← Front Row Desk

Privacy Policy

Effective Date: September 20, 2026

Overview: Front Row Desk provides communications software to businesses. Each customer business controls the customer information processed in its workspace (acting as Data Controller); Front Row Desk processes that information on the business's behalf (acting as Data Processor).

1. Scope & Roles (Data Controller vs. Data Processor)

Front Row Desk ("we", "us", or "our") provides business communications, AI orchestration, scheduling, and CRM software to commercial organizations ("Customers"). In the context of data protection laws (including the EU/UK General Data Protection Regulation and the California Consumer Privacy Act): • For Customer Business Accounts: Front Row Desk acts as a Data Controller with respect to account administrative data, business contact information, team credentials, and direct communications between Customer administrators and Front Row Desk. • For End-User Customer Communications: When our Customers use Front Row Desk to receive, process, draft, and send communications to their own clients and prospective customers ("Customer Communications" and "Customer Data"), Front Row Desk acts strictly as a Data Processor / Service Provider. The Customer business controls what data is collected and serves as the Data Controller.

2. Categories of Information We Process

We collect and process the following categories of information: • Account & Identity Information: Business name, business address, administrator name, business email, billing information, and user credentials. • Customer Communications & Inbound Payloads: Message bodies, sender/recipient telephone numbers, email addresses, social profile handles, conversation histories, audio voicemails/transcripts, and file attachments received across connected channels (SMS, WhatsApp, Instagram DM, Facebook Messenger, email, web chat, and voice calls). • Scheduling & Appointments: Appointment titles, dates, times, duration, attendee names, contact details, notes, and calendar identifiers synced via Google Calendar. • CRM & Pipeline Data: Customer names, phone numbers, email addresses, lead sources, deal values, stages, follow-up notes, and task assignments. • Connected Channel Identifiers: Authorization tokens, page access tokens, phone number IDs, and channel credentials necessary to maintain APIs with Meta, Google, Twilio/Sent.dm, and Resend. • Technical & Device Telemetry: IP addresses, browser user agents, session tokens, request timestamps, and diagnostic error logs used to maintain system security and uptime.

3. How We Use Information & Legal Bases for Processing

We process personal information under the following legal grounds and for the following purposes: • Contract Performance: To provide, operate, maintain, and deliver the unified inbox, messaging dispatch, AI drafting, CRM, and appointment scheduling features requested by the Customer. • Legitimate Interests: To monitor system health, detect and prevent telecommunications fraud, troubleshoot errors, enforce security controls, and protect our infrastructure. • Legal Compliance: To comply with applicable statutory, telecommunications, tax, and regulatory obligations (e.g., maintaining required opt-out records under CAN-SPAM and TCPA). • Consent: Where a Customer or end-user has explicitly consented to specific optional features or integrations.

4. Mobile Telephony, SMS & 10DLC Carrier Compliance

Front Row Desk facilitates SMS, MMS, and WhatsApp business communications on behalf of our Customers. We maintain strict adherence to CTIA guidelines, mobile carrier policies, and TCPA requirements: NO MOBILE INFORMATION SHARING (MANDATORY CARRIER CLAUSE): No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties or affiliates. Opt-In & Opt-Out Protocols: • Customers using Front Row Desk represent and warrant that they have obtained verified prior express written consent before transmitting text messages to any recipient. • Recipients may opt out of receiving text messages at any time by replying with standard keywords including STOP, CANCEL, END, QUIT, or UNSUBSCRIBE. • Recipients may request assistance at any time by replying HELP. • Message and data rates may apply. Messaging frequency varies based on the Customer's interaction with the recipient.

5. Google API Services User Data Policy Disclosure

Front Row Desk allows workspace administrators to connect Google services, including Google Calendar (for appointment scheduling and two-way calendar sync) and Google Business Profile (for review monitoring and customer engagement). LIMITED USE DISCLOSURE: Front Row Desk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We request only the minimum required Google OAuth scopes (e.g., viewing and managing calendar events scheduled through the platform, and reading public business profile reviews). Google user data is accessed solely to perform requested calendar and review features and is never used for advertising, surveillance, or transferred to third-party data brokers.

6. Meta Platform Data (Facebook & Instagram)

When a Customer connects Facebook Pages or Instagram Professional accounts via Meta OAuth: • We request only permissions displayed and approved during the authorization flow (such as pages_messaging, instagram_manage_messages, and pages_read_engagement). • We use Page and account access tokens exclusively to receive customer inquiries, transmit authorized replies, publish posts approved by the Customer, and ingest engagement metrics. • We do not sell Meta platform data, use it for third-party advertising profiles, or transfer it to data brokers. • Disconnection and Data Deletion: Workspace administrators can immediately disconnect Meta integrations within workspace settings. For instructions on deleting Meta platform data, please visit our Data Deletion page (https://www.frontrowdesk.com/data-deletion).

