Legal

Ansabell Privacy Policy

Effective

This Privacy Policy explains how Ansabell, operated by Haven Technologies, collects, uses, shares, and protects information when businesses use our AI voice receptionist and when people call or text an Ansabell-powered phone line. Ansabell answers, records, and transcribes calls, sends text messages, and books appointments — and we treat that information carefully under Washington and U.S. privacy law. We do not sell personal information, and we do not use call content for cross-context behavioral advertising or to train third-party foundation models. Consumer health information is also addressed in our separate Consumer Health Data Privacy Policy, reachable from a distinct link on our homepage.

1. 1. Who We Are and Scope

Ansabell is an AI voice receptionist service for small businesses, operated by Haven Technologies, Inc., a Washington State company located at 2103 Harrison Ave SW, Ste 1034, Olympia, WA 98502 ("Ansabell," "Haven," "we," "us," or "our"). Ansabell answers inbound business phone calls with a natural AI voice, records and transcribes those calls, sends and receives SMS text messages, books appointments, integrates with Google Calendar and CRMs, and can take payments.

This Privacy Policy applies to https://ansabell.com, our web dashboard and applications, our telephone and messaging services, and all related features (collectively, the "Services"). It describes how we handle information for two groups of people: (1) the businesses that subscribe to Ansabell (each a "Customer"), and (2) the people who telephone or text a Customer's Ansabell-powered line (each an "End Caller").

This Policy provides NOTICE of our information practices. If you are a Customer, using the Services is subject to our Terms of Service. If you are an End Caller, this Policy tells you how information from your call or text is handled — but it does not, by itself, obtain any legally required consent from you. Recording consent (RCW 9.73.030) and messaging consent (the TCPA) are the Customer's statutory responsibility, not something satisfied merely by your continued use of a line. Each Customer is responsible for making this Policy (or its own compliant privacy notice) available to its End Callers and for obtaining any consents the law requires.

Consumer health data is also addressed in a separate, standalone Consumer Health Data Privacy Policy, which we maintain in addition to this Policy and make available through a distinct, conspicuous link on our homepage, as required by Washington's My Health My Data Act. Section 11 summarizes that policy and links to it.

2. 2. Our Dual Role: Processor and Controller

Our privacy responsibilities depend on whose data is involved:

  • End-Caller data (processor / service provider): When we handle the personal information of End Callers — such as call recordings, transcripts, phone numbers, and appointment details — we act on behalf of and at the direction of the Customer. In privacy-law terms, the Customer is the controller (or "business") who decides why and how that data is used, and Ansabell is the processor (or "service provider"). The Customer is responsible for having a lawful basis to collect this data, for providing any required notices, and for obtaining any required consents (including call-recording, health-data, and messaging consents).
  • Customer account and billing data (controller): When we handle information about the Customer's own account — for example, the business's name, contact details, login credentials, plan, and billing — we act as the controller and determine how that information is used, consistent with this Policy.

Where we act as a processor, our handling of End-Caller data is also governed by our Data Processing Addendum (DPA) with the Customer, which controls if there is any conflict with this Policy as to that data.

3. 3. Information We Collect (CCPA Notice at Collection)

We collect the following categories of information. We do not invent or infer categories beyond what the Services actually process. The table in Section 3.6 maps each category to its sources, the business or commercial purpose for collecting it, and the categories of third parties to whom it may be disclosed, so that this section also functions as a notice at collection under the California Consumer Privacy Act, as amended by the CPRA (CCPA/CPRA).

3.1 Account and Business Data (we are controller)

  • Business name, contact name, email address, and business phone number.
  • Login credentials, including passwords, which we store only in hashed form.
  • Plan, subscription, and billing information (see Payments below).

3.2 Call Data (we are processor for the Customer)

  • Audio recordings of calls placed to or handled by the Customer's Ansabell line.
  • Transcripts of those calls, generated by automated speech-to-text.
  • End-Caller phone numbers (in E.164 format).
  • End-Caller names and any details the caller provides during the call, which may include sensitive personal information such as health information (see Sections 11 and 13.2).
  • Appointment and booking details (such as requested date, time, and service).
  • Call metadata, including time, duration, and outcome/disposition.

3.3 Messaging Data (we are processor for the Customer)

  • The content of SMS text messages sent and received on the Customer's behalf, together with associated phone numbers and delivery metadata.

