Privacy Policy
Carver Sync LLC ("Carver Sync", "we", "us") is a custom software and AI systems studio based in Surprise, Arizona. This policy describes what we collect through our websites, our own products, and the work we do for clients, where that information goes, how long we hold it, and how to get it back or deleted. It is written to match how our systems actually work, so it names the specific companies your information passes through rather than hiding them behind a phrase like "trusted partners".
This page is written to be read, not survived. It is not legal advice, and it does not tell you what privacy law requires of your own business. Where you have signed a separate agreement with us, a statement of work, an order form, a data processing agreement, or a business associate agreement, that signed document governs over this page if the two ever conflict. The commercial terms of buying from us are in the Terms of Service, the terms that apply when we handle data on a client's behalf are in the Data Processing Agreement, and the terms for people who promote us are in the Affiliate Agreement.
What this policy covers
It covers every surface Carver Sync runs under its own name. That includes the websites carversync.com, gocarve.ai, app.gocarve.ai, 3d.carversync.com and totalanalytics.gocarve.ai, the funnel and checkout pages we publish on go.carversync.com, and the sign-in page at login.carversync.com, which is our white labelled client CRM login. Those last two run on the GoHighLevel platform, so the platform provider handles data there alongside us, and we say so plainly rather than implying we built them.
It also covers our products:
- Horsie and Horsie Cloud. Our AI Architect for CRM and ERP systems, as a Mac app and in the browser. In beta.
- Total Analytics. An attribution and revenue dashboard. In early access.
- GoCarve Trades. An operating system for trade businesses: pricebook, customer app, booking and dispatch. In early access.
- GoCarve Studio. Multi-tenant booking software for studios and rentable spaces. In early access.
- GoCarve Creatives. An agency operating system: asset vault, storyboards, content pipeline and client portals. In early access.
- GoCarve Voice. AI call center, phone systems and IVR, sold as a self-serve monthly subscription. Live.
- GoCarve Events. Ticketing, event calendars and payments. Coming soon, and this policy will be updated before it starts collecting anything.
- AI Forge. The self-serve questionnaire that configures a purchased Voice agent. Live.
- Carver City. The 3D version of our site at 3d.carversync.com. Live.
And it covers the services we sell: custom software and apps, Websites and CRM: CORE, prebuilt SaaS solutions, AI voice and call systems, MasterCarve marketing, social media management, email marketing, data-as-a-service, video and photo production, 3D modeling and printing, and consulting and coaching. We build inside GoHighLevel, alongside it, or fully custom, depending on the engagement, and the privacy picture differs accordingly. Where it does, we say so below.
When we are the processor and not the controller
There are two different relationships in this document, and it matters which one you are in. When you visit our sites, contact us, book a call, buy a subscription, or run one of our products as the account holder, we decide what happens to your information and this policy describes it. That is the controller role.
When you are a customer, caller, patient, tenant or lead of a business that uses our software, we hold your information on that business's behalf and under its instructions. We do not decide what it is used for, and we will not delete it, disclose it, or change it on our own initiative. If you want access, correction or deletion in that situation, ask the business you dealt with, and they will ask us. We will help them respond. The rules we follow in that role are in the Data Processing Agreement. If you cannot work out which business holds your record, write to us and we will try to point you to the right one.
What this website collects
Four surfaces on carversync.com collect information, and each one collects something different.
- The contact form and the chat widget.Your name, email, which option you picked for what you need, and whatever you type in the message box. Chat conversations are handled by our CRM's chat widget, so what you send in chat lands in the CRM as a conversation.
- Booking a Zoom. Your name, email, phone and company when you give them, the time slot and time zone you pick, and the build brief the flow assembles from your answers (foundation, modules, integrations, data to migrate, timeline, budget band, and your notes).
- The AI Forge questionnaire. Your answers about how your business runs, because that is what configures a voice agent: business hours, numbers and people to transfer to, service areas, what you charge and how you handle refunds, warranty terms, scripts, and the questions your callers actually ask. Some of that is commercially sensitive, and some of it may be about other people at your company, which is why the questionnaire asks you to confirm you have the right to share it.
