Skip to main content
Features Demo How it works Pricing
Sign in Start free
Features Demo How it works Pricing
Legal documents Terms of ServicePrivacy PolicyAcceptable Use PolicyData Processing AddendumCookie Policy Security Contact

Privacy Policy

Effective date: 1 September 2026 Version: 2.7

This Privacy Policy explains how Mango Dog Pty Ltd (ABN 33 628 425 481), trading as Mango Receptionist ("Mango Dog", "we", "us", "our"), collects, uses, stores, discloses, transfers, and protects personal information in connection with the Mango Receptionist service ("Service"). The Service includes the website at https://mangoreceptionist.com, the client console, the admin console, the Aimee AI receptionist for phone calls, the website assistant, SMS follow-up, recruitment and affiliate workflows, knowledge-base ingestion, and related products.

We have written this Policy to be clear, practical, and consistent with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Spam Act 2003 (Cth), the Notifiable Data Breaches scheme, and, where applicable, the EU GDPR and UK GDPR.

This Policy applies to personal information about website visitors, prospective customers, Mango Receptionist customers, end-callers and chat visitors who interact with Aimee on behalf of a customer, job applicants, affiliates, and other people who contact us.

1. Our role

Mango Dog may act in different roles depending on the context:

  • For website visitors, prospects, customers, job applicants, affiliates, and people who contact Mango Dog directly, we usually act as the organisation that decides why and how the information is handled.
  • For end-callers and website/chat visitors who interact with Aimee on behalf of one of our business customers, the customer is usually responsible for deciding why the information is collected, and Mango Dog processes it to provide the Service.
  • Where GDPR or UK GDPR applies, this means Mango Dog may be a controller for its own business information and a processor for customer-controlled end-caller or visitor information.

Customers are responsible for making sure their own callers, website visitors, staff, and customers receive any notices or consents required for their use of Aimee, including where calls are transcribed, summarised, or routed to an AI receptionist.

Two groups of people. This Policy covers two groups whose position is different.

If you are a Mango Receptionist customer — a business that has signed up — we are the organisation that decides why and how your account information is handled, and this Policy explains what we do with it.

If you called a business that uses Mango Receptionist and spoke to Aimee, we handled your information on behalf of that business. That business decides why your information is collected and what happens to it, and it is the first place to direct a request about your information. We handle it on that business's instructions and under this Policy. If you contact us instead, we will pass your request to that business and tell you we have done so. Your rights depend on where you live — see §11 and §15.

For our controller processing, Mango Dog is established in Australia and can be contacted at privacy@mangoreceptionist.com. We do not currently appoint a statutory Data Protection Officer. If Mango Dog makes an offering that requires an EU/EEA or UK Article 27 representative, we will appoint and publish that representative's contact details before that offering begins. This does not alter a customer's responsibility as controller for its own callers and visitors.

2. Personal information we collect

2.1 Website visitors and prospects

We may collect:

  • name, email address, phone number, business name, industry, and enquiry details;
  • form submissions, demo requests, support requests, and messages sent to us;
  • referral, campaign, affiliate, or attribution information;
  • technical information such as IP address, browser, device, pages visited, timestamps, and cookie or local-storage identifiers.

2.2 Customers and account users

We may collect:

  • account contact details, business details, login identifiers, and support correspondence;
  • authentication information, including password hashes or OAuth identifiers from Google or Microsoft;
  • billing metadata, subscription status, invoices, and payment events. Stripe handles card details directly; we do not store full card numbers;
  • receptionist scripts, Aimee instructions, business rules, services, pricing notes, escalation contacts, opening hours, and other configuration information;
  • knowledge-base content customers provide or authorise us to process, such as documents, notes, web content, and email content used to help Aimee answer questions;
  • Mango calendar bookings, calendar configuration, internal availability blocks, imported iCalendar feed URLs and busy-time events, access tokens used to publish a Mango schedule feed, and, when a customer chooses to connect one, Google or Microsoft calendar OAuth tokens and the free/busy and booking-event data needed to operate that connection;
  • when a customer chooses to connect a specialist support or sales inbox, inbound email message content, message identifiers, replies, connection metadata, and the Google or Microsoft OAuth token needed to operate that inbox;
  • receipts, invoices, and bank or credit-card statements that a customer emails or uploads for itemisation, including extracted transaction rows, proposed matches, review status, and accounting records. We do not need or ask for online-banking passwords, full payment-card numbers, PINs, or card security codes; and
  • personal memory and relationship context that an authorised account user voluntarily shares with Console Aimee, such as preferences, family or pet context, and other facts intended to help Aimee serve that user. This private context is not customer-facing knowledge and is not made available to Public Aimee.