3.4 Payment Data

  • Payments are processed by Stripe. We store only payment tokens and the last four digits of a card. We do not collect or store full card numbers on our systems.

3.5 Usage and Technical Data (we are controller)

  • Log data, including IP address, timestamps, and actions taken in the dashboard.
  • Device and browser data.
  • Cookies and similar technologies, and analytics data (see Cookies section).

3.6 Categories, Sources, Purposes, and Recipients (CCPA/CPRA)

Category of Personal InformationSourcesBusiness / Commercial PurposeCategories of Third Parties Disclosed To
Account and business data (identifiers, contact, hashed credentials)The Customer directly; the Customer's use of the dashboardCreating and securing accounts, authentication, support, communicationsCloud hosting (AWS); the Customer
Billing and payment data (tokens, last4, plan)The Customer; StripeProcessing subscription payments, fraud prevention, tax and accountingPayment processor (Stripe); cloud hosting (AWS)
Call recordings and transcripts (may include sensitive/health data)The End Caller during a call; generated by the ServicesAnswering, recording, transcribing, and responding to calls at the Customer's directionTelephony (Telnyx, Twilio); speech-to-text (Deepgram); LLM reasoning (OpenAI, Anthropic); text-to-speech (Cartesia, ElevenLabs); cloud hosting (AWS); the Customer
Caller identifiers (phone number, name, appointment details)The End Caller during a call or textHandling the call, booking appointments, calendar/CRM syncTelephony (Telnyx, Twilio); Google (Calendar, if connected); the Customer's connected CRM; cloud hosting (AWS); the Customer
SMS content and messaging metadataThe Customer's direction; the End Caller's repliesSending and receiving messages, appointment reminders, opt-out handlingTelephony/SMS (Telnyx, Twilio); cloud hosting (AWS); the Customer
Usage and technical data (IP, device, cookies, analytics)Automatically from your device and browserSecurity, troubleshooting, reliability, product improvementCloud hosting (AWS); analytics providers (see Cookies section)

5. 5. How We Use Information

We use information to provide, operate, secure, and improve the Services. Specifically, we use it to:

  • Answer, record, transcribe, and summarize calls, and understand and respond to callers in real time.
  • Send and receive SMS messages, book appointments, and sync with Google Calendar or a connected CRM at the Customer's direction.
  • Process transcript text through large language models to generate appropriate spoken and written responses during a call.
  • Create the Customer's account, authenticate logins, provide the dashboard, and deliver support.
  • Process subscription payments and prevent fraud (via Stripe).
  • Monitor, troubleshoot, secure, and improve reliability and quality of the Services.
  • Comply with legal obligations and enforce our agreements.

5.1 What We Do NOT Do With Personal Information

We want to be unambiguous about certain uses:

  • We do NOT sell personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under California and other state privacy laws.
  • We do NOT use End-Caller call content — recordings or transcripts — to train third-party foundation models. Our AI subprocessors (including OpenAI and Anthropic) process call text transiently to generate responses. We configure our use of these services to prohibit the use of our data to train foundation models and to apply zero- or limited-retention API terms where those terms are available; we describe our vendors' commitments accurately rather than making assurances about vendor settings we do not control.
  • We do NOT use End-Caller call content for cross-context behavioral advertising or for building advertising profiles.
  • We do NOT use audio to create a biometric voiceprint (see the Biometrics section).

6. 6. Text Messaging, SMS, and the TCPA

Ansabell sends and receives SMS text messages on a Customer's behalf and only at the Customer's direction — for example, appointment confirmations, reminders, and replies to callers. Messaging is regulated by the Telephone Consumer Protection Act (TCPA), 47 U.S.C. 227, and FCC rules.

  • Consent is the Customer's responsibility: The Customer must have the legally required consent to text each recipient, and must obtain prior express written consent before any marketing or promotional text is sent. Ansabell does not send marketing messages on its own initiative.
  • Opt-out (STOP): Recipients can opt out of further messages at any time by replying STOP (or another recognized opt-out keyword). We honor opt-outs and propagate them so that a recipient who opts out stops receiving messages.
  • Help (HELP): Recipients can reply HELP to receive assistance and contact information.
  • Rates: Message and data rates may apply, and message frequency varies by Customer and use.
  • Direction and records: Because Ansabell acts as the Customer's messaging conduit, the Customer is responsible for the content it directs us to send and for maintaining records of consent.

If you received a text you did not expect from a business using Ansabell, reply STOP to stop messages and contact that business directly; you may also contact us at privacy@ansabell.com and we will assist the Customer as their processor.

