Privacy Policy

Last updated: October 7, 2026

Temaro ("we," "us") provides communication automation software to local service businesses. This policy covers how we handle information for both our business customers (the companies using Temaro) and their end customers (the people who call, text, or submit forms to those businesses).

Information We Collect

From business customers: the business name and address, the owner's name, email and mobile number, ZIP code, time zone and working days, billing details (handled by Stripe — we store a customer reference, never card numbers), the price list, message templates and Tempe settings a business writes, photos of its own past work it uploads, and counts of the texts, calls and AI actions its account uses each month (for fair-use limits and billing).

Texting registration. Mobile carriers require every business that texts its customers to be registered. When a business registers through Temaro, we collect its legal business name, business type, tax ID (EIN) if it has one, business address and website, and the name, email and mobile number of a contact person (a sole proprietor without an EIN gives a mobile number that receives a one-time verification code). We send these to Twilio, which passes them to The Campaign Registry and the mobile carriers so they can review and approve the business. We keep only the last four digits of the EIN, and keep the other details so a rejected registration can be corrected without retyping everything. Each registered business also gets its own public page, privacy notice and texting terms on temaro.io, built from the business name, phone number and links it has given us.

From team members a business adds: name, phone number and email; which jobs they are assigned; the times they tap On my way, On site and Completed; time off they mark and the hours those add up to; and photos they upload from a job, labelled with their name. The business owner adds this information and can see all of it; a team member sees their own.

From end customers (a business's own customers): name, phone number, email (if provided), address (if provided), project details and photos submitted through intake forms, quote and appointment history, invoice and payment history (the amount, date, whether it was paid by card or bank account, and a Stripe reference — never card or bank account numbers; a customer who pays by bank account links it through Stripe, and we only learn whether the payment cleared), appointment details such as the job address, kind of property, size and when you said you're available, measurements you enter or trace on the business's measuring page, and SMS consent status.

We also store the content of text messages exchanged between you and a business through their Temaro number — both the messages sent to you and the replies you send back. Your replies are stored so the business can read and answer them; before this, a reply had nowhere to go. Treat these messages the way you would any other text to a business: they are kept on record, and people who work at that business may read them.

If voicemail is enabled by a business, we store voicemail recordings tied to that missed call.

Partly completed intake forms. If you start filling in a business's project request form and do not press Send, we save what you had entered — your name, phone number, email, address and answers — so the business can follow up with you. This only happens once you have entered a phone number or an email address; a form with no way to reach anyone is discarded. The business sees these separately from completed requests, marked as unfinished. We delete a partly completed form automatically 30 days after you last touched it, or immediately if you come back and submit it. No automated text message is ever sent to a partly completed form — you did not finish, and you did not give consent, so the business can only reach you by calling or emailing you directly.

If you use the Temaro app on a phone and allow notifications, we store that phone's notification address (a token from Apple or Google), the kind of phone, and when it was last used, so alerts reach the right device. We remove it when you sign out. If you turn on Face ID or fingerprint unlock, that check happens on the device: your Face ID or fingerprint never leaves your phone and is never sent to us.

Cookies and Authentication

We use a strictly necessary authentication cookie to keep business customers securely logged in. We do not use advertising or cross-site tracking cookies.

How We Use This Information

We use this information solely to operate the features a business has enabled: sending automated text replies to missed calls, requesting reviews after completed jobs, re-engaging past customers, sending and tracking quotes, scheduling appointments, carrying text conversations between a business and its customers, and — when a business turns these on — automated follow-ups such as a check-in on a quote that hasn't been answered, a reminder about an unpaid invoice, a check-in on a date a customer said they'd get back to the business, and picture messages showing the business's own past work — as well as sending quotes, invoices and receipts by text or email, collecting payments a customer chooses to make by card or bank account, and coordinating the business's own crew (a crew member assigned to your job is sent the job's details, including your name, address and phone number, so they can find you and reach you). Every automated text includes opt-out instructions. We do not sell this information to third parties. We do not read message content to build profiles, target advertising, or train models.

Call Recording Notice

If a business you're calling has voicemail or missed-call handling enabled through Temaro, your call may be recorded or transcribed as part of that automated response. By calling a business using Temaro's service, you consent to this recording. If you do not wish to be recorded, please inform the business directly by another means of contact.

