Connect your phone

Trust & Data · Permissions

What is the worst Spillway could actually do with the access I give it?

The maximum authority Spillway gets.

What every connection technically allows, what Spillway actually uses, what could go wrong, and how you shut it off.

Spillway connects to real business systems. That creates real authority.

We think you should be able to inspect the maximum authority behind every connection before granting it.

This page separates what the provider technically allows from what Spillway actually uses.

If a provider gives Spillway broader technical access than the product uses, we say that too.

What are you actually risking?

The $299 activation payment is not the only thing at risk when you connect software to your business.

Your calls, recordings, messages, business identity, payment method, and customer relationships matter more than the dollar.

Do not ask only: “What does Spillway intend to do?”
Also ask: “What does the access I’m granting technically make possible?”

That is what this page answers.

Four boundaries, not one permission claim.

These concepts are different. Each connection below states all four.

1

Provider-granted authority

What the provider credential, OAuth grant, API key, or authorization technically permits. This is the ceiling.

2

Spillway-used authority

What Spillway actually uses that authorization to do. This can be narrower than the provider ceiling.

3

Spillway-enforced restrictions

What Spillway’s application prevents itself from doing even when the provider authorization is broader.

4

Worst-case authority

What could plausibly happen if the authorization were misused, a control failed, or an authorized credential were compromised.

Connection

Call history.

Spillway uses authorized completed-call information to find legitimate roofing conversations that ended without an inspection.

Why Spillway needs it

The original call is the evidence for what happened, whether the call is eligible, and what follow-up would be truthful.

What Spillway can change

This connection is used for authorized call reads and event intake. It does not authorize changes to the contractor’s CRM or schedule.

What Spillway actually uses

  • Completed-call identity, timing, direction, participants, and duration.
  • Recording or transcript when the provider account exposes it.
  • Available recent completed-call history when the provider supports it.
  • New completed-call events after service starts.

Provider-granted authority

The OAuth grant or provider credential may expose more calls, recordings, numbers, or account resources than a single recovery requires. The provider’s grant screen is the technical ceiling.

Spillway-used authority

Spillway limits normal use to eligible-call analysis, recovery continuity, reconciliation, and provider-health checks.

Spillway-enforced restrictions

  • Tenant-bound provider account.
  • No homeowner message before service starts.
  • Eligibility and contactability checks before any continuation.
  • No cross-tenant provider identifiers.
  • No generated success from missing call evidence.

Worst case if this access were misused

If this authorization were compromised, the call records, phone numbers, recordings, or transcripts exposed by the grant could be read until the authorization was revoked.

What reduces that risk

  • Pipedream Connect tenant binding.
  • Server-side token custody.
  • Signed and replay-controlled event intake where available.
  • Redacted operational logs.
  • Revocation and fail-closed capability state.

How you shut it off

  1. Disconnect the provider in Spillway.
  2. Revoke the connected account through the provider or Pipedream Connect.
  3. New call ingestion and dependent recovery stop after revocation is confirmed.
View technical permissions
Technical details

The provider’s authorization is the technical ceiling. Spillway’s application behavior may be narrower.

Connection broker
Pipedream Connect with a Spillway-owned project and server-issued, short-lived connect token.
Authorization method
Provider-specific OAuth or credential form presented by Pipedream Connect.
Authorized resources
Only the resources exposed by the provider grant accepted for the selected account.
Read operations
Provider-specific completed-call, recording, transcript, number, and reconciliation reads after capability verification.
Write operations
None through the call-history role.
Events
Provider-specific call events or bounded reconciliation reads.
Tenant binding
The authorization is bound server-side to one contractor account and setup session.
Credential storage
Provider credentials remain server-side and are not returned to the browser, analytics, or public logs.
Auditability
Relevant authorization, provider, messaging, activation, and billing events use tenant-bound operational records.
Revocation
Disconnect through Spillway and revoke directly through the provider when the provider offers that control.
Failure behavior
Expired, revoked, or incomplete authority stops dependent action; it does not become a fabricated success.
Last reviewed
August 24, 2026. The actual account capabilities are checked again after authorization.

Connection

Customer messaging.