7. 7. Subprocessors and Service Providers

We use the trusted third-party service providers ("subprocessors") listed below to deliver the Services. Each is bound by contractual obligations to protect the data they process and to use it only to provide their service to us. A current list is maintained here and in our DPA.

SubprocessorPurposeData Involved
TelnyxTelephony and SMS delivery (primary)Call audio, phone numbers, SMS content, call/message metadata
TwilioTelephony and SMS delivery (secondary/fallback)Call audio, phone numbers, SMS content, call/message metadata
DeepgramSpeech-to-text transcriptionCall audio, resulting transcript text
CartesiaText-to-speech voice generationResponse text converted to spoken audio
ElevenLabsText-to-speech voice generationResponse text converted to spoken audio
OpenAILarge language model reasoningTranscript/call text processed transiently to generate responses; we contract to prohibit use of our data for foundation-model training and to apply zero/limited-retention terms where available
AnthropicLarge language model reasoningTranscript/call text processed transiently to generate responses; we contract to prohibit use of our data for foundation-model training and to apply zero/limited-retention terms where available
StripePayment processingBilling details; tokenized card data and last4 (no full card numbers stored by us)
Amazon Web Services (AWS)Cloud hosting and encrypted storage (Amazon S3), U.S. regionRecordings, transcripts, account and application data at rest
GoogleGoogle Calendar integration (only if the Customer connects it)Appointment/booking details written to the Customer's calendar

We may update this list as our operations evolve. Where we act as a processor, we will provide Customers a mechanism to receive notice of new subprocessors as described in the DPA. The subprocessors that may receive call content potentially containing consumer health data are identified in Section 11 and in our Consumer Health Data Privacy Policy.

8. 8. How We Disclose Information

We disclose information only as described here:

  • To the Customer: End-Caller data we process is made available to the Customer whose line was called, through the dashboard, exports, and integrations.
  • To subprocessors: as listed above, solely to provide the Services.
  • For legal reasons: to comply with applicable law, a subpoena, court order, or lawful government request; to enforce our terms; or to protect the rights, safety, and property of Ansabell, our Customers, End Callers, or the public.
  • Business transfers: if Ansabell or Haven Technologies is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy and, where applicable, the DPA. We will provide notice as required by law.
  • With consent or direction: at the Customer's direction, or with the applicable person's consent.

We do not disclose personal information for money or other valuable consideration in a manner that constitutes a "sale" under applicable privacy laws, and we do not sell or share consumer health data.

9. 9. Data Retention

We retain personal information only as long as needed for the purposes described in this Policy, and we disclose below the retention period, or the criteria used to determine it, for each category, consistent with Cal. Civ. Code 1798.100(a)(3).

9.1 End-Caller Call and Messaging Data (Customer-configurable)

Call recordings, transcripts, appointment details, and message content are retained according to the Customer's settings. By default, recordings and transcripts are retained for 90 days and then deleted or de-identified, and the Customer may configure a shorter or longer period (subject to plan limits) or trigger earlier deletion. The Customer, as controller, may adjust retention and request deletion or export through the dashboard or by contacting us.

9.2 Account and Billing Data (we are controller)

Account data is retained for as long as the Customer maintains an account and for up to 90 days after account closure to allow reactivation and wind-down. Billing, tax, and transaction records are retained for up to 7 years to meet legal, tax, accounting, and recordkeeping obligations and to resolve disputes.

9.3 Backups and Logs

Encrypted backups are retained on a rolling basis for up to 35 days before being overwritten. Operational and security logs are retained for up to 18 months, after which they are deleted or de-identified. Data deleted from active systems may persist in backups until the backup rotates out on this schedule.

9.4 Account Closure

When a Customer's account is closed, we delete or de-identify the End-Caller data we process on that Customer's behalf within 90 days, except where retention is required by law or permitted under the DPA, and subject to the backup rotation window above.

10. 10. Security and Breach Notification

We maintain administrative, technical, and physical safeguards designed to protect information appropriate to its sensitivity, including:

  • Encryption of data in transit (TLS) and at rest (including recordings and transcripts stored in Amazon S3).
  • Access controls, authentication, and least-privilege permissions limiting who can access data.
  • Hashing of passwords and tokenization of payment data (via Stripe).
  • Network protections, logging, and monitoring for unauthorized access.
  • Vendor diligence and contractual data-protection commitments from subprocessors.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Customers are responsible for safeguarding their login credentials and for configuring their account and integrations securely.