- The GoCarve Voice checkout page. Your name, email, phone and company. Your record is created in our CRM the moment you start checkout, tagged with the plan you were looking at, and that happens whether or not you go on to pay. We would rather say that than hide it: if you start a checkout and do not finish it, we may follow up by phone or email about the plan you were looking at. Tell us to stop and we stop.
If you buy a GoCarve Voice agent, payment itself happens on a hosted page run by our payment provider (Stripe) or by the GoHighLevel platform, depending on the plan and how it is sold. Either way your card number never touches this site and we never see it. What comes back to us is the fact of the payment, the plan, the last four digits, and the email and billing name you gave that provider.
What our products collect
Each product collects what it needs to do its job, and no more. Where a product is in beta or early access, it is only running for accounts we set up directly, and we will update this page as each one opens up.
- Horsie and Horsie Cloud. Your account email and license status, your usage of the AI features (counts, token totals and timestamps, which is how we meter a plan), and the credentials or API keys you connect so Horsie can read and write in your CRM or ERP. The schemas, automations, batch edits and prompts you work on pass through our own AI gateway, a Carver Sync service that holds the provider keys and meters usage, to the model providers named below. We store the keys you connect so the app keeps working between sessions, and you can disconnect them at any time.
- Total Analytics.The dashboard reads your connected systems: contact records, opportunities, invoices and payments, call logs and message history, tags, and ad or source attribution. Most of that is your own customers' information rather than yours, which puts us in the processor role for it.
- GoCarve Trades.Your business's pricebook and job data, and, through the customer app and booking flow, your customers' names, service addresses, phone numbers, emails, job and estimate history, job photos, signatures on agreements, and payment status.
- GoCarve Studio. Tenant and staff accounts, the spaces and calendars you configure, and, for the people who book, their name, email, phone, the slot and resource booked, any notes they add, waiver or agreement acceptance, and payment or deposit status through Stripe.
- GoCarve Creatives.Scripts, storyboards, shot lists, schedules, client portal accounts, and the media you upload to the asset vault. That media often contains identifiable people: faces, voices, names on screen. Getting the releases for the people in it is the account holder's job, not ours.
- GoCarve Voice.Phone numbers you point at us, your agent's configuration, and, for each call, the caller's number, the time and duration, the routing outcome, and whatever the agent collected during the conversation. Where call recording or transcription is switched on for your agent, the audio and the transcript are stored too. Whether recording is on, and whether the agent announces it, is your decision and your legal responsibility as the business making or answering the call.
- GoCarve Events. Not live yet. When it ships it will handle attendee names, emails, ticket purchases and payment status through Stripe, and this page will say so before it does.
- AI Forge. The answers described above, plus which questions you have completed and when, so you can leave and come back.
- Carver City. The 3D site has no account and asks for nothing. It renders in your browser, keeps your graphics and audio preferences in your own browser storage, and hands off to the same contact and booking flows described above when you use them.
What an engagement collects
When you hire us to build or run something, we end up holding more than a web form ever would. Typically that means the contact and billing details of the people we work with at your company, the access we need to your systems (CRM logins or API keys, domain and DNS access, ad and analytics accounts, repositories, phone and messaging accounts), the data we migrate for you, brand and creative assets, and the notes, recordings and documents that come out of scoping calls. For video and photo production we hold the footage and stills, which are personal information about everyone in them. For data-as-a-service work we hold whatever dataset the engagement is about, under your instructions. We ask for the narrowest access that gets the job done, and when a project ends we will remove our access on request.
