Security

How we protect
your data — and
your customers'.

When you hand a business over to a platform, you're trusting it with your customer list, your call history, and your revenue. Here's a plain-English account of how that information is handled.

Our practices

What we do,
described accurately.

No security theatre and no badges we haven't earned. Where a protection comes from one of our providers rather than from us, we say so.

Encryption in transit and at rest

Every site we build is served over HTTPS, so traffic between your customers and your website — including anything typed into a booking or contact form — is encrypted in transit using industry-standard TLS.

Data stored on our behalf is encrypted at rest by the hosting, database and storage providers we use. That protection is provided by those platforms; we configure our systems to rely on it rather than rolling our own.

Payment data never touches our systems

Card payments — yours and your customers' — are handled entirely by PCI-compliant third-party payment processors. Card details go directly to the processor.

We do not store full card numbers, CVV codes, or bank credentials anywhere in our systems. What we can see is limited to what the processor exposes for reconciliation: things like the last four digits, card brand, amount and status.

To be precise about who is certified: the processor holds PCI DSS compliance. We are not making a claim about certification of our own infrastructure.

Calls, recordings and customer data

The AI receptionist processes calls to understand what a caller wants, book appointments and write call summaries. Depending on your configuration this may involve recordings, transcripts, or both.

Recording laws differ by province and state. Where notice or consent is required, your call handling is set up to give it — we go through this with you during onboarding, and you decide what's recorded and what isn't.

  • Call data is used to operate your service — not sold, and not used for advertising
  • You can ask us to stop recording, or to delete specific recordings and transcripts
  • Your customer list belongs to your business, not to us
  • Retention periods are set out in your agreement; tell us your requirements and we'll configure to them
Access controls

Because this is a done-for-you service, our team does hold access to the systems running your business — that's how we build your site and configure your receptionist. We keep that access as narrow as the work allows.

  • Access is limited to team members who need it to deliver your service
  • Administrative accounts are protected with multi-factor authentication
  • Access is removed when someone leaves the team or changes role
  • Credentials for your accounts are kept in a password manager, not in email or chat
Third-party providers

We don't build every layer ourselves. Hosting, telephony, payments, email and advertising all run on established platforms, chosen partly because their security resources far exceed what a company our size could build alone.

Those providers process data on our behalf under their own terms and security programs. The table below sets out the categories involved and what each one touches.

Your data stays yours

Your domain, your website content, your customer records and your reviews belong to your business. We don't sell client or customer data, and we don't share it with anyone beyond the providers needed to run your service.

  • Ask for a copy of your data at any time
  • Ask us to delete specific records, subject to any legal retention we're required to observe
  • If you cancel, your domain is released to you and your content is handed over
What we're not claiming

Plenty of companies our size decorate a page like this with compliance logos. We'd rather be straight with you: FrontDesk Launch does not currently hold SOC 2, ISO 27001, HIPAA or any other formal security certification, and we haven't undergone an independent compliance audit.

What we've described above is what we actually do. If your business operates under a regulatory regime with specific requirements — healthcare records, for instance — talk to us before signing up so we can be clear about whether we're a fit, rather than discovering it later.

Who else is involved

The providers behind
your service.

These are the categories of third parties that may process data as part of running your platform. We'll name the specific providers used for your setup on request.

Category What it handles
Website hosting Serving your website and storing its content, images and video
Telephony & AI voice Carrying calls to your AI receptionist, and generating transcripts and summaries
Payment processing Card and online payments. Card data goes to the processor directly, never to us
Email & SMS delivery Sending appointment reminders, follow-ups and review requests
Scheduling & calendar Storing and syncing your appointments
Analytics Website traffic figures used to build your monthly report
Advertising platforms Running and measuring campaigns where marketing is part of your package
Report a concern

Found something? Tell us.

If you believe you've found a vulnerability in our platform or in a website we built, please report it to us directly rather than disclosing it publicly. We read every report and we won't pursue action against anyone who reports a genuine issue in good faith.

[email protected]

Helpful things to include: what you found, the URL or phone number involved, the steps to reproduce it, and how you came across it. We'll acknowledge your report and keep you posted on what we do about it. For anything that isn't a security issue, the contact page is the faster route.

This page describes our practices in general terms and is not a contract. Specific commitments for your business are set out in your service agreement. Last reviewed: pending pre-launch review.