Last updated: August 7, 2026
AI Sales Assistant ("we", "us", or "our"), operated by Artillac Inc., operates the web application at https://www.aisalesassistant.ca and related services (the "Service"). This Privacy Policy explains how we collect, use, store, and share information when businesses use our dashboard and when their website visitors interact with our embeddable chat widget.
When a business creates an account, we collect information such as:
When a website visitor uses the chat widget, we may collect information they provide during the conversation, such as:
This data is stored on behalf of the business that embedded the widget. The business is the primary controller of lead data; we process it to provide the Service.
If a business connects Google Calendar in dashboard settings, we access Google Calendar data only after an authorized user grants OAuth consent. With that permission, we may:
We request the scope https://www.googleapis.com/auth/calendar for these scheduling features. We do not use Google Calendar data for advertising, sell it to third parties, or use it for purposes unrelated to meeting scheduling and dashboard functionality.
We use collected information to:
When a website visitor chats with your embedded widget, messages may be sent to the OpenAI API to generate responses. Here is how we handle that data:
For more detail, see our Trust Center and OpenAI API data usage policies.
When a business connects Google Calendar, we receive and use Google user data (for example, OAuth tokens, calendar identifiers, calendar availability, and event details needed to create or update bookings). This section describes with whom we share, transfer, or disclose that data. We do not sell Google user data.
We share, transfer, or disclose Google user data only to the parties below, and only for the purposes described:
We do not share, transfer, or disclose Google user data to advertising networks, data brokers, or parties unrelated to providing the Service. In particular, Google user data is not shared with Clerk (team sign-in), Stripe (billing), Resend (email), or Twilio (SMS) for their own purposes.
We may disclose Google user data if required by applicable law, regulation, legal process, or enforceable governmental request, or when we believe disclosure is necessary to protect rights, safety, or security. We may also disclose data with your explicit consent or at your direction (for example, when you disconnect Google Calendar or request deletion).
AI Sales Assistant's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is used only to provide calendar scheduling features for the business that connected the account—not for advertising, sale to third parties, or purposes unrelated to meeting scheduling and dashboard functionality.
When a business on a Growth or Pro plan connects Meta business messaging under Settings → Channels, we receive and store messages sent to that member's connected WhatsApp Business number, Facebook Page, or linked Instagram account. This includes:
Meta messaging data is processed to display the Channel inbox, create contacts and leads when your team approves a thread, and send replies you compose in the dashboard. We do not use Meta messaging content to train public AI models. Meta messaging is separate from the website chat widget and from transactional SMS sent through Twilio.
Team members in your organization who have access can view channel threads according to your roles: each member sees their own threads; organization owners and admins may see all org threads. Disconnecting Meta under Settings → Channels stops new message sync; previously stored thread messages remain until you request deletion, subject to our retention practices in section 8.
Meta (Meta Platforms, Inc.) processes messages according to its own policies when users interact through WhatsApp, Messenger, or Instagram. We call Meta's Graph API to deliver outbound replies authorized by your connected accounts.
When a business enables SMS in dashboard settings, website visitors who provide a phone number in the chat widget may receive transactional text messages from that business (for example, appointment confirmations and reminders). Messages are sent through our platform on the business's behalf; the business name appears in the message content.
Opt-in.Before SMS is sent, the visitor sees a notice in the chat widget such as: "By continuing, you agree to receive appointment text messages from [Business Name]. Reply STOP to opt out." The notice includes links to this Privacy Policy and our Terms & Conditions. By continuing the conversation and providing a phone number after seeing that notice, the visitor consents to receive these messages from that business only, delivered through AI Sales Assistant (Artillac Inc.) on that business's behalf. Consent obtained through one business's widget does not apply to other businesses on the platform.
Message frequency. Frequency varies by user activity. Typically, a visitor receives one confirmation message per booked appointment and up to one reminder message before the scheduled time. We do not use this SMS feature for marketing or promotional messages.
Opt-out. Recipients can opt out at any time by replying STOP to a message. After opting out, we will not send further SMS to that phone number for that business unless the person opts in again.
Help. For assistance, recipients may reply HELP or contact the business that embedded the chat widget directly.
Mobile information sharing. We do not sell, rent, or share mobile phone numbers or SMS opt-in data with third parties or affiliates for their marketing or promotional purposes. Phone numbers are used only to deliver transactional messages described in this policy and to operate the Service (including delivery through providers such as Twilio).
Message and data rates may apply.Standard message and data rates from the recipient's wireless carrier may apply.
We use trusted subprocessors to run the Service, including:
Each provider processes data according to its own privacy policy and our agreements with them.
We retain account and lead data while a business maintains an active account, unless a longer retention period is required by law or requested by the business. Businesses may disconnect Google Calendar at any time in dashboard settings, which stops new calendar access. Stored OAuth tokens can be removed by disconnecting the calendar integration.
Subscription cancellation. If you cancel a paid subscription through the Stripe customer portal (Settings → Billing in the dashboard), you keep access to paid features — including the website chat widget — until the end of your current billing period. After that period ends, the widget stops responding on your website. You can still sign in to the dashboard to view leads and settings unless you request account deletion. Lead and conversation data is retained as described above unless you contact us to delete it, subject to legal and billing record requirements.
Plan downgrades. If you move to a lower plan, the change takes effect at the start of your next billing period. If the new plan allows fewer connected calendars or team members, excess calendar connections are disconnected and the newest non-owner team members are removed at that rollover. The organization owner is always retained.
We use industry-standard measures to protect data, including encrypted connections (HTTPS), access controls for dashboard features, HTTP security headers, and secure storage of credentials and tokens. See our Trust Center for an overview of our security practices. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
The Service is intended for use by businesses and their website visitors. We do not knowingly collect personal information from children under 13 without appropriate consent. If you believe we have collected such information, contact us and we will take steps to delete it.
Our Service is operated from Canada. If you access the Service from other regions, your information may be processed in Canada and in locations where our subprocessors operate.
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date. Material changes may also be communicated by email or in-app notice.
Questions about this Privacy Policy or our data practices: