Last updated: October 1, 2026
This Privacy Policy ("Policy") describes how Pharsale LLC, a Wyoming limited liability company ("Provider," "we," "us," "our"), collects, uses, stores, and discloses personal information in connection with our field service workspace and owner assistant, Orsyle and SamPlumber (the "Service"). The website chat service, conversational sales SMS, and legacy AI phone receptionist service have been retired for both brands. This Policy continues to cover historical Chat Data and Call Data under the retention and support access terms below. The current workspace and dashboard owner assistant remain available. This Policy is incorporated by reference into our Terms of Service.
This Policy applies to four categories of individuals whose data we may process:
If you are a Chat Visitor or a Caller, please note that your conversation or call was handled on behalf of the Customer (the business whose website you visited or whose number you called). The Customer is the data controller for your conversation data; we act as their service provider (processor). Questions about how a specific business handles your data should be directed to that business.
When you create an account or subscribe to the Service, we collect:
When a Chat Visitor used the retired virtual agent on a Customer's website, we collected:
Historical website conversations began with an AI disclosure. Messages were processed by a third-party large language model to generate replies. The retired website assistant was write-only and could create service requests from Visitor-provided information. It did not read back or confirm existing customer records.
Details a Visitor provided were forwarded to the Customer by SMS and/or email, labeled as coming from an unverified website visitor. Historical chat transcripts remain covered by the retention terms below and may be requested through support at contact@orsyle.com. There is no dashboard transcript viewer.
When the legacy phone receptionist service answered an inbound call on a Customer's behalf, we collected:
Legacy calls began with a mandatory AI and recording disclosure that could not be disabled by the Customer.
When you visit our websites or use the Service dashboard, we may collect:
The Service is designed to avoid collecting sensitive personal information through the dashboard assistant. The retired website and voice agents were also instructed not to solicit:
If a Caller or Chat Visitor volunteers such information, it may be captured in the recording or transcript. We implement commercially reasonable measures to flag and redact such data, but cannot guarantee complete redaction.
WE DO NOT USE CUSTOMER DATA, CHAT DATA, CALL DATA, CALL RECORDINGS, CHAT OR CALL TRANSCRIPTS, OR AI-GENERATED CONTENT TO TRAIN, FINE-TUNE, IMPROVE, BENCHMARK, OR DEVELOP OUR AI MODELS OR ANY THIRD-PARTY AI MODELS. THIS PROHIBITION APPLIES REGARDLESS OF ANONYMIZATION OR AGGREGATION.
This commitment is central to our data practices and is also a key element of our compliance with the California Invasion of Privacy Act (CIPA), under which we operate as the Customer's authorized agent—not as a third-party interceptor.
In addition, we do not:
We use the following categories of third-party service providers to deliver the Service. Each provider processes data only as necessary for its designated function and is bound by contractual obligations regarding data protection.
Key sub-processors include:
We require each sub-processor to maintain security standards consistent with industry best practices. We do not permit sub-processors to use your data for their own purposes, including AI model training, except as necessary to provide their service to us.
A current list of sub-processors is available upon request by contacting contact@orsyle.com.
We retain all Call Data—including call recordings, transcripts, and AI-Generated Content—for four (4) years from the date of each call. This retention period applies regardless of whether the Customer's subscription remains active. After the four-year period, data is permanently deleted.
Call Data may be moved to cold storage after 30 days of account inactivity; retrieval from cold storage may take up to 24 hours.
We retain Chat Data—including chat transcripts and Visitor-provided contact details—for four (4) years from the date of each conversation, the same period that applies to Call Data. Hashed IP addresses and session metadata are retained with the associated conversation record; raw Visitor IP addresses are not stored for chat. Active and former Customers may request historical transcripts and captured details through support at contact@orsyle.com during the retention period. The Service does not provide a dashboard transcript viewer.
We retain Customer account information for as long as the account is active and for a reasonable period thereafter to fulfill legal obligations, resolve disputes, and enforce our agreements. If a Customer deletes their account, we will delete or anonymize account data within 90 days, except where retention is required by law.
Website analytics and usage data is retained for up to 24 months. Cookies expire as described in Section 9.
Active and former Customers may request retrieval of their archived Call Data and Chat Data for legal or audit purposes by contacting contact@orsyle.com. Retrieval requests may be subject to a reasonable administrative fee.
We implement commercially reasonable technical and organizational measures to protect your data, including:
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
We do not collect, store, or process payment card data through the dashboard assistant or the retired website and voice agents. Payment processing is handled entirely by Stripe (our PCI-DSS Level 1 certified payment processor) and, where applicable, through the Customer's FSM platform's own payment portal. This architecture descopes our Service from PCI-DSS requirements.
