Privacy Policy
Last updated: July 6, 2026. Version: 2026-07-06.
SurgeIQ is a software product operated by ProfitLine AI LLC ("ProfitLine," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and retain information when you use SurgeIQ, including the application, legal pages, support form, billing flows, lead intelligence, workflow tools, and calling features.
1. Business Use
SurgeIQ is intended for business use by companies, solo operators, ProfitLine internal users, and authorized representatives. It is not intended for children or for personal, household, or family use. Do not use SurgeIQ if you are under 18.
2. Account and Membership Information
We collect account and configuration information such as email address, authentication records, company membership, role, active status, company or operator name, team invitations, timezone, service-area settings, target categories, billing mode, legal acceptance timestamps and versions, company and membership settings, preferred Twilio area code, outreach account labels or connection records, and related administrative activity. Current signup requires email and password; other profile fields may be created through onboarding, settings, invitations, support, or operational administration.
3. Personal Callback Phone Numbers
If you provide a personal callback phone number, we store it on your membership and use it to forward inbound callbacks from your assigned SurgeIQ/Twilio number. Twilio and telecommunications carriers may process the assigned SurgeIQ number, callback number, routing metadata, and call status information to complete the forwarding. You can update the callback number in your settings; inbound callbacks may not work without one.
4. Billing Information
Stripe processes payment details. SurgeIQ stores and processes related billing records such as Stripe customer IDs, subscription IDs, subscription status, plan or billing mode, seat counts, item IDs, current-period dates, cancellation status, invoices or payment status, billing errors, and at-cost Twilio usage billing records. We do not directly store full card numbers.
5. Lead, Business, Crisis, and Derived Information
SurgeIQ processes business and lead information, including business names, categories, phone numbers, email addresses, websites, social/profile URLs, addresses, city, state, ZIP code, geography, public listings, review information where used, source metadata, public profile data, business hours, and website-derived enrichment signals. Sources may include public websites, Overture Maps, Google Places where enabled, other third-party or provider data, customer activity, and internal lead workflow records.
We also process crisis and event data, impact/geographic data, enrichment attempts, website analysis, inferred business signals, surge scores, timing outputs, evidence summaries, offer recommendations, scripts, and other derived recommendations. These outputs may be associated with company lead pools, claims, assignments, suppression, notes, touch history, and pipeline movement.
6. Calling Data
When calling features are used, we and Twilio may process call attempts, caller and recipient numbers, assigned SurgeIQ/Twilio numbers, personal callback numbers, call timestamps, statuses, duration, connected seconds, provider call identifiers, routing metadata, answered-by metadata where available, webhook records, usage charges, and billing outcomes. Call recording is disabled by default. If recording is enabled for a deployment, recording-related data may be processed according to the configuration and applicable consent requirements.
7. Outreach and Workflow Data
We process workflow activity such as lead claims, reservations, assignments, suppression records, notes, touches, provider/native outreach launches, pipeline transitions, offer interactions, recommendation interactions, membership activity, and company configuration. SurgeIQ may open native provider compose or profile pages for email, Facebook, Instagram, or similar outreach; customers remain responsible for what they send through those providers.
8. Support and Email
We use email providers such as Resend or SMTP providers to send transactional, verification, account, billing, support, and operational messages. If you submit the support form, we process the name, email, company, subject, message, authenticated user and company if available, request path, IP address, user agent, and reply-to address so we can respond and investigate the issue.
9. Logs, Security, Device, and Diagnostics
We process logs and security information such as IP addresses, request metadata, browser or user-agent details, device/browser characteristics available to the server, pages or actions taken, authentication/session events, provider webhook events, errors, diagnostics, and security signals. Cloudflare, hosting infrastructure, Django, and other providers may process network metadata, including IP addresses, to route traffic, protect the Service, and operate the application.
Sentry is used for error and performance monitoring when configured. The current application initializes Sentry with default PII collection disabled and relies on scrubbing controls to reduce unnecessary sensitive-data collection, but diagnostics may still include operational context needed to debug issues. We do not promise that logs, providers, or diagnostics can never process sensitive information.
10. Cookies and Sessions
SurgeIQ uses cookies and similar browser storage for authentication, session management, CSRF protection, security, and application operation. We do not currently use advertising cookies or installed marketing trackers in the application code. Disabling cookies may prevent login or core workflows from working.
11. How We Use Information
- provide, operate, secure, troubleshoot, and improve SurgeIQ;
- authenticate users and manage company, solo, ProfitLine, and invitation memberships;
- source, enrich, score, distribute, claim, assign, suppress, and manage lead records;
- enable calling, callback forwarding, call metadata, and exact-cost usage billing;
- manage subscriptions, Stripe billing, invoices, payment status, and Customer Portal access;
- send verification, transactional, account, billing, support, and operational email;
- detect abuse, enforce terms, maintain security, and handle incidents; and
- comply with legal, tax, accounting, billing, privacy, telecommunications, fraud-prevention, and recordkeeping obligations.
12. Sharing and Processors
We may share information with service providers and processors that help operate SurgeIQ, including Stripe for billing, Twilio for calling and phone-number services, Resend or SMTP providers for email, Sentry for diagnostics, Cloudflare for proxy/security services, hosting and infrastructure providers, backup/storage providers, data and enrichment providers, and support or professional advisers. We may also share information with your company and authorized users, with connected or launched third-party services at your direction, to comply with law or protect rights, or in a merger, financing, sale, restructuring, or similar transaction.
We do not sell personal information in the ordinary sense of exchanging it for money. We do not knowingly sell or share children's personal information.
13. Retention
We retain information for as long as reasonably necessary to provide SurgeIQ, maintain accounts, support billing and taxes, preserve suppression and audit records, resolve disputes, enforce agreements, prevent abuse, investigate security events, comply with legal obligations, and maintain backups. Exact periods vary by record type and provider. Provider records, logs, and backups may persist for limited periods after deletion from the live application.
14. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including authenticated access, role-based company boundaries, CSRF/session protections, provider signature validation where configured, secure proxying, deployment hardening, and operational monitoring. No internet, software, payment, or telecommunications system is completely secure.
15. Your Choices and Requests
You can update certain account, callback phone, outreach label, company, and billing information through the application where your role permits. Depending on your location and relationship to us, you may have rights to request access, correction, deletion, portability, restriction, objection, or other privacy actions. These rights vary by jurisdiction and may be limited by business, legal, billing, security, backup, suppression, or audit needs. To make a request, contact us at [email protected].
16. Customer Outreach Responsibilities
Customers are responsible for lawful downstream handling of lead and contact information, including notices, consent, do-not-contact requests, suppression, call recording, telemarketing, email, platform, privacy, and industry-specific rules. If a business or person asks not to be contacted, customers must honor that request and update suppression or other records as appropriate.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Updated versions will be posted here with a revised date or version. We may require renewed acknowledgment for material updates. Continued use after changes become effective means you acknowledge the updated policy.
18. Contact
Questions, privacy requests, and do-not-contact requests may be sent to ProfitLine AI LLC at [email protected].