Security & your data

Know where your information goes.

Your website is public. Your customer records are working business information. Here is where we keep them, who helps process them and what you can do if something goes wrong.

Reviewed September 12, 2026

The website and the records behind it.

Your public website

Pages and site assets are served from Cloudflare’s network over HTTPS. Your site is plain HTML, CSS and images, so there is no plugin behind the public pages to keep patched. Contact forms send what a visitor types to the services behind your site, and those submissions are not published on the page.

Inquiries and business records

Website inquiries are stored in a Cloudflare D1 database and emailed to you as they arrive. Console records and uploaded files use Cloudflare databases and file storage. The inquiry archive described below covers the form records.

Payment details

The Plainsmith subscription is paid through a Stripe-hosted checkout, so your card number never touches our systems. Payments from your own customers go through your own payment provider’s link. Keep card numbers out of forms, messages and uploaded files.

Cloudflare documents encryption at rest for D1 databases and encrypted connections between Workers and D1. Read Cloudflare’s D1 security documentation.

Access depends on what you open.

Account sign-in, private Console links and documents shared with customers have different jobs. Keep a private link as carefully as you keep a password.

Your account

Passwords are stored as salted hashes, so we cannot read yours. You can turn on an authenticator app from your account page and keep the recovery codes somewhere safe. That protects account sign-in. It doesn’t add a sign-in step to every shared link.

Private and shared links

A private Console key link grants access to whoever holds it. A crew member’s link can be switched off from the Console the day they leave. Customer document and upload links open the one item or action they were made for. If a private link is exposed or a phone is lost, email us right away.

Plainsmith support

Jason and Tadar have production access to run and support the service. The privacy policy says when we look at customer information and how we tell you about an incident.

The services involved.

Which providers handle information depends on the services you use. We do not sell or rent your information.

Cloudflare
Website hosting, databases, file storage and the models that read call transcripts and voicemails.
Stripe
Plainsmith subscription payments and billing records.
Twilio
The front desk’s phone line, in a Twilio account in your own name. Voicemail audio stays in that account under its retention settings. We fetch it once to make the transcript we text you.
ElevenLabs
The front desk’s spoken greeting.
Resend
Email delivery, including inquiry notifications.
Pushover
Alerts to Plainsmith’s own phones. A questionnaire alert carries the name and email entered, nothing more.

Plainsmith does not use your customer information to train AI models. Cloudflare’s Workers AI policy says it does not train models on customer content without explicit consent. That is a policy for this part of the service, not a claim that every provider handles every record the same way.

What recovery covers.

An archive, a database rollback and an export protect against different kinds of loss. A successful check of one does not prove that every record and file can be restored.

Database history

Cloudflare D1 can restore the database to any point in the last 30 days. That is a rollback inside Cloudflare, not a separate copy of every uploaded file.

Website inquiry archive

The form service also writes every inquiry as its own archive file, retries any write it missed, and copies each file to storage in a separate account. Every inquiry records whether each copy was made.

Your own exports

Download your contacts, messages and appointments from your Console as CSV. Keep a copy outside Plainsmith if you want an independent record. Tell us if the export does not include something you need.

Exports, cancellation and deletion.

Canceling the website plan stops the site and the workflow tools at the end of your paid period. The Console stays open for viewing and exporting the records you already have. Canceling a subscription is a different request from asking us to delete data.

Email from the address on your account to ask for a copy, a correction or a deletion. Our published policy allows seven days for the live systems and up to thirty more for the older rollback copies to expire. Recordings held in your own phone-provider account follow that account’s settings.

Something wrong? Tell us what you saw.

Send the page or feature, what happened and when to support@plainsmith.co. For a security issue, we reply within one business day. Please leave passwords and full customer records out of the first email. If you report something in good faith, we will not come after you for looking.

If customer information is accessed improperly or lost, our policy is to email affected clients within 24 hours of learning something may be wrong, even while the investigation is still under way. We have no staffed overnight support desk and no contractual uptime guarantee.