Legal

Privacy Policy

Last updated September 28, 2026

This policy explains how Spokk US, Inc. (“Spokk”, “we”, “us”) collects, uses and shares personal information when you visit spokk.io, use our apps and services (the “Services”), or receive a message or fill in a form sent by a business that uses Spokk.

We have two roles:

  • For the businesses that use Spokk, their team members and visitors to our website, we decide how information is used, and this policy describes what we do.
  • For the customers, clients and patients of those businesses, we handle information on the business’s behalf and follow its instructions. The business’s own privacy policy also applies. Patients of healthcare practices, see Healthcare practices and HIPAA.

In short: we do not sell personal information, businesses control their customers’ data, you can stop texts at any time by replying STOP, and practices on our Healthcare plan are covered by a signed Business Associate Agreement.

1. Information we collect

From businesses and their team members

  • Account details, such as your name, email address, phone number and role.
  • Business details, such as your business name, locations, website, logo and staff names.
  • Billing details. Payments are handled by Stripe. We see the card brand, last four digits and expiry date, never the full card number.
  • The forms, questions, messages, automations and settings you create.
  • Messages you send our support team.
  • Access to services you connect, such as Google, HubSpot, GoHighLevel, Zoho or your own email server. We store these credentials encrypted.
  • If you bought Spokk through a partner such as AppSumo, your license details.

From businesses, about their customers

Businesses add their customers to Spokk so they can ask them for feedback. This can include names, phone numbers, email addresses, visit or appointment dates, the location visited, the staff member seen, whether the person agreed to receive messages, and loyalty, membership or referral records. It may come from a file the business uploads or from a system it connects.

From people who receive a business’s messages or use its forms

  • Ratings, written feedback and answers to questions.
  • Voice recordings, which are converted to text.
  • Photos and videos, if the business asks for a testimonial and you choose to record one.
  • Review text you draft through Spokk, and whether you went on to post it.
  • Your language preference, and sign-in codes if you use a business’s customer portal.
  • Whether messages were delivered, and whether links in them were opened.

From Google, when a business connects it

Sign-in details (name, email address and profile photo) and, from Google Business Profile, the business’s locations, its public reviews with reviewer names and photos, and its replies. See Google user data.

Automatically

Your IP address (which suggests an approximate location), browser and device type, the pages you visit, the page that referred you, and when you visited. We also use cookies. See our Cookie Policy.

From public sources, for our own sales outreach

To find businesses that may benefit from Spokk, we collect publicly available business information such as business names, websites, public business email addresses and phone numbers, and public reviews. We check that email addresses are valid before we write to them.

2. How we use information

  • To provide the Services. Running accounts and forms, sending messages on behalf of businesses, importing data, syncing reviews, and showing feedback and reports.
  • To avoid asking twice. We compare new public reviews with the people a business has asked, so that someone who has already left a review is not asked again.
  • For AI features. Drafting review text from feedback, suggesting replies to reviews, transcribing voice feedback, translating forms and summarizing feedback. See AI and automated processing.
  • For billing, support and service messages, including onboarding and product emails to account holders.
  • For our own marketing to businesses, by email and through online ads. You can opt out at any time.
  • For security and compliance. Preventing fraud and abuse, enforcing our Terms, honoring opt-outs, and meeting legal obligations.
  • To improve Spokk. Understanding how the product is used, and producing aggregated, de-identified statistics such as industry benchmarks. These never identify a person or a business, and never include information from our Healthcare plan.

3. AI and automated processing

Our AI features send the relevant text to an AI provider and return the result: OpenAI on our standard plans, and Amazon Bedrock on our Healthcare plan. Under their business terms, these providers do not use the data we send them to train their models. We do not train AI models on your information either.

AI output can be wrong. Businesses review suggested replies before publishing them, and a customer decides whether to post a drafted review, and in what words. We do not make decisions about people by automated means that have legal or similarly significant effects.

4. How we share information

We do not sell personal information. We share it only in these situations:

  • With the business you dealt with. Your feedback, answers and contact details go to the business that asked for them.
  • With service providers that process information for us under contract, listed below.
  • With services a business connects. For example, a reply the business approves is posted to Google, and contacts may be imported from HubSpot, GoHighLevel or Zoho.
  • When you post publicly. A review you post on Google or another site is public under that site’s rules. A business may show a testimonial you gave it permission to use.
  • For legal and safety reasons, when the law requires it or to protect the rights and safety of people and of Spokk.
  • In a business transfer, such as a merger or acquisition, under the terms of this policy.
  • With your consent.
Service providerWhat they do for us
SupabaseDatabase, sign-in and file storage for our standard plans
VercelHosting for our website and standard plans
Amazon Web ServicesEmail delivery. For the Healthcare plan, all hosting, storage, messaging and AI
TwilioText message delivery
FitSMSText message delivery to Sri Lankan phone numbers
OpenAIAI drafting, transcription and translation on our standard plans
StripePayments and billing
MuxVideo testimonial hosting and playback
CloudinaryImage and video processing for testimonials
UpstashRate limiting and abuse prevention
LoopsEmails to our account holders
GoogleBusiness email, sign-in, the Business Profile integration, maps, translation of testimonial pages, and website analytics
MetaMeasuring our own advertising
NeetoSupport chat on our website and dashboard
Reoon, Maildoso and FirecrawlResearching businesses, verifying their email addresses and sending our own sales emails

We use advertising and analytics tools from Google and Meta on our marketing website and in the business dashboard, to measure our own advertising. They never load on the forms, portals and other pages that a business’s customers use, and never on our Healthcare plan. Some US state laws call this “sharing” for targeted advertising. See Your choices and rights to opt out.

