Solutions · Legal and Compliance
For the reviewer, not the buyer.
This page is written so that it can be forwarded to counsel without a covering explanation. It sets out what is captured, how consent is obtained on both sides, what the hardware cannot do, what is retained and for how long, who processes what, and where the evidence sits.
This page is not legal advice. Every deployment follows the retailer’s own counsel, state by state and door by door.
The review pack
Six things a reviewer asks for, each with a document behind it.
A two-sided consent architecture
Customer consent through visible signage at entry and at every capturing counter, a QR to a plain-language notice, and a one-line verbal disclosure in the greeting. Associate consent inside the employment relationship, backed by firmware that cannot run capture with the indicator off.
A state-by-state consent posture
All fifty states and DC, with the all-party consent states identified and the commercially difficult ones named. We will tell you plainly when a state is a poor first deployment.
No voiceprints, anywhere
Gaincraft creates no voiceprints and no voice embeddings, for customers or associates. Speaker attribution is by seat and shift assignment. Voiceprints are treated as biometric identifiers under Illinois BIPA and analogous statutes; there is no biometric identifier here to consent to, store, breach or litigate over.
Retention you control
Audio is auto-deleted at the end of your configured window — 30 days by default, with 7-day and 24-hour options. There is no manual step to forget. What persists is the derived behaviour score, not the conversation.
A DPA signed before capture
Gaincraft acts as processor. The DPA, including standard contractual clauses and the subprocessor annex, is executed before a single conversation is captured in a pilot.
A published subprocessor list
A real table — subprocessor, purpose, data category, region — kept current, with advance notice of material changes. No subprocessor may use your data to train its own models.
Documents
Everything a reviewer needs, in four links and one memo.
Nothing here is behind a form except the SOC 2 report and the DPA, which are sent by a person under NDA.
- The full consent framework and signage kit
Both sides of consent, item by item, including the physical kit that ships before capture is armed.
- State consent map
All fifty states and DC, with our understanding of the posture in each and the poor first deployments named.
- Subprocessor list
Subprocessor, purpose, data category and region, kept current.
- Certifications and security controls
SOC 2 Type II and ISO 27001 with auditor, period and scope, plus encryption, access, logging and residency detail.
In practice
How a review actually runs with us
The scoping session happens before the product demonstration, not after it. You define which zones capture and which are excluded, and the zone map you sign becomes part of the compliance record for that store.
Where your position is narrower than our proposal, we take the narrower position. Exam rooms in optical, fitting room interiors in fashion, F&I offices in automotive and staff areas everywhere are excluded by default rather than by request.
Your review does not depend on trusting a policy statement. The no-covert-mode guarantee is enforced by signed firmware that refuses an unsigned image, and every access to a conversation is audit-logged, including access by Gaincraft staff, with the log available to you.
Nothing on this page is legal advice, and we do not ask you to accept our reading of any statute. Every deployment follows your own counsel, state by state and door by door.
FAQ
Questions a reviewer asks
Put us in front of your counsel first.
We would rather spend the first hour on scope, consent and retention than on a product tour. The programmes that survive are scoped this way.