Last Updated: September 2026
Guidecall respects your privacy and is committed to protecting your personal data. This Privacy Policy informs you as to how we look after your personal data when you visit our website, use our application, or utilize our services, and tells you about your privacy rights. We may update this Privacy Policy from time to time; we will notify you of material changes by posting the revised policy on our website and updating the "Last Updated" date above. Your continued use of the platform after the revised policy is posted constitutes your acceptance of the changes. You must be at least 18 years old to create an account or use any of our services. We do not knowingly collect personal data from anyone under 18.
We may collect, use, store, and transfer different kinds of personal data about you, including data you provide directly and data collected automatically (such as IP address, browser type, device identifiers, and access logs):
We rely on the following categories of third-party processors to operate the platform (current providers are listed for transparency and may be updated from time to time). Each provider receives only the data needed to perform its function and is bound by its own privacy and security obligations.
Guidecall utilizes Twilio to transmit critical account alerts, secure messages, booking updates, trip reminders, and payout notifications via SMS.We do not sell, share, or distribute your mobile number to third parties or affiliates for marketing or promotional purposes.
Mobile information collected internally (your phone number and per-category opt-in selections) is used solely to deliver the platform notifications you explicitly requested via the checkboxes in your Account Settings. All SMS data handling complies with CTIA messaging principles and 10DLC carrier requirements. You may opt out at any time by replying STOP to any message we send or by toggling SMS off in your Dashboard Settings.
Deal Alerts (marketing messages). You may opt in to Guidecall Deal Alerts — recurring automated marketing texts and/or emails about discounted fishing-trip openings matching preferences you choose (location, species, timing, minimum discount, and maximum frequency) — on our public signup page at /deal-alerts. Deal-alert signups made on /deal-alerts are verified with a one-time code before any text is sent.
Separately, favoriting a captain or a specific trip enrolls your account in email alerts about that captain’s openings and deals by default; this is a plain opt-out — every email includes a link to turn it off, and you can also turn it off any time in Account Settings. Text alerts for favorites are off by default: they require turning on the “Deals” text notification category in Account Settings, where its own disclosure is shown before your consent is recorded, and go to the phone number on your account. Favoriting a captain without an account, or through a captain’s own invite link, offers the same choice up front — a “Text me” checkbox with the same disclosure shown before your phone number is verified and your consent is recorded. These are the only marketing SMS we send; each requires its own opt-in, and consent is not a condition of any purchase. Marketing texts go only to US mobile numbers, and only during the texting hours permitted by the recipient’s state law. The mobile number and preferences you provide are used solely by Guidecall to send these alerts and are never sold or shared with third parties for their marketing. Reply STOP to any alert to opt out of texts, use the manage link in every message or the Alerts section of Account Settings to change preferences or unsubscribe, and reply HELP for assistance. Message and data rates may apply; message frequency for /deal-alerts signups is limited to the cap you select there.
Scheduled Calls and On-Call sessions take place inside private 2-participant video rooms hosted by Daily.co. All call sessions are recorded to the cloud. Recordings are retained for dispute resolution, refund review, and platform integrity. Recordings are visible only to Guidecall admins for review purposes and to the call participants themselves on request. By joining a call, both parties consent to being recorded.
Certain information you provide is intentionally public so the marketplace can function:
We use session cookies via our authentication provider (Clerk) to keep you signed in, and a signed first-party guest-session cookie to keep a guest checkout or booking-manage session recognized without requiring an account. If you save a favorite without creating an account by verifying a one-time code sent to your email, we set a separate signed first-party cookie (retained 14 days) recognizing your device so your favorites and alert preferences are remembered without asking you to prove your email again. If you use the "use my location" control, we store your chosen location in a short-lived first-party cookie so it persists as you browse. If you arrive via a referral or partner link, we set a first-party cookie (retained 30 days) recording which link you followed, so the resulting booking or signup can be attributed to the right partner. During a pre-launch period we may also set a first-party cookie recognizing an early-access visitor, so the site can be reached before public launch. We use lightweight first-party local-storage and session-storage flags to remember UI preferences (calendar view, recent searches, autoscroll position) and to group your page views together, within a single browser session, for analytics. We also set one first-party analytics cookie (gc_aid, retained for one year) that assigns your browser a random identifier so we can understand how the site is used (pages viewed, searches, bookings started). This data is used only by Guidecall for product analytics, is never sold or shared with third parties, and is not used for advertising. We do not use third-party advertising cookies. We do not currently use cross-site tracking pixels. We do not currently respond to "Do Not Track" browser signals because no uniform industry standard for DNT has been adopted.
We will only use your personal data when the law allows us to. The legal bases we rely on include: performing our contract with you, pursuing our legitimate business interests (provided your rights do not override those interests), complying with legal obligations, and, where applicable, your consent. Most commonly, we use your personal data to:
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way. However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. We limit access to your personal data to those employees, agents, contractors, and processors who have a strict business need to know. Credential documents are stored in segregated, access-controlled buckets and are visible only to Guidecall admins. When automated reading is used — for credential documents or for a Guide's connected calendar — the content is transmitted securely to our AI processor for a single read. It is never used for model training, and is not retained beyond returning the result except where the provider's safety systems flag it or the law requires it.
We retain personal data only as long as necessary to provide the service and to satisfy our legal, tax, accounting, and dispute-resolution obligations. Specifically:
Depending on your jurisdiction, you may have the following rights. We may need to verify your identity before fulfilling any request to protect the security of your personal data:
Logged-in users may request deletion from Account Settings. Guests and former users may use guidecall.app/privacy/delete. We will anonymize your name, email, and phone within thirty (30) days of confirmation, except that the phone number and email address preserved in the marketing-SMS consent/opt-out log (Section 10) are retained for that log's own seven-year period as our suppression-list and compliance record. Past booking, payment, and refund records remain in our systems in anonymized form to satisfy our obligations under federal, state, tax, and payment-network rules (including IRS retention and payment-network dispute-history requirements).