After service starts, Spillway uses an authorized business-messaging route to continue the unfinished homeowner conversation.

Why Spillway needs it

The recovery conversation must use an authorized sender, receive replies, observe delivery, and honor opt-outs.

What Spillway can change

This authority can create outbound messages through the selected sender and receive messaging events. It cannot edit the contractor’s CRM or schedule.

What Spillway actually uses

  • Select an authorized business number.
  • Send recovery messages only after service starts and readiness checks pass.
  • Receive homeowner replies and delivery events.
  • Recognize human participation and enforce opt-out or suppression state.

Provider-granted authority

The messaging authorization can expose the numbers, conversations, messages, and send operations allowed by the provider grant. Some grants may be broader than Spillway’s normal use.

Spillway-used authority

Spillway uses the selected sender only for tenant-bound eligible recovery situations and the office-confirmed inspection exchange.

Spillway-enforced restrictions

  • No homeowner message before the authorized connection is ready and the $299 activation payment succeeds.
  • Exact tenant, provider, and sender binding.
  • Messaging registration and entitlement checks.
  • STOP, START, HELP, quiet-hours, suppression, and duplicate-message controls.
  • Release authority defaults closed.

Worst case if this access were misused

If messaging authority were compromised or its controls failed, an unauthorized message could be sent through the contractor’s approved business identity, creating customer, brand, carrier, and regulatory harm.

What reduces that risk

  • Provider capability verification.
  • Tenant and selected-number binding.
  • Production release controls.
  • Idempotent dispatch.
  • Inbound signature and replay checks where available.
  • Delivery reconciliation.
  • Immediate opt-out suppression.

How you shut it off

  1. Pause messaging for the tenant.
  2. Disconnect the messaging provider.
  3. Revoke the account through the provider or Pipedream Connect.
  4. Existing delivery events may still arrive for messages accepted before shutdown.
View technical permissions
Technical details

The provider’s authorization is the technical ceiling. Spillway’s application behavior may be narrower.

Connection broker
Pipedream Connect; a separate supported messaging provider can be connected when the call provider does not supply messaging.
Authorization method
Provider-specific OAuth or credential form.
Read operations
Selected-number inventory, supported message thread or event reads, replies, opt-out state, and delivery evidence.
Write operations
Create approved SMS messages through the selected authorized sender.
Events
Inbound message and delivery-status events, or documented reconciliation where the provider requires it.
Tenant binding
The authorization is bound server-side to one contractor account and setup session.
Credential storage
Provider credentials remain server-side and are not returned to the browser, analytics, or public logs.
Auditability
Relevant authorization, provider, messaging, activation, and billing events use tenant-bound operational records.
Revocation
Disconnect through Spillway and revoke directly through the provider when the provider offers that control.
Failure behavior
Expired, revoked, or incomplete authority stops dependent action; it does not become a fabricated success.
Last reviewed
August 24, 2026. The actual account capabilities are checked again after authorization.

Connection

Office email handoff.

Spillway emails the contractor’s verified work address when homeowner availability requires office times and when a time is confirmed.

Why Spillway needs it

The office remains the authority for its real schedule without granting Spillway access to a CRM or calendar.

What Spillway can change

Email delivery can notify and request a response. It cannot create or change an appointment in the contractor’s system.

What Spillway actually uses

  • Use the operational email associated with the contractor’s invitation or recovery session.
  • Request a small set of real available inspection times.
  • Send the final homeowner-confirmed time and context for the office to schedule.
  • Send connection and billing notices required by the service.

Provider-granted authority

Spillway’s transactional email provider can send approved transactional messages from the configured Spillway sender to verified service recipients.

Spillway-used authority

No newsletter or marketing list is created from setup email authority.

Spillway-enforced restrictions

  • Verified setup identity.
  • Transactional templates only.
  • No homeowner content in analytics event names.
  • Expiring and session-bound verification codes.
  • Rate and attempt limits.

Worst case if this access were misused

If this authority were misused, incorrect or excessive transactional email could be sent from Spillway’s domain.

What reduces that risk

  • Resend credential custody.
  • Verified sender domain.
  • Template and recipient validation.
  • Rate limiting.
  • Redacted error logs.

