Legal
Legal information and product controls
This page explains operational controls found in the current GeoQuote product and the decisions contractors still own. It is not legal advice, a legal opinion, or a certification that GeoQuote or any contractor's campaign complies with a particular law.
Controls support a process; they do not certify compliance
TCPA, FCC, FTC, CRTC, CASL, privacy, recording, payment, and state or provincial rules can depend on facts the software cannot determine by itself. Feature selection, deployed configuration, recipient location, consent evidence, message purpose, vendor behavior, and current law all matter.
When can AI Follow-Up run?
- The contractor must select and configure AI Follow-Up; it is not active for every quote request.
- The request must pass the active consent, phone-status, do-not-call, request-state, and calling-policy checks.
- An eligible call may still be deferred, blocked, unanswered, or fail. No exact call time or booking is guaranteed.
- Voicemail, SMS, retry, calendar, and CRM behavior depends on the enabled workflow and connected services.
- Use the request, call, message, calendar, and CRM records to confirm what actually happened.
📝 Consent and request evidence
Review requiredMay be relevant to TCPA, CRTC, CASL, and other consent rules
Current product controls and limits
- The configured quote flow can record the consent text shown, timestamp, request context, and phone-verification status.
- AI Follow-Up is intended to run only when the feature is enabled and the request passes the active consent, verification, and outbound-policy checks.
- A successful OTP step shows that a code was returned from the submitted phone. It does not by itself prove identity, purchase intent, or permission for every type of contact.
🤖 AI and caller disclosure
Review requiredMay be relevant to FCC, TCPA, FTC, CRTC, and state or provincial rules
Current product controls and limits
- The current GeoQuote voice-agent call path builds a greeting that identifies the assistant as AI and names the contractor.
- The current greeting also states that the call may be recorded. The exact deployed greeting must be tested before a contractor enables calling.
- Alternate providers, custom scripts, or configuration changes can alter behavior and require a fresh review.
🕒 Calling policy and timing
Review requiredMay be relevant to federal, state, provincial, and local calling restrictions
Current product controls and limits
- The outbound workflow contains policy checks for consent, do-not-call state, request state, and configured calling windows.
- A call can be queued, deferred, blocked, unanswered, or fail. GeoQuote does not promise an exact first-attempt time or a successful connection.
- Location and timezone data can be incomplete or wrong. A configured time window is an operational control, not proof that every call is lawful.
🛑 Opt-out and do-not-call handling
Review requiredMay be relevant to TCPA, CRTC, CASL, and internal do-not-call duties
Current product controls and limits
- GeoQuote voice and messaging workflows include recognized opt-out paths and do-not-call storage.
- GeoQuote SMS templates include STOP instructions; custom messages and third-party tools must be reviewed separately.
- Automation can fail. Operators should monitor delivery and outcome logs and manually honor any opt-out that is received outside the automated path.
🎙️ Call recording
Review requiredRecording and consent rules vary by state, province, country, and call context
Current product controls and limits
- The configured voice workflow can disclose that a call may be recorded and can store recording metadata when recording is enabled.
- A disclosure does not automatically establish valid consent in every jurisdiction, and continuing a call must not be treated as a universal legal rule.
- Recording should remain off unless the contractor has confirmed the applicable notice, consent, access, security, and retention requirements.
🔐 Privacy and data requests
Review requiredMay be relevant to PIPEDA, GDPR, CCPA/CPRA, and other privacy laws
Current product controls and limits
- The Privacy Policy describes the principal data categories and service-provider categories used by GeoQuote.
- Access, correction, and deletion requests can be submitted to support@getgeoquote.com for review.
- GeoQuote does not promise automatic deletion exactly 90 days after cancellation. Retention depends on the data type, active systems, backups, security needs, contracts, and applicable legal obligations.
💳 Payment processing
Review requiredStripe payment services and PCI DSS responsibilities
Current product controls and limits
- GeoQuote uses Stripe-hosted payment flows so customers enter card details on Stripe-controlled surfaces rather than GeoQuote forms.
- Stripe describes its own PCI DSS status. That status does not certify every part of GeoQuote or a contractor's systems.
- Payment configuration, webhook handling, access controls, and surrounding business processes still require operational review.
✅ Pre-launch verification
Review requiredRequired operational review; not a certification
Current product controls and limits
- Before calling is enabled, test the exact production quote flow, consent record, phone step, disclosure, calling policy, opt-out path, calendar connection, and CRM handoff.
- Review logs after launch. Do not infer that a call, message, booking, sync, or deletion occurred without the corresponding system evidence.
- Re-run the review after provider, script, configuration, jurisdiction, or legal changes.
Have a legal question or need to discuss a Data Processing Agreement?
Contact GeoQuoteProduct-control summary last reviewed: July 9, 2026