Text.st respects your privacy and is committed to handling personal information responsibly. This Privacy Policy explains how Text.st ("Text.st," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit text.st, use app.text.st, interact with a Text.st-powered website form or widget, communicate through a Text.st-enabled texting number, or otherwise use our websites, applications, and related services (collectively, the "Services").
Text.st AI helps service businesses capture website leads, start SMS conversations, answer questions, understand customer needs, and turn conversations into bookings and other meaningful next steps.
1. Who this Policy applies to
This Policy applies to:
- Website Visitors: people who visit Text.st websites or contact Text.st directly.
- Customers: businesses that create or use a Text.st workspace, including workspace owners, administrators, and team members.
- End Users: people who interact with a Customer through a Text.st-powered widget, form, text conversation, booking flow, or support channel.
For personal information that Text.st collects directly for our own website, account administration, subscriptions, compliance, security, and support, Text.st determines why and how the information is processed.
For leads, messages, bookings, and other information processed through a Customer's workspace, the Customer generally determines why the information is processed, and Text.st processes it on the Customer's behalf. The Customer's privacy policy and notices may also apply. If you are an End User with a privacy request about a business you contacted, please contact that business first. We will assist our Customer in responding where required.
2. Personal information we collect
The information we collect depends on how you use the Services.
2.1 Account and sign-in information
When you create or access a Text.st account through an external identity account, we may receive your name, email address, profile image, unique account identifier, authentication status, and related sign-in or session information. We do not receive the password you use with the external identity service.
2.2 Business and workspace information
We may collect your business name, website, business address, service area, industry, business description, products or services, operating hours, availability, team details, authorized contacts, workspace settings, business knowledge and instructions supplied to Text.st AI, texting-number preferences, lead-flow settings, and booking rules.
2.3 Messaging-registration and compliance information
To provision numbers and support messaging compliance, we may collect information submitted through A2P 10DLC, toll-free verification, campaign registration, number-provisioning, and related carrier or compliance forms. This may include:
- legal business name, trade name, entity type, registration jurisdiction, business address, website, and industry;
- tax or business-registration identifiers;
- the name, title, email address, and phone number of an owner or authorized representative;
- messaging use cases, expected volume, sample messages, and the numbers associated with a campaign;
- descriptions and evidence of how recipients provide consent, including form URLs, screenshots, disclosures, timestamps, and opt-in language; and
- campaign, vetting, verification, carrier, and number-status information.
We use this information to submit, administer, verify, and support messaging registrations and to meet carrier, industry, fraud-prevention, and legal requirements.
2.4 Subscription and transaction information
We may collect your selected plan, billing contact, billing address, transaction history, invoices, subscription status, usage, overage information, and limited payment-related details. Payments are handled by a specialized payment processor. Text.st does not store complete payment-card numbers or card security codes.
2.5 Lead, conversation, and booking information
When an End User submits a Text.st-powered widget or communicates with a Customer, we may process:
- name, phone number, and other contact details the End User chooses to provide;
- service interests, questions, needs, requested times, booking details, and other form responses;
- page URL, source URL, widget or lead-flow identifier, and the Customer contacted;
- message content, conversation history, delivery status, and related timestamps;
- booking status, appointment details, notes, and human-takeover activity; and
- opt-in, opt-out, HELP, and STOP records.
Text messages may contain sensitive or confidential information. Customers should request only information that is reasonably necessary, and End Users should avoid sending highly sensitive information unless it is necessary and appropriate for the interaction.
2.6 Consent records
We may keep records showing when, where, and how consent was provided or withdrawn. These records may include the consent language displayed, phone number, date and time, source page, IP address, browser or device information, user agent, and subsequent opt-out activity. We use these records to operate the Services, honor communication choices, investigate complaints, and help Customers demonstrate compliance.
2.7 Communications with Text.st
We collect information you provide when you contact support, submit a form, request a demonstration, respond to a survey, report a problem, or otherwise communicate with Text.st. This may include contact details, correspondence, attachments, and information needed to resolve your request.
