Privacy Policy

What we collect, and what we never do with it.

Effective September 5, 2026. This policy covers CustomerLedger, operated by Haygood Ideas, Inc. ("we", "us"). By using the service you agree to it.

What CustomerLedger is

A record of your customers, built for you, not for us.

CustomerLedger stores the record every AI agent or team member you connect reads from and writes to: one file per person, the facts they told you or your agents, where each fact came from, and the consent they gave before you contacted them again. It is your customers' data, held on your behalf. We act as a processor of it, not an owner of it.

Information we collect

What actually lands in the record.

  • Your account information: your name, business name, address, email, phone number and billing details.
  • Customer records you or your connected agents create: names, contact details, call and message transcripts, notes, tags, and any other fact your business chose to keep about a person, each one stamped with where it came from.
  • Consent records: what a person agreed to, in their own words, and when.
  • Usage information: contact counts, API calls and login activity, used for billing and to keep the service working.
Your customers' information

It belongs to your business, not to us.

The people in your ledger are your customers, not ours. We process their information on your behalf, the same way any records system would. We do not sell it, and we do not use it to market to your customers or anyone else's. You are responsible for having a lawful basis to collect and store what you put in CustomerLedger about the people you deal with — the consent tooling here helps you keep evidence of that, it does not create it for you.

How we use information

Four reasons, and no others.

  • To store and serve the record back to you and the AI agents or people you connect to it.
  • To enforce the consent gate before any automated outreach you send through a connected system.
  • To bill you and support your account.
  • To meet legal obligations.
Tenant isolation

Your ledger is a file, not a row.

Each client tenant on your account is a separate store on disk, not a shared table filtered by an ID. There is no query that can accidentally return one tenant's people to another's agent, because there is no shared table to filter in the first place.

Security, in brief

Encrypted at rest, backed up hourly.

We run full-disk encryption on every server we operate, sitting behind Cloudflare's edge. Local versioned snapshots run every hour; the full set is encrypted and copied offsite once a day. The full breakdown of who touches your data and what they can see is on our Security page, kept as one page rather than repeated here so it cannot drift out of date in two places at once.

Tamper-evident by design

Every write is signed and chained.

Every change to a record is stamped with who made it, and the append-only history is hash-chained so an edit cannot be quietly rewritten after the fact. A correction is a new entry, not an erased one — the one exception is a deletion you request, which is logged as its own event rather than left invisible. See Architecture for how the chain itself is verified.

Retention and deletion

Delete means delete, on request, within 30 days.

We keep records for as long as your account is active and for a reasonable period afterward for billing and dispute resolution. Email [email protected] to access, correct, export or delete a person's record, or to purge an entire tenant. A deletion leaves a logged erasure behind rather than disappearing silently, so you can prove it happened. We respond within 30 days.

Service providers

Who we hand things to, and why.

We use third parties to run the service: hosting and edge security, the AI models behind search and import, and payment processing. Card details are handled by our payment processor and never touch our own systems. If you connect your own AI voice or chat provider to write into your ledger, that provider's own handling of call audio or message content is governed by your agreement with them, not this policy — our Security page lists every provider we ourselves rely on.

Children

This is a business service.

CustomerLedger is sold to businesses for records about their own customers. We do not knowingly collect information directly from children under 13.

Changes and contact.

We will post updates here with a new effective date. Questions go to [email protected].

HAYGOOD IDEAS, INC., a Florida corporation, Tampa, Florida | page generated 2026-09-06