Privacy policy
Propel Digital Inc. d/b/a Elllo.ai
Effective Date: October 8, 2026
Last updated: October 8, 2026
1. ABOUT THIS POLICY
This Privacy Policy explains how Propel Digital Inc., an Ontario corporation doing business as Elllo.ai ("Elllo," "we," "us," or "our"), collects, uses, discloses, stores, and protects personal information in connection with the Elllo.ai AI phone assistant, our website, applications, APIs, and related services (the "Service"). The Service is used by individuals for a personal phone line and by businesses as a front desk and outbound calling tool.
Our Privacy Officer is accountable for our compliance with this Policy and with applicable privacy laws, including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial private-sector privacy laws. You can reach the Privacy Officer at contact@elllo.ai or by mail at Propel Digital Inc., Attention: Privacy Officer, 120 Eglinton Avenue East, Suite 202, Toronto, Ontario, M4P 1E2, Canada.
Capitalized terms not defined here have the meanings given in our Terms of Use.
2. OUR TWO ROLES: CUSTOMER DATA AND CALL DATA
We handle personal information in two different roles.
(a) Information about our customers, users, and prospects. When you create an account, request a demo, subscribe, or contact us, we decide how that information is used. We are the organization responsible (the "controller") for it.
(b) Information about Callers. When someone calls a phone number served by Elllo, or receives a call that an Elllo customer scheduled, the Service records, transcribes, and summarizes the call for that customer. The customer decides why the calls are made and answered and what the agent says; we process the resulting Call Content on the customer's behalf as a service provider (a "processor"). The customer is responsible for giving Callers any notice the law requires, including that the call is recorded and handled by an AI agent, and for obtaining any consent required to place outbound calls.
If you called, or were called by, someone using Elllo: the personal information from that call is held for the customer whose number you called or who called you. You can exercise your rights over it with that customer directly, or contact us at contact@elllo.ai and we will identify the customer and forward your request to them, or act on it ourselves where the law requires us to.
3. INFORMATION WE COLLECT
(a) Account and contact information: first and last name, email address, mobile phone number, organization name, role within an organization, plan, and the one-time sign-in codes we send you. When you request a demo, we collect the same details and the outcome of the demo call.
Profile photo (optional): if you add one, we store it encrypted and show it to you and the members of your organization in Elllo and its apps. We remove its embedded metadata (such as location) when you upload it and do not use it for facial recognition. It is deleted when you remove it or close your account.
(b) Agent configuration: the agent name, voice, greeting, instructions, and knowledge-base text you provide, any calendar, booking, or website details you add, and, on business plans, the names and phone numbers of the people you allow your agent to transfer a Caller to. The agent is told those names but never the numbers; the transfer itself is placed by our voice platform.
(c) Call Content (about Callers and about you when you are on a call): the call audio recording, the transcript, the AI-written summary, the Caller's phone number and the name they give, the reason for the call, whether a message was left or an appointment booked, the sentiment and other analysis produced by the agent, the call duration, and the cost of the call.
(d) Outbound call lists: for each person you schedule a call to, the name, phone number, optional email, the purpose of the call, and any message you ask the agent to deliver, plus the scheduled time and the result of each attempt.
(e) Payment information: we use Stripe to process payments. Stripe collects your card details directly; we receive a Stripe customer identifier, a tokenized reference to your payment method, the card brand and last four digits, your billing postal code, and transaction and wallet-balance records. We never receive or store full card numbers or security codes.
(f) Integration data: if you connect Google Calendar, we receive access tokens and read your free/busy availability and create events; if you connect Slack, we receive a workspace identifier and the webhook or channel you choose; if you connect HubSpot, we receive access tokens and the identifier of your HubSpot account; if you connect Telegram, we receive the identifier of your chat with our bot, your Telegram first name and username, and the messages you send to the bot; if you connect WhatsApp, we receive your WhatsApp number and profile name and the messages you send to our WhatsApp number. We store the tokens and identifiers needed to keep the integration working until you disconnect it.
(g) Device, network, and usage information: IP address and the country derived from it, browser and device type, pages and features used, the date and time of requests, and diagnostic logs. We use the IP address to set your default currency, to protect sign-in and sign-up forms against abuse, and to enforce rate limits.
(h) Communications: emails, support requests, feedback, and survey responses you send us.
We do not collect precise geolocation, biometric identifiers, or voiceprints, and we do not try to identify a Caller from the sound of their voice. Call audio is processed to produce a transcript and is not analyzed to build a biometric template. We do not knowingly collect sensitive personal information such as health or financial account details unless a Caller chooses to say it during a call, in which case it is handled only as Call Content for the customer concerned.
4. HOW WE USE INFORMATION
(a) To provide the Service: to answer and place calls, record and transcribe them, generate summaries and notifications, deliver them to your inbox, email, text messages, push notifications, and connected tools, book appointments, and manage your lines and wallet.
(b) To authenticate you and secure the Service: to send one-time sign-in codes, keep you signed in, detect abuse and fraud, and protect our systems.
(c) To bill you: to process subscription payments and wallet reloads, charge usage, send receipts, and detect payment fraud.
(d) To support you and improve the Service: to answer your questions, monitor quality, diagnose problems, and understand how features are used. Our team may review call summaries and, when you ask us for help or we investigate a problem, the underlying transcript or recording.
(e) To communicate with you: to send transactional messages (sign-in codes, call notifications, receipts, low-balance and renewal reminders, security and policy notices) and, where you have opted in or the law otherwise permits, product updates and marketing (see Section 12).
(f) To comply with law and enforce our terms.
We do not sell or rent personal information, and we do not share it for cross-context behavioural advertising.
5. AI PROCESSING AND CALL MEMORY
The agent that speaks with Callers is powered by third-party AI models. During a call, the audio is streamed to a speech-recognition provider, the transcript and your agent's instructions are sent to a large-language-model provider to generate the agent's replies, and the replies are converted to speech by a voice-synthesis provider. After the call, the same model provider produces the summary and extracts details such as the Caller's name and the reason for the call.
Call memory: to let the agent recognize returning Callers, the Service keeps, for each of your lines, the name and summary from a Caller's recent calls (up to the last three) and includes them in the agent's instructions when that phone number calls again. This is done for the customer's line only and is not shared between customers. Call memory is a separate record from the call itself: it is kept for the life of your account so that your agent keeps recognizing returning Callers, even after the call it came from has been deleted or has aged out of your plan's window, and it is deleted with your account.
We do not use your Content or Call Content to train AI models, and our AI providers process it under service-provider terms that do not permit them to train their models on it. The Service does not make decisions about Callers that have legal or similarly significant effects on them; summaries and sentiment are information for the customer to review.
6. HOW WE SHARE INFORMATION
We share personal information only as described here.
(a) Service providers that process data for us, under contracts that restrict them to providing their service to us:
• Vapi (voice-agent platform that runs calls and keeps a copy of each recording until the call is deleted), Deepgram (speech recognition), OpenAI (language model for the agent's replies and summaries), and ElevenLabs (voice synthesis);
• Twilio, Telnyx, and Vonage (phone numbers, call connectivity, and text messages);
• Stripe (payments);
• Mailgun (email delivery, including call notifications and our mailing list), OneSignal (browser and app push notifications), and Slack (call notifications to your workspace when you connect it, and our internal operations channel, which receives the Caller's name and the call summary but not the phone number, transcript, or recording), and Telegram and Meta's WhatsApp Business Platform (call summaries to your own chat or number when you connect them);
• Cloudflare (bot protection on our forms and network delivery), Google Analytics (website usage statistics, see Section 7), and Calendly (demo scheduling on our website);
• Amazon Web Services (cloud storage of call recordings, one audio file per call) and our other hosting and infrastructure providers.
(b) Integrations you connect. When you connect Google Calendar, the Service reads your availability and creates calendar events that include the Caller's name, phone number, and, if provided, email address, and Google may send the Caller an invitation. When you connect Slack, call details are posted to the channel you choose. When you connect HubSpot, after each call we log a record on the matching contact in your HubSpot account — the Caller's name, phone number, email address if we have it, and the call summary with a link back to Elllo, but not the transcript or recording — and we create the contact if one does not already exist. When you connect Telegram, after each call our bot sends your own Telegram chat the Caller's name and phone number, the time and length of the call, and the call summary with a link back to Elllo, but not the transcript or recording; a reply you send to the bot is stored in Elllo as a message for that Caller. When you connect WhatsApp, after each call we send your own WhatsApp number the same details — the Caller's name and phone number, the time and length of the call, and the call summary with a link back to Elllo, but not the transcript or recording — through the WhatsApp Business Platform operated by Meta, and a reply you send there is stored in Elllo as a message for that Caller; you can stop these messages at any time by sending STOP. Records we send to a connected service are stored in your account with that service, under that service's privacy policy and your control; deleting a call in Elllo does not delete the copy already sent to HubSpot, Telegram, WhatsApp, or another connected service. Data sent to a connected service is governed by that service's privacy policy. If you configure webhooks or create an API key (business plans), we send call details to the endpoints you specify and act on requests your own systems make with your key; those endpoints are yours to secure.
(c) Your organization. Authorized Users of your organization can see the Call Content of the lines they have access to, and administrators can see billing and wallet records.
(d) Legal and safety. We may disclose information to comply with law, a court order, or a lawful request from a public authority; to enforce our terms; or to protect the rights, property, or safety of Elllo, our customers, Callers, or the public. Where permitted, we will tell you before disclosing information in response to a legal request.
(e) Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy.
Google API Services: Elllo's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request the calendar.events and calendar.freebusy scopes only, use them solely to check availability and create bookings for your line, do not use Google user data for advertising, and do not allow humans to read it except with your consent, for security purposes, or to comply with law.
7. COOKIES AND SIMILAR TECHNOLOGIES
We use the following cookies and browser storage.
(a) Strictly necessary: a session cookie (PHPSESSID) that keeps you signed in during a visit; a remember-me cookie (ACCOUNT_STATE) that keeps you signed in for up to one year and is cleared when you sign out; a token that protects forms against cross-site request forgery; and a cookie (ELLLO_COOKIE_CONSENT) that records your cookie choice for twelve months. These cannot be switched off while using the Service.
(b) Preferences: a cookie (ELLLO_DARK_MODE) that remembers your light or dark theme for one year.
(c) Analytics: on our production website we use Google Analytics 4, which sets cookies (such as _ga) to measure page views and usage in aggregate. We do not use it for advertising. You can opt out with Google's browser add-on at tools.google.com/dlpage/gaoptout. We ask every visitor before loading Google Analytics: it loads only if you choose Accept in the cookie banner, and nothing is sent to Google if you choose Decline or make no choice. You can change your choice at any time through the "Cookie settings" link in the page footer or on your Account page; switching to Decline removes our analytics cookies and stops analytics on your next page load.
(d) Third-party components: the OneSignal push-notification SDK (which stores a subscription only if you accept your browser's notification prompt), Cloudflare Turnstile on our sign-up form, the Stripe payment element on billing pages, and the Calendly scheduling widget on our marketing pages may set their own cookies or storage under their own policies.
You can delete or block cookies in your browser settings; blocking the strictly necessary cookies will prevent you from signing in.
8. RETENTION AND DELETION
(a) Call Content. How long an inbound call is kept depends on your plan. On the Starter plan, calls are kept for at least thirty (30) days; on the Growth plan, for at least ninety (90) days, both counted from the start of the current month; calls older than that are deleted automatically by a nightly process, recording, transcript, and summary included. On business plans and custom plans, inbound calls are kept until you delete them. Outbound calls are kept until you delete them on every plan. If you move to a plan with a shorter window, the longer window stays in force for thirty (30) days first. Deleting a call in the Service removes it from your inbox at once, and the record and its recording are permanently deleted by the nightly process within a day; a copy of the recording held by our voice platform is deleted at the same time. Recordings are stored in our cloud storage and are accessible only through your account.
(b) Outbound call lists remain until you delete the scheduled calls or close your account. Uploaded lists that you do not confirm are discarded within 24 hours.
(c) Account and billing records are kept while your account is open and for seven (7) years after it is closed, as required for tax, accounting, and fraud-prevention purposes. Wallet ledger entries are kept for the same period.
(d) Demo requests and mailing-list records are kept until you ask us to delete them or unsubscribe.
(e) Server, security, and diagnostic logs are kept for a limited period and then rotated, unless we need to keep specific entries for an investigation or legal obligation.
(f) Closing your account. You can delete your account yourself from the Account page in the Service, or email contact@elllo.ai from the email address on your account. Deletion starts immediately: we end your sessions, cancel scheduled calls, release your phone numbers, disconnect integrations, delete your Content, Call Content, call memory, and call lists, and destroy the encryption keys that protected them, usually within minutes and in any case within thirty (30) days, keeping only the records described in (c) and anything we are legally required to retain. If you are the last full member of an organization, its view-only members and the organization itself are deleted with you. Backups are overwritten on their normal cycle after deletion.
