LoadBear
Platform Front Office Who It's For Security
Sign in Book a call →
Legal

Privacy Policy

Effective: August 28, 2026 Version: 2.1 Contact: hello@loadbear.co
Privacy Policy Terms of Service DPA Acceptable Use

1. Introduction and Scope

This Privacy Policy ("Policy") explains how LoadBear ("LoadBear," "we," "us," or "our") collects, uses, discloses, and protects information when you visit loadbear.co, use the LoadBear Platform, call or text a phone number operated through LoadBear, communicate with our team, or otherwise interact with us (collectively, the "Services"). LoadBear is operated from the State of Ohio, United States.

By using the Services, you acknowledge that you have read and understood this Policy. If you are using the Services on behalf of an organization (a "Customer"), you represent that you have authority to bind that organization to this Policy, to our Terms of Service, and to our Acceptable Use Policy.

Two different roles, and it matters which one applies. LoadBear handles information in two capacities:

  • As a business, for our own purposes — your account, our billing, our security, our own marketing. That processing is governed by this Policy.
  • On a Customer's behalf, as their service provider or processor — the leads, callers, contacts, messages, and business records a Customer runs through their LoadBear workspace. That processing is governed by our Data Processing Addendum and the Customer's own instructions, not by this Policy. If you are a customer, caller, or contact of a LoadBear Customer and you want your information accessed or deleted, the business you dealt with controls that decision — see Section 12.5.

2. Information We Collect

2.1 Information you provide directly

We collect information you submit when you create an account, book a call, complete a form, contact support, or otherwise communicate with us. This may include your name, business email address, phone number, business name, role, billing contact details, postal address, and any content you choose to provide in messages, forms, or chats with our website assistant.

We do not collect or store full payment card numbers. Card details are entered directly with our payment processor (Stripe, Inc.) and we receive only a customer identifier, the card brand and last four digits, and the status of your subscription.

2.2 Information collected automatically

When you visit our website or use the Services, we and our infrastructure provider automatically collect technical and operational information, including: IP address, browser type and version, operating system, referring URL, pages and features accessed, dates and times of access, and request outcomes. Our edge platform (Cloudflare, Inc.) generates traffic and security logs as a normal part of hosting.

Inside the product, we log authentication events and material actions to an audit log — what happened, which user and workspace it belonged to, the IP address, the user agent, and a timestamp. This exists so a Customer can see who did what in their own workspace, and so we can investigate security incidents.

2.3 Customer Data

When a Customer configures a workspace on the LoadBear Platform, the Customer (and the Customer's own callers, leads, and end users) submit data to be processed by that workspace ("Customer Data"). Customer Data commonly includes the personal information of the Customer's own customers, prospects, employees, or vendors — names, phone numbers, email addresses, addresses, message content, call content, quotes, invoices, appointments, and business documents. With respect to Customer Data, LoadBear acts as a service provider (under U.S. state privacy laws) or processor (under the GDPR/UK GDPR), and the Customer is the business or controller.

2.4 Calls, voice, messages, and email

Because LoadBear answers phones, sends texts, and sends email on a Customer's behalf, some of what we process is communications content. Section 5 describes this in full. In summary, depending on which features a Customer has enabled, we may process: caller and recipient phone numbers, call times and durations, call audio, call transcripts, voicemail recordings, SMS message bodies and delivery status, and email addresses, subjects, bodies, and delivery/bounce status.

2.5 Information from third parties

We may receive information from third-party sources, including: our payment processor; our telephony and email providers (delivery, bounce, and opt-out status); publicly available business listing and web data retrieved on a Customer's instruction; and services a Customer or you authorize us to connect to via OAuth (for example a calendar, mailbox, accounting system, or social account). We only pull from a connected account the scopes that were granted, and only while the connection remains authorized.

3. How We Use Information

We use the information described above for the following purposes, each of which corresponds to a permissible purpose under applicable law (including, where applicable, GDPR Article 6):

  • To provide and operate the Services — provisioning workspaces, authenticating users, configuring and running agents, answering and placing calls, sending messages a Customer instructs us to send, processing payments, providing support, and keeping the system running. Legal basis: performance of a contract; legitimate interests.
  • To develop and improve the Services — diagnosing and fixing issues, reviewing failures, and building new features. Legal basis: legitimate interests.
  • To communicate with you — service notices, transactional messages, billing communications, security alerts, and (where permitted) our own marketing. Legal basis: performance of a contract; legitimate interests; consent where required.
  • To secure the Services and prevent abuse — detecting unauthorized access, rate-limiting, and investigating incidents. Legal basis: legitimate interests; legal obligations.
  • To comply with legal obligations — responding to lawful requests, tax and accounting obligations, and enforcing our agreements. Legal basis: legal obligations.
  • To exercise or defend legal claims. Legal basis: legitimate interests; establishment, exercise, or defense of legal claims.