Trip participants without an account: if you were listed as a participant on someone else's booking and never created a Guidecall account, you can still exercise your privacy rights — email privacy@guidecall.app or use guidecall.app/privacy/request. If you never signed a waiver, your information is deleted automatically ninety (90) days after the trip (or sooner on request). If you signed a waiver, we can remove your contact details on request, but the signed waiver itself is a legal record we must retain as described in Section 10.
Contacts a Guide invited, without an account: if a Guide uploaded your name and email address or phone number to invite you to Guidecall, and you never created an account, you can still exercise your privacy rights — email privacy@guidecall.app or use guidecall.app/privacy/request to have your contact information deleted immediately (rather than waiting for the 180-day automatic deletion described in Section 10) and to stop being invited again.
Guides may connect a Google account so Guidecall can read their calendar and write bookings into it. We request four permissions: view, create, edit and delete events on calendars you own (calendar.events.owned); view your list of calendars (calendar.calendarlist.readonly); and your Google account identity and email (openid, email). Guidecall's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data accessed. Your calendar list (so you can pick one), the events on the calendar you choose, and the Google account's email address.
How we use it. Reading: only to work out which dates and seats are already taken, as described in Section 2. Writing: we place one event per accepted Guidecall booking in the chosen calendar, titled with the trip name, customer name and booking code; its description repeats those details with party size and status and a link to the booking, and the meeting spot is the event's location. We update or remove that event as the booking changes. We never use Google data for advertising, never sell it, and no person at Guidecall reads it except with your consent, for security, or as the law requires.
Sharing. Event titles and descriptions are sent to Anthropic for a single automated read (Section 3) and are not used to train AI models. Guidecall does not use any data obtained through Google Workspace APIs to develop, improve, or train generalized (non-personalized) AI or machine-learning models. Google data otherwise lives only on our hosting providers (Vercel, Supabase) and is shared with no one else.
Protection. Your Google tokens are encrypted at rest (AES-256-GCM, under a key held outside the database), sent only over TLS, and never displayed. We store the account email, the permissions granted, and the chosen calendar's id and name; never event titles, descriptions, locations or attendees — and the identifiers Google issues for change notifications, which carry no event content either.
Retention and deletion. Tokens are kept only while the connection exists. Disconnecting (Dashboard → Calendar) revokes our access at Google and deletes every hold, rule and cached reading derived from the connection — the events we already wrote stay in your Google Calendar as your own record of your own trips, and a later reconnect updates those same events rather than duplicating them. Deleting your Guidecall account does the same, with one limit: if your Google access had already lapsed by then, we have no way to remove those events first, so they simply remain in your calendar; otherwise we keep the encrypted access for up to 7 days solely to finish removing them, then delete it. You can also revoke access at any time at myaccount.google.com/permissions.
Guides may connect a Microsoft (Outlook / Office 365) account so Guidecall can read their calendar and write bookings into it, the same two-way connection offered for Google Calendar above. We request permission to view your list of calendars, read and write events on the calendar you choose (Calendars.ReadWrite), and your Microsoft account identity and email (openid, email, offline_access). Our use of data obtained through Microsoft Graph is consistent with Microsoft's API Terms of Use and Microsoft identity platform policies.
Data accessed. Your calendar list (so you can pick one), the events on the calendar you choose, and the Microsoft account's email address.
How we use it. Reading: only to work out which dates and seats are already taken, as described in Section 2. Writing: we place one event per accepted Guidecall booking in the chosen calendar, titled with the trip name, customer name and booking code; its description repeats those details with party size and status and a link to the booking, and the meeting spot is the event's location. We update or remove that event as the booking changes. We never use Microsoft data for advertising, never sell it, and no person at Guidecall reads it except with your consent, for security, or as the law requires.
Sharing. Event titles and descriptions are sent to Anthropic for a single automated read (Section 3) and are not used to train AI models. Guidecall does not use any data obtained through Microsoft Graph to develop, improve, or train generalized (non-personalized) AI or machine-learning models. Microsoft data otherwise lives only on our hosting providers (Vercel, Supabase) and is shared with no one else.
Protection. Your Microsoft tokens are encrypted at rest (AES-256-GCM, under a key held outside the database), sent only over TLS, and never displayed. We store the account email, the permissions granted, and the chosen calendar's id and name; never event titles, descriptions, locations or attendees.
Retention and deletion. Tokens are kept only while the connection exists. Disconnecting (Dashboard → Calendar) deletes the access we stored and every hold, rule and cached reading derived from the connection — the events we already wrote stay in your Outlook Calendar as your own record of your own trips, and a later reconnect updates those same events rather than duplicating them. Deleting your Guidecall account does the same, with one limit: if your Microsoft access had already lapsed by then, we have no way to remove those events first, so they simply remain in your calendar; otherwise we keep the encrypted access for up to 7 days solely to finish removing them, then delete it. Microsoft does not let us revoke a single app's access remotely — review or revoke it yourself at any time at myaccount.microsoft.com/permissions.
Guidecall is intended for users 18 years of age or older. We do not knowingly collect personal data from anyone under 18, and our services are not directed to children under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA). If you believe a minor has provided us with personal information, please contact us at the email below and we will promptly delete it.
For privacy questions, data-access requests, or to report a concern, contact us at privacy@guidecall.app or submit a request at guidecall.app/privacy/request.