Legal
Privacy policy
What we hold, where it lives, who else sees it, how long it stays, and what you can make us do about it.
Last updated July 31, 2026.
Draft — not yet in force. Ringfully does not yet have an incorporated legal entity, so the party, address and governing law below read [TBD]. This document is published for review and does not bind anyone until those are filled in and it has been through a lawyer.
Two things worth knowing before the detail: everything is stored in the United States, and nothing is deleted on a schedule. Both are stated plainly in clauses 4 and 6 rather than buried, because they are the two answers most likely to change somebody’s mind.
1Who is responsible for what
Ringfully is sold to businesses, and almost everything it holds is about someone else’s business. That makes two different relationships, and which one you are in decides who you should be asking.
- If you are a customer’s employee, or someone who called a customer
- Your employer — or the business you called — decides what is collected and why. They are the controller. We hold and process it on their instructions, as their processor. Ask them first; if you come to us we will pass the request on and tell you we have.
- If you are a Ringfully customer, a prospect, or a visitor to this site
- We are the controller. This policy is ours to answer for, and the contacts in clause 10 are the ones to use.
[TBD], of [TBD], is the company behind this. Our person responsible for the protection of personal information is [TBD], [TBD], reachable at [TBD].
2What we hold
Account and identity. An agent’s name, work email, a hash of their password, their role and permissions, their extension, and — where they have chosen to set them — a mobile number and a forwarding number. Also when they last signed in, how many times they have failed to, and a free-text location on their profile.
Call records. For every call: the numbers on each end, who answered, when it started, was answered and ended, how long it lasted, which queue it went through, every hold and transfer, and who was on the conference at any moment. Agent notes attached to a call. A timeline of each agent’s availability status.
Recordings and voicemail. Where an organization records calls, the audio is held by Twilio and we keep a reference and its metadata. Voicemail audio is transcribed automatically, and we store the transcript text.
Messages and contacts. The full text of every SMS sent and received on a customer’s numbers. Contact records — name, number, company, free-text notes — many of which the system creates automatically from an unrecognised number on an inbound or outbound call.
Call-flow data. Digits a caller entered, anything a flow looked up about them, and callback numbers left by people waiting in a queue.
Security records. For each session: the IP address and browser it was created from, and when it was last used. The IP address a password reset was requested from. A log of emails and SMS the system sent, including the address or number they went to.
Emergency calls. A permanent record of every 9-1-1 or 9-3-3 dial: who dialled, what number was presented, whether it was a test, the outcome, and who acknowledged the alert. This one is kept deliberately and is not deleted on request — see clause 6.
This website. Nothing. See clause 8.
3Why we hold it, and on what basis
To run the telephone service our customer is paying for: connecting calls, routing them, showing an agent who is calling, letting an administrator see what happened, and metering usage so an invoice is right. That is the performance of our contract with the customer, and the legitimate interest of a business in keeping a record of its own communications.
To keep accounts secure — the IP addresses and sign-in counts exist to detect a stolen session and to lock an account under attack, and nothing else reads them.
To meet legal obligations, including the emergency-call record, which exists so that a regulator or a responder can reconstruct what happened.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use it to train machine-learning models, ours or anyone else’s.
4Where it is held, and why that matters
Our database and servers are in the United States — Amazon Web Services’ US East (Northern Virginia) region. Nothing is stored in Canada. Call and voicemail audio, and voicemail transcription, are handled by Twilio, which does not guarantee a storage region to us.
Ringfully’s launch market is Canada. If you are a Canadian business, or a person in Canada who called one, this means personal information about you is stored outside the country and is subject to the laws of the country it sits in — including lawful access by authorities there, under process we would not be a party to.
We are telling you this plainly rather than in a footnote because Quebec’s Law 25 requires a business to assess a transfer like this before making it, and because a customer in a regulated sector may simply not be permitted to accept it. Ask before you buy rather than after.