2.8 Information collected automatically
When you use the Services, we may automatically collect:
- IP address and approximate location derived from it;
- browser, device, operating system, language, and time-zone information;
- pages viewed, referring pages, buttons or features used, and dates and times of activity;
- cookie, session, and similar identifiers; and
- diagnostic, security, audit, error, and performance logs.
2.9 Information from third parties
We may receive information from identity and sign-in services, payment and subscription processors, telecommunications networks, carriers, number and campaign-registration organizations, fraud-prevention services, hosting and infrastructure providers, and services a Customer directs us to connect with.
2.10 Inferences and Text.st AI outputs
Text.st AI may generate or process conversation summaries, suggested or automated replies, detected intent, lead status, service needs, booking intent, language, urgency, routing signals, and other inferences used to assist the Customer and continue the conversation.
3. How Text.st uses personal information
We use personal information to:
- provide, operate, maintain, and improve the Services;
- authenticate users and protect accounts;
- create and manage workspaces, widgets, lead flows, conversations, bookings, and settings;
- send, receive, route, and display text messages;
- allow Text.st AI to answer questions, understand requests, qualify and organize leads, suggest next steps, and support bookings;
- enable Customers to pause automation, take over a conversation, add private notes, and manage leads;
- provision texting numbers and complete A2P 10DLC, toll-free, campaign, carrier, and other compliance processes;
- manage subscriptions, invoices, usage allowances, and overage charges;
- deliver transactional, service, security, and administrative communications;
- respond to support requests and resolve technical problems;
- monitor performance, understand feature use, and improve reliability and user experience;
- prevent spam, fraud, abuse, security incidents, and unlawful activity;
- enforce our agreements and protect the rights, safety, and integrity of Text.st, our Customers, End Users, and others; and
- comply with applicable laws, legal process, carrier rules, and regulatory obligations.
We may send marketing communications to Customers and prospective Customers where permitted by law. You may unsubscribe from marketing emails at any time. We may still send essential account, security, billing, compliance, and service communications.
4. How Text.st AI processes information
Text.st AI uses the information provided by a Customer—such as its business profile, instructions, services, availability, and conversation settings—together with relevant End User messages and conversation history to generate replies, summaries, classifications, routing signals, and booking-related actions.
Text.st AI can make mistakes. Customers can review conversations, pause automated replies, take over a conversation, and correct information. Text.st AI is not designed to make decisions that produce legal or similarly significant effects concerning employment, credit, housing, insurance, education, healthcare access, or other high-impact matters.
Text.st does not sell Customer Content or use private Customer Content to train general-purpose AI models for unrelated customers. Service providers supporting AI processing may process Customer Content only to provide, secure, and maintain the applicable service, subject to contractual and legal restrictions.
If Text.st later uses automated decisionmaking in a manner that creates additional notice, access, or opt-out rights under applicable law, we will provide the required controls before or at the time of that use.
5. How we disclose personal information
We may disclose personal information to the following categories of recipients for the purposes described in this Policy:
5.1 Service providers and contractors
We use providers that support cloud hosting, databases, security, authentication, AI processing, customer support, analytics, billing, payment processing, communications, and other technical operations. They may process personal information only for defined services and subject to contractual restrictions.
5.2 Messaging and compliance ecosystem
We may disclose phone numbers, message-routing information, message content, consent records, business-registration data, campaign details, and related technical information to telecommunications providers, carriers, number providers, messaging intermediaries, registration and vetting organizations, and compliance partners as necessary to provision numbers, register campaigns, deliver messages, prevent abuse, and satisfy legal or industry requirements.
5.3 Customers and authorized workspace users
Information submitted through a Customer's widget, form, texting number, or booking flow is made available to that Customer and its authorized workspace users. Workspace owners and administrators may access and manage information associated with their workspace.
5.4 Customer-directed services
We disclose information when a Customer directs us to send it to a connected service, webhook endpoint, booking system, or other recipient. Once information is transferred at the Customer's direction, the recipient's terms and privacy practices apply.
