ESPO.AI
How It WorksWebsitesDemoPricingResultsAbout
Log InBook a Strategy Call
How It WorksWebsitesDemoPricingResultsAbout
Log InContact

Privacy Policy

Last updated: February 2026

1. Information We Collect

We collect information in several ways when you use our platform and services.

a) Information You Provide Directly

  • Account registration details (name, email address, phone number)
  • Business information submitted through forms (company name, industry, website URL)
  • Phone numbers provided for SMS communications
  • Content of messages sent through our chat interfaces
  • Files and attachments uploaded to the CRM
  • Payment and billing information (processed by third-party payment processors — we do not store full card numbers)
  • Any other information you voluntarily provide when contacting us or using our services

b) Information Collected Automatically

  • Device and browser information (browser type, operating system, device type)
  • IP address and approximate geographic location
  • Pages visited, time spent on pages, and navigation patterns
  • Referral source (how you arrived at our site)
  • Cookies and similar tracking identifiers (see Section 5)

c) Information from Third-Party Sources

  • Authentication data from Google or Apple when you sign in via OAuth
  • Delivery status information from email and SMS service providers
  • Scheduling data from integrated calendar services

2. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, operate, and maintain our platform and services
  • To create and manage your account
  • To process transactions and send related information (invoices, receipts)
  • To send transactional communications (appointment reminders, service notifications, account alerts)
  • To send marketing communications (only with your consent — you may opt out at any time)
  • To send SMS messages in accordance with Section 6 of this policy
  • To respond to your inquiries and provide customer support
  • To monitor and analyze usage trends to improve our services
  • To detect, prevent, and address fraud, abuse, and technical issues
  • To comply with legal obligations and enforce our Terms of Service

3. Information Sharing and Disclosure

We do not sell your personal information. We do not sell, rent, or trade your personal data to third parties for their marketing purposes.

We share information with trusted third-party service providers who assist us in operating our platform, solely for the purpose of delivering our services to you. These providers are bound by contractual confidentiality obligations and are prohibited from using your information for any purpose other than providing services to us. Our service providers include:

  • Cloud hosting and database (Supabase, Vercel) — for hosting our application and securely storing your data
  • Email delivery (Resend) — for sending transactional and marketing emails on your behalf
  • SMS and voice communications (Twilio) — for sending text messages, processing inbound messages, and facilitating voice calls
  • Scheduling (Cal.com) — for appointment booking and calendar integration
  • Authentication (Google, Apple) — for secure sign-in via OAuth
  • Analytics (Vercel Analytics) — for understanding how our services are used

We may also disclose your information in the following limited circumstances:

  • When required by law, regulation, subpoena, court order, or other legal process
  • To protect the rights, property, or safety of Espo.ai, our users, or the public
  • In connection with a merger, acquisition, or sale of all or a portion of our assets (you will be notified via email or prominent notice on our website)
  • With your explicit consent

For clarity: we never share your mobile phone number or SMS opt-in consent data with third parties for marketing or promotional purposes.

4. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • All data transmitted between your browser and our servers is encrypted using TLS (HTTPS)
  • Data at rest is encrypted in our database infrastructure
  • Access to personal data is restricted to authorized personnel on a need-to-know basis
  • Authentication is handled through industry-standard OAuth providers
  • We conduct regular reviews of our security practices and infrastructure
  • API access is controlled through cryptographically generated keys with configurable rate limits

While we implement commercially reasonable security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your information to the best of our ability.

5. Cookies and Tracking

We use cookies and similar tracking technologies to track activity on our website and hold certain information. We use the following types of cookies:

  • Essential cookies — required for the platform to function (authentication, session management)
  • Analytics cookies — help us understand how visitors interact with our website (page views, navigation patterns)
  • Preference cookies — remember your settings and preferences

We do not use third-party advertising cookies or tracking pixels for behavioral advertising.

Most browsers allow you to control cookies through their settings. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. Disabling essential cookies may prevent you from using certain features of our platform.

6. SMS/Text Message Communications

When you provide your phone number through our forms or services, you may receive SMS text messages from Espo.ai related to:

  • Appointment reminders and confirmations
  • Follow-up communications regarding your inquiry
  • Service updates and notifications
  • Marketing messages (only with explicit opt-in consent)

We send SMS messages exclusively through Twilio, a TCPA-compliant communication platform registered for A2P 10DLC messaging. Compatible with all major US carriers including AT&T, T-Mobile, Verizon, and others.