We do not sell personal information for monetary or other valuable consideration, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").

4. AI Processing and Automated Decision-Making

The LoadBear Platform uses third-party large language models and other AI systems to run agents, answer calls, draft text, summarize information, and produce other outputs. Being specific about this matters more than being reassuring about it:

  • We do not use Customer Data to train any general-purpose AI model, and we do not permit our model providers to do so. Our model providers are used through their business/API tiers, whose standard terms provide that inputs and outputs submitted through the API are not used to train their models. We do not have a separate negotiated no-training agreement with every model provider, and we do not control their retention windows for abuse-monitoring purposes; each provider's own policy governs that. If that distinction matters to your organization, ask us which providers are in the path for the features you plan to use and we will tell you.
  • Inputs to our public website assistant are sent to a model provider to generate the reply, and are stored by us so we can review and improve how the assistant answers prospects.
  • Solely automated decisions producing legal or similarly significant effects are not made by the Services as we configure them. A Customer may configure agents to take actions on their behalf; the Customer is responsible for ensuring those configurations comply with applicable law, including GDPR Article 22 and analogous U.S. state provisions on profiling.
  • AI outputs can be wrong. We disclose the use of AI on the surfaces where a person is interacting with it. Outputs should be reviewed by a human before being relied on for a material decision.

5. Calls, Recordings, Transcription, and Voice AI

This section describes exactly what happens on the phone, because a generic answer would not be a true one.

5.1 Recorded lines

Some phone numbers operated through LoadBear record the call — for example, voicemail capture on a Customer's published business line. On every such line, the caller is told the call is recorded before any recording begins. The announcement is played by the same code path that serves the call's instructions, so a line cannot record without announcing it first. Recordings are stored by our telephony provider (Twilio Inc.) under the account associated with the line, and are accessible to the Customer that operates the line.

5.2 The live AI receptionist (inbound)

When a caller reaches a live AI receptionist, the call audio is streamed in real time to a third-party speech model provider (OpenAI, L.L.C.) so the assistant can hear and respond. On this inbound path LoadBear does not store the call audio or a transcript of it — we store the call metadata (number, time, duration, outcome) and any structured result the call produced, such as a booking, a message taken, or a contact record. The caller is told the call is transcribed as part of the assistant's opening.

5.3 Outbound follow-up calls

Where a Customer has enabled outbound follow-up calling, the assistant discloses that it is an AI assistant and that the call is transcribed, and the transcript is stored in the Customer's workspace so the operator can read what was said and what was agreed.

5.4 Consent law

Ohio is a one-party-consent jurisdiction for the interception and recording of communications (Ohio Rev. Code § 2933.52). Other states require the consent of all parties. LoadBear's design does not depend on resolving which state a caller is in: every recorded line announces the recording, and the live assistant discloses transcription, which is the notice-plus-continued-participation approach used to satisfy all-party-consent jurisdictions. That said, call-recording law varies and is fact-specific. A Customer that operates a line through LoadBear is responsible for its own compliance with the recording, monitoring, and disclosure laws that apply to its calls, and for not disabling or altering the disclosures.

5.5 SMS and email

Text messages sent or received through a Customer's workspace, including message bodies, phone numbers, timestamps, delivery status, and STOP/HELP opt-out state, are stored in that workspace. The same applies to email we send on a Customer's behalf, including delivery and bounce events reported back by our email provider. Our own SMS program is described in Section 7.3.

6. Sharing and Disclosure

We disclose information in the following circumstances:

  • Service providers and subprocessors. We share information with vendors that perform services on our behalf — edge hosting and storage, AI model inference, telephony and SMS, email delivery, payment processing, scheduling, and integrations a Customer connects. The complete, current list of subprocessors, what each one does, and where it processes, is published in Annex 3 of our DPA, which is the authoritative list; we do not maintain a shorter summary here that could drift out of step with it.
  • At Customer direction. Where we process Customer Data on behalf of a Customer, we share it at that Customer's direction or as necessary to deliver the Services to them — including sending a message, publishing a post, or writing to a system the Customer has connected.
  • Legal requirements. We may disclose information if we believe in good faith that disclosure is necessary to comply with a law, regulation, legal process, or governmental request; to enforce our agreements; to protect the rights, property, or safety of LoadBear, our users, or others; or to detect, prevent, or address fraud, security, or technical issues.
  • Business transfers. If LoadBear is involved in a merger, acquisition, financing, reorganization, sale of assets, or insolvency proceeding, information may be transferred as part of that transaction, subject to continued protection consistent with this Policy.
  • With your consent, or at your direction.