5.5 Legal, professional, safety, and compliance disclosures
We may disclose information to auditors, insurers, legal counsel, accountants, and other professional advisers where reasonably necessary. We may also disclose information when we reasonably believe it is necessary to comply with law, regulation, subpoena, court order, or legal process; respond to lawful government requests; protect rights or safety; investigate fraud, spam, or abuse; enforce agreements; or establish, exercise, or defend legal claims.
5.6 Business transactions
We may disclose information in connection with a financing, merger, acquisition, reorganization, sale of assets, or similar transaction. Any recipient will be required to handle personal information consistently with applicable law and the commitments made in this Policy.
5.7 Aggregated or deidentified information
We may use and disclose information that has been aggregated or deidentified so that it cannot reasonably be linked to an individual. We will not attempt to reidentify deidentified information except to test whether our deidentification measures are effective or as otherwise permitted by law.
6. No sale of personal information or use for targeted advertising
Text.st does not sell personal information for money or other valuable consideration. Text.st does not share personal information for cross-context behavioral advertising, and we do not use private Customer Content for targeted advertising.
We do not sell, rent, or disclose mobile phone numbers, SMS opt-in data, or messaging-consent records to third parties or affiliates for their own marketing or promotional purposes. We may disclose this information only to the Customer on whose behalf the communication occurs, to providers and carriers that help deliver or secure the messaging service, to registration or compliance organizations, or where disclosure is required by law.
We have not sold or shared personal information for these purposes during the preceding 12 months, and we do not knowingly sell or share the personal information of people under 16.
7. Cookies, analytics, and browser choices
Text.st may use cookies, local storage, pixels, and similar technologies to keep users signed in, remember preferences, secure the Services, understand site and feature usage, diagnose problems, and improve performance.
Some service providers may collect device and usage information when performing services for us. We do not permit them to use private Customer Content for their own targeted advertising.
Because there is no universally accepted standard for browser "Do Not Track" signals, the Services may not respond to those signals. Where required by law, we recognize legally valid opt-out preference signals, such as Global Privacy Control, as requests to opt out of sale or sharing for the browser or device sending the signal. Because Text.st does not sell or share personal information for cross-context behavioral advertising, such a signal does not change our current practices.
You can control cookies through your browser settings. Disabling essential cookies or storage may prevent parts of the Services from working correctly.
8. SMS choices and consent
Customers are responsible for sending messages only when they have a lawful basis and any consent required for the type of message being sent. Consent to receive marketing text messages is not a condition of purchasing goods or services.
End Users can opt out of messages from a Customer by replying STOP or by using another reasonable method communicated by the Customer. We may send one confirmation message after an opt-out request. Replying HELP may provide assistance or contact information. Message and data rates may apply, and message frequency varies based on the interaction.
Opting out of one Customer's messages does not automatically opt you out of messages from a different business with which you have a separate relationship. Text.st and its Customers may retain limited suppression and consent records to ensure an opt-out continues to be honored.
9. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, comply with legal and carrier obligations, resolve disputes, prevent abuse, and enforce agreements. The retention period depends on the type of information, the Customer's instructions and workspace settings, the nature of our relationship, and applicable legal or operational requirements.
- Customer Content: Leads, messages, bookings, and related workspace content may remain available while the workspace is active unless the Customer deletes it or asks us to delete it. After a workspace is closed, we delete or deidentify Customer Content within a reasonable period, subject to backups and legal, fraud-prevention, dispute, or compliance requirements.
- Account and transaction records: We retain these records for the relationship and for any additional period required for tax, accounting, fraud-prevention, chargeback, and legal purposes.
- Consent and messaging-compliance records: We may retain these records after messages stop or an account closes when reasonably necessary to honor opt-outs, demonstrate consent, address complaints, or meet carrier and legal requirements.
- Security and technical logs: We retain these for a limited period appropriate to security, diagnostics, fraud prevention, and service reliability.
- Support communications: We retain these as needed to resolve requests, maintain service history, improve support quality, and protect legal rights.
When deletion is required, we take reasonable steps to delete or deidentify the information. Residual copies may remain temporarily in backups or be retained where required by law.
10. Data security
Text.st uses reasonable administrative, technical, and organizational safeguards designed to protect personal information. Depending on the information and system, these safeguards may include access controls, workspace-level data separation, authentication protections, encrypted transmission, logging, monitoring, backups, and restrictions on service-provider access.
