
Privacy Policy — Revenue Recovery System
Effective Date: 7/25/26
Last Updated: 7/25/26
Ai Partner Solutions, LLC
7831 110th Ave E, Parrish, FL 34219
1. Overview
AI Partner Solutions, LLC ("we," "us," "our") operates the Revenue Recovery System (RRS). This Privacy Policy explains how we collect, use, store, and protect information in connection with the Service — both information about our Clients (med spa businesses) and information about their patients and leads that flows through the system.
2. Information We Collect
2.1 Client Business Information
When you sign up for or use RRS, we may collect:
- Business name, address, and contact details
- Billing and payment information (processed via secure third-party payment processors)
- Integration credentials and API keys for connected platforms
- Communication records (emails, onboarding calls, support interactions)
2.2 Patient & Lead Data (Processed on Behalf of Clients)
As part of delivering the Service, RRS processes contact data provided by or generated through Client's business systems, including:
- Names, phone numbers, and email addresses of leads and patients
- Appointment and booking data
- SMS communication logs generated by RRS workflows
- Engagement data (message delivery, response status)
AI Partner Solutions acts as a data processor for this patient/lead data. The Client is the data controller and is responsible for the lawful basis of processing, including obtaining required consents.
2.3 Usage & Technical Data
We may collect technical data related to Service usage, including:
- Dashboard access logs
- Workflow performance and delivery metrics
- Browser and device information for dashboard access
3. How We Use Information
We use collected information to:
- Deliver, configure, and operate the RRS Service
- Process billing and manage Client accounts
- Communicate with Clients regarding onboarding, support, and Service updates
- Monitor system performance and troubleshoot issues
- Improve and develop the Service (using aggregated, de-identified data only)
- Comply with legal obligations
We do not sell Client data or patient/lead data to third parties. We do not use patient/lead data for any purpose other than delivering the Service to the applicable Client.
4. SMS Communications & TCPA Compliance
RRS delivers automated SMS messages on behalf of Clients to their own leads and patients. In this capacity:
- Ai Partner Solutions is a service provider, not the sender of record. The Client is responsible for ensuring all SMS recipients have provided proper consent as required by the TCPA and applicable state law.
- Clients must maintain records of opt-in consent for all contacts enrolled in RRS workflows.
- All RRS SMS workflows include opt-out handling (e.g., STOP keyword processing) to honor recipient preferences.
- We do not initiate unsolicited SMS communications independently.
5. Data Sharing & Third-Party Processors
We work with trusted third-party platforms to deliver the Service. These include:
| Platform | Purpose |
|---|---|
| GoHighLevel (GHL) | CRM, SMS delivery, workflow triggers |
| Twilio | SMS message delivery infrastructure |
| Supabase | Data storage and workflow state management |
| Digital Ocean | Cloud hosting and infrastructure |
| Stripe or equivalent | Payment processing |
Each third-party processor is subject to their own privacy and data protection policies. We share only the minimum data necessary for each platform to perform its function.
6. Data Retention
- Client account data is retained for the duration of the active subscription and for 12 months following termination, after which it is deleted or anonymized.
- Patient/lead data processed through RRS workflows is retained only as long as necessary to deliver the Service or as required by applicable law. Upon termination, Clients are responsible for exporting any data they wish to retain.
- Billing records are retained for 7 years in accordance with standard accounting and tax requirements.
7. Data Security
We implement industry-standard technical and organizational measures to protect data, including:
- Encrypted data transmission (TLS/HTTPS)
- Access controls and credential management
- Containerized, isolated infrastructure per client environment where applicable
- Regular security reviews and monitoring
No system is 100% secure. In the event of a data breach affecting Client data, we will notify affected Clients in accordance with applicable law.
8. HIPAA Considerations
RRS is designed as a sales and marketing follow-up system and is not intended to process Protected Health Information (PHI) as defined under HIPAA. Clients operating as Covered Entities or Business Associates should:
- Avoid inputting PHI (clinical records, diagnosis, treatment information) into RRS workflows
- Contact us at [email protected] if a Business Associate Agreement (BAA) is required for your use case
9. Your Rights (Florida & U.S.)
Depending on applicable law, you or your patients may have rights including:
- Access — the right to know what data is held
- Correction — the right to correct inaccurate data
- Deletion — the right to request deletion of data
- Opt-out of SMS — by replying STOP to any RRS message
To exercise any of these rights, contact: [email protected]
10. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to active Clients via email at least 14 days before taking effect. The "Last Updated" date at the top of this page reflects the most recent revision.
12. Contact
For any questions, concerns, or data requests related to this Privacy Policy:
Ai Partner Solutions, LLC
Josh Riley
7831 110th Ave E, Parrish, FL 34219