SMS Consent and Opt-Out

Every automated text we send includes opt-out instructions. A business can also write and send you an individual message as part of a conversation; those are written by a person and may not repeat the opt-out line, in the same way a reply from someone's own phone wouldn't.

Replying STOP works either way. It immediately and automatically stops all future messages to that number — automated and hand-written alike — and it cannot be undone by the business. Only you can turn texts back on, by replying START. Consent status is tracked and respected across every message type. No mobile opt-in data will be shared with third parties or affiliates for marketing or promotional purposes at any time.

We do not sell, rent or share mobile phone numbers or text messaging opt-in data and consent with third parties or affiliates for their marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except the service providers that deliver our messages (such as Twilio), which may use it only to provide that service to us.

How You Opt In

You opt in to receive text messages from a business in one of these ways: by checking the optional, unchecked box on their Project Intake form or online booking page (either can be sent without checking it, and no automated texts are sent unless you do); by tapping "Yes, text me" on the personal opt-in page the business sends you; by telling the business in person or on the phone that it may text you, after it tells you the same terms (texts are optional, message frequency varies, message and data rates may apply, reply STOP to stop), which the business then records in Temaro; or by texting START to a business you previously opted out from. If you call a business and the call isn't answered, you'll receive a single automated text reply inviting you to describe your project. This reply is sent because you initiated contact, not as an unsolicited message. Consent to receive texts is never a condition of any purchase. Message frequency varies; message and data rates may apply.

Texting a business's Temaro number directly also opens the door to a reply. If you start a text conversation with a business, they can text you back, because you contacted them first. That is a conversation you began, and you can end it at any time by replying STOP.

Third-Party Services

We use Twilio to send and receive text messages and calls and to register businesses for texting with The Campaign Registry and the mobile carriers, Stripe for payment processing, a managed Postgres database provider for secure data storage, Cloudflare for storing photos — those submitted through intake forms, a business's own work photos, and photos its crew upload from a job — Resend for sending transactional email, Google Fonts for the typefaces on our public pages (your browser requests the font files from Google, which sees your IP address as part of that request), Firebase Cloud Messaging (Google) to deliver notifications to the Temaro app — it receives the phone's notification address and the short alert text — and Sentry for automated error monitoring (which can incidentally capture technical details about a request, such as the page or data involved, when something goes wrong). Each of these providers has its own privacy practices governing the data they process on our behalf. All of our infrastructure and data storage is located in the United States.

We also use Anthropic's Claude AI ("Tempe") to help a business run its day — for example, turning a voicemail transcript into a structured lead summary, drafting quote line items from the business's own price list, drafting a reply to a customer's text, suggesting appointment times, noting when a customer said they would get back in touch, and — using only that business's own past quotes and messages — suggesting settings the business might want to adopt, which the business can accept or ignore. To do this, the text messages a customer exchanges with a business, the customer's name, job address and quote and appointment details, and the business's own settings and the names of its crew may be sent to Anthropic. Anthropic processes this data only to generate that output for us and does not use it to train its models. Each business decides how much of this is automatic: by default Tempe only drafts and a person at the business sends; a business can choose to let Tempe send certain replies itself, in which case those messages come from the business's own number and are marked as sent by Tempe in the business's records.

To group nearby jobs when suggesting appointment times, job addresses (the street address only — no names or phone numbers) are sent to the U.S. Census Bureau's public geocoding service to place them on a map. To show a business its local weather, its ZIP code is sent to Open-Meteo, a weather data service. When a business or its customer measures a property from the satellite picture, the map is provided by Google Maps and loads from Google's servers under Google's privacy policy; Temaro keeps only the outline that was traced and the resulting measurements, never the map imagery.

Photos a business uploads of its own finished work can be attached to picture messages the business sends to customers; to make that possible they are served from an unguessable link that anyone holding the link can open. Businesses are asked not to include people or identifying details in those photos.

A business can also turn on a private calendar subscribe link that lets their own phone's Calendar app or Google Calendar display their Temaro schedule. If enabled, appointment times, job titles, and the associated customer's name and phone number become visible in whatever calendar app the business subscribes with. This is opt-in, controlled entirely by the business, and the link can be turned off or regenerated at any time from Settings.