If we experience a breach of security affecting personal information, we will notify affected parties and regulators as required by applicable law, including Washington's data-breach notification statutes (RCW 19.255.010 and, for state agencies, RCW 42.56.590), and other state and federal breach-notification laws. Where we act as a processor, we will notify the affected Customer without undue delay as set out in the DPA so the Customer can meet its own notification obligations.

11. 11. Consumer Health Data (Washington My Health My Data Act)

Ansabell is used by healthcare-adjacent businesses — including dental, medical, med spa, veterinary, and chiropractic practices — and calls to those businesses may reveal information that relates to a person's health. Washington's My Health My Data Act (MHMDA), RCW 19.373, imposes specific requirements when consumer health data is collected, used, or shared.

IMPORTANT: Consumer health data is also governed by our separate, standalone Consumer Health Data Privacy Policy, which we maintain in addition to this Policy and make available through a distinct, prominent link on the Ansabell homepage, as RCW 19.373.020 requires. The disclosures below summarize that standalone policy; the standalone policy controls for consumer health data.

"Consumer health data" means personal information linked or reasonably linkable to a consumer that identifies that consumer's past, present, or future physical or mental health status — for example, an appointment reason, a symptom, a diagnosis, or a treatment mentioned during a call.

11.1 Categories of Consumer Health Data We Collect and Why

We may collect consumer health data that an End Caller voluntarily states during a call or text, such as the reason for an appointment, symptoms described, medications or treatments mentioned, provider or specialty requested, and health-condition details relevant to scheduling. We collect this data solely to provide the AI receptionist service — answering the call, transcribing it, and booking or routing the request — at the direction of the Customer, and only as necessary to do so.

11.2 Sources of Consumer Health Data

The source of consumer health data is the End Caller, who provides it directly during a phone call or text message to a Customer's Ansabell-powered line. We do not purchase consumer health data or acquire it from data brokers.

11.3 Categories of Third Parties and Affiliates With Whom We Share It

To provide the Services, call content that may contain consumer health data may be processed by the following categories of subprocessors, acting on our and the Customer's behalf: telephony providers (Telnyx and Twilio), speech-to-text transcription (Deepgram), large language model reasoning (OpenAI and Anthropic), and cloud hosting and encrypted storage (Amazon Web Services). The processed data is made available to the Customer whose line was called. We do not share consumer health data with affiliates for their own purposes, and we do not share it for advertising.

11.4 Our Role and the Customer's Consent Obligations

When Ansabell handles consumer health data revealed during a call, we do so as a processor at the direction of the Customer, which is the entity that has the direct relationship with the consumer. The Customer is responsible for providing the notice MHMDA requires and for obtaining the consumer's consent before consumer health data is collected or shared, where such consent is required. Ansabell processes this data solely to provide the Services.

11.5 No Selling of Consumer Health Data

We do NOT sell consumer health data, and we do not authorize any subprocessor to sell it. Neither Ansabell nor a Customer using Ansabell may sell consumer health data without a valid, separate written authorization that meets MHMDA's requirements. We do not use geofencing around any facility that provides health-care services to identify, track, or send messages to consumers.

11.6 How to Exercise Consumer Health Data Rights

Consumers have the right to (a) confirm whether their consumer health data is being collected, shared, or sold and to access that data; (b) withdraw consent to the collection and sharing of their consumer health data; and (c) request deletion of their consumer health data. To exercise these rights with respect to data an Ansabell Customer holds, contact that business directly. You may also contact us at privacy@ansabell.com, and we will assist the relevant Customer or, where we are the controller, respond directly. Violations of MHMDA are enforceable under the Washington Consumer Protection Act, RCW 19.86.

12. 12. Biometric Identifiers (No Voiceprints)

Ansabell does NOT enroll, create, capture, or use biometric voiceprints or any other biometric identifier for identification purposes. We do not use voice audio as a biometric to identify or authenticate any individual.

When Ansabell processes call audio, it converts speech to text (transcription) so the AI can understand and respond. That audio is not used to generate a biometric identifier within the meaning of Washington's biometric-identifiers law, RCW 19.375, and we do not sell or disclose any biometric identifier because we do not create one.