2.3 End-callers, chat visitors, and assistant users

When Aimee answers calls, assists through the website assistant, or handles an embedded customer assistant, we may collect:

  • caller ID, phone number, forwarded-from number, routing metadata, and call timing;
  • name, email, phone number, address, job details, booking preferences, and other details voluntarily provided during the conversation;
  • transcript text, summaries, outcome tags, notes, and SMS or email follow-up content;
  • booking, quote, invoice, payment, review-request, and finite follow-up records generated through the customer relationship;
  • chat session identifiers, origin URL, browser metadata, and conversation history for the relevant session;
  • real-time audio needed to understand speech and produce a spoken response.

To answer on the Customer's behalf, Aimee also draws on configuration and content the Customer provides, which we process and store, including:

  • the Customer's receptionist script, business rules, and Aimee Instructions
  • the Customer's services and pricing entries
  • the Customer's knowledge base — documents (PDF, DOCX, TXT, MD), notes, and email content sent to aimee@mangoreceptionist.com from a verified Customer address, processed into deduplicated Markdown and stored in an isolated per-tenant vector index
  • routing configuration (forwarded-from phone number, conditional vs full forwarding mode)
  • caller-safe tenant schedule information and the outcome of booking, rescheduling, or cancellation operations; Aimee does not expose another customer's diary or private calendar event details

Unless a specific feature or customer configuration says otherwise, Aimee does not keep a call audio recording by default. Audio may be streamed through speech and AI providers in real time so the Service can understand and respond, while transcript text, summaries, and operational metadata may be retained.

2.4 Job applicants, recruitment candidates, and affiliates

If you apply for a role, contractor opportunity, affiliate relationship, or sales representative opportunity, we may collect:

  • contact details, location, country, availability, work history, sales experience, resume or profile information, and application answers;
  • interview consent, written answers, interview transcripts, AI-generated interview notes, scorecards, recommendations, and reviewer decisions;
  • affiliate onboarding details, payment details, tax or business information where needed, referral codes, and performance records.

Recruitment and affiliate information is used to assess suitability, communicate with you, administer the program, and comply with law.

2.5 Information from third parties

We may receive information from:

  • Google or Microsoft when you sign in, and Google Workspace when Mango's own knowledge-ingestion mailbox receives customer-authorised material;
  • Twilio, SMS providers, email providers, and telecommunications carriers that provide routing, delivery, and call metadata;
  • Stripe for payment and subscription events;
  • affiliates, referrers, customers, or business contacts who introduce you or submit information on your behalf.

3. Sensitive information and information we do not want

Please do not provide government identifiers, payment card numbers, passwords, health information, or other sensitive information to Aimee unless it is genuinely necessary and you have a lawful basis to do so.

We do not intentionally collect biometric information for the purpose of identifying a person. Voice processing is used to understand speech and generate responses, not to create a voiceprint or identify the speaker.

Customers must not configure Aimee to collect sensitive information unless they have given appropriate notice, obtained any required consent, and confirmed that the Service is suitable for that use.

4. Why we use personal information

We use personal information to:

  • provide, operate, secure, maintain, and improve the Service;
  • route calls, chats, messages, booking requests, and SMS follow-ups to the correct customer;
  • maintain each customer's isolated CRM, bookings, business knowledge, financial evidence, and authorised personal memory;
  • generate transcripts, summaries, notes, structured outcomes, and customer notifications;
  • compute a weekly business digest from structured operational records and narrate a small number of grounded, descriptive observations without sending raw call transcripts to the weekly reflection prompt;
  • maintain customer accounts, subscriptions, billing, support, onboarding, and configuration;
  • operate Mango's tenant-scoped named calendars and selected private iCalendar busy-time feeds;
  • process customer-authorised knowledge material sent to Mango's own knowledge-ingestion mailbox;
  • operate AI receptionist, website assistant, recruitment, and affiliate workflows;
  • assess job applicants, recruitment candidates, affiliates, and contractor applicants;
  • send transactional emails, service notices, support messages, and permitted commercial communications;
  • monitor quality, debug issues, prevent fraud, investigate abuse, and protect the Service;
  • comply with legal, tax, accounting, regulatory, and dispute-resolution obligations.

