Privacy Policy
Operator: PalomaFinTech LLC, doing business as PalomaCEO.ai. Draft of September 4, 2026, pending final review; the effective date will be set when the app is published on the Clover App Market.
1. What we do
PalomaCEO.ai provides an AI receptionist, phone ordering and business chat for merchants who use Clover point-of-sale systems.
2. Data we process on behalf of merchants (as a processor)
Clover merchant data obtained through Clover's APIs with the merchant's authorization: business profile, hours, catalog, orders, payment metadata, customers, employees and shifts. Call audio and transcripts. SMS metadata. Knowledge base content the merchant provides.
3. Data we collect from callers (on behalf of the merchant)
Phone number, voice, order details, delivery or pickup details. Callers are told at the start of each call that they are speaking with an AI assistant and that the call is recorded.
4. Data we collect from merchant users (as a controller)
Account email, name, role and usage logs.
5. No card data
Payments are completed on Clover-hosted pages. We never receive card numbers, and card numbers are never accepted by voice.
6. No AI training
Merchant and caller data are used only to provide the service. They are not used to train models, and our model providers are contractually bound not to train on them.
7. Sub-processors
Linode / Akamai (hosting, United States); Anthropic, OpenAI and Google (language models); Deepgram (speech recognition); Cartesia (speech synthesis); LiveKit (media); Twilio or Telnyx (telephony and SMS); Stripe (billing for customers who subscribe directly); GitHub (source hosting).
8. Retention
Call recordings are kept 30 days by default and can be configured by the merchant up to 90 days. Transcripts and call cards are kept while the merchant account is active. Clover data is kept while the connection is active. Everything is deleted within 30 days after the merchant disconnects or deletes the account: the merchant's database is dropped and stored recordings are removed.
9. Your rights
Access, correction, deletion and export under CCPA/CPRA and PIPEDA. Send requests to privacy@palomaceo.ai. Merchants handle requests from their callers with the tools we provide.
10. Security
Each merchant has an isolated database. Credentials are encrypted in transit and at rest. Access follows least privilege, and agent actions are recorded in audit logs.
11. Children, international transfers, changes, contact
The service is for businesses and is not directed at children. Data is stored in the United States. We will announce material changes to this policy in the app and on this page. Questions: privacy@palomaceo.ai.