9. SECURITY
We protect personal information with administrative, technical, and physical safeguards appropriate to its sensitivity. All data is encrypted in transit between you, our servers, and our providers using TLS (versions 1.2 and 1.3). Call Content and the personal information in our database — transcripts and summaries, names, phone numbers, email addresses, and call memory — are encrypted at rest under keys that are separate for each customer, wrapped by a master key kept outside the database, and destroyed when an account is deleted. Our other safeguards include signed authentication tokens and one-time sign-in codes instead of passwords, access to production systems and Call Content limited to personnel who need it, per-account access checks on every call record and recording link, rate limiting and bot protection on public forms, and hosting with providers that maintain their own physical and infrastructure security programs. No system is completely secure. If we become aware of a breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify you and the applicable regulators as required by law.
10. WHERE INFORMATION IS STORED AND INTERNATIONAL TRANSFERS
We are based in Canada. Our application database and the service providers listed in Section 6, including the cloud storage that holds call recordings, the voice platform, and our AI, telephony, email, and payment providers, operate primarily in the United States. Personal information, including Call Content, is therefore transferred to, stored, and processed in the United States, where it may be accessible to authorities under United States law. We use contracts with our providers that require them to protect personal information to a standard comparable to this Policy. Customers in Quebec should note that personal information is communicated outside Quebec as described here; we have assessed those transfers as required by Quebec's private-sector privacy law. If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on standard contractual clauses or other approved mechanisms for transfers to Canada and the United States.
11. YOUR RIGHTS AND CHOICES
Subject to applicable law, you may ask us to give you access to the personal information we hold about you, to correct it, to delete it, to stop using it for a particular purpose, or to provide it in a portable format, and you may withdraw consent where our processing is based on it. You may also ask what personal information we hold about you and how it has been used and disclosed.
To make a request, email contact@elllo.ai from the email address on your account, or write to the Privacy Officer at the address in Section 1. We will confirm your identity, which may include sending a code to your registered email or phone number, and respond within thirty (30) days, or tell you if we need more time as the law allows. We do not charge for requests unless the law permits a reasonable fee for excessive requests, and we will not treat you differently for exercising your rights.
Callers: if your request concerns a call with an Elllo customer, see Section 2. We will forward it to the customer or act on it ourselves where the law requires.
Residents of the United States: where a state privacy law applies, we act as a service provider or processor for Call Content and as a business or controller for customer account data. We do not sell personal information or use it for targeted advertising.
You may also complain to the Office of the Privacy Commissioner of Canada, to your provincial privacy regulator, or, if you are outside Canada, to your local data protection authority. We would appreciate the chance to address your concern first.
12. MARKETING COMMUNICATIONS
We send transactional messages that are part of the Service, including sign-in codes, call notifications to the destinations you configure, receipts, low-balance and renewal reminders, a reminder when your agent has not taken a call for a while (each one carries a link that stops them), and notices about changes to our terms or this Policy. These are sent by email, text message, and push notification according to your settings.
We send product updates, tips, and other marketing email only if you opted in when you signed up, or where we may otherwise do so under Canada's Anti-Spam Legislation, for example because you are an existing customer. Every marketing email includes an unsubscribe link that takes effect immediately, and you can also ask us to stop at contact@elllo.ai. We do not send marketing text messages.
13. CHILDREN
The Service is intended for adults. We do not knowingly create accounts for, or collect personal information from, anyone under eighteen (18). If we learn that an account holder is under eighteen, we will close the account and delete the information. Callers of any age may call a customer's line; the customer is responsible for handling those calls appropriately, and we process the resulting Call Content only for the customer.
14. CHANGES TO THIS POLICY AND CONTACT
We may update this Policy to reflect changes in the Service, our providers, or the law. We will post the updated Policy with a new effective date and, for material changes, notify you by email or in the Service before they take effect. Your continued use after the effective date means you accept the updated Policy.
Questions, requests, or complaints: contact@elllo.ai, or Propel Digital Inc., Attention: Privacy Officer, 120 Eglinton Avenue East, Suite 202, Toronto, Ontario, M4P 1E2, Canada. We aim to acknowledge correspondence within seven (7) days and to resolve complaints within thirty (30) days.