Our access to your account. Temaro's operator can see each business's plan and billing state, how much of its monthly allowance it has used, the packs it has bought, its business phone number and that number's status, and record counts — the figures needed to run the service and keep numbers and costs in check. We do not routinely read a business's messages or customer records, and we open an account's contents only to investigate a problem the business has reported, to protect the service or its other users, or when the law requires it.

Our Role as a Data Processor

For information about a business's own end customers, Temaro acts as a data processor on that business's behalf — the business is the data controller responsible for the underlying relationship with their customer, including obtaining any consent required to collect and use that data. Requests to access or delete end-customer data should generally go through the business first; we will assist the business in fulfilling those requests. If you contact us directly, we will forward your request to the relevant business and assist as needed. Our Terms of Service require business customers to indemnify us for claims arising from their own collection practices or misuse of end-customer data.

Data Retention

We keep a business's data for as long as their account exists. This includes text message content, kept so the conversation stays readable to the business the way any message history would, and records related to SMS consent, kept for as long as the account exists to help resolve any future dispute about opt-in status. If a subscription lapses or is cancelled for non-payment, the account stops working but the data is not automatically deleted. The business's dedicated phone number is placed on hold when a subscription is cancelled and released to our carrier 30 days later if the subscription is not restarted; the data stays.

Records of payments made through Temaro (amount, date, Stripe reference) and of top-up packs bought are kept for as long as the account exists, for the business's own bookkeeping and ours (and the limited payment safety records described below are kept after the account is deleted). A top-up pack's unused balance expires twelve months after purchase; the purchase record remains.

Partly completed intake forms are the one exception to keeping data for the life of the account. They are deleted automatically 30 days after they were last edited, whether or not the business's account is still active, and immediately if the person comes back and submits the form.

A business can delete their own account at any time from Settings. Deletion immediately stops the account's texts, calls, forms and sign-ins, but the data itself is held for 30 days so the business can restore the account if they change their mind or deleted it by mistake. During those 30 days the data is used only to make that restore possible and to finish shutting the account down: cancelling the subscription, closing payment pages a customer may still have open, sending the business a reminder before the data is erased, and handling any payment, refund or dispute still in progress.

After 30 days, the account and its records — including customer contact details, quotes, invoices, message logs and their contents, uploaded photos, and SMS consent history — are permanently deleted from our systems and cannot be recovered. Stored photos and files are removed from storage at the same time; if storage can't be reached, we keep a note of the file's address (and nothing else about it) and keep trying until it is gone.

What we keep after deletion, and why. A small set of payment safety records is not deleted with the account, because money can still move after an account closes (a late refund, a dispute, or an amount owed between the business and Temaro). These records hold payment and refund reference numbers, amounts and dates, the status of refunds and disputes, and short notes our staff wrote while resolving a payment problem, which can include the business's name. We keep them only as long as we need them to finish those payments and to meet our own legal, tax and accounting obligations. Our payment processor (Stripe) and our telephone carrier (Twilio) also keep their own records of payments and messages under their own policies, which we do not control.

Routine database backups taken before deletion are not individually edited; they expire on our hosting provider's normal retention schedule, after which no copy remains.

Data Security and Breach Notification

We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. In the event of a breach involving unencrypted personal information, we will notify affected individuals without unreasonable delay, and no later than 45 days after discovery, consistent with Arkansas law. If a breach affects 1,000 or more Arkansas residents, we will also notify the Arkansas Attorney General within that same window.

Children's Privacy

Temaro is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact us at admin@temaro.io and we will delete it.

Your Rights

End customers who want their information removed, or businesses with questions about their data, can contact us at admin@temaro.io. Depending on where you live, you may have additional rights to access, correct, or delete your personal information; we will honor these requests to the extent required by applicable law.

Limitation of Liability

To the maximum extent permitted by law, our liability for any claim arising from this policy or our handling of personal information is subject to the same disclaimers and liability cap set out in the Limitation of Liability section of our Terms of Service, which is incorporated here by reference.

Governing Law

This policy is governed by the laws of the State of Arkansas, without regard to its conflict-of-laws principles, and any dispute is subject to the arbitration and dispute-resolution terms in our Terms of Service.

Changes to This Policy

We may update this policy from time to time. If we make material changes, we will update the "Last updated" date above. Continued use of Temaro after changes constitutes acceptance of the updated policy.

Contact

Questions about this policy can be sent to admin@temaro.io.