We do not share your information with other LoadBear Customers. Each workspace's data is scoped to that workspace on every request path.

7. Sale, Sharing, and Text Messaging

7.1 No sale, no cross-context advertising

We do not "sell" personal information for monetary or other valuable consideration. We do not "share" personal information for cross-context behavioral advertising as defined under the CCPA/CPRA. We do not knowingly sell or share the personal information of consumers under 16 years of age.

7.2 Global Privacy Control

We honor Global Privacy Control (GPC) signals as a valid opt-out request from California residents and residents of other states whose laws recognize GPC. Because we do not run advertising pixels or third-party behavioral trackers on our site (see Section 8), there is presently nothing for such a signal to switch off — but the commitment stands if that ever changes.

7.3 SMS / text messaging

No mobile information is shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent are never shared with any third party, except our SMS delivery provider (Twilio Inc.) solely to deliver the messages you have consented to receive. Full program terms — opt-in methods, message types, frequency, and opt-out — are published at loadbear.co/sms-consent. Reply STOP to any message to opt out at any time, or HELP for help. Message and data rates may apply. Consent to receive text messages is never a condition of purchasing or receiving any service.

8. Cookies and Similar Technologies

We use a deliberately small number of cookies, and we would rather describe them exactly than gesture at categories:

  • Strictly necessary only. The cookies we set are for authentication and session management. We do not set analytics cookies, advertising cookies, or cross-site tracking pixels, and we do not run third-party web analytics or fingerprinting on our site.
  • Edge logs. Our infrastructure provider (Cloudflare) produces aggregate traffic and security logs as part of hosting. We use these for reliability and abuse prevention, not for behavioral profiling.
  • Third-party requests on some pages. Certain pages load fonts from Google Fonts and, where a booking widget is embedded, resources from Cal.com. Those providers receive your IP address and browser information as an ordinary consequence of your browser requesting the file. No cookie is set by us for either purpose.

You can control cookies through your browser settings. Disabling the session cookie will prevent you from signing in.

9. International Data Transfers

LoadBear is operated from the United States, and our service providers are principally located in the United States. If you access the Services from the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with data export restrictions, your information will be transferred to and processed in the United States, which may not provide the same level of data protection as your home jurisdiction.

Where applicable, we rely on the European Commission's Standard Contractual Clauses (Module Two or Three as appropriate), the UK International Data Transfer Addendum, and the Swiss equivalents, as incorporated in our DPA. A copy of the relevant transfer mechanism is available on request to hello@loadbear.co.

10. Data Retention

We retain personal information for as long as necessary to provide the Services and to meet legal, accounting, and dispute-resolution obligations. We want to be precise about how that actually works today, because a stated retention schedule we did not enforce would be worse than no schedule at all:

  • Customer Data is retained until it is deleted. A Customer's workspace data persists for as long as the workspace exists. We do not currently run an automated clock that ages out call logs, messages, transcripts, or CRM records after a fixed period. Deletion happens when a Customer deletes the record, deletes the workspace, or closes the account (Section 11), or on termination under our DPA § 10.
  • Account and billing information — for the life of the account and for a reasonable period afterward to meet tax, accounting, and dispute obligations.
  • Audit and security logs — retained for the life of the workspace, so that a Customer can review who did what in their own account. Edge and platform logs are retained according to our infrastructure provider's own retention windows.
  • Call recordings and transcripts — recordings are retained by our telephony provider under the account holding the line; stored transcripts persist in the workspace until deleted. The live inbound receptionist path stores neither (Section 5.2).
  • Marketing and suppression — we keep opt-out and STOP records indefinitely, because deleting them is how someone gets contacted again by accident.
  • Short-lived security tokens — sign-in codes, confirmation links, and password reset tokens expire within minutes and are purged automatically.

If your organization requires a defined maximum retention period — for example, "delete call transcripts after 90 days" — tell us before you onboard. That is a configuration we will build for you as a term of your agreement; it is not something the platform does on its own today.

Where we aggregate or de-identify information so it can no longer be associated with an identifiable individual, we may retain and use it indefinitely.

