RRE

Privacy Policy

Last updated: 2026-10-02

Revenue Recovery Engine (“RRE”, “we”, “us”) is a service operated by SmartFlow Digital LLC, a West Virginia limited liability company. We operate an AI-powered phone-answering, lead-reactivation, and follow-up service. This policy explains what we collect, why, and how we protect it.

Who is the data controller?

When a business signs up for RRE, that business is the data controller for its callers and leads. RRE acts as a data processor on its behalf. The same applies to any data uploaded as part of onboarding (e.g. an old leads CSV).

What we collect

Call recording

Calls are recorded and transcribed by our voice-agent provider (Synthflow). Every call opens with a notice that the call is recorded and that the caller is speaking with an AI assistant.

SMS compliance

All outbound SMS includes opt-out language (STOP) and is subject to TCPA, CTIA, and carrier rules. We honor opt-outs immediately and suppress further messages to that phone number across all campaigns for that business. Reactivation campaigns include an opt-out hint in every message and a quiet-hours window.

Who we share data with

We use a small number of third-party processors to operate the Service. Each is contractually limited to using your data only for our benefit (not for their own commercial purposes). The full list — what each vendor does, what data flows to them, and their privacy policy — lives at /subprocessors and is kept current. We notify active customers at least 14 days before adding or replacing a subprocessor.

We don’t sell personal data for money. Our website’s advertising tools may count as a “sale” or “sharing” under California law; they only run if you accept them, and you can opt out on our Do Not Sell or Share page. We do not share data across customers. We do not use customer data, call transcripts, or SMS content to train RRE’s own AI models or our LLM vendors’ models. Anthropic operates under their zero-retention API terms for our account.

AI use disclosure

RRE uses large language models (currently Anthropic Claude) to draft SMS replies, summarize calls, and operate the voice agent (via Synthflow, which uses third-party LLMs under the hood). When the AI voice agent answers a call, it identifies itself as an AI assistant at the start of every call. AI-generated transcripts and summaries may contain errors; the source recording is the authoritative record. We do not use customer or caller data to train any AI model.

Retention

Call recordings and transcripts are kept for 12 months unless you request shorter. Your account’s leads, contacts, appointments and messages are kept while your account is active and for 6 months after it ends, then deleted. After that we keep a minimal record of each text message — the phone number, date, campaign and the basis for contacting them, not the message itself — for 4 years, to respond to legal claims about those messages. Opt-out records are kept indefinitely so anyone who opted out is never contacted again. We keep your own account contact details (your name, email and phone) after your account ends. If you start signing up but don’t finish, we delete what you entered and any list you uploaded after 10 days, and may contact you about finishing for up to 12 months unless you unsubscribe. Website chat conversations are kept for 12 months. Operational logs are kept for 30 days, except call-processing logs, which follow the 12-month recording limit. You can request export or deletion at any time at privacy@smartflow.tools. Records subject to a legal hold, subpoena, or pending litigation are retained until that obligation lapses.

Data breach notification

If we discover or are notified of a security breach affecting your data, we will notify affected customers without undue delay and, in any event, within 72 hours of confirmation. The notification will describe the nature of the breach, the data affected, the steps we are taking, and recommended actions you may want to take.

Children’s data

RRE is built for business-to-business use and is not intended for or directed at children under 18. We do not knowingly collect personal information from individuals under 18. If you believe we have inadvertently collected such information, contact privacy@smartflow.tools and we will delete it.

Security

All data is encrypted in transit (TLS 1.2+) and at rest. Database access is gated by row-level security; no customer can see another’s data even if they have a valid session. Service-role keys live only in server-side environments, never in the browser.

Your rights

You can access, export, correct, or delete your data, or restrict how we process it, by emailing privacy@smartflow.tools. We respond within 45 days for CCPA/CPRA requests (extendable once by up to 45 more days where permitted) and within 30 days for GDPR / UK GDPR requests (extendable by up to two further months for complex requests, with notice). Residents of CA, EU, UK, and other regions with applicable privacy laws have the rights granted by those laws (CCPA/CPRA, GDPR, UK GDPR). California residents see also our Do Not Sell or Share page.

Changes

We’ll post material updates here and notify active customers by email at least 14 days before they take effect.

Questions? Back to home or email privacy@smartflow.tools.