and content-delivery providers to operate the Website and Portal, secure them, and prevent abuse.
  • Portal Usage Data: Pages and features used inside the Portal, and session and authentication records needed to keep your account secure.

We do not run third-party analytics or advertising trackers on the Website.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve our AI workforce services, including voice answering, SMS automation, scheduling, and analytics.
  • Create and manage your Portal account, authenticate users, and deliver personalized dashboards and reports.
  • Process payments.
  • Send transactional communications such as appointment confirmations, follow-up messages, review requests, and service notifications.
  • Generate performance reports and revenue analytics for your business.
  • Train and improve our AI models to deliver more accurate call handling, smarter scheduling, and better business outcomes. Client data used for model improvement is anonymized and aggregated.
  • Detect, investigate, and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations and respond to lawful requests from authorities.

4. How We Share Your Information

We do not sell your personal information. We share information only in the following circumstances:

  • Service Providers (Sub-processors): We use third-party providers for voice processing, SMS delivery, payment processing, email delivery, database hosting, content delivery, scheduling, and business messaging. These providers process data on our behalf under written terms and use it only to provide services to us. Client-facing operational messaging (such as daily briefs, approvals, and photo filing for business owners who opt in) is delivered through Telegram's Bot platform; messages sent through that channel transit Telegram's servers and are not end-to-end encrypted, and are subject to Telegram's own privacy policy.
  • AI Model Providers: Portions of call and interaction data may be processed by third-party AI model providers to generate responses, transcripts, and analytics. We select providers whose terms restrict use of customer data to providing the service, and we rely on those providers' published API and enterprise terms, which generally state that data submitted through the API is not used to train their models.
  • Your End Customers: When our AI handles calls or messages for your business, your customers interact with our systems. Information necessary to complete scheduling, follow-ups, and service delivery is processed as part of the service.
  • Legal Requirements: We may disclose information when required by law, subpoena, court order, or government request, or when necessary to protect our rights, safety, or property.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

5. Voice Call & SMS Consent (TCPA Compliance)

Our Services involve automated voice calls and text messages on behalf of our clients. We comply with the Telephone Consumer Protection Act (TCPA) and all applicable federal and state telecommunications regulations:

  • All AI-handled calls begin with a disclosure that the caller is interacting with an AI assistant and that the call may be recorded.
  • Automated messages are sent on one of two bases, depending on the message type. Transactional messages (such as appointment confirmations and reminders) are sent to individuals who provided their phone number for that purpose, such as by booking an appointment or submitting a service request. Recovery and follow-up messages, where enabled by a client, are sent on the basis of an Established Business Relationship between the client and the recipient (for example, a prior or existing customer who gave the client their number in the course of a transaction or inquiry). For those messages, the client, not Ironclad, holds and attests to the underlying relationship and the recipient information. Ironclad does not send recovery or follow-up messages on a client's behalf unless the client has signed an attestation that an Established Business Relationship exists.
  • Recipients may opt out of SMS communications at any time by replying STOP. Opt-out requests are processed automatically and immediately.
  • We honor quiet hours and do not send automated messages outside of reasonable business hours unless specifically requested.
  • Message frequency varies based on service activity. Message and data rates may apply.

6. Data Security

We implement industry-standard security measures to protect your information:

  • All data in transit is protected by TLS/SSL encryption (256-bit).
  • Sensitive data at rest is encrypted using AES-256-GCM with versioned encryption keys.
  • Database access is restricted by tenant-scoped access controls so that clients can only access their own data.
  • API endpoints are authenticated and rate-limited to prevent unauthorized access.
  • We conduct regular security audits and maintain access logs for all administrative operations.
  • Payment data is handled by PCI DSS-compliant processors and never stored on our infrastructure.

While we take every reasonable precaution, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.

7. Data Retention

  • Account Data: Retained for the duration of your active subscription and for up to 12 months after termination to support potential reactivation and compliance requirements.
  • Call Recordings & Transcripts: Retained for up to 24 months for service improvement, dispute resolution, and quality assurance, unless a shorter retention period is required by law.
  • SMS Records: Message logs are retained for up to 12 months. Opt-out records are retained indefinitely to ensure ongoing compliance.
  • Analytics & Aggregated Data: Anonymized and aggregated data may be retained indefinitely to improve our Services.
  • Lead Data: Information from non-clients who submit lead forms is retained for up to 24 months, after which it is deleted unless the individual becomes a client.