Where GDPR or UK GDPR applies, we rely on the following lawful bases as appropriate: performance of a contract (account, subscription and requested Service features); legitimate interests (security, fraud prevention, service reliability and proportionate product improvement); consent (optional cookies, marketing where consent is required, and other optional features); compliance with legal obligations; and, where relevant, the customer's lawful basis for its own end-caller or website visitor processing. You may withdraw consent at any time without affecting processing already performed; see our Cookie Policy or contact privacy@mangoreceptionist.com.

We do not sell personal information.

5. AI processing

AI processing is central to the Service. Aimee may use speech-to-text, text generation, text-to-speech, retrieval from a customer's knowledge base, scoring, classification, and summarisation to respond to people and produce customer-facing records.

We send the minimum information reasonably needed for a feature to configured AI service providers. Google Gemini services support live voice and some language tasks. DeepSeek's API supports configured non-voice text tasks and weekly narration. A weekly reflection receives a computed digest rather than raw call transcripts. Google Workspace email and attachments ingested through Mango's own mailbox are marked as Google-origin knowledge: when a tenant has that knowledge, its non-voice AI requests are processed through Google Gemini and are not sent to DeepSeek, OpenRouter, or another non-Google generative-AI provider. The provider used can vary by feature and configured production boundary; the current sub-processor list is in our Data Processing Addendum.

We use AI providers to deliver the Service, not to sell personal information. We do not intentionally use customer content, caller content, recruitment transcripts, or private assistant conversations to train Mango Dog-owned public models. Third-party processing is governed by the relevant provider terms and our arrangements with that provider. Customers should review those boundaries before configuring Aimee to handle sensitive information.

AI systems can make mistakes. Customers remain responsible for the information, scripts, business rules, knowledge-base content, and instructions they provide to Aimee, and for reviewing outputs where a human decision is required.

6. Cookies and similar technologies

We use cookies, local storage, and similar technologies for authentication, security, preferences, assistant sessions, analytics, and service operation. For more detail, see our Cookie Policy.

We do not currently use third-party behavioural advertising cookies on the Mango Receptionist website.

7. Disclosure and service providers

We disclose personal information only where reasonably needed to operate Mango Receptionist, comply with law, protect rights and safety, complete a business transaction, or where you direct or authorise us to do so.

Our service providers may include:

Provider category Example purpose Information handled
Cloud hosting and database providers Application hosting, storage, authentication, logging, and infrastructure Service data, account data, logs, metadata
AI and speech providers Speech-to-text, language model responses, text-to-speech, scoring, summaries Real-time audio, prompts, transcripts, summaries, relevant context
Telephony and SMS providers Call routing, caller ID, SMS delivery, phone number services Phone numbers, call metadata, SMS content, delivery metadata
Email providers Transactional email, support, knowledge ingestion, recruitment and affiliate emails Email addresses, email content, attachments where provided
OAuth login providers Account sign-in with Google or Microsoft OAuth identifiers, email address, basic profile
Google Workspace mailbox provider Mango-owned knowledge-ingestion mailbox Customer-authorised emails and attachments sent to Mango's mailbox
Payment providers Subscription billing and payment processing Billing details, payment metadata, invoice data
Accounting integration providers Optional invoice, payment, account, contact, and tax synchronisation when the customer connects an accounting service The mapped accounting and customer records needed for that integration
Error monitoring and analytics providers Reliability, security, diagnostics, product improvement Logs, device/browser metadata, errors, usage events
Professional advisers Legal, accounting, audit, compliance, dispute management Relevant records only where needed

We require service providers to handle personal information consistently with applicable privacy and data-protection obligations. If a current sub-processor list is published in our Data Processing Addendum, that list should be read together with this Policy.

We may also disclose information if required by law, court order, subpoena, regulator, government agency, or to prevent harm, fraud, abuse, security incidents, or unlawful activity.

8. International transfers

Mango Dog is based in Australia. Some service providers may process or store personal information in Australia, Singapore, the United States, the European Union, the United Kingdom, the People's Republic of China, or other countries where they or their infrastructure operate. The current provider and location disclosures are listed in our Data Processing Addendum.

