This Privacy Policy explains how Aileen Landon LLC ("Tarmac," "we," "us," "our") collects, uses, and protects information in connection with the Tarmac CRM and sales-dialer platform, offered as Outbound, at outbound-crm.com and app.outbound-crm.com, including our marketing website, and at the earlier addresses go-tarmac.com and app.go-tarmac.com (the "Service").
1 · Information we collect
Account information: name, email, password, company, and phone number you provide when you create an account.
Workspace / CRM data: the contacts, accounts, notes, activities, and pipeline records you create or import into your workspace.
Communications data: call and message logs (phone numbers, timestamps, duration, and disposition) generated when you use the dialer and messaging features; call recordings and saved transcripts, where your workspace turns them on; and voicemails that callers leave for you, with their transcripts. See section 4.
Usage data: log data, device and browser information, and analytics about how the Service is used.
Campaign data: when you arrive from a link or an ad, first-party cookies on our own domain record the campaign tag, the first page you visited and, for a Google ad, the click identifier Google adds to the link. We store these with your account when you sign up, and with a click on Add to Chrome, so we can tell which campaigns bring us customers. When a visitor who came from one of our Google ads clicks Add to Chrome, we tell Google Ads that the ad click led to an Add to Chrome click, using only Google's click identifier, the time of the Add to Chrome click and a random reference number; nothing else about you is sent. We do not use the Google tag or Google cookies on our site.
2 · How we use information
To provide, operate, secure, and improve the Service;
To place calls and send or receive the messages you initiate;
To authenticate you and protect against fraud and abuse;
To provide support and send you service-related communications.
Separately from model training, we use aggregate call-timing measurements from all calls, never audio or words, to operate and tune the dialer.
3 · SMS & mobile messaging
We do not sell, rent, or share your information, including mobile phone numbers and SMS opt-in data, with third parties or affiliates for their own marketing or promotional purposes. Mobile opt-in and consent information is never shared with any third party for marketing.
Phone numbers and messaging data are used only to operate the messaging features you use (sending, receiving, delivery, and opt-out handling) and are shared only with the communications providers strictly necessary to deliver your messages (for example, our telephony carrier), under contract and solely for that purpose. Reply STOP to any message to opt out, or HELP for help. Message and data rates may apply.
4 · Call recordings and transcripts
Opt-in. Call recording and saved transcripts are available on every plan that dials on an Outbound line, and both are off by default. A workspace owner or admin turns each one on, separately, after acknowledging a recording-law notice.
Consent is your responsibility. You are responsible for complying with recording-consent laws on every call you record, including in states that require the consent of all parties to the call.
Which calls. When recording is on, we record calls placed through our dialer (in the web app or the Chrome extension's panel) and inbound calls to your Outbound number, including inbound calls forwarded to your mobile phone. Calls made through a host CRM's own dialer, including when our extension auto-advances that dialer for you, are never recorded by Outbound; your CRM's own dialer may record them under its own settings.
Who can play them. Recordings play back inside your own Outbound workspace: owners and admins can play the whole team's calls, and reps can play their own. Owners and admins can delete recordings; for recordings made before our move to Telnyx, this removes them from your workspace but does not delete any copy Twilio still holds. Outbound staff never listen to or read your calls, including when support staff view your workspace.
Model training (training contributions). Model training is a separate switch from recording and transcripts. For workspaces created on or after September 28, 2026, it is on by default, as described in our Terms of Service; workspaces created before that date are unaffected unless a workspace owner or admin turns it on. While it is on, the recordings and transcripts your workspace chooses to keep are used to improve Outbound's call-detection and AI models. Outbound staff never listen to or read your calls, including when support staff view your workspace; training on them is automated (automated answering-machine detection learning, automated model fitting on derived measurements, and anonymous statistics). Voicemails callers leave are never contributed, and recording and transcripts stay off until you turn them on. A workspace owner or admin can turn model training off at any time in Settings or on the Chrome extension's consent card. Turning it off stops future calls from contributing immediately. Contributions already made are retained and may continue to be used to improve our models, including after the workspace is deleted. Only calls made while model training is on are ever contributed; turning it back on does not add calls made while it was off. If the law gives you a right to have contributed data deleted, contact us and we will handle the request as the law requires.
Attaching recordings to your CRM. If an owner or admin turns on attaching recordings to your CRM, we place a link to the recording on the call record in your CRM (HubSpot and Salesforce add it when the recording finishes; other CRMs get it only if the recording is ready when the call is logged). Anyone who has the link, including anyone with access to that record, can play it. Your CRM provider may then process that audio under its own terms. Turning off recording, or the attach option, disables those links.
Live transcription. Calls through our dialer, and inbound calls to your Outbound number, are transcribed live by Deepgram so the dialer can detect answering machines and show the transcript during the call. Live transcripts are used during the call and held only in our servers' working memory; they are not written to disk or saved to your call history unless your workspace turns saved transcripts on. Transcripts of answered inbound calls are not saved. For workspaces that have both model training and saved transcripts on, a call's text may also be sent to an AI provider, Anthropic, to classify whether a person or an answering machine answered; for other workspaces, call text is not sent to Anthropic for this. AI call summaries are currently limited to Outbound's own internal workspaces. Under its commercial terms, Anthropic does not use that text to train its models.
