Skip to main content
Skip to content

Legal

Privacy policy

What is stored, for how long, who else sees it, and how to get it back or have it deleted.

Last updated 24 August 2026. Applies to Ringback.

Who is responsible for what

Two different things happen here and it matters which one you are asking about.

Your account with us. When a business signs up, [REGISTERED COMPANY NAME] is the data controller for that business’s own details — the name of the business, the people who sign in, and billing records. We decide what is collected and why.

Your customers’ details. When somebody rings a business using Ringback and books a job, the business is the data controller for that person’s details and we are a processor acting on the business’s instructions. If you are a member of the public wanting your data removed, the business you called decides — and they can do it from their own console.

What is stored

Calls
The caller’s number, when the call came in, how long it rang, and whether it was answered. Recordings and transcripts are off by default and only exist if a business deliberately switches them on — in which case the caller is given the disclosure that business has set.
Text messages
The number texted, when, whether the network accepted it, and the message content. Content is kept for a shorter period than the record that a message was sent — see below.
Bookings and customers
Name, phone number, and whatever else the business asks for on its booking page — typically an email address and an address for the job. Free-text notes describing the problem, if the business allows them.
Payments
Amounts, status and Stripe’s own reference. Card numbers are never seen by us — they are entered on Stripe’s pages and stay there.
Security records
An audit trail of significant actions. IP addresses in it are stored as a one-way hash, never in full, which is enough to spot abuse and not enough to identify a household.

How long it is kept

The periods below are the defaults. They are each business’s own setting, adjustable in their console, and the sweep that enforces them runs on a schedule rather than on request.

  • Message content: 12 months, after which the text is erased and only the record that a message was sent remains.
  • Call records: 24 months.
  • Transcripts, where enabled at all: 30 days.
  • Uploaded files: 12 months.

Booking and payment records are kept while the business needs them for its own accounting obligations.

Opting out of messages

Replying STOP to any message stops all of them, immediately and permanently, and the block is checked again at the moment of sending rather than only when a message is queued — so a message already waiting in the queue is still not sent.

Opting out applies to marketing and to transactional messages alike. A reply to a missed call is transactional, but nobody has to accept one to be left alone.

Who else sees it

These are the only third parties involved, and several apply only to businesses that have switched something on.

Twilio
Carries the phone calls and text messages. Sees caller numbers, the numbers texted, and the content of those messages.
Supabase
Hosts the PostgreSQL database where everything described above is stored.
Vercel
Hosts and serves the application itself.
Stripe
Takes deposits and card payments. Card details are entered on Stripe’s own pages and are never held by us. Only when a business turns on payments.
Google
Reads free/busy times and writes confirmed jobs into a calendar. The access token is encrypted before it is stored. Only when a business connects a Google Calendar.
Resend
Delivers confirmation and reminder emails. Only when email delivery is configured.
Anthropic
Classifies what a missed call was probably about. Off by default and never required — the booking flow works identically without it. Only when a business opts in to call classification.

Nothing is sold, and nothing is shared for advertising.

Getting a copy, or having it deleted

A business can export everything held about one of its customers, or erase it, from its own console — the export gathers the customer record, their bookings, the messages sent to them, payments and any review; the erasure removes the personal details and the message content while leaving the anonymous record that a booking happened, which the business needs for its accounts.

If you are a member of the public, ask the business you dealt with. If you cannot reach them, write to us at dawoodghani91@gmail.com and we will pass it on and, if they do not act, act ourselves.

Security

Each business’s data is separated at the database level by row-level security policies rather than by application code, so a mistake in a query cannot return another business’s rows. Calendar access tokens are encrypted before storage. Links sent to customers carry a random token that is stored only as a hash, is scoped to a single booking, and expires.

Complaints

Write to us first at dawoodghani91@gmail.com. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk, and you do not have to come to us first.

[REGISTERED COMPANY NAME], [REGISTERED OFFICE ADDRESS]. Company number [COMPANY NUMBER]. ICO registration [ICO REGISTRATION NUMBER].

Related