Regardless of your location, you may:
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
For Callers and Chat Visitors:We act as a "service provider" (as defined under CCPA) on behalf of the Customer. CCPA requests from Callers or Chat Visitors regarding their conversation data should be directed to the Customer (the business they called or whose website they used). We will reasonably assist Customers in responding to such requests.
For Customers: You may exercise your rights by contacting us at contact@orsyle.com. We will verify your identity using commercially reasonable methods before processing your request. We will respond within 45 days (extendable by an additional 45 days with notice).
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy legislation may have similar rights. We will honor requests consistent with applicable law. Contact contact@orsyle.com to exercise your rights.
If you are located in the EEA, UK, or Switzerland, and your personal data is processed in connection with the Service:
Essential authentication cookies keep you signed in and remain active regardless of your analytics choice. Optional Vercel Analytics and Speed Insights run only after you accept. We do not use advertising cookies or cross-site behavioral advertising. Declining or withdrawing consent stops new optional analytics events; it does not delete measurements already sent.
Anonymous visitors’ choices are stored in this browser’s local storage. When you sign in, your choice, privacy policy version, and last-change timestamp are saved with your account in Supabase. An existing account preference takes precedence over this browser’s anonymous choice. Your account preference is checked when you sign in or return to a browser window. We store your latest choice, not a separate consent audit history.
Use Privacy preferences in the website footer or account settings to change your choice at any time. Essential login cookies remain in your browser; their token values are not copied into your consent record. Browser preferences remain until replaced or cleared, and account preferences remain until changed or your account is deleted. If preferences cannot be loaded or synchronized, optional analytics stay off. A revised policy may require a new choice.
Every historical website chat conversation began with an AI disclosure that could not be removed by the Customer. Contact details were collected only when a Visitor chose to share them. Website chat and conversational sales SMS no longer accept new conversations.
Every call handled by the retired phone receptionist service began with a mandatory disclosure informing the Caller that:
This disclosure is designed to satisfy federal and state requirements including the Telephone Consumer Protection Act (TCPA), California Invasion of Privacy Act (CIPA), and state AI disclosure laws (including Texas SB 140, California AB 2905, Utah SB 149, and Colorado SB 24-205).
Customers may customize the wording of the disclosure but may not reduce it below the minimum required by applicable law. If a Caller does not wish to be recorded, they may disconnect the call.
When the legacy phone receptionist service accessed existing customer records on behalf of a Customer, it used a two-factor verification process:
This approach is designed to satisfy the CCPA's "reasonable degree of certainty" standard for identity verification when accessing low-sensitivity personal information. Only non-sensitive record information (name, address, upcoming appointments) is accessible through the AI; financial data and invoices are never exposed.
The retired website virtual agent could not read back, confirm, or disclose existing customer records. It could create a service request from Visitor-provided information and match a provided phone number to avoid duplicates without revealing the result to the Visitor. Historical record retrieval now takes place through support, subject to verification of the requesting Customer.
The Service is a business-to-business platform designed for use by home services contractors. It is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly.
If you believe a child's information has been collected through the Service, contact us at contact@orsyle.com.
The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
For transfers from the EEA, UK, or Switzerland, we implement appropriate safeguards including:
We may update this Policy from time to time. When we make material changes, we will:
Your continued use of the Service after the effective date of a revised Policy constitutes acceptance. If you disagree with any changes, you may cancel your subscription before the effective date.
Customers may retain or manage an optional Google Calendar connection in dashboard Settings. The retired website chat used this connection to check availability and book appointments. Retaining a connection does not enable those retired features in the workspace. Connections are initiated by the Customer and are never enabled by default.
The stored Google Calendar authorization includes permission to:
The retained connection uses the existing Google Calendar authorization. We do not request access to your Gmail, Google Contacts, Google Drive, or any other Google service.
Orsyle's use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You may disconnect Google Calendar at any time from the Service dashboard, or revoke the Service's access directly in your Google Account at myaccount.google.com/permissions. When you revoke access, we stop accessing your calendar and delete the stored OAuth token. Any events already created on your calendar remain under your control.
If you have questions about this Privacy Policy, wish to exercise your data rights, or have a data protection concern, contact us at:
Pharsale LLC
1309 Coffeen Avenue STE 1200
Sheridan, Wyoming 82801
Email: contact@orsyle.com
Phone: +1 307 218 3046
For CCPA-specific requests, you may also submit a verifiable consumer request by emailing contact@orsyle.com with the subject line "CCPA Request."
For GDPR-specific inquiries, including requests for a Data Processing Agreement, email contact@orsyle.com with the subject line "GDPR Inquiry."