Where personal information is disclosed overseas, we take reasonable steps required by the Privacy Act and APP 8. Where GDPR or UK GDPR applies, we use appropriate safeguards such as data-processing terms, standard contractual clauses, transfer addenda, encryption, access controls, and provider due diligence where required.

Australia has not been the subject of an adequacy decision by the United Kingdom or the European Commission. Where we rely on a transfer safeguard for personal data received from the UK or the EEA, you can obtain a copy of that safeguard by emailing privacy@mangoreceptionist.com, and we will provide it or a summary of its terms.

9. Security

We take reasonable administrative, technical, and organisational steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. These steps may include access controls, authentication, encryption in transit, encrypted provider storage where available, audit logging, monitoring, provider security reviews, and staff access limitations.

No internet service can be guaranteed completely secure. If we become aware of a data breach that is likely to result in serious harm, we will assess and notify affected people and regulators where required by the Notifiable Data Breaches scheme or other applicable law.

10. Retention

We keep personal information only for as long as reasonably needed for the purposes described in this Policy, unless a longer period is required or permitted by law, contract, dispute handling, security, accounting, tax, or backup requirements.

Typical retention periods are:

Category Typical retention
Active customer account information For the life of the account
Closed customer account information Usually 90 days after closure, except records we need for tax, audit, legal, billing, security, or dispute reasons
Call/chat transcripts and summaries Usually up to 12 months, unless a different retention setting, legal need, support issue, or customer request applies
Knowledge-base content Until the customer deletes it, asks us to remove it, or the closed-account retention process completes, subject to backup and legal limits
Personal memory and relationship context Until the authorised user deletes or corrects it, asks us to remove it, or the closed-account retention process completes, subject to backup and legal limits
Calendar configuration, bookings, and imported busy-time data While needed to provide scheduling and for the applicable operational retention period; disconnected feed credentials are removed when no longer needed
Uploaded or emailed financial documents and extracted transaction evidence Until the customer deletes it, asks us to remove it, or the closed-account retention process completes, except derived accounting, tax, audit, or dispute records that must be retained longer
OAuth tokens Until the integration is disconnected, revoked, deleted, or no longer needed
Billing and payment records Usually up to 7 years where required for tax and accounting
Security, audit, and operational logs Usually up to 12 months, unless needed longer for security or legal reasons
Recruitment and affiliate records As long as reasonably needed to assess, administer, defend, or comply with law
Backups Kept for a limited backup cycle and then overwritten or deleted

Customers may request deletion or shorter retention for eligible records by contacting us. Some records may remain in backups until the normal backup cycle expires.

11. Access, correction, deletion, and other rights

You may contact us to request access to, correction of, or deletion of personal information we hold about you. We may need to verify your identity before acting on a request.

Australian individuals may request access and correction under the APPs. We will respond within a reasonable period and explain if we cannot comply with a request.

Where GDPR or UK GDPR applies, you may have rights to access, rectification, erasure, restriction, portability, objection (including to processing based on legitimate interests and direct marketing), withdrawal of consent, and complaint to a supervisory authority. We do not make solely automated decisions about you that have legal or similarly significant effects in our controller role. Recruitment assistance may generate a score or recommendation, but a human reviewer makes or confirms the decision.

If your information was handled by Aimee on behalf of one of our customers, we may need to refer your request to that customer or act on the customer's instructions.

12. Marketing, opt-out, and unsubscribe

We may send service messages, support messages, account notices, billing notices, security notices, recruitment messages, affiliate messages, and permitted commercial emails.

Commercial emails will include an unsubscribe option where required. You can also opt out by contacting privacy@mangoreceptionist.com. Opting out of marketing does not stop important account, security, billing, support, or transactional messages.

We do not use end-caller information collected for a customer's receptionist service to market Mango Receptionist to that end-caller.

13. Children

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from children for our own marketing or account creation. If you believe a child has provided personal information to us, contact privacy@mangoreceptionist.com.

14. Recruitment and automated assistance

Mango Receptionist recruitment workflows may use an AI assistant to collect application answers, conduct or transcribe an interview, prepare notes, score responses against job-related criteria, and send a report to a human reviewer.

Final recruitment, contractor, affiliate approval, denial, or second-round decisions should be made or confirmed by an authorised human reviewer. Candidates may contact us to request correction of inaccurate information or to ask for human review where appropriate.