What we collect automatically, and the cookies involved
We see ordinary technical data: IP address, browser and device type, pages requested, timestamps, and the referring page. Your IP address is used to rate-limit form submissions so the site cannot be spammed. Where our own analytics is switched on for a site, it records page views, and once you submit a form it links your earlier page views to your record in our CRM. That analytics product is Total Analytics. We build it and we run it on our own infrastructure, but its beacon is served from totalanalytics.gocarve.ai, a separate Carver Sync origin rather than a first-party script on this one. We do not load Google Analytics, advertising pixels, or third-party ad trackers on this site. The chat widget is a third-party script from our CRM provider, and it loads as soon as you interact with the page, or after a short delay if you do not, whether or not you ever open it, so it can set its own cookies and fetch its own fonts for any visitor. Your theme preference is kept in your own browser.
So the cookies and similar storage in play are: the ones that keep you signed in and keep a session secure, the ones that remember a preference like your theme, the ones our own analytics sets, and the CRM chat widget's own. You can block or clear any of them in your browser. Blocking the essential ones will break sign-in and booking. Our client-facing apps and portals use session cookies of the same kind, and a tenant of one of our products may configure its own analytics on top, in which case that tenant's privacy policy applies to it.
One thing we will not pretend about: we do not currently run a cookie consent banner, so visitors in the EEA and the UK are not asked to consent before the analytics and chat widget storage described above is set. Your browser controls are the way to refuse it today. If we add a banner, this section changes first.
What we get from other sources
Not everything reaches us directly from you. We also receive information from:
- Our clients.A business that hires us hands us lists, records and files to migrate or work with. Those are their customers, and we process them under that client's instructions.
- Payment and messaging providers. Stripe tells us the status of a payment, subscription or dispute. Twilio and our carriers return call and message metadata: delivery status, duration, and the numbers involved.
- Platform and integration providers. When you connect a system to one of our products, that system returns the records the integration is for, and an account you sign in with returns the identity details you let it share.
- Affiliates and referral partners. Someone in our affiliate program may pass us your name and contact details as a referral, and the program records which affiliate a signup is attributed to. The rules for that are in the Affiliate Agreement.
- Public and commercial sources.Business listings, public company records and the public parts of social profiles, used to understand a prospective client's business before a call.
How we use it
To answer you, to schedule and prepare for calls you book, to configure and deliver the products and services you ask for, to run and support what we have built for you, to bill you and collect payment, to meter usage against your plan, to keep our systems secure and free of abuse and fraud, to improve our products, to tell you about changes that affect what you are paying for, and to meet our own legal, tax and accounting obligations.
We also use it to market to you, within limits. If you give us a phone number, we may call or text you about your enquiry or your account. If you start a checkout and do not finish it, we may follow up by phone or email about the plan you were looking at. Reply STOP to opt out of texts at any time, and reply to any email, or write to us, to opt out of email. Your Forge answers are used to build and run your own agent, and for nothing else: we do not mine them for our own products and we do not share them with other clients. The same rule holds for the data inside any account we run for you.
How AI is involved
Several of our products send content to AI providers to do their work. Horsie sends the schema and automation context you are working on. GoCarve Voice sends the conversation so the agent can understand and answer, and sends text to a voice provider so it can be spoken. The providers are OpenAI and Anthropic for model inference, and ElevenLabs for voice synthesis, reached through that same gateway so we can meter usage and keep keys out of client devices.
Two honest notes on that. First, we do not use your content to train public models, and we use these providers on terms that are meant to keep your content out of their training, but their handling of it is governed by their own terms, which we do not control. Second, AI output is generated, not verified. Do not put anything into an AI surface that you would not be comfortable having repeated back imperfectly, and do not put protected health information anywhere in our general business surfaces before a business associate agreement is signed.
Legal bases, if you are in the EEA or the UK
Where the GDPR or the UK GDPR applies to our processing, we rely on these bases:
- Performance of a contract. Delivering what you bought, running your account, supporting it, and billing for it.
- Legitimate interests. Running and securing our sites and products, preventing fraud and abuse, understanding how our products are used, keeping records of our dealings with you, and direct marketing to business contacts, balanced against your rights and subject to your objection.
