Legal · Data Governance

Privacy Policy

How Simply Sterling AI collects, uses, stores, and protects information across our HVAC operational automation, intake, dispatch-triage, and quote-recovery systems — including A2P 10DLC messaging.

Last Updated: September 29, 2026

1. Introduction

Simply Sterling AI ("Simply Sterling," "we," "us," or "our") builds operational infrastructure — automated intake, dispatch-triage, and quote-recovery systems — for residential and commercial HVAC contractors. This Privacy Policy explains how we collect, use, store, share, and protect information in connection with our services.

We act as a service provider and data processor on behalf of our clients (the HVAC businesses that engage us). The end customers of those businesses — homeowners and commercial contacts whose information flows through the pipelines we build — are the clients' customers, not ours. This policy addresses both relationships.

2. Information We Collect

Client business information: company name, owner and manager contact details (name, mobile number, email), dispatch and CRM platform identifiers, and configuration details needed to build and operate your workflows.

End-customer information (processed on behalf of clients): names, phone numbers, email addresses, property addresses, service and equipment history, quote details, and consent records captured through intake forms, calls, and SMS interactions.

Usage and diagnostic data: system logs, message delivery status, routing outcomes, and performance metrics generated as our pipelines operate. This data is used to monitor reliability and improve routing logic.

3. How We Use Information

We use client business information to scope, build, stage, and maintain your operational pipelines, and to communicate with you about your engagement.

We use end-customer information solely to operate the automated intake, triage, follow-up, and re-engagement workflows you have commissioned — for example, qualifying an after-hours emergency call, re-engaging an unsold quote, or routing a surge-period replacement candidate to priority dispatch.

We use diagnostic data to detect failures, tune routing rules, and report on pipeline performance to the engaging client. We do not use end-customer data to build generalized models, and we do not sell or rent contact information to third parties.

5. A2P 10DLC Messaging & SMS Privacy

Where our services include application-to-person (A2P) text messaging using 10-digit long code (10DLC) numbers, messages are provisioned under the U.S. A2P 10DLC framework administered by The Campaign Registry and the major mobile carriers.

End customers receive messaging only where the engaging client has obtained appropriate consent and registered an appropriate campaign use case. Message and data rates may apply to recipients. Recipients may reply STOP at any time to opt out of SMS messages, and HELP for support; opt-out preferences are honored across our routing infrastructure.

We do not send, and our systems are configured to reject, content prohibited by carrier rules, including SHAFT categories (sex, hate, alcohol, firearms, tobacco) and any content that violates applicable law.

6. Sharing & Subprocessors

We share information only as necessary to deliver the services: with the dispatch and CRM platforms you connect (such as ServiceTitan, Housecall Pro, FieldEdge, Jobber, and HighLevel), with messaging and telephony carriers that transport SMS and calls, and with infrastructure providers that host and route data.

We do not share end-customer data with your direct competitors, and we do not use it to provide services to them. A current list of categories of subprocessors can be provided to active clients on request.

We may disclose information where required by law, court order, or to protect our rights, safety, or the safety of others, and in connection with a merger, acquisition, or asset sale subject to confidentiality obligations.

7. Data Retention

We retain client and end-customer data for as long as needed to operate the commissioned workflows and for the period specified in your engagement letter. After an engagement ends, we wind down active automations and, unless a longer period is required by law or agreed in writing, delete or de-identify operational data within a defined transition window.

Diagnostic and aggregate metrics may be retained in de-identified form for reliability analysis and service improvement, but are not attributable to specific end customers.

8. Security

We apply reasonable technical and organizational measures to protect data in transit and at rest, including access controls, encryption of transmission channels, and least-privilege access for personnel.

No system is perfectly secure. We will notify affected clients without undue delay of any confirmed security incident affecting their data, to the extent required by applicable law and our engagement terms, and cooperate in any required notifications to their customers or regulators.

9. Your Rights & Choices

Clients may request access to, correction of, or deletion of the business and configuration data we hold on their behalf, and may instruct us to export or purge end-customer data stored within their pipelines.

End customers of our clients should direct privacy requests — including access, deletion, and opt-out of automated outreach — to the HVAC business that engaged us; we will cooperate with that business to fulfill valid requests. Recipients of SMS may opt out at any time by replying STOP.

10. Children's Privacy

Our services are directed to HVAC businesses and their adult customers. We do not knowingly collect personal information from children, and our messaging workflows are not designed to target minors. If you believe a minor's information has been processed through a client pipeline, contact us and we will investigate and take appropriate action.

11. International & Cross-Border Data

Our services are primarily directed to HVAC contractors operating in the United States. Where data is processed or stored by infrastructure providers located outside the United States, we rely on appropriate transfer safeguards and limit the data shared to what is necessary to deliver the service.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active clients in advance and posted with an updated revision date. Continued use of the services after changes take effect constitutes acknowledgment of the revised policy.

13. Contacting Us

If you are a client or a client's customer with a privacy question or request, contact us using the details below. We will acknowledge requests within a reasonable timeframe and respond in accordance with applicable law and your engagement terms.

Privacy Questions or Requests?

Reach our team directly for access, correction, deletion, or opt-out requests.