Privacy Policy
The short version. This website sets no cookies, runs no analytics, and does not track you. Information reaches us only when you choose to send it, such as by submitting the workflow audit form, replying to an email, or calling a phone line we operate for a client. We do not sell personal information or share it for advertising.
This policy explains what personal information Spark & Wonder Labs LLC,
operating as AI Business Systems, collects, why, how long we
keep it, and how to ask us to delete it. It covers this website
(abs.corycopeland.dev), our related pages at
frontdesk.corycopeland.dev and intake.corycopeland.dev,
our email outreach, and the AI front desk phone services we build and operate
on behalf of client businesses.
Who we are
Spark & Wonder Labs LLC is a single-member Florida limited liability company (state entity ID L26000371779). AI Business Systems is a service line operated under that entity. We are the data controller for the information described in this policy, except where we act as a service provider to a client business, which is explained under AI front desk services below.
Privacy questions and deletion requests: [email protected].
This website
The site sets no cookies, uses no localStorage,
and loads no analytics or advertising scripts. There is no
tracking pixel, no session identifier, and no cross-site profiling. You can
read every page here without sending us anything about yourself.
The site loads a web font from Google Fonts, which means your browser requests
a file from fonts.googleapis.com and fonts.gstatic.com.
Google receives your IP address as part of that request, as it would for any
externally hosted asset. We receive nothing from it.
The site is served through Cloudflare, which processes requests in transit and keeps short-lived operational logs for security and abuse prevention. That processing is Cloudflare's, under its own terms.
Workflow audit form
When you submit the audit form, we store what you type:
| What | Why |
|---|---|
| Name and email address | To reply to you. Required. |
| Business name, business type, website | To understand your context before responding. Optional. |
| Phone number | Only if you provide one. Optional. |
| Your description of the workflow and the tools you use | This is the substance of the request. Required. |
| IP address and browser user agent | Spam and abuse prevention, and rate limiting. Not used to build a profile of you. |
| Submission timestamp and source page | To know which page the request came from. |
Submissions are stored in a database on our own self-hosted infrastructure, not in a third-party form service. We use this information to respond to your enquiry and, if we end up working together, to carry out that work.
Email we send you
We send business-to-business outreach and follow-up email to organisations we believe may find our services relevant, and transactional email to people who have contacted us. Outreach messages are sent through Resend, our email provider.
Some outreach messages contain a uniquely tracked link to a demo or proposal page. When that link is opened, we record that the link was opened, when, and the requesting browser's user agent, so we can tell a genuine visit from an automated security scanner and know whether following up is worthwhile. We do not embed tracking pixels in message bodies.
Every outreach message includes a way to opt out. Ask us to stop, by reply or at [email protected], and we will suppress your address from future sends and honour that suppression going forward.
Replies you send us arrive in a mailbox we operate. We use an automated classifier to sort incoming replies by intent, for example to detect an opt-out request so it is acted on promptly. A person reviews the outcome.
Business contact information we collect about prospects
We maintain a database of business contact details, such as company name, business phone number, business email address, website, industry, and service area, gathered from public sources such as company websites and public business directories. Where a named contact is a person at that business, that record is personal information and this policy applies to it.
We use this to decide who to contact about our services. We do not sell it, rent it, or share it for advertising. To have your business record corrected or removed, email [email protected] and we will remove it and suppress the address from future contact.
AI front desk services
We build and operate AI phone and messaging systems for client businesses. When you call a phone number answered by a system we operate for one of our clients, you are contacting that business. The business is the controller of that conversation and its own privacy practices apply. We act as its service provider.
In the course of handling such a call, the system may process:
- Your phone number and the time and duration of the call.
- Audio of the call, and a written transcript produced from it, so the business has an accurate record of what was asked.
- Details you give in order to be helped, such as your name, address, and the reason for calling.
- A summary sent onward to the business owner, typically by SMS or email, so a person can follow up.
Call recording and Florida law. Florida requires the consent of all parties to record a private conversation. Where a system we operate records or transcribes calls, it is configured to disclose this at the start of the call, and continuing the call indicates consent. If you would prefer not to be recorded, say so or hang up and contact the business by another means. Client businesses are responsible for the disclosure their line is configured to give, and we will not knowingly operate a line that records without one.
Demonstration lines shown on this site are staffed by fictional example businesses and exist so you can hear how the system behaves. Calls to a demo line are still processed as described above.
Client project information
When we work with a client, we handle the material needed to build the system, which may include business documents, customer records, and access to relevant tools and accounts. We use it only to deliver the agreed work, we do not use it to train our own models, and our handling is governed by the client agreement, which takes precedence over this policy where the two differ.
Service providers
We keep the list of third parties deliberately short. Each one receives only what its function requires:
| Provider | Function |
|---|---|
| Cloudflare | DNS, network protection, and inbound email routing |
| Resend | Sending outbound email |
| Google (Gmail) | The mailbox that receives replies to our email |
| Anthropic | AI processing, including reply classification and assisted drafting |
| Vapi | Voice handling for AI front desk lines |
| Twilio | Telephone numbers and SMS notifications |
Application data sits on infrastructure we host and administer ourselves rather than on a third-party application platform. We disclose personal information beyond the above only where required by law, or to a client business that is the controller of a conversation directed to it.
How long we keep things
- Audit form submissions and prospect records: for as long as there is an active or plausible business relationship, and reviewed periodically thereafter. Records with no engagement are removed.
- Suppression and opt-out records: kept indefinitely, on purpose. Deleting the record of your opt-out is what would let us mail you again by mistake, so we retain the minimum needed to keep honouring it.
- Call audio and transcripts: retained according to the instructions of the client business whose line it is, and deleted on that business's request.
- Client project material: per the client agreement, and returned or deleted at the end of the engagement on request.
Your choices
You can ask us to:
- tell you what information we hold about you;
- correct it if it is wrong;
- delete it;
- stop contacting you.
Email [email protected]. We aim to respond within 30 days. You do not need an account and we will not charge you. If your request concerns a call to a client business's line, we may need to refer you to that business, and we will tell you who they are.
Depending on where you live, you may have additional rights under laws such as the Florida Digital Bill of Rights, the California Consumer Privacy Act, or the UK and EU GDPR. We will honour the rights above regardless of where you live, which covers the substance of those laws.
Security
Traffic is encrypted in transit. Application data is held on infrastructure we administer, with access limited to the operator and administrative interfaces kept off the public internet or behind authentication. Credentials are held in a secrets manager rather than in code. No system is perfectly secure, and we do not claim otherwise, but the small footprint here is deliberate.
Children
These are business services and are not directed at children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, contact us and we will delete it.
International visitors
We operate from the United States, and information you send us is processed there.
Changes
If this policy changes, the date at the top changes with it. Material changes affecting how we use information already collected will be communicated directly where we have a way to reach you.
Contact
Spark & Wonder Labs LLC
7901 4th St N, STE 300, St. Petersburg, FL 33702
[email protected]