8. Cookies & Tracking Technologies

Our Website and Portal use the following technologies:

  • Essential Cookies & Local Storage: Used only for site functionality, Portal authentication and sessions, and security. The public Website sets no tracking cookies.

We do not run third-party analytics on the Website, we do not use advertising cookies, and we do not sell data to ad networks. Most browsers allow you to control cookies through settings; disabling them may affect Portal sign-in.

9. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal information, subject to legal retention requirements.
  • Portability: Request your data in a structured, machine-readable format.
  • Opt-Out: Opt out of automated SMS by replying STOP, or contact us to opt out of other communications.

To exercise any of these rights, contact us at mitch@ironcladsolutions.ai. We will respond within 30 days.

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with additional rights regarding your personal information:

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions (e.g., completing a transaction, legal obligations, security purposes).
  • Right to Correct: You may request that we correct inaccurate personal information.
  • Right to Opt Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising as defined under the CCPA/CPRA.
  • Right to Limit Use of Sensitive Information: We only use sensitive personal information (such as phone numbers and precise location) as necessary to provide our Services.
  • Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To submit a verifiable consumer request, contact us at mitch@ironcladsolutions.ai. We will verify your identity before processing your request and respond within 45 days. You may also designate an authorized agent to submit requests on your behalf.

In the preceding 12 months, we have collected the following categories of personal information: identifiers (name, email, phone), commercial information (service records, transaction history), internet or electronic network activity (server logs, Portal usage data), audio information (call recordings), and professional information (business details, trade, service area).

11. Data Breach Notification

In the event of a data breach that compromises your personal information, we will:

  • Notify affected individuals and relevant authorities as required by applicable law, including but not limited to the Puerto Rico Data Breach Notification Act, CCPA breach notification requirements, and any other applicable state breach notification laws.
  • Provide notification without unreasonable delay and no later than 72 hours after becoming aware of the breach, where feasible.
  • Include in the notification: a description of the incident, the types of information involved, steps we are taking to address the breach, and recommended actions you can take to protect yourself.
  • Conduct a thorough investigation, remediate the vulnerability, and implement measures to prevent recurrence.

12. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will promptly delete it.

13. Google User Data (Calendar Integration)

When you connect your Google account to Ironclad Solutions to enable calendar-based appointment booking, we request the following Google OAuth scopes:

  • userinfo.profile: to identify the connected Google account and display your name in the application.
  • calendar.events: to create, update, and cancel appointment events on your Google Calendar when your AI receptionist books a job during a customer call.
  • calendar.readonly: to read your existing calendar availability so our AI can offer customers valid time slots that do not conflict with other commitments.

Limited Use compliance. Ironclad Solutions' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide user-facing appointment-scheduling features. We do not sell Google user data, transfer it to third parties for advertising, use it for serving ads, or allow humans to read it unless: (a) we have your affirmative permission, (b) it is necessary for security (e.g., fraud investigation), (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.

Data access, retention, and deletion. We store OAuth refresh tokens in encrypted form and retain calendar event identifiers we create on your behalf so we can update or cancel them. You can revoke Ironclad's access to your Google account at any time by visiting myaccount.google.com/connections or by disconnecting the integration from within your Ironclad portal settings. Upon revocation or account deletion, we delete all associated OAuth tokens and stop all calendar access within 30 days.

14. Third-Party Links

Our Website and Portal may contain links to third-party websites or integrations with external tools used by your business (e.g., CRM systems, field-service management tools). We are not responsible for the privacy practices of these third parties and encourage you to review their privacy policies.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to active clients and by posting the revised policy on this page with an updated effective date. Your continued use of our Services after changes are posted constitutes acceptance of the revised policy.

16. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, contact us at:

Ironclad Solutions LLC

San Juan, Puerto Rico

Email: mitch@ironcladsolutions.ai

General: mitch@ironcladsolutions.ai