- Consent. Marketing where consent is required, and any special category data you choose to give us. You can withdraw consent at any time by telling us, and withdrawing it does not undo what was lawful before. We do not currently ask for cookie consent, and the cookies section above says so plainly instead of this page claiming a consent we never collected.
- Legal obligation. Tax, accounting, and responding to lawful requests.
Where we process data on a client's behalf, that client is the controller and sets the legal basis. We are the processor.
Where your information lives
Bookings, Forge answers and our product databases are stored in Postgres, hosted with our infrastructure provider (Railway) in the United States. From there, depending on what you did and which product you use, your information passes through these services, each of which processes it for us under its own agreement:
- GoHighLevel / LeadConnector (HighLevel, Inc.) as our CRM, chat widget, and one of the channels we message you from. Client sign-in at login.carversync.com runs on that platform and is governed by its terms as well as this policy.
- Twilio for SMS and voice, including the phone numbers and call legs behind GoCarve Voice.
- Stripe for payments and subscriptions. Checkout happens on a hosted page run by Stripe or by the GoHighLevel platform, depending on the plan, so your card details go to that provider and never touch our systems.
- Resend to send confirmation emails, calendar invites, reminders, and your AI Forge link.
- Zoom to create the meeting you booked and its join link.
- Microsoft 365 (Outlook calendar, via Microsoft Graph) to check our availability and put your meeting on our calendar.
- Railway for application and database hosting.
- OpenAI and Anthropic for AI inference.
- ElevenLabs for voice synthesis.
If you are a client with your own CRM sub-account, your Forge answers are also written into that sub-account as custom values. That is the point of the questionnaire: those values are what your voice agent reads on every call. They sit in your CRM, under your account. The current subprocessor list, with what each one does and where it sits, is maintained in Annex C of the Data Processing Agreement.
Your AI Forge link is a key
We email you a private link so you can leave the questionnaire and come back to it without making an account. Anyone holding that link can read and edit your answers, so treat it like a password and do not forward it. If it gets loose, tell us right away and we will sort it out with you. The same warning applies to any portal or preview link we send you for a build in progress.
Who else we share it with
Beyond the service providers named above, information leaves us in a small number of situations:
- Our own people and any related entity. Employees and contractors who need it to do their work, under confidentiality obligations, and any entity under common control with Carver Sync, on the same terms as this policy.
- Partners and resellers. Where a partner referred you or is delivering part of your engagement, we share what that work requires, and nothing more.
- Affiliates in our program. They see attribution and commission data, which can include that a named referral converted. They do not get your account contents.
- Advertising.We do not share your personal information with advertising networks or data brokers, and we do not run cross-context behavioral advertising from our own sites. Where we advertise, we use the ad platform's own reporting, not your record.
- Law, safety and enforcement.When a law, a subpoena or a court order requires it, or where we reasonably need to protect our rights, our systems, or someone's safety. We tell you when we are allowed to.
- A sale or merger. If Carver Sync is bought, merged or reorganized, or sells a product line, information transfers with the business, and the buyer stays bound by this policy until it gives you notice of a different one.
- With your direction. Anything else you ask us to share, for as long as you ask.
We do not sell your personal information
We do not sell personal information, we do not rent it, we do not trade it, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law and the other state privacy laws. We have not sold or shared personal information in the twelve months before the date at the top of this page, and we do not sell or share the personal information of anyone we know to be under 16. If that ever changes, this page changes first and you get a way to opt out before it takes effect.
How long we keep it
We keep what we need for as long as we need it, and no longer. In practice that means enquiries and booking records stay while there is a live conversation or an active engagement, and for a reasonable period afterward so we can answer questions about the work. Forge answers and agent configurations stay for as long as they are running your agent, because deleting them would break it. Account and product data stays for the life of the account. Billing and tax records are kept for as long as accounting and tax law requires, which is longer than the rest. Call recordings and transcripts are deleted after 90 days unless a different schedule was agreed for your build, because audio of a third party who called your business is the most sensitive thing we hold and it should not sit here waiting for somebody to ask about it.