7. Artificial Intelligence Processing & Model Training Disclaimers

Front Row Desk incorporates artificial intelligence capabilities provided by reputable AI providers (such as Anthropic Claude, OpenAI, and Voyage AI) to assist with message classification, semantic search caching, and suggested reply drafting. Our Commitments Regarding AI Data: 1. No Public Model Training: We do NOT use Customer Data, customer communications, or personal information to train, retrain, fine-tune, or improve public foundation artificial intelligence models. 2. Isolated Context: Conversation text is submitted to AI APIs transiently over encrypted connections solely to generate responses, classifications, or vector embeddings for the specific customer workspace requesting the action. 3. Assistive Suggestions: AI outputs are generated as suggestions for human review and approval, unless the workspace administrator has explicitly enabled automated auto-reply workflows.

8. Sharing & Subprocessors

We do not sell, rent, or trade personal data. We share information only with trusted third-party service providers ("Subprocessors") strictly necessary to operate Front Row Desk: • Cloud Infrastructure & Hosting: Vercel (frontend and API hosting), Supabase / AWS (database hosting and authentication). • Communications & Dispatch: Twilio / Sent.dm (SMS & WhatsApp telephony), Resend (transactional and outbound email). • Artificial Intelligence: Anthropic, OpenAI, and Voyage AI (assistive language understanding and embeddings). • Third-Party Channel APIs: Meta Platforms, Inc. (Facebook/Instagram), Google LLC (Google Calendar/Business). All subprocessors are bound by data processing agreements requiring confidentiality, strict purpose limitation, and technical security controls equivalent to our own standards.

9. Data Security, Storage & Retention

Security Measures: We maintain robust administrative, physical, and technical safeguards to protect personal data, including: • End-to-end HTTPS / TLS 1.3 encryption for all data in transit. • AES-256 encryption for data at rest. • Strict row-level tenant isolation ensuring one business workspace cannot view another business's data. • Role-based access controls, credential rotation, and multi-factor authentication for production systems. Retention: We retain Customer Data for as long as your workspace account remains active. Operational logs, rate-limiting buckets, and temporary webhook delivery receipts are purged periodically (e.g., within 7 to 30 days). Following account termination, Customer Data is deleted or irreversibly anonymized in accordance with our retention policy, except where retention is required by legal or accounting obligations.

10. Your Privacy Rights (GDPR & CCPA/CPRA)

Depending on your geographic location, you may have specific statutory privacy rights: Under GDPR (EEA/UK Residents): • Right of Access & Data Portability: You may request copies of personal data held about you. • Right to Rectification: You may request correction of inaccurate or incomplete information. • Right to Erasure ("Right to be Forgotten"): You may request deletion of your personal data. • Right to Restrict or Object to Processing: You may object to processing based on legitimate interests. Under CCPA / CPRA (California Residents): • Right to Know: You have the right to know the categories and specific pieces of personal information collected, disclosed, or sold. • Right to Delete & Correct: You have the right to request deletion or correction of your personal data. • No Sale or Sharing of Personal Information: Front Row Desk does NOT sell personal information and has not sold personal information in the preceding 12 months. • Non-Discrimination: We will not discriminate against you in pricing or services for exercising your privacy rights. Exercising Rights: If you are an end-customer communicating with a business that uses Front Row Desk, please contact that business directly (the Data Controller). If you are a workspace account holder or need assistance, contact us at hello@frontrowdesk.com.

11. Cookies & Local Storage

We use strictly necessary session cookies and browser local storage solely to authenticate users, maintain secure active sessions, and preserve workspace user interface preferences. We do not use third-party tracking cookies or behavioral advertising trackers on our authenticated platform.

12. Children's Privacy (COPPA)

Front Row Desk is a B2B business software service designed for commercial enterprises and working professionals. Our Services are not directed to or intended for children under the age of 16. We do not knowingly collect personal information from children.

13. International Data Transfers

Front Row Desk is headquartered and operated in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States and other jurisdictions where our cloud subprocessors operate. We utilize standard contractual clauses and appropriate safeguards where required for cross-border transfers.

14. Updates to This Policy

We may revise this Privacy Policy periodically to reflect enhancements in our Services or changes in legal requirements. Material modifications will be signaled by updating the "Effective Date" at the top of this page and, where appropriate, through an in-app notice or email notification.

15. Contact Us & Data Deletion Requests

For questions, privacy inquiries, or data deletion requests, please reach out to us: Front Row Desk Email: hello@frontrowdesk.com Data Deletion Instructions: https://www.frontrowdesk.com/data-deletion Terms of Service: https://www.frontrowdesk.com/terms