5Who else touches it
The full list, what reaches each of them, and where, is on the sub-processors page. In summary: Twilio carries every call and message and holds the recording and voicemail audio; Amazon Web Services runs our servers, database and secrets; Stripe handles payment details, which never touch our systems; Sentry receives error reports, configured not to include request bodies or IP addresses; and Anthropic receives caller speech from a call flow that uses the AI assistant block, which is switched off unless a customer has asked for it.
We will also disclose information where the law compels it. Where we are permitted to tell the customer that we have been compelled, we will.
If the business is ever sold, personal information would move with it, and you would be told before it did.
6How long we keep it
Currently: until someone asks us to delete it. There is no automatic expiry. Call records, recordings, voicemail and its transcripts, message content, contacts and session records are all kept indefinitely. A configurable retention schedule is planned and does not exist today, and we would rather say that than imply a discipline we do not have.
Two things are treated differently. A deactivated agent is retained rather than erased, because their name is attached to call records that have to stay attributable. And the emergency-call record is kept permanently as a compliance artefact, because its whole purpose is to survive.
7Your rights, and how to use them
Depending on where you are, you can ask us to:
- tell you what we hold about you and why;
- give you a copy, in a structured and commonly-used format;
- correct it where it is wrong;
- delete it, where we are not required to keep it;
- explain a decision reached by automated means, including what information was used and what mattered most, and have a person look at it instead; and
- withdraw a consent you previously gave.
These are handled by hand, and being precise about what that means: an administrator can already delete a contact record or a voicemail from inside the product, and deactivate an agent. What does not exist is any way to export what we hold about one person, to remove that person from every table at once, or to delete a call recording at all. There is no self-service export and no exportable audit log an administrator can pull without us. See making a request for exactly how to ask and what we can answer. Write to [TBD] and we will respond within thirty days. If you are an employee of a Ringfully customer, we will pass your request to them, because it is their data and their decision.
If you are unhappy with how we handle a request you can complain to your regulator: the Office of the Privacy Commissioner of Canada, or the Commission d’accès à l’information du Québec if you are in Quebec.
8This website
ringfully.com sets no cookies, runs no analytics, embeds no third-party scripts, and loads nothing from another company’s servers. Typefaces are served from our own domain. There is no contact form; the buttons open your own mail client, and what you write there reaches us only because you sent it.
The one thing stored is your answer to the cookie banner, so we do not ask twice. The banner exists even though there is nothing optional to consent to — the cookies page explains that rather than glossing over it, and lists every one of the eleven other things the signed-in product stores. A test loads every page in both languages on every build and asserts nothing else is written.
Do Not Track. Because we do not track visitors at all, a Do Not Track or Global Privacy Control signal has nothing to change. We honour it by construction.
The signed-in product is different — it stores a session so you stay signed in, and a theme preference. Those are strictly necessary to make it work.
9How it is protected
Passwords are hashed with bcrypt and never stored in a form we can read. Access tokens are short-lived; refresh tokens rotate, and re-using an old one is treated as theft and revokes the whole chain. Repeated failed sign-ins lock the account. Traffic is encrypted in transit. Every customer-scoped query filters on an organization id read from the verified token, and a test suite exists whose only job is to attempt cross-customer access and assert it fails.
Being equally clear about the gaps: we hold no SOC 2 report or equivalent certification, agents cannot enable a second factor, and the service is not suitable for protected health information or anything else needing HIPAA-grade handling. Multi-factor authentication is mandatory on our own operator console, not on customer accounts. Our security page is more detailed and just as direct.
If a breach creates a real risk of significant harm we will notify the affected people and the relevant regulator, and we keep a record of incidents whether or not they meet that threshold.
10Contact, and changes
Privacy questions and requests: [TBD], or by post to [TBD], marked for [TBD].
We will post changes here and update the date at the top. Where a change materially affects how we handle information already collected, we will tell customers directly rather than rely on you noticing.