We have not set a fixed calendar period for every record type, and we would rather say that plainly than publish a number we do not enforce. Ask us to delete something and we delete it, other than what we have to keep. Data we hold for a client is kept on that client's instructions and deleted or returned at the end of the engagement under the Data Processing Agreement. Backups age out on their own cycle, so a deleted record can persist in a backup for a short period after it is gone from the live system.
How we protect it
Traffic to our sites and apps runs over TLS, and data at rest sits on encrypted managed storage. Access is role-based and granted on a least-privilege basis, administrative actions in our own systems are logged, secrets and API keys are held in managed environment storage rather than in code, and we review who has access when people and projects change. Payment card data never reaches us, because Stripe handles it. Where the underlying infrastructure is a vendor's, the control is theirs and we name them rather than claim their work as our own.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach affects your personal information, we will notify you and any regulator we are required to notify, without undue delay, and we will tell you what we know rather than what sounds best. Where we hold data for a client, we notify that client so they can meet their own obligations. The measures we commit to contractually are set out in Annex B of the Data Processing Agreement. We hold no privacy or security certification, and we do not claim one.
Children
Our sites, products and services are for businesses and for adults. They are not directed to children, and we do not knowingly collect personal information from anyone under 18, which matches the age requirement in the Terms of Service. If you believe a child has given us information, write to us and we will delete it. A client using our software to serve a younger audience is responsible for the consents that requires, and must tell us before that data reaches our systems.
Links to other sites
Our pages link out, and our products sit next to systems we do not run: your CRM, your payment provider, a partner's site, a social profile, a client's own website we built. Once you follow a link out to a site we do not run, the other site's policy governs, not ours. login.carversync.com and go.carversync.com are a different case, and we said so above: they are our own branded pages on a third-party platform, so this policy still covers what reaches us and the platform provider's terms cover its own processing. We choose our vendors carefully, and we still cannot promise anything about a site we do not control.
Do Not Track
Browsers can send a Do Not Track signal, but there is still no agreed standard for what a site must do about it, so our sites do not respond to it. We do not need to: we do not track you across other companies' websites, and we do not run third-party advertising trackers. Where a browser sends a Global Privacy Control signal, we treat it as a valid opt out of sale and sharing for that browser, which is a request we already honor by default because we do not sell or share.
Your choices
Whoever you are and wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. You can opt out of marketing texts by replying STOP, opt out of marketing email by replying to any email from us or using the unsubscribe link, and opt out of marketing calls by telling us on the phone. Opting out of marketing does not stop the messages we have to send about your account, your build or your bill. You can clear cookies and browser storage yourself, and you can disconnect any integration you connected to one of our products.
Your rights by where you live
Some places give you specific, enforceable rights. Here is what applies where, and we extend the core of it to everyone regardless.
California
Under the CCPA as amended by the CPRA you can ask us to tell you what categories and specific pieces of personal information we collected about you, where we got them, why we collected them, and who we disclosed them to; ask us to correct inaccurate information; and ask us to delete it. You can opt out of the sale or sharing of personal information, though as stated above we do neither. You can limit the use of sensitive personal information, and we do not use it beyond the purposes permitted without a limit request. To be specific about what that covers, because a right you cannot locate is not much of a right: the sensitive personal information we collect is the account credentials and API keys you connect to one of our products, and the contents of calls and messages where a product processes them for you, which means GoCarve Voice recordings and transcripts and the call and message history Total Analytics reads. We collect those only to deliver the product you bought, we never use them to infer characteristics about you, and where we hold them for a client we hold them as that client's service provider under the Data Processing Agreement. We will not discriminate against you for exercising any of this: no worse price and no worse service. You may use an authorized agent, and we will ask for proof of that authority. California's Shine the Light law lets you ask whether we disclosed personal information to third parties for their direct marketing; we do not.