13. 13. Your Privacy Rights (U.S. State Laws)

Depending on where you live, you may have rights under state privacy laws, including the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and the comprehensive privacy laws of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah, Texas, Oregon, and Montana. These rights may include the right to:

  • Know and access the personal information we hold about you and how it is used and disclosed.
  • Delete personal information, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Obtain a portable copy of your personal information.
  • Opt out of the sale of personal information and of targeted/cross-context behavioral advertising.
  • Opt out of certain profiling in furtherance of decisions that produce legal or similarly significant effects.
  • Limit the use and disclosure of sensitive personal information (see 13.2).
  • Not receive discriminatory treatment for exercising your rights.

As stated above, Ansabell does NOT sell personal information and does not use End-Caller call content for targeted or cross-context behavioral advertising, so there is no such activity to opt out of.

13.1 Automated Call Handling and Profiling

The Services use AI to answer calls, transcribe speech, generate responses, and schedule appointments at the Customer's direction. This automated call handling supports the human-run business; it does not make solely automated decisions that produce legal or similarly significant effects about you (such as eligibility for credit, employment, housing, or insurance), and we do not use End-Caller data for profiling to make such decisions. Where a Customer configures the Services in a way that could constitute such profiling, the Customer is the controller responsible for honoring any applicable opt-out under the Colorado, Connecticut, and Virginia laws, and we will support the Customer as its processor.

13.2 Sensitive Personal Information (CCPA/CPRA)

Call recordings and transcripts may contain sensitive personal information (SPI) under the CPRA — most commonly health information, and potentially precise geolocation or other sensitive details a caller volunteers. We collect and process SPI only to provide the Services at the Customer's direction and for the related purposes permitted under Cal. Civ. Code 1798.121 (for example, to perform the service, ensure security and integrity, and detect and prevent fraud). We do not use or disclose SPI to infer characteristics about a consumer or for any purpose outside those permitted business purposes. Because our use is limited to these exempt purposes, the CPRA right to limit the use and disclosure of SPI does not require any change to how we handle it; you may nonetheless contact us with questions or requests as described below.

13.3 How to Exercise Your Rights, Verification, and Appeals

If your information was collected because you called or texted a business that uses Ansabell, that business is the controller of your data. Please direct your request to that business; we will support them as their processor. For account data where we are the controller, or if you are unsure whom to contact, email privacy@ansabell.com with your request and enough detail to locate your information. We will verify your identity before responding — typically by confirming information already associated with your account or the relevant phone number — and will act within the timeframes required by applicable law (generally within 45 days, extendable once by an additional period where the law allows). You may use an authorized agent where the law permits.

If we decline your request, you may appeal by replying to our decision or emailing privacy@ansabell.com with "Appeal" in the subject line. We will respond to appeals within the statutory deadline (within 45 days under the Virginia, Colorado, and Connecticut laws, extendable by 60 days where permitted, and within 60 days under Texas), and we will explain our reasoning. If your appeal is denied, we will provide a method to contact your state Attorney General to submit a complaint.

14. 14. HIPAA and Covered Entities

Some Customers are "covered entities" or their business associates under the Health Insurance Portability and Accountability Act (HIPAA). Ansabell offers a Business Associate Agreement (BAA) to such Customers and, under an executed BAA, acts as a Business Associate with respect to the protected health information (PHI) processed through the Services. Ansabell enters into a BAA or equivalent written commitment with each subprocessor that processes PHI on its behalf, including its cloud infrastructure provider, Amazon Web Services.

If you are a covered entity or handle PHI, you may use the Services to create, receive, maintain, or transmit PHI only under a mutually executed BAA. Absent an executed BAA, you must not submit PHI, and the Customer is responsible for ensuring PHI is not submitted into the Services until a BAA is in effect.

15. 15. International Data Transfers (GDPR / UK GDPR)

Ansabell is operated from the United States, and our infrastructure (including AWS hosting and Amazon S3 storage) is located in the United States. If you access the Services or your data is processed from the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred to and processed in the United States.

Where the EU or UK GDPR applies, we process ordinary personal data on a lawful basis such as performance of a contract, our or the Customer's legitimate interests, legal obligation, or consent, as applicable, and, for the End-Caller data we process, on the Customer's documented instructions as processor.

15.1 Special-Category (Health) Data

Where a call reveals health information or other special-category data within the meaning of Article 9 of the GDPR, we do not rely on legitimate interests. Instead, such data is processed on the basis of the End Caller's explicit consent obtained by the Customer as controller (Article 9(2)(a)), and/or the Customer's other applicable Article 9 condition, with Ansabell processing that data only on the Customer's documented instructions as processor. The Customer is responsible for establishing a valid Article 9 condition before special-category data is processed through the Services.

