Trust Center
Privacy is the architecture, not a feature.
In four of the six verticals we serve, this page decides the deal. So it is written for your privacy counsel and your security team rather than for a buyer: what the hardware cannot do, how consent is obtained on both sides, what happens to the audio, and where the evidence is.
This page is not legal advice. Every deployment follows the retailer’s own counsel.
Certifications
A badge on its own proves nothing. Here is the evidence path.
Every certification below is stated with the auditor, the period and the scope, because those three facts are what your security team will ask for, and a logo without them is decoration.
SOC 2 Type II
- Auditor
- [CONFIRM: auditor name]
- Audit period
- [CONFIRM: audit period]
- Scope
- [CONFIRM: scope — systems, trust service criteria, and which environments are in scope]
ISO/IEC 27001
- Auditor
- [CONFIRM: certification body]
- Audit period
- [CONFIRM: certificate issue and expiry dates]
- Scope
- [CONFIRM: scope statement as written on the certificate]
Shared under NDA. We do not publish the report on the open web.
Consent, by design
Two sides, two different mechanisms, both handled before launch.
Customer consent and associate consent are not the same legal problem, and treating them as one is how these programmes fail a legal review.
Customer side
- Visible signage at the entry door and again at every capturing counter, placed before capture is armed and not after.
- A QR code on each card leading to a plain-language notice: what is captured, why, how long it is kept, and how to ask for it to be deleted.
- A one-line verbal disclosure written into the greeting script, so a customer who never reads a sign is still told.
- The option to ask that a conversation not be captured, honoured at the counter without argument.
Associate side
- Consent sits in the employment relationship: a written policy, an acknowledgement at onboarding, and the programme announced as coaching rather than discovered by rumour.
- Firmware guarantees rather than promises: capture cannot run without the indicator lit, and there is no covert mode to enable.
- Nothing runs on a personal phone. The device is company hardware in a company space.
- The right to dispute any score, with the audio behind that score available to them and their manager.
Hard limits
What Gaincraft never does.
This list is definitive rather than illustrative. If a capability is not on the platform, it cannot be enabled later by a setting, a contract or a request.
- No video. There is no camera in any Gaincraft device.
- No facial recognition, because there is nothing to run it on.
- No customer identification. We do not know who the customer is and we do not try to find out.
- No voiceprints and no voice embeddings, of customers or of associates.
- No biometric identifiers of any kind, created, derived or stored.
- No data resale, and no aggregate resale to brands, landlords or anybody else.
- No individual customer profiles. There is no per-customer record to build one from.
- No covert recording capability in the hardware. Capture cannot run with the indicator off.
Speaker identification is by seat and shift, not by voice.
Gaincraft knows which associate was speaking because it knows which counter captured the conversation and who the roster placed there on that shift. It does not know because it recognised anybody’s voice.
This distinction is the whole reason the architecture looks the way it does. Voiceprints and voice embeddings are treated as biometric identifiers under the Illinois Biometric Information Privacy Act and analogous state statutes, which carry a private right of action and per-violation damages. Gaincraft does not create them, so there is no biometric identifier to consent to, to store, to breach, or to litigate over.
US recording consent
Roughly a dozen states require all-party consent. That is a design problem, not a blocker.
Most US states allow one-party consent to the recording of a conversation. About a dozen require the consent of every party, and several of the largest retail markets are among them.
The commercially significant all-party states — the ones that decide whether a national rollout is viable — include the following, and they are precisely where high-ticket retail concentrates:
Illinois deserves separate mention, because alongside its eavesdropping statute it has BIPA. That is why Gaincraft creates no voiceprints anywhere, in any state.
How consent is actually obtained at the counter
- 1A door decal at entry states that conversations at service counters may be recorded for training and quality purposes, with a QR to the full notice.
- 2A counter card repeats it at the point of capture, in English and Spanish, positioned in the customer’s line of sight rather than behind a display.
- 3A one-line verbal disclosure is written into the greeting script, so the disclosure is spoken and not only posted.
- 4Continuing the conversation at a posted and verbally disclosed counter is the consent mechanism. A customer who prefers not to be captured says so and the counter is stood down.
This page is not legal advice.
We are not your lawyers, and nothing here is a legal opinion about your deployment. Every Gaincraft deployment follows the retailer’s own counsel, state by state and door by door. Where your counsel wants a narrower scope than we propose, we take the narrower scope.
Data lifecycle
Five steps, and the audio does not survive step four.
Step 1
Capture
Audio only, on company hardware, in a posted zone, with the indicator lit.
Step 2
Redact at ingestion
Names, card and payment detail, and personal identifiers are removed before any human or model can open the transcript.
Step 3
Analyse
Behaviours are scored against your playbook. Attribution is by seat and shift.
Step 4
Auto-delete audio
The audio is destroyed automatically at the end of your configured window. There is no manual step to forget.
Step 5
Retain derived insight
What remains is the behaviour score, the coaching prompt and the aggregate trend. The conversation itself is gone.
Retention is configurable per account. The default audio retention window is 30 days, and shorter windows — including 7 days and 24 hours — are available on request. Derived behaviour data is retained for as long as your contract runs, and is exportable and deletable on your instruction.
Security
The controls your security team will ask about.
- Encryption at rest
- AES-256 across audio, transcripts and derived behaviour data.
- Encryption in transit
- TLS 1.3 from device to platform and platform to browser.
- Access control
- Role-based access. A district manager sees their district; an associate sees themselves.
- Audit logging
- Every access to a conversation or a score is logged, including by our own staff, and the log is available to you.
- Single sign-on
- SAML and OIDC SSO, with SCIM provisioning where your identity provider supports it.
- Device attestation
- Each capture device authenticates with a hardware-held identity. An unattested device cannot enrol or send audio.
- Signed firmware updates
- Firmware is cryptographically signed. A device refuses an unsigned image, which is what makes the no-covert-mode guarantee enforceable rather than a promise.
- Data residency
- United States and India residency options. Data stays in the region you select, including backups.
- Subprocessors
- Published and kept current, with purpose, data category and region for each.
- DPA
- A data processing agreement is available and signed before any pilot captures a conversation.
The current list is at Subprocessors.
Model governance
A score that cannot be challenged is not evidence.
These conversations become part of how people are coached and, eventually, how they are paid. That imposes obligations on the measurement itself.
Human review sampling
A sample of scored conversations is reviewed by trained human reviewers every week, and reviewer agreement with the model is tracked per behaviour. Where agreement drops below threshold on a behaviour, that behaviour is suspended from scoring rather than quietly reported.
Accuracy and fairness checks across languages and accents
Scoring accuracy is measured separately by language, by code-switched conversation, and by accent group, because a model that scores one group more harshly is not a measurement tool, it is a liability. Results of these checks are shared with customers on request, including when they are unflattering.
The right to dispute
Any associate can dispute any score. The audio behind that score is made available to them and their manager, a human reviews it, and an overturned score is corrected in the record rather than annotated. Dispute rates by behaviour are one of the signals we use to find a broken behaviour definition.
FAQ
The objections we actually get
Bring your privacy counsel to the first call.
We would rather spend the first hour on scope, consent and retention than on a product tour. The programmes that survive are the ones scoped this way.