Colorado
Under the Colorado Privacy Act you can confirm whether we process your personal data and access it, correct it, delete it, obtain a portable copy of data you provided to us, and opt out of targeted advertising, sale, and profiling that produces legal or similarly significant effects. We do not sell, and we do not profile in that way. If we refuse a request you can appeal, as described below, and if the appeal is denied you can complain to the Colorado Attorney General.
Connecticut
The Connecticut Data Privacy Act gives you the same set: confirmation and access, correction, deletion, a portable copy, and an opt out of targeted advertising, sale, and significant profiling. It also carries an appeal right, and you can complain to the Connecticut Attorney General if we deny the appeal.
Utah
The Utah Consumer Privacy Act gives you confirmation and access, deletion of data you provided, a portable copy, and an opt out of targeted advertising and sale. Utah does not grant a correction right or an appeal right, so those are not statutory obligations for us there. We will correct your information on request anyway, because arguing about accuracy helps nobody.
Virginia
The Virginia Consumer Data Protection Act gives you confirmation and access, correction, deletion, a portable copy, and an opt out of targeted advertising, sale, and significant profiling, plus an appeal right and the ability to complain to the Virginia Attorney General.
Other states
More states pass a version of this law every year. Rather than list every one as it arrives, we apply the same process to everybody: if your state gives you a right, ask us and we will honor it. If it does not, ask anyway and we will almost certainly honor it regardless.
Europe and the United Kingdom
Under the GDPR and the UK GDPR you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to processing including direct marketing, to data portability, to withdraw consent where consent is the basis, and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, which we do not do. You also have the right to complain to your supervisory authority, or to the Information Commissioner's Office in the United Kingdom. We would rather you came to us first, but that right is yours either way.
How to make a request, and what happens next
Call 602-560-5546, use the contact form, email info@carversync.com, or reply to any email from us. Tell us what you want and which email, phone number or account it relates to.
We verify who you are before we hand anything over or delete anything, usually by matching what you tell us against the record and by replying to the address already on it. For a sensitive request we may ask for more. An authorized agent can act for you if you give them written permission and we can verify it. There is no charge for a reasonable request, and we will not make your service worse for asking. We respond to a US state privacy request within 45 days, extendable where the law allows, and we tell you before the first 45 days are up if we need the extension. We respond to a request under the GDPR or the UK GDPR within one month, extendable by up to two further months for a complex request, in which case we tell you inside the first month. Requests that are clearly excessive or repetitive may be refused, and we will explain why.
If we deny a request and you live somewhere with an appeal right, reply to our denial and say you are appealing. A different person reviews it, and we will write back within 45 days with the decision and the reason. If we still say no, we will give you the contact details for your state Attorney General or supervisory authority so you can take it further.
Where your information is processed, and international transfers
Carver Sync operates in the United States. Our hosting, our databases and our team are in the United States, and the vendors named above process information in the United States and, for some of them, in other countries where they run infrastructure. If you are outside the United States and you use our sites, products or services, your information is transferred to and processed in the United States, where privacy law differs from the law where you live.
Where personal data protected by EU or UK law is involved, we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum to those Clauses where UK data is involved and the vendor offers it, together with the supplementary measures described in our Data Processing Agreement. Carver Sync holds no cross-border transfer certification from any government or certification body, and we make no claim to any such certification or participation. Standard Contractual Clauses are the mechanism we rely on, and they are the only one we claim.
Changes to this policy
When we change what we collect, add a product that collects something new, or change which services your information passes through, we update this page and the date at the top. For a change that materially reduces your rights or materially expands what we collect, we will give notice by email or in the product before it takes effect, where we have a way to reach you. This version reflects Carver Sync as of September 16, 2026. Older versions are available on request.
How to contact us
Carver Sync LLC, 14090 W Gray Fox Trail, Surprise, AZ 85387, United States. Call 602-560-5546, email info@carversync.com, or use the contact form. Carver Sync LLC is the controller of the information described in this policy, except where we say we are the processor. We have not appointed an EU or UK representative under Article 27. Write to the address above and your request reaches the people who can act on it.