15.2 Transfer Safeguards

For international transfers, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, incorporated through our DPA. EEA/UK/Swiss data subjects may have rights to access, correct, delete, restrict, object to, and port their data, and to lodge a complaint with a supervisory authority. Requests concerning End-Caller data should be directed to the relevant Customer as controller.

15.3 EU and UK Representatives (Article 27)

Ansabell is established in the United States and does not target its services to individuals in the EEA or the United Kingdom, and we have not appointed a representative under Article 27 of the GDPR or UK GDPR. If our processing later requires one, we will designate a representative and update this Policy. In the meantime, individuals in the EEA or UK may contact us about our processing at privacy@ansabell.com, or by writing to Haven Technologies, Inc., 2103 Harrison Ave SW, Ste 1034, Olympia, WA 98502, USA.

16. 16. Children's and Minors' Privacy

The Services are intended for businesses and are not directed to children. Consistent with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 other than as an incidental part of a call an End Caller placed to a Customer, we will delete it.

Separately, the Services are not directed to minors under 16, and we do not knowingly sell or share the personal information of consumers under 16, consistent with the CCPA/CPRA and, for EEA/UK users, applicable minimum-age rules under the GDPR. If you believe a child's or minor's information has been provided to us, contact privacy@ansabell.com.

17. 17. Cookies and Analytics

Our website and dashboard use cookies and similar technologies for authentication, security, remembering preferences, and understanding how the Services are used. Some cookies are strictly necessary to operate the dashboard; others support analytics.

17.1 Cookie Inventory

Cookie / TechnologyCategoryPurposeTypical Duration
Session / auth cookieStrictly necessaryKeeps you logged in and secures the dashboardSession to 30 days
CSRF / security tokenStrictly necessaryProtects against cross-site request forgerySession
Preference cookieFunctionalRemembers settings such as language and displayUp to 12 months
Analytics cookieAnalytics / performanceMeasures usage and improves the ServicesUp to 24 months

17.2 Your Choices and EU/UK Consent

You can control cookies through your browser settings, though disabling strictly necessary cookies may affect functionality. For users in the EEA and the UK, we obtain prior consent before setting non-essential cookies (including analytics cookies) through a cookie banner or consent tool, consistent with the ePrivacy Directive and the GDPR; strictly necessary cookies are set without consent.

17.3 Global Privacy Control

For users covered by the CPRA and comparable state laws, we treat a Global Privacy Control (GPC) or similar browser opt-out signal as a valid request to opt out of the sale or sharing of personal information. Because we do not sell personal information or use it for cross-context behavioral advertising, we do not use advertising or tracking cookies for those purposes, and we do not disclose personal information for cross-context behavioral advertising regardless of the signal.

18. 18. Subscriptions and Auto-Renewal

Ansabell is offered as an auto-renewing subscription. The specific auto-renewal terms — including the price, the renewal cadence (for example, monthly or annually), how and when you are billed, and how to cancel through the dashboard or by contacting us — are disclosed in our Terms of Service and at the point of purchase, consistent with Washington's subscription auto-renewal requirements and the federal Restore Online Shoppers' Confidence Act (ROSCA) and FTC rules. We provide a clear and easy method to cancel to prevent future renewals. This Policy addresses the handling of billing information; please refer to the Terms of Service for the operative auto-renewal and cancellation terms.

19. 19. Electronic Records and Communications

By creating an account and using the Services, you consent, under the federal E-SIGN Act and the Washington Uniform Electronic Transactions Act (UETA), to transact electronically and to receive this Policy, agreements, disclosures, and notices in electronic form. You may withdraw this consent by closing your account, though doing so may prevent you from continuing to use the Services.

20. 20. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the Effective Date above and provide notice through the Services or by other reasonable means. Your continued use of the Services after an update takes effect constitutes acceptance of the revised Policy.

21. 21. Contact Us and How to Submit a Request

If you have questions about this Policy or wish to exercise a privacy right, contact us:

If your information relates to a call or text you made to a business that uses Ansabell, that business is the controller of your data; please contact them directly, and we will assist as their processor. To help us respond, please include your name, the relevant phone number, and a description of your request. We will verify your identity before disclosing or deleting information.

Questions about this document? Email legal@ansabell.com.