No method of transmission or storage is completely secure. We cannot guarantee absolute security. Customers are responsible for maintaining the security of their accounts, limiting workspace access to authorized users, and promptly notifying us of suspected unauthorized access.
If a security incident affects personal information, we will investigate and provide notices as required by applicable law.
11. Your choices and privacy rights
Depending on where you live and our relationship with you, you may have the right to:
- know whether we process your personal information and access that information;
- receive information about the categories, sources, purposes, and recipients of personal information;
- correct inaccurate personal information;
- delete personal information, subject to legal exceptions;
- receive a portable copy of certain information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- opt out of the sale, sharing, targeted advertising, or certain profiling or automated processing, where applicable; and
- appeal a decision we make about a privacy request, where applicable.
To exercise a right concerning information Text.st controls directly, email support@text.st with the subject line Privacy Request. Please describe your request and identify your relationship with Text.st. We may need to verify your identity and authority before completing the request. We will use verification information only for that purpose and will respond within the period required by applicable law.
If your request concerns a conversation, lead, or booking with a Text.st Customer, please contact that Customer. If you contact us, we may refer or transmit your request to the appropriate Customer and assist it in responding.
You may use an authorized agent where permitted by law. We may require proof that the agent is authorized and may ask you to verify your identity directly. We will not discriminate against you for exercising a privacy right.
12. California Notice at Collection and Privacy Rights
This section supplements the rest of this Policy for California residents. The categories below describe personal information Text.st may collect, the sources, why we use it, and the categories of recipients to which it may be disclosed for business purposes.
| California category | Examples | Sources | Business purposes and recipient categories |
|---|---|---|---|
| Identifiers and customer-record information | Name, email address, phone number, business address, IP address, online identifiers, account identifier, billing contact | You, Customers, End Users, sign-in services, payment services, devices and browsers | Provide accounts and Services; communicate; secure the Services; billing and compliance. Disclosed to Customers, infrastructure, identity, support, payment, security, and messaging providers as necessary. |
| Commercial and professional information | Business role, organization, subscription, transactions, invoices, service usage, business profile, products and services | Customers, account users, payment services, Service activity | Operate workspaces; manage subscriptions; support Customers; analyze and improve the Services. Disclosed to payment, infrastructure, support, analytics, and professional advisers as necessary. |
| Internet or other electronic-network activity | Browser and device data, page activity, source and referral URLs, cookies, session information, logs, interactions with widgets and features | Devices, browsers, cookies, Service activity, security and infrastructure providers | Authentication; security; fraud prevention; diagnostics; analytics; service improvement. Disclosed to infrastructure, security, analytics, and technical providers as necessary. |
| Communications and Customer Content | Form responses, message content, conversation history, service requests, lead data, private notes, booking details, support communications | Customers, End Users, account users, communications with Text.st | Provide SMS conversations, Text.st AI, lead management, bookings, human takeover, support, safety, and compliance. Disclosed to the relevant Customer, AI and infrastructure providers, messaging providers and carriers, and Customer-directed services as necessary. |
| Compliance and registration information | Tax or registration identifiers, authorized representative details, consent evidence, opt-in language, campaign use cases, sample messages, number and campaign status | Customers, authorized representatives, registration and vetting organizations, messaging providers, carriers | Number provisioning; A2P 10DLC, toll-free, campaign, and carrier compliance; fraud prevention; dispute handling. Disclosed to relevant messaging, carrier, registration, vetting, compliance, professional, and government recipients as necessary. |
| Approximate geolocation | General location inferred from IP address, country, region, and time zone | Devices, browsers, IP-address information | Security; localization; fraud prevention; diagnostics; service operation. Disclosed to infrastructure, security, and analytics providers as necessary. Text.st does not intentionally collect precise geolocation through the standard Services. |
| Sensitive personal information | Account and session credentials; contents of text messages; tax, government, or business-registration identifiers associated with an individual; payment information handled by a payment processor | You, Customers, End Users, sign-in and payment services, compliance forms | Authenticate users; provide requested communications; process payments; complete compliance registration; prevent fraud and meet legal obligations. Disclosed only as reasonably necessary to provide the Services, at the Customer's direction, or to meet legal and compliance obligations. |
| Inferences | Lead intent, conversation summary, service need, urgency, language, routing signal, qualification or booking status | Information submitted to the Services and Text.st AI processing | Provide Text.st AI features, organize leads, continue conversations, route requests, and support bookings. Disclosed to the relevant Customer and providers supporting AI and Service operations. |
Text.st does not use or disclose sensitive personal information for purposes that require a right to limit under California law. We use it only as reasonably necessary to provide the Services, maintain security, process authorized transactions, satisfy compliance requirements, and perform other legally permitted purposes.
