Legal
Privacy policy
What we hold, where it lives, who else sees it, how long it stays, and what you can make us do about it.
Last updated August 30, 2026.
Draft: not yet in force. Ringfully does not yet have an incorporated legal entity, so the party, address and governing law below read [TBD]. This document is published for review and does not bind anyone until those are filled in and it has been through a lawyer.
One thing worth knowing before the detail: everything is stored in the United States. It is stated plainly in clause 4 rather than buried, because it is the answer most likely to change somebody’s mind. Clause 6 sets out how long each kind of data is kept before it is deleted.
1Who is responsible for what
Ringfully is sold to businesses, and almost everything it holds is about someone else’s business. That makes two different relationships, and which one you are in decides who you should be asking.
- If you are a customer’s employee, or someone who called a customer
- Your employer, or the business you called, decides what is collected and why. They are the controller. We hold and process it on their instructions, as their processor. Ask them first; if you come to us we will pass the request on and tell you we have.
- If you are a Ringfully customer, a prospect, or a visitor to this site
- We are the controller. This policy is ours to answer for, and the contacts in clause 10 are the ones to use.
[TBD], of [TBD], is the company behind this. Our person responsible for the protection of personal information is John, [TBD], reachable at [email protected].
2What we hold
Account and identity. An agent’s name, work email, a hash of their password, their role and permissions, their extension, and (where they have chosen to set them) a mobile number and a forwarding number. Also when they last signed in, how many times they have failed to, and a free-text location on their profile.
Call records. For every call: the numbers on each end, who answered, when it started, was answered and ended, how long it lasted, which queue it went through, every hold and transfer, and who was on the conference at any moment. Agent notes attached to a call. A timeline of each agent’s availability status.
Recordings and voicemail. Where an organization records calls, the audio is held by Twilio and we keep a reference and its metadata. Voicemail audio is transcribed automatically, and we store the transcript text.
Messages and contacts. The full text of every SMS sent and received on a customer’s numbers. Contact records (name, number, company, free-text notes), many of which the system creates automatically from an unrecognised number on an inbound or outbound call.
Call-flow data. Digits a caller entered, anything a flow looked up about them, and callback numbers left by people waiting in a queue.
Security records. For each session: the IP address and browser it was created from, and when it was last used. The IP address a password reset was requested from. A log of emails and SMS the system sent, including the address or number they went to.
Emergency calls. A permanent record of every 9-1-1 or 9-3-3 dial: who dialled, what number was presented, whether it was a test, the outcome, and who acknowledged the alert. This one is kept deliberately and is not deleted on request. See clause 6.
This website. What you send through the contact form: your name, email, company if you give one, the plan you picked, how many people answer your phones and your message, with the page and language you sent it from. If you accept analytics, Google Analytics counts your visit for us. The free tools under /tools read your file inside your own browser and send nothing to us: there is no upload and no copy on our side. See clause 8.
3Why we hold it, and on what basis
To run the telephone service our customer is paying for: connecting calls, routing them, showing an agent who is calling, letting an administrator see what happened, and metering usage so an invoice is right. That is the performance of our contract with the customer, and the legitimate interest of a business in keeping a record of its own communications.
To keep accounts secure: the IP addresses and sign-in counts exist to detect a stolen session and to lock an account under attack, and nothing else reads them.
To meet legal obligations, including the emergency-call record, which exists so that a regulator or a responder can reconstruct what happened.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use it to train machine-learning models, ours or anyone else’s.
4Where it is held, and why that matters
Our database and servers are in the United States: Amazon Web Services’ US East (Northern Virginia) region. Nothing is stored in Canada. Call and voicemail audio, and voicemail transcription, are handled by Twilio, which does not guarantee a storage region to us.
Ringfully’s launch market is Canada. If you are a Canadian business, or a person in Canada who called one, this means personal information about you is stored outside the country and is subject to the laws of the country it sits in, including lawful access by authorities there, under process we would not be a party to.
We are telling you this plainly rather than in a footnote because Quebec’s Law 25 requires a business to assess a transfer like this before making it, and because a customer in a regulated sector may simply not be permitted to accept it. Ask before you buy rather than after.
5Who else touches it
The full list, what reaches each of them, and where, is on the sub-processors page. In summary: Twilio carries every call and message and holds the recording and voicemail audio; Amazon Web Services runs our servers, database and secrets, and delivers this website’s contact form messages through Amazon SES; Cloudflare hosts this website and runs the contact form’s spam check; Google Analytics counts visits to this website for visitors who accept it; Stripe handles payment details, which never touch our systems; Sentry receives error reports, configured not to include request bodies or IP addresses; and Anthropic receives caller speech from a call flow that uses the AI assistant block, which is switched off unless a customer has asked for it.
We will also disclose information where the law compels it. Where we are permitted to tell the customer that we have been compelled, we will.
If the business is ever sold, personal information would move with it, and you would be told before it did.
6How long we keep it
Most of it is now deleted on a schedule. There are eight retention windows, one for each class of data. An administrator sets them in the product, under Settings, Data Retention; until they do, our defaults apply. A job runs nightly and deletes whatever has passed its window. Our defaults are thirty days for call recordings; ninety days for voicemail and its transcripts; one year for message content, the log of what the system sent by email and text message, and the record of agent availability; and about seven years for call records and the audit log, which are billing and dispute evidence. Each of the eight can be set between one day and ten years.
