Station AI — Privacy Policy
station.solutions · Terms · Privacy · SMS Terms · Cancellation
Effective July 16, 2026 · Station Automations Group LLC
1. Who we are
Station Automations Group LLC ("Station," "we," "us"), 1856 Branard St, Houston, TX 77098, operates Station AI — a done-for-you AI receptionist and automation platform for local businesses — along with the marketing site station.solutions and the client dashboard app.station.solutions. Privacy questions: main@station.solutions.
2. Two roles — read this first
(a) We are the controller for data about site visitors, prospects, and our clients' own account data — the business owner's name, email, phone, billing details, and dashboard activity. For this data, we decide how and why it's processed, and this policy applies directly.
(b) We are a processor for our clients' end-customer data — the names, phone numbers, messages, call recordings, and booking details of the customers who contact a business that uses Station AI. For that data, the business you contacted is the controller; we process it only on that business's instructions to run its receptionist and automations.
If you are a customer of a business that uses Station AI and you want your data accessed, corrected, or deleted, contact the business you interacted with — they control that data, and we support them in fulfilling your request.
3. What we collect
As controller (visitors, prospects, client accounts):
- Contact and account details — name, business name, email, phone, role.
- Billing information — plan, invoices, and payment status. Card details are handled by Stripe; we never see or store full card numbers.
- Site and dashboard usage — pages visited, basic device/log data, support correspondence.
- For businesses that request an audit or demo — the business details you submit and any preview materials we build from them.
As processor (our clients' end-customers, on the client's instructions):
- Contact details the end-customer provides to the business — name, phone number, email.
- Conversation content — SMS/chat messages, call handling records, appointment and booking details, review requests and responses.
- SMS consent records — when and how an end-customer opted in, and any STOP/HELP events.
4. Why we use it
- To provide, configure, and support the service — answering, routing, booking, follow-ups, and reporting for each client business.
- To bill for the service and communicate about accounts.
- To respond to inquiries and audit/demo requests from prospective clients.
- To keep the platform secure, prevent abuse, and comply with law.
- We never sell personal data (your name, email, phone). On our marketing site, if you accept advertising cookies we use the Meta (Facebook) Pixel to retarget you with our own ads — under some state laws this "sharing for cross-context behavioral advertising" requires a choice, which is exactly what the cookie banner gives you. Choose "Essentials only" to decline, or opt out anytime in your Meta ad preferences. See our Cookie Notice for details.
5. Subprocessors & service providers
We use a small set of vendors to run the service. Each processes data only to provide its function to us:
- CRM & communications platform provider — powers our CRM, telephony, messaging, and automation backbone.
- Stripe — payment processing.
- Email delivery providers — transactional and account email.
- AI language-model providers — generating conversational responses. Conversation content is sent to these providers solely to produce the response; it is not used to market to you.
We may update this list as the service evolves; material changes will be reflected in this policy.
6. Retention
- Client and end-customer data: kept while the client's account is active, then permanently deleted 60 days after account closure (after the client receives their full data export — see the Cancellation & Refund Policy).
- Audit-request leads: preview sites and materials built for a prospective client expire 30 days after creation unless the prospect becomes a client.
- Billing records: kept as required for tax and accounting law.
- SMS opt-in and opt-out records: kept as proof of consent for as long as messaging-compliance rules require.
7. Your privacy rights
If you are a California resident (CCPA/CPRA) or a Texas resident (Texas Data Privacy and Security Act), or live in another US state with a similar law, you have the right to:
- Access the personal data we hold about you;
- Delete it;
- Correct inaccurate data;
- Portability — receive a copy in a usable format;
- No sale — we don't sell personal data, so there is nothing to opt out of;
- No discrimination for exercising any of these rights.
To exercise a right, email main@station.solutions with "Privacy request" in the subject. We verify requests and respond within the timeframe the applicable law requires. You may also use an authorized agent where the law allows. If you are located where the GDPR or a similar law applies, we honor the equivalent rights (access, rectification, erasure, restriction, portability, and objection) under that law.
8. SMS consent data
When an end-customer opts in to receive texts from a business using Station AI, we keep a record of that opt-in (source, timestamp, and number) as proof of consent, and we log every STOP and HELP event. STOP requests are honored immediately and platform-wide. Details are in the SMS Terms & Consent Policy.
9. Cookies
Our sites use functional cookies — session/login state for the dashboard and, on the marketing site, first-party analytics. If you accept advertising on the marketing site's cookie banner, we also load the Meta (Facebook) Pixel to retarget you with Station ads; choosing "Essentials only" turns that off. You can block cookies in your browser; the dashboard requires session cookies to work. Our Cookie Notice lists exactly what each choice loads.
10. Children
Our services are for businesses and are not directed at children under 13. We do not knowingly collect personal data from children under 13; if you believe we have, contact us and we will delete it.
11. Security
We protect data with encryption in transit (TLS), least-privilege access controls (staff access only to what their role requires), vendor security review, and account-level isolation between client businesses. No system is perfectly secure, but we treat your data — and your customers' data — as the core asset it is.
12. Breach notification
If a security breach affects your personal data, we will notify affected clients without undue delay after we confirm it, tell you what happened and what we're doing about it, and notify regulators where the law requires.
13. Changes to this policy
We may update this policy as the service evolves. Material changes will be announced by email or dashboard notice before they take effect, and the effective date at the top will always be current.
14. Contact
Station Automations Group LLC
1856 Branard St, Houston, TX 77098
main@station.solutions · station.solutions
Effective date: July 16, 2026.