Subject to exceptions and legal applicability, California residents may request access to the categories or specific pieces of personal information collected about them; request correction or deletion; receive information about sources, purposes, and recipients; opt out of sale or sharing; limit certain uses of sensitive personal information; and receive equal service and pricing when exercising their rights.
Text.st does not sell personal information or share it for cross-context behavioral advertising, so there is no sale or sharing to opt out of. We do not offer financial incentives in exchange for personal information. We also do not disclose personal information to third parties for their own direct-marketing purposes.
To submit a California privacy request, email support@text.st with the subject line California Privacy Request. You may make a request to know or access up to the frequency permitted by law. We will verify and respond to requests as required by California law.
13. International users and legal bases
Text.st is based in the United States, and personal information may be processed in the United States and other countries where Text.st or its service providers operate. Those countries may have privacy laws different from the laws where you live. Where required, we use legally recognized safeguards for international transfers.
Where the laws of the European Economic Area, United Kingdom, Switzerland, or another jurisdiction require a legal basis, Text.st relies on one or more of the following:
- Contract: processing necessary to provide the Services or take requested steps before entering a contract;
- Legitimate interests: operating, securing, supporting, and improving the Services; communicating with users; preventing fraud and abuse; and protecting legal rights, where those interests are not overridden by individual rights;
- Legal obligation: complying with applicable laws, lawful requests, tax rules, messaging requirements, and regulatory obligations; and
- Consent: where consent is requested and may be withdrawn.
When Text.st processes Customer Content on a Customer's behalf, the Customer is responsible for establishing the applicable legal basis and providing required notices. Depending on applicable law, individuals may also have rights to object, restrict processing, receive data portability, withdraw consent, or complain to their local data-protection authority.
14. Children's privacy
Text.st accounts are intended for adults acting on behalf of a business. The Services are not directed to children under 13, and we do not knowingly collect personal information directly from children under 13. If you believe a child under 13 provided personal information to Text.st, contact support@text.st so we can investigate and take appropriate action.
Customers must not intentionally use the Services to collect personal information from children in violation of applicable law. Text.st does not knowingly sell or share the personal information of anyone under 16.
15. Third-party websites and services
The Services may link to or connect with websites, applications, and services operated by others. Text.st-powered widgets may also appear on a Customer's website. Text.st does not control the independent privacy practices of a Customer or another third party. Review their privacy notices before providing information.
16. Changes to this Privacy Policy
We may update this Policy as Text.st evolves or legal requirements change. We will post the updated Policy, revise the "Last updated" date, and provide additional notice when required by law. Material changes apply prospectively unless otherwise stated or permitted by law.
17. Contact Text.st
For privacy questions, requests, or complaints, contact:
Text.st Privacy Team
Los Angeles, California, United States
support@text.st
If you have an unresolved concern, you may also have the right to contact the privacy or data-protection authority where you live.
18. Governing law and venue
To the extent a dispute concerning this Privacy Policy is not governed by a mandatory privacy law or by the dispute-resolution provisions in an applicable agreement with Text.st, this Policy is governed by the laws of the State of California, without regard to conflict-of-law principles.
Any such dispute must be brought exclusively in the state or federal courts located in Los Angeles County, California, and the parties consent to the personal jurisdiction and venue of those courts. Nothing in this section limits privacy or consumer rights that cannot lawfully be waived or restricts the authority of a competent regulator.