All the above categories exclude text messaging originator opt-in data and consent; this information won’t be shared with any third parties.

5. Text messages

Businesses use Spokk to text their own customers, and only people who have agreed to receive texts from that business. The business is responsible for collecting that agreement and keeping a record of it. Each business’s messaging terms are published at spokk.io/sms-terms followed by the business’s name.

  • Message frequency varies. Message and data rates may apply.
  • Reply STOP to any message to stop receiving texts. Reply HELP for help.
  • No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.

6. Healthcare practices and HIPAA

Our standard plans are not designed to hold protected health information (PHI), and our Terms do not allow businesses to upload it there.

Healthcare practices covered by HIPAA use our Healthcare plan instead. It runs in a separate, dedicated environment hosted by Amazon Web Services in the United States. Each practice signs a Business Associate Agreement (BAA) with us, and we have one with Amazon Web Services. The Healthcare plan loads no advertising, analytics or chat tools, uses Amazon Bedrock for AI, and we use its data only to provide the service to the practice. The statistics and marketing uses in this policy do not apply to it.

If you are a patient, the practice’s Notice of Privacy Practices explains your rights. Contact the practice to see or correct your information. If you contact us, we will pass your request to the practice.

7. Google user data

What we access. If you sign in with Google, we receive your name, email address and profile photo. If you connect Google Business Profile, we access your business’s locations, reviews (including reviewer names and profile photos) and replies, and we can post replies on your behalf.

How we use it. To sign you in; to show your reviews in Spokk; to match new reviews to the customers you asked; to draft suggested replies, which sends the review text to our AI provider only when a reply is drafted; and to post replies you approve.

What we don’t do. We don’t use Google user data for advertising, sell it, or use it to train AI models. People at Spokk don’t read it unless you ask us to help with your account, or we need to for security or to comply with the law.

Removing access. When you disconnect Google in Spokk, we delete your Google access credentials and the locations and reviews we imported. You can also remove Spokk’s access at myaccount.google.com/permissions.

Spokk’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Cookies

We use cookies to keep you signed in, remember your preferences and, on our marketing website and dashboard only, to measure our advertising. The pages a business’s customers use set only the cookies those pages need to work. Our Cookie Policy lists them.

9. How long we keep information

  • We keep account information and customer data while a business’s account is open. A business can delete its customers’ data, or ask us to, at any time.
  • After an account is closed, we delete its data within 90 days of the business asking us to, and we may delete data from accounts that have been closed or inactive for more than two years.
  • We keep records of opt-outs for as long as we need them to honor the opt-out.
  • We keep invoices and billing records for as long as tax law requires.
  • Deleted information can remain in encrypted backups for a limited time, usually up to 30 days, until those backups are overwritten.
  • Healthcare plan data is kept and destroyed as the practice’s BAA requires.

10. How we protect information

We encrypt information in transit and at rest, store access credentials for connected services encrypted, limit which people and systems can reach personal information, and monitor for misuse. No system is perfectly secure. If a breach affects your information, we will notify you, or the business we work for, as the law requires.

11. Where information is processed

Spokk is based in the United States and stores information in the United States. Some service providers process information in other countries, for example our Sri Lankan text message provider for Sri Lankan phone numbers, and people who work for us may access information from other countries. Where the law requires it, we put appropriate safeguards in place for these transfers, such as standard contractual clauses.

12. Your choices and rights

  • Account holders can update most information in their settings, and can ask us to delete their account.
  • Marketing emails: use the unsubscribe link in any email, or email us.
  • Texts: reply STOP to any message.
  • Advertising cookies: you can block or delete cookies in your browser, and adjust ad settings at Google and Meta.

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict how we use it, to opt out of targeted advertising, and to withdraw consent you have given. To make a request, email hello@spokk.io or use our support page. We will verify your request, respond within the time the law requires, and not treat you differently for making it. You can use an authorized agent, and you can appeal a decision by replying to our response.

If you are a customer of a business that uses Spokk, please contact that business first, because it controls your information. If you contact us, we will pass your request on or act on the business’s instructions.

If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on these legal bases: performing our contract with you; our legitimate interests in running, securing, improving and marketing Spokk to businesses; your consent, where the law requires it; and complying with the law. You can complain to your local data protection authority.

13. Children

Spokk is a service for businesses and is not directed to children. We do not knowingly collect personal information from children under 13, and businesses must not use Spokk to contact children under 13 directly. If you believe a child has given us information, contact us and we will delete it.

14. Do Not Track

Our website does not currently respond to Do Not Track signals from browsers.

15. Changes to this policy

We will update the date at the top of this page when we change this policy. If we make a material change, we will tell account holders by email or in the dashboard before it takes effect.

16. Contact us

Spokk US, Inc.
651 N Broad St, Suite 201, Middletown, DE 19709, United States
hello@spokk.io

Terms of ServiceCookie PolicySpokk US, Inc., 651 N Broad St, Suite 201, Middletown, DE 19709, United States