Legal
Privacy Policy
This Privacy Policy explains how GoldStep (“GoldStep,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you visit goldstep.io, contact us, or use our managed services — including our AI Phone Receptionist, Smart Website, Reputation System, CRM-connected workflows, and related support. We operate from Niagara Falls, Ontario, Canada, and design this Policy to align with Canadian privacy expectations, including the Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies.
1. Who we are
GoldStep is a Canadian marketing and systems agency. We build and manage customer-capture systems that sit beside a business’s team — phone answering and booking support, websites, reputation workflows, and related automations — primarily for restaurants, hotels, spas, and other local businesses across Canada.
Contact: [email protected] · +1 (647) 699-1994 · Niagara Falls, Ontario, Canada
2. Scope and roles
This Policy covers:
- Website visitors and leads — people who browse goldstep.io, submit forms, book demos, call, or email us.
- Clients — businesses that purchase or trial GoldStep services.
- End customers — callers, SMS recipients, form submitters, reviewers, and other individuals who interact with a client’s GoldStep-configured systems.
Important role split: For end-customer data processed through a client’s live systems (calls, bookings, SMS, CRM records, review requests, website forms), the client is generally responsible for deciding why that data is collected and for having a lawful basis to collect it (including notices, consents, and call-recording disclosures where required). GoldStep typically acts as a service provider processing that information on the client’s instructions to deliver the subscribed services. Clients must not use GoldStep systems to collect or use personal information unlawfully.
If a signed Master Service Agreement, Plan Summary, Data Processing Addendum, or similar contract says something different about privacy or data roles, that contract controls for the paid relationship.
3. Information we collect
Depending on how you interact with us, we may collect:
- Identity and contact details — name, business name, role, email, phone, city/region, and message contents from forms, demos, calls, or email.
- Business and configuration details — hours, menus/services, booking rules, transfer preferences, scripts, brand assets, Google Business Profile access, website content, and Launch Kit materials needed to build and run your system.
- Billing and account details — plan selection, payment method metadata, invoices, and service history (card numbers are typically handled by payment processors, not stored in full by GoldStep).
- Service usage data — Voice AI minutes, call logs, SMS logs, booking/enrollment events, CRM activity, website analytics for client sites we host or manage, support tickets, and system diagnostics.
- End-customer interaction data (for client systems) — caller/SMS party phone numbers, names provided, appointment details, messages, call recordings or transcripts where enabled, review feedback, and related CRM fields.
- Technical data — IP address, device/browser type, pages viewed, referring URL, approximate location derived from IP, and cookie identifiers on goldstep.io.
We do not intentionally seek sensitive personal information unless a client or user provides it in the course of a call, form, or message. Please do not submit unnecessary sensitive data.
4. How we use information
We use personal information to:
- Respond to inquiries, book demos, and communicate about GoldStep.
- Set up, configure, host, maintain, and support AI Phone Receptionist, Smart Website, Reputation System, CRM, SMS, and related workflows.
- Route calls, send confirmations/notifications, capture leads, request reviews, and log activity as configured by the client.
- Bill for services, enforce plan limits (including Voice AI minutes and overages), and manage cancellations or buyouts.
- Improve reliability, train support workflows, troubleshoot issues, and protect against fraud or misuse.
- Comply with law, respond to lawful requests, and establish, exercise, or defend legal claims.
- With appropriate consent or as otherwise permitted, send marketing about GoldStep. You can opt out of marketing emails using the unsubscribe link or by emailing us.
We do not sell personal information. We do not use client end-customer data to market unrelated third-party products.
6. Calls, SMS, AI, and CRM data
GoldStep systems may answer or assist with calls, send SMS, log bookings, and store interaction details in a CRM. AI outputs can be imperfect. Clients remain responsible for:
- Providing accurate business information, hours, pricing, and policies used in scripts and automations.
- Complying with applicable call-recording, one-party/two-party consent, and notice rules in the jurisdictions where they operate or where callers are located.
- Complying with Canada’s Anti-Spam Legislation (CASL) and any other messaging consent rules before GoldStep systems send commercial or transactional texts on their behalf.
- Reviewing and approving configurations before go-live, and promptly correcting errors after launch.
End customers who have questions about a specific restaurant, hotel, spa, or other business’s use of their information should contact that business first. GoldStep can assist clients with access or deletion requests that relate to systems we operate for them.
7. Cookies and site analytics
goldstep.io may use cookies, pixels, or similar technologies for basic site function, preference memory, analytics, and (where enabled) advertising measurement. You can control cookies through your browser settings. Blocking some cookies may affect site features.
Client websites we host or manage may also use analytics or marketing tags configured for that client. Those sites may have additional notices.
8. Retention
We keep personal information only as long as needed for the purposes described above, including service delivery, billing, dispute handling, legal compliance, and security — unless a longer period is required or permitted by law or by a client agreement. After cancellation, client websites may be taken offline and archived per our Terms; residual backups may persist for a limited period before deletion or anonymization.
9. Security
We use reasonable administrative, technical, and organizational measures appropriate to the nature of the information and our services. No method of transmission or storage is completely secure. Clients should protect their login credentials, limit staff access, and notify us promptly of suspected unauthorized access related to GoldStep systems.
10. Your choices and rights
Subject to applicable Canadian privacy law, you may request access to, or correction of, personal information we hold about you, and you may ask questions about our practices. Depending on the context, you may also request deletion or withdraw consent where consent is the basis for processing, subject to legal or contractual limits (for example, we may retain billing records).
To exercise these rights, email [email protected] with enough detail for us to verify and respond. If you are an end customer of a GoldStep client, we may redirect your request to that client when they are the organization responsible for the data.
11. Storage and transfers
We are based in Ontario, Canada. Some service providers may process or store information in Canada, the United States, or other countries. When information is transferred outside Canada, it may be subject to the laws of those jurisdictions, including lawful access by foreign authorities. We take steps we consider appropriate in the circumstances when engaging processors.
12. Children
GoldStep services and this website are directed to businesses and adults. We do not knowingly collect personal information from children under 13 (or the age required by local law). If you believe a child has provided personal information to us, contact us and we will take appropriate steps.
13. Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may also be communicated by email or a notice on the website. Continued use of the site or services after an update means you acknowledge the revised Policy, to the extent permitted by law.
14. Contact
Privacy questions or requests:
- Email: [email protected]
- Phone: +1 (647) 699-1994
- Mail / location: Niagara Falls, Ontario, Canada
See also our Terms and Conditions.
This page is provided for transparency and risk management. It is not a substitute for legal advice. If you need counsel review for your industry or province, ask before you rely on it. Questions: [email protected].