Voicemails. Voicemails that callers leave for you, and their transcripts, are saved regardless of these settings, because the caller chooses to leave a message. We notify the rep of each new voicemail by email and, when the rep has a forwarding number and texting is active, by text message; both include the transcript when one is available, shortened in the text.
Where recordings are stored. Recordings are stored with our voice carrier, Telnyx. Twilio, our previous voice carrier, may still hold recordings and voicemails from before our move to Telnyx.
Deletion. When you delete your account, any workspace where you are the only member is deleted, and we ask our carrier, Telnyx, to delete the recordings stored for that workspace, including voicemails. This is best effort, and a recording that another workspace also references is not deleted. Recordings from before our move to Telnyx are not deleted from Twilio by this process. Training data already derived from calls the workspace contributed (for example, entries in our answering-machine detection library and measurements derived from those calls in our training datasets) is retained, as described in Model training. Any copies your CRM kept of recordings you attached are governed by that CRM.
5 · Google user data
Some features connect to your Google account. This section describes every Google connection we offer, what each one accesses, and how that data is used, stored, and shared. Outbound's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Sign in with Google. Uses your Google identity (name, email address, and profile picture) to create your account and sign you in. We do not store the Google tokens from sign-in; a returning sign-in goes through Google again.
Google Calendar (calendar events): if you connect your calendar, we read your upcoming events to show your agenda inside the CRM, and we create and update events for the follow-ups you schedule. Your calendar is displayed to you, not copied into our systems; the only calendar records we keep are the follow-ups you create.
Gmail sending: if you connect Gmail, we send the emails you compose in the CRM from your own address, so they come from you and land in your Sent folder. The message you composed is stored as part of your CRM activity history. We never send an email you did not initiate.
Gmail email logging (read-only): a separate, optional upgrade with its own Google consent. When it is on, we periodically read message headers and short snippets from your mailbox only to match messages to contacts already in your CRM, and we save the subject and snippet of matching messages to that contact's timeline. Messages that do not match a CRM contact are read transiently and discarded. Full message bodies are never stored, and chats, spam, and trash are excluded.
Google Sheets (read-only): if you import from a spreadsheet, we read the sheet you select to bring its rows into your CRM, at your direction.
Storage and protection. Google access and refresh tokens for connected features are encrypted at rest with AES-256-GCM and are never exposed to your browser; every Google API call happens on our servers.
Sharing and use limits. Google user data is never sold, never used for advertising, never used to determine creditworthiness, and never shared with third parties, except the service providers that host our infrastructure (section 6), under contract, to operate the Service. No human at Outbound reads your Google data, except with your explicit permission for support, when necessary for security or abuse investigation, or where required by law. Google user data is not used to train AI or machine-learning models.
Deletion and revocation. Disconnecting a Google feature in Settings revokes our access with Google and deletes the stored tokens. You can also revoke access at any time at myaccount.google.com/permissions. Deleting your account removes every Google connection the same way.
6 · How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose it only:
to service providers (e.g., cloud hosting, telephony/messaging carriers, transcription, email delivery, sign-in and calendar services, address autocomplete, website analytics on our marketing pages and in the web app, payment processing) that process it on our behalf, under contract, to provide the Service. Deepgram, our transcription provider, transcribes call audio for us; we opt out of Deepgram's model improvement program on every request, so Deepgram does not use our call audio to train its models. We also use Anthropic, only for AI features we have enabled: answering-machine classification sends call text to Anthropic only for workspaces that have both model training and saved transcripts on; AI call summaries are currently limited to Outbound's own internal workspaces. Under its commercial terms, Anthropic does not use that text to train its models;
to Google Ads, only the click identifier, the time of an Add to Chrome click and a random reference number, for a visitor who came from one of our Google ads, as described under Campaign data in section 1. Google processes these for us to measure our ads; we do not use them to build audiences or advertising lists;
when required by law, or to protect rights, safety, and security;
in connection with a business transfer (such as a merger or acquisition), subject to this Policy.
7 · Data retention
We retain information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we ask our carrier, Telnyx, to delete the recordings stored for the workspaces deleted with it; this is best effort, and a recording that another workspace also references is not deleted. If your workspace had model training on, training data already derived from contributed calls (for example, entries in our answering-machine detection library and measurements derived from those calls in our training datasets) is retained, including after your account is deleted, as described in Model training in section 4. You may request deletion as described below.
We keep an ad click identifier for no more than 90 days after the click, then delete it.
8 · Security
We use administrative, technical, and physical safeguards designed to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9 · Your choices & rights
You may access, correct, export, or delete your account information, and opt out of non-essential communications, by contacting us. Depending on where you live, you may have additional rights under laws such as the CCPA/CPRA or GDPR.
Do Not Track and Global Privacy Control. If your browser sends a Global Privacy Control or Do Not Track signal, our website does not save the ad click identifier described under Campaign data in section 1, so your visit is never reported to Google Ads.
10 · Children
The Service is intended for business use and is not directed to individuals under 18. We do not knowingly collect information from children.
11 · Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.