11. Your Data Is Yours — Export, Cancellation, and Deletion

These are commitments we make because they are already built, not aspirations:

  • Full export, any time, from inside the product. A Customer can export their entire workspace from account settings. The export walks the live database schema rather than a fixed list, so every workspace-scoped table is included and new tables are picked up automatically. Credentials and API keys are redacted, session and security tables are excluded, and stored files are included as a manifest of keys downloadable through the product rather than as inline blobs. The export names what it contains and what it skipped — including if any table hit the per-table row cap — so there is no silent gap. There is also a per-user export covering your own individual records.
  • Cancel any time, yourself. You can cancel from account settings without contacting us, without a retention call, and without a support ticket. Cancellation takes effect at the end of the period you have already paid for; you keep access until then. Consistent with our Terms, we do not refund the unused part of a period you have already paid for, so "cancel any time" means "stop the next charge and keep what you paid for," not "get a partial refund."
  • Delete your account and your data. You can delete your account from account settings, confirming by typing your email address. Deleting the account hard-deletes your user record and, for any workspace where you are the sole owner, that workspace and its associated data — including stored files and search indexes — not merely a hidden flag. If you are a member of a workspace with other owners, we remove your membership and leave that workspace's data intact for the people who still own it. Deletion is not reversible, which is why it asks you to type your address first.
  • No lock-in on your contacts. Contact records can be exported to CSV independently of a full export.

Export and deletion actions are written to the audit log, so there is a record that they happened.

12. Your Privacy Rights

12.1 California residents (CCPA/CPRA)

If you are a California resident, you have the right to: know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; request deletion, subject to exceptions; request correction of inaccurate information; opt out of any "sale" or "sharing"; limit the use of "sensitive personal information" to permitted purposes; not be discriminated against for exercising your rights; and designate an authorized agent, subject to verification.

Categories of personal information we have collected in the preceding 12 months include identifiers, commercial information, internet or network activity, and — where a Customer has enabled voice or messaging features — the contents of electronic communications. Sources, purposes, and recipients are described in Sections 2, 3, 5, and 6. We have not sold or shared personal information in the preceding 12 months.

12.2 Other U.S. states

If you are a resident of a state with a comprehensive consumer privacy law in effect — including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia — you may have rights to access, correct, delete, or obtain a portable copy of your personal information; to opt out of targeted advertising, sale, and certain profiling; and to appeal a denial. The exact scope varies by state. We honor these requests on the same process described in Section 12.4, and we will tell you which state's law we are applying.

12.3 EEA, United Kingdom, and Switzerland

If the GDPR, UK GDPR, or Swiss FADP applies to our processing of your personal data, you have the right to: access your data and information about how it is processed; request rectification; request erasure; restrict or object to processing, including for direct marketing; receive your data in a portable format; withdraw consent at any time where processing is based on consent, without affecting prior processing; and lodge a complaint with your local supervisory authority.

12.4 How to exercise your rights

Email hello@loadbear.co with the subject line "Privacy Request," describing what you want and the jurisdiction whose rights you are invoking. We verify requests using means proportionate to the sensitivity of what is being requested — typically by confirming control of the email address on the account, and by requiring additional proof for deletion of, or access to, communications content. We respond within the timeframes required by applicable law: generally 45 days under U.S. state laws (extendable once where permitted), and one month under the GDPR/UK GDPR.

If you are an account holder, the fastest route for access, portability, and erasure is not to email us at all — it is the export and delete controls described in Section 11, which run immediately.

12.5 If you are a customer, caller, or contact of a LoadBear Customer

If we hold your information because a business uses LoadBear to run its operations, that business — not LoadBear — decides what happens to it. Contact them directly. If you contact us instead, we will not act on the request ourselves; we will forward it to the relevant Customer and, on their instruction, assist them in responding, as required by our DPA § 6.4.

13. Security

We maintain administrative and technical safeguards designed to protect personal information against unauthorized access, loss, alteration, and disclosure. Rather than list controls generically, here is what is actually in place:

  • Two-factor authentication on every sign-in. After a password is verified, a six-digit code is emailed and required. This is not optional and cannot be disabled — there is no account that signs in on a password alone. Codes are stored hashed, expire in ten minutes, and are rate-limited.
  • Workspace isolation enforced on every request path, with an automated check that runs against new code before it ships and fails the build if a query reaching tenant data is not scoped to the owning workspace.
  • Encryption in transit (TLS) for all external communication, and encryption at rest for stored data as provided by our managed cloud platform.
  • Secrets are held in the platform's encrypted secret store, not in source code, and are redacted from data exports.
  • An audit log of authentication events and material actions, queryable by the Customer for their own workspace.
  • Automated pre-deploy checks and a production smoke suite that gate releases, plus scheduled runtime checks against the live product.

What we do not claim. LoadBear does not currently hold a SOC 2 Type II report or ISO 27001 certification, and we have not undergone a third-party penetration test. We say so plainly rather than implying certifications we do not have. If your organization requires either before purchasing, tell us and we will tell you honestly where we are.