Message frequency varies. Message and data rates may apply. You can opt out of SMS communications at any time by replying STOP to any message. Additional opt-out keywords include UNSUBSCRIBE, CANCEL, END, and QUIT. After opting out, you will receive one final confirmation message and no further texts will be sent.

For SMS support, reply HELP to any message. You will receive instructions for getting assistance.

Your mobile phone number and text messaging opt-in data will NOT be shared with third parties or affiliates for marketing or promotional purposes. Text messaging opt-in data and consent will not be shared with any third parties under any circumstances.

For questions about our SMS practices, contact us at contact@espo.ai.

7. Third-Party Services

Our platform integrates with third-party services to deliver its functionality. These services have their own privacy policies that govern their collection and use of your data:

  • Supabase (database and authentication) — supabase.com/privacy
  • Vercel (hosting and deployment) — vercel.com/legal/privacy-policy
  • Twilio (SMS and voice) — twilio.com/legal/privacy
  • Resend (email delivery) — resend.com/legal/privacy-policy
  • Cal.com (scheduling) — cal.com/privacy
  • Google (authentication) — policies.google.com/privacy
  • Apple (authentication) — apple.com/legal/privacy

Our website may also contain links to third-party websites not operated by us. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access — Request a copy of the personal information we hold about you
  • Correction — Request that we correct inaccurate or incomplete information
  • Deletion — Request that we delete your personal information, subject to legal retention requirements
  • Portability — Request a copy of your data in a structured, machine-readable format
  • Restriction — Request that we limit the processing of your information in certain circumstances
  • Objection — Object to our processing of your information for certain purposes
  • Withdraw consent — Withdraw consent for marketing communications or SMS at any time (this does not affect the lawfulness of processing based on consent before withdrawal)

To exercise any of these rights, contact us at contact@espo.ai. We will respond to your request within 30 days. We may need to verify your identity before processing your request.

9. Data Retention

We retain your personal information for as long as necessary to provide our services, fulfill the purposes described in this policy, and comply with legal obligations. Specifically:

  • Account data — Retained while your account is active and for 30 days after a deletion request to allow for recovery
  • Chat and message history — Retained while your account is active; deleted upon account termination
  • CRM data — Retained for the duration of your organization's subscription; exported to you or deleted upon request after termination
  • Usage and analytics logs — Retained for up to 12 months for service improvement purposes
  • SMS and email records — Retained for up to 24 months for compliance and delivery verification
  • Billing records — Retained as required by applicable tax and accounting laws

When data is no longer needed, it is securely deleted or anonymized.

10. Children's Privacy

Our services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at contact@espo.ai. If we learn that we have collected personal information from a child under 13, we will take steps to delete that information promptly.

Users must be at least 18 years old or the age of majority in their jurisdiction to create an account and use our services.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know — You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it
  • Right to Delete — You may request deletion of your personal information, subject to certain exceptions
  • Right to Opt Out of Sale — We do not sell your personal information. No opt-out is necessary because no sale occurs
  • Right to Non-Discrimination — We will not discriminate against you for exercising your CCPA rights

To submit a request, email contact@espo.ai with the subject line "CCPA Request." We will verify your identity and respond within 45 days.

In the preceding 12 months, we have collected the categories of information described in Section 1 and shared them with the service providers listed in Section 3 for the business purposes described in Section 2. We have not sold personal information to any third party.

12. International Data Transfers

Our services are hosted in the United States. If you access our services from outside the United States, your information may be transferred to, stored, and processed in the United States where our servers and service providers operate. By using our services, you consent to the transfer of your information to the United States. We take reasonable steps to ensure that your data is treated securely and in accordance with this privacy policy regardless of where it is processed.

13. Do Not Track Signals

Some browsers offer a "Do Not Track" (DNT) setting. There is currently no industry standard for how companies should respond to DNT signals. At this time, we do not respond to DNT signals, but we do not engage in cross-site behavioral tracking.

14. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

15. Contact Us

If you have any questions about this Privacy Policy, please contact us at contact@espo.ai

ESPO.AI|

The growth engine for real estate teams.

How It WorksWebsitesDemoPricingResultsAboutResourcesContact
PrivacyTerms|© 2026 Espo.ai