When a recording or a voicemail passes its window, the audio is deleted at Twilio first, and the record here is only cleared once Twilio has confirmed it is gone. A deleted recording leaves behind a marker holding its identifier, when the audio was destroyed and why, so the deletion can be evidenced afterwards. A call record carrying such a marker is not removed by the schedule and outlives its own window.
Some things sit outside the schedule. Contact records have no window: a directory entry is address-book data rather than the record of an event, so it is deleted on request rather than on a timer. Session records have none either. A deactivated agent is retained rather than erased, because their name is attached to call records that have to stay attributable. And the emergency-call record is kept for about seven years as a compliance artefact, because its whole purpose is to outlive the incident.
7Your rights, and how to use them
Depending on where you are, you can ask us to:
- tell you what we hold about you and why;
- give you a copy, in a structured and commonly-used format;
- correct it where it is wrong;
- delete it, where we are not required to keep it;
- explain a decision reached by automated means, including what information was used and what mattered most, and have a person look at it instead; and
- withdraw a consent you previously gave.
What the product itself can do, precisely: an administrator holding the necessary permissions can pull everything we hold about one person as a single JSON file, or one section of it at a time as a CSV, and can run an erasure that acts on every table at once. An erasure has to be confirmed by typing the subject’s own identifier, and it rehearses by default, so a mistyped request deletes nothing. Call recordings and voicemail can be deleted, one at a time or by an erasure: the audio is removed at Twilio first, and the record here is only cleared once Twilio has confirmed. The audit log can be exported as a CSV file without involving us. All of this sits in the product, under Settings and on the audit log page, and every export and every erasure writes an audit entry of its own.
Two things an erasure does not do, said here rather than left to be discovered. Call records are not deleted: the identifiers in them are removed and the row survives, because it is the record an invoice was computed from and tax law requires it to be kept. The audit log is not erased either, because it is the evidence that we honoured the request; the name and work email of a departed employee therefore survive in the entries describing what they did.
The process around it is still manual. Nothing in the product records who asked, checks that they are who they say they are, or starts the thirty-day clock, and there is no way for you to make a request yourself. Making a request sets out exactly how to ask and what we can answer. Write to [email protected] and we will respond within thirty days. If you are an employee of a Ringfully customer, we will pass your request to them, because it is their data and their decision.
If you are unhappy with how we handle a request you can complain to your regulator: the Office of the Privacy Commissioner of Canada, or the Commission d’accès à l’information du Québec if you are in Quebec.
8This website
ringfully.com sets no cookies and stores nothing in your browser until you answer the cookie banner, and it loads Google Analytics only if you choose “Accept all”. Typefaces are served from our own domain. Cloudflare hosts the site, so every page request passes through its network.
Google Analytics. If you accept, Google Analytics 4 counts visits and which pages are read. It sets the _ga cookie, and Google receives your IP address and the page you are on. It is configured for measurement only: advertising storage, ad personalisation and ad user data are all denied. When a contact form message is sent, it records that one was sent and which plan was picked, never what you typed. If you choose “Essential only”, or do not answer, the script is never loaded and nothing is sent to Google.
The contact form. What you type is sent to a Cloudflare Pages Function on this domain. Cloudflare’s Turnstile check confirms that a person sent it, and to do that it reads signals from your browser and receives your IP address. The message is then delivered to our sales mailbox by Amazon SES, in the United States. The website itself keeps no copy. We use it to reply to you.
Your answer to the cookie banner is stored in your browser so we do not ask twice. The cookies page lists it, the Google Analytics cookie, and every one of the eleven things the signed-in product stores. A test loads every page in both languages and asserts nothing is written before you answer.
Do Not Track. If your browser sends a Do Not Track or Global Privacy Control signal, we treat it as a refusal: the banner is not shown, and Google Analytics is never loaded, even if you accepted it earlier.
The signed-in product is different: it stores a session so you stay signed in, and a theme preference. Those are strictly necessary to make it work.
9How it is protected
Passwords are hashed with bcrypt and never stored in a form we can read. Access tokens are short-lived; refresh tokens rotate, and re-using an old one is treated as theft and revokes the whole chain. Repeated failed sign-ins lock the account. Traffic is encrypted in transit. Every customer-scoped query filters on an organization id read from the verified token, and a test suite exists whose only job is to attempt cross-customer access and assert it fails.
Being equally clear about the gaps: we hold no SOC 2 report or equivalent certification, and the service is not suitable for protected health information or anything else needing HIPAA-grade handling. Agents can turn on a second factor for their own account, but an organization cannot yet require it of every agent. Multi-factor authentication is mandatory on our own operator console, not on customer accounts. Our security page is more detailed and just as direct.
If a breach creates a real risk of significant harm we will notify the affected people and the relevant regulator, and we keep a record of incidents whether or not they meet that threshold.
10Contact, and changes
Privacy questions and requests: [email protected], or by post to [TBD], marked for [TBD].
We will post changes here and update the date at the top. Where a change materially affects how we handle information already collected, we will tell customers directly rather than rely on you noticing.