15. Complaints

Complain to us first

You have a right to complain to us directly about how we handle personal information.

Privacy contact

Mango Dog Pty Ltd ABN 33 628 425 481 Email: privacy@mangoreceptionist.com Website: https://mangoreceptionist.com

We will acknowledge a privacy complaint within 30 days and respond without undue delay. To protect everyone, we may ask for information reasonably necessary to verify a requester's identity. We do not charge for an ordinary access, correction, or rights request; we will explain any lawful reason we cannot meet a request.

You can also complain to a regulator

Complaining to us does not replace your right to complain to a regulator. Depending on where you are:

Where you are Regulator
Australia Office of the Australian Information Commissioner — https://www.oaic.gov.au
New Zealand Office of the Privacy Commissioner — https://www.privacy.org.nz
Canada Office of the Privacy Commissioner of Canada — https://www.priv.gc.ca. In Quebec, the Commission d'acces a l'information. In Alberta or British Columbia, the provincial Information and Privacy Commissioner
United Kingdom Information Commissioner's Office — https://ico.org.uk
United States The Attorney General of your state; in California, the California Privacy Protection Agency — https://www.cppa.ca.gov
European Economic Area Your national data protection supervisory authority

Appeals

If we refuse a request you made under §11, you may appeal by replying to our decision or emailing privacy@mangoreceptionist.com with "Appeal" in the subject line. We will respond to an appeal within 45 days, in writing, with our reasons. If we deny your appeal, we will tell you how to contact the relevant regulator listed above.

16. Google user data and the Google API Services User Data Policy

When you use Google sign-in or Mango's Google Workspace mailbox processes customer-authorised material, our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google sign-in does not by itself grant mailbox access.

  • Account sign-in (openid, email, profile). We receive your Google account identifier, email address, and basic profile to create and secure your Mango Receptionist account.
  • Mango-owned knowledge-ingestion mailbox (https://www.googleapis.com/auth/gmail.modify). Our internal aimee@mangoreceptionist.com listener uses this narrower Gmail permission on Mango Dog's own Google Workspace mailbox so it can receive customer-authorised knowledge and financial-document emails, process supported attachments, send the required acknowledgement through our transactional email service, and label or delete processed copies from that internal mailbox according to its configured mode. We do not request this permission from a customer's Google account.
  • No Google Drive access. Mango Receptionist does not request a Google Drive scope. Documents enter the Service only when a customer directly uploads them, emails them through an authorised route, or otherwise deliberately provides them.
  • How we use Google user data. We use Google user data solely to provide, secure, and maintain the described feature. We do not use it for advertising, sell it, or use it to train generalised or third-party AI/ML models. Human access is limited to the user's direction, security or abuse investigation, legal obligations, or properly aggregated or anonymised data.
  • Storage and sharing. Listener credentials are stored server-side and are not returned through customer-facing application responses. Google Workspace email and attachment content is not transferred to DeepSeek, OpenRouter, or another non-Google generative-AI provider. The processing boundary routes a tenant with Google-origin knowledge to Google Gemini for its non-voice AI work. We otherwise transfer Google user data only to service providers acting for us where necessary to operate the enabled feature, when the user directs or consents to the transfer, or where applicable law requires it, consistently with this Policy and the Limited Use requirements.
  • Access and deletion. The Google Workspace mailbox is Mango Dog's service mailbox, not a customer-connected inbox. You may request deletion of eligible stored Google-derived data by contacting privacy@mangoreceptionist.com, subject to the retention, backup, legal, security, and accounting limits in Section 10.

17. Changes to this Policy

We may update this Policy from time to time. When we make a material change, we will update the effective date and, where appropriate, notify customers by email, in-product notice, or website notice.

The version published at https://mangoreceptionist.com/privacy is the current version.

Mango Receptionist

Operated by Mango Dog Pty Ltd, an Australian private company.

Company

AboutContactSecurityCareers

Developers

Developer hubREST API / OpenAPIMCP endpointDeveloper manifestllms.txt

Policies

PrivacyCookiesAcceptable Use

Agreement

Terms of ServiceData Processing Addendum
© 2026 Mango Dog Pty Ltd.Legal: legal@mangoreceptionist.comBuilt for service businesses worldwide.