How you shut it off

  1. Disable transactional email delivery.
  2. Rotate or revoke the Resend credential.
  3. Contact Spillway to change or remove the office recipient.
View technical permissions
Technical details

The provider’s authorization is the technical ceiling. Spillway’s application behavior may be narrower.

Provider
Resend transactional email.
Read operations
Delivery status required for support and reliability.
Write operations
Send approved transactional email templates.
Tenant binding
The authorization is bound server-side to one contractor account and setup session.
Credential storage
Provider credentials remain server-side and are not returned to the browser, analytics, or public logs.
Auditability
Relevant authorization, provider, messaging, activation, and billing events use tenant-bound operational records.
Revocation
Disconnect through Spillway and revoke directly through the provider when the provider offers that control.
Failure behavior
Expired, revoked, or incomplete authority stops dependent action; it does not become a fabricated success.
Last reviewed
August 24, 2026. The actual account capabilities are checked again after authorization.

Connection

Starting payment and subscription.

Stripe collects the $299 activation payment when service can begin and keeps the approved payment method for later recurring charges.

Why Spillway needs it

The $299 activation and later recovery-anchored recurring charges must be verified server-side and processed without Spillway storing raw card details.

What Spillway can change

The billing service can create authorized payment and subscription objects in Spillway’s Stripe account. It cannot affect calls or messages.

What Spillway actually uses

  • Collect exactly one $299 activation payment when service can begin.
  • Store a reusable Stripe payment-method reference under the accepted terms.
  • Record the first qualifying confirmed recovered inspection as a $0 recurring-billing anchor.
  • Charge the next $299 exactly 30 days after that recovery, then every 30 days.
  • Receive signed payment, subscription, refund, and dispute events.

Provider-granted authority

Stripe authority can create charges and subscriptions against saved payment methods within Spillway’s merchant account. Misuse could create an unauthorized charge.

Spillway-used authority

Spillway permits the $299 activation after an exact provider connection and permits recurring billing only from the first authoritative qualifying confirmed-recovery timestamp.

Spillway-enforced restrictions

  • Raw card details stay with Stripe.
  • Browser redirects never establish payment truth.
  • Signed webhook verification and event deduplication.
  • No recovered inspection means no second $299 charge.
  • The first recovery creates no charge and anchors the next $299 exactly 30 days later.
  • Ten elapsed days never manufacture billing authority.
  • Disputed, paused, or offboarded state blocks the transition.

Worst case if this access were misused

If payment authority were compromised or the billing controls failed, a saved payment method could be charged outside the accepted product rule.

What reduces that risk

  • Stripe-hosted payment fields.
  • Signed webhook authority.
  • Idempotency.
  • Tenant-bound billing state.
  • Release kill switch.
  • Audit records and dispute handling.

How you shut it off

  1. Pause or cancel the subscription.
  2. Remove or replace the payment method through the supported billing path.
  3. Disable monthly-billing release authority.
  4. Raise a disputed charge with Spillway and the card issuer.
View technical permissions
Technical details

The provider’s authorization is the technical ceiling. Spillway’s application behavior may be narrower.

Provider
Stripe.
Authorization method
Stripe-owned payment fields or Stripe-hosted checkout and authenticated Stripe webhooks.
Read operations
Payment, payment-method reference, subscription, invoice, refund, and dispute state.
Write operations
One $299 activation payment and the later recovery-anchored $299 recurring subscription.
Webhook authority
Only signature-verified, replay-safe Stripe events advance payment state.
Tenant binding
The authorization is bound server-side to one contractor account and setup session.
Credential storage
Provider credentials remain server-side and are not returned to the browser, analytics, or public logs.
Auditability
Relevant authorization, provider, messaging, activation, and billing events use tenant-bound operational records.
Revocation
Disconnect through Spillway and revoke directly through the provider when the provider offers that control.
Failure behavior
Expired, revoked, or incomplete authority stops dependent action; it does not become a fabricated success.
Last reviewed
August 24, 2026. The actual account capabilities are checked again after authorization.

Usually asked next.