No system is perfectly secure, and we cannot guarantee that personal information will never be subject to unauthorized access. You are responsible for safeguarding your own account credentials and the mailbox that receives your sign-in codes.

14. Ohio-Specific Disclosures

LoadBear is operated from Ohio, and Ohio law shapes several things worth stating directly:

  • Ohio has no comprehensive consumer privacy statute. Unlike California, Colorado, or Virginia, Ohio has not enacted a general consumer data privacy law granting access, correction, deletion, and opt-out rights. We extend the rights described in Section 12 to Ohio residents anyway, on the same process and the same timelines, because we would rather run one standard than sort people by ZIP code.
  • Breach notification (Ohio Rev. Code § 1349.19). If we discover a breach of the security of the system involving unencrypted computerized personal information of Ohio residents that is reasonably likely to result in identity theft or fraud, we will notify affected Ohio residents in the most expedient time possible and no later than 45 days after discovery, subject to the needs of law enforcement and of determining the scope of the breach. Our contractual commitment to business Customers under the DPA is stricter: notice without undue delay and in any event within 72 hours of becoming aware.
  • Call recording (Ohio Rev. Code § 2933.52). Ohio permits recording a communication with the consent of one party. LoadBear does not rely on that: recorded lines announce the recording, and the live assistant discloses transcription. See Section 5.4.
  • Ohio Data Protection Act (Ohio Rev. Code Chapter 1354). Ohio offers a safe-harbor affirmative defense to certain tort claims for businesses that maintain a written cybersecurity program reasonably conforming to a recognized framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO/IEC 27001. We do not currently claim that safe harbor, because claiming it requires a written program formally mapped to one of those frameworks and we have not completed that work. The controls in Section 13 are real; the formal program document is on our roadmap, and we will say so here when it exists rather than before.
  • Consumer Sales Practices Act (Ohio Rev. Code Chapter 1345). The Ohio CSPA governs consumer transactions — those primarily for personal, family, or household purposes. LoadBear is sold to businesses for business use, which generally places it outside the CSPA. Nothing in this Policy or our Terms is intended to waive any right an individual may have under the CSPA where it does apply.
  • Governing law and venue. Our Terms of Service are governed by Ohio law, with disputes resolved as set out in Terms § 25.

15. Children's Privacy

The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If we learn we have collected personal information from a child under 16 without verifiable parental consent, we will delete it as soon as reasonably possible. If you believe a child has provided personal information to us, contact hello@loadbear.co.

16. Third-Party Links and Services

The Services may contain links to, or embed resources from, third-party websites and services we do not operate. We are not responsible for their privacy practices. We encourage you to review their notices. Where a Customer connects a third-party account to their workspace, that provider's own terms and privacy policy govern what it does with data on its side.

17. Financial Incentives and Do Not Track

Financial incentives. We do not offer discounts, credits, or other financial incentives in exchange for the collection, retention, sale, or sharing of personal information. Pricing and promotional terms we offer, including founding-customer terms, are not conditioned on providing personal information beyond what is necessary to deliver and bill for the Services. If that ever changes, we will publish a notice of financial incentive describing the material terms before the program starts.

Do Not Track. Browsers may transmit "Do Not Track" signals. Because there is no industry-standard interpretation of these signals, we do not respond to them, except where required by law. We do honor Global Privacy Control signals as described in Section 7.2.

18. Changes to This Policy

We may update this Policy. If we make material changes, we will post the updated Policy here and, where required, notify you by other means such as email or an in-product notice. The "Effective" date at the top indicates when it was last revised. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

19. Contact Us

Questions, concerns, or requests about this Policy or our privacy practices:

  • Email: hello@loadbear.co
  • Subject line: "Privacy Request"
  • Location: LoadBear is operated from the State of Ohio, United States. A postal address for formal legal notices is available on request.
  • To report unwanted calls or messages, or other abuse of the Services: subject line "Abuse Report" — see our Acceptable Use Policy § 11. To stop texts immediately, reply STOP to any message.

If you are in the EEA, UK, or Switzerland and we do not resolve your concern, you have the right to lodge a complaint with your local data protection supervisory authority.

LoadBear

The white-label AI Operations Platform for businesses ready to run themselves like software.

hello@loadbear.co
Product
  • Platform
  • Front Office
  • Cora
  • What It's Worth
Company
  • Who It's For
  • Security
  • Book a call
  • hello@loadbear.co
Legal
  • Privacy
  • Terms
  • DPA
  • Acceptable Use
  • SMS Terms
© 2026 LoadBear. All rights reserved. loadbear.co