Privacy Policy
What we collect when you use a callmins number, who else touches it, and how to get it out of our systems.
Last updated
This policy covers callmins.com and the callmins web app. It describes the personal data we process, why, and who we share it with. It is written to be specific rather than reassuring — if something is stored, it says so.
The service is operated by [TO BE CONFIRMED: registered company name](“callmins”, “we”). Registered address: [TO BE CONFIRMED: registered address]. For anything in this document, email support@callmins.com.
The short version
- We store your account details, your wallet ledger, and metadata for every call and the full text of every SMS you send or receive on a callmins number. We have to — it is how the service bills and delivers.
- If a call is recorded or a voicemail is left, we store the audio file until you delete it.
- Call transcription is off by default. If an administrator turns it on, calls are transcribed to text while they are in progress and that text is stored and readable by an administrator. No audio recording is made by that feature.
- We do not sell personal data, and we do not use your calls for advertising.
- Your calls and SMS pass through a licensed carrier (Telnyx) to reach the public phone network. That is unavoidable for real telephony.
What we collect
Account and identity
Email address, display name, and locale. A hash of your password and a hash of your app PIN — never the values themselves. Your phone number in E.164 form and the date you verified it. If you sign in with Google, the Google account identifier. Account status, including whether and when an account was suspended.
Verification codes
When you verify a phone number we store the delivery channel, the destination number, a hash of the code, the provider’s message identifier, how many attempts were made, and when the code expired or was used.
Calls
For each call: direction, which of your numbers was used, start / answer / end timestamps, duration in seconds, the amount billed and the per-minute rate applied, the reason the call ended, and the carrier and media-server call identifiers needed to trace a fault. We do not store the audio of a call unless it was recorded — see below.
Messages
For each SMS: direction, which number was used, the carrier message identifier, delivery status, and the message body. Message content is stored so your conversation history works. If you want it gone, delete the conversation or close your account.
Recordings and voicemail
Where a call is recorded, or a caller leaves voicemail, the audio is stored in object storage and linked to the call or message record. You can delete these. Recording a call is your decision and your legal responsibility — many jurisdictions require you to tell the other party, and some require their consent. See the Terms for where that responsibility sits.
Call transcripts
Call transcription is off by default. It can only be switched on for the whole service by a platform administrator — it is not a per-call or per-user setting, so while it is on it applies to calls placed on callmins.
While it is on, our carrier (Telnyx) converts the audio of a call to text as the call happens, and we store that text against the call record: what was said, which side said it, and when. No audio file is created or kept by this feature — the audio is processed in transit and not retained by us.
Transcripts can be read and downloaded as a text file by a platform administrator. They are private call content, so they are never cached by our servers or shared with anyone outside the operator of this service.
Transcribing a call is treated the same as recording it in many places: you may be required to tell the other party, and in some jurisdictions to obtain their consent, even though no audio is stored. Where transcription is enabled, meeting that obligation is the operator’s responsibility — see the Terms.
Contacts
Contacts you create in the app: name, avatar, whether it is a favourite, and any notes you add. These are yours; we do not mine them.
Devices and sessions
For each signed-in device: a hash of the session token, the browser or app user agent, the platform, the IP address, and when it was last seen. This is what powers the “signed-in devices” list and lets us detect account takeover. Push notification tokens are stored per device so notifications can reach you.
Payments
Your wallet balance and the full transaction ledger — top-ups, call charges, bundle purchases, refunds. Your customer identifier at our payment processor. We never see or store your full card number. Card details go directly to Stripe or Braintree.
Numbers, bundles, and plans
Which virtual numbers are assigned to you, their country, monthly price, expiry and status; and any bundles or calling plans on your account, including minutes remaining and renewal dates.
Why we process it
- To provide the service — route calls and SMS, assign numbers, keep your history. This is performance of our contract with you.
- To bill accurately — rate calls, maintain the wallet ledger, process payments. Contract, and our legal obligation to keep financial records.
- To keep accounts secure — verification codes, session tracking, fraud and abuse detection. Legitimate interests, and in places a legal obligation.
- To fix faults — error reports and carrier call identifiers. Legitimate interests.
- To understand product usage — analytics on the marketing site and app. Consent, where consent is required.
Who else touches your data
These are the processors and sub-processors actually in the path. We share the minimum each one needs.
- Telnyx — licensed carrier. Handles number provisioning, SIP trunking, SMS delivery, and call control. Sees calling and called numbers, call timing, and SMS content. Where call transcription is enabled, Telnyx also processes the audio of those calls in order to produce the transcript text.
- Our own media servers(Janus Gateway and a TURN relay on infrastructure we run) — bridge your browser’s WebRTC audio to the carrier. Media passes through; it is not recorded there.
- Cloudflare — hosting, CDN, and object storage for recordings and voicemail.
- MongoDB and Upstash Redis — primary database and cache.
- Stripe and Braintree / PayPal — payments and applicable sales tax or VAT.
- Google — optional sign-in, and analytics via Google Tag Manager and Firebase.
- Infobip — delivery of phone verification codes.
- OneSignal and web push — notification delivery.
- Freshchat — support conversations.
- Sentry — error monitoring. Reports can incidentally include a user identifier and request details.
We may also disclose data where we are legally required to — a valid court order, lawful carrier or regulatory request, or to establish or defend a legal claim. Telephony records are a common target of such requests.
We do not sell personal data and we do not share it with advertisers or data brokers.
International transfers
Our processors operate globally, so your data may be processed outside your country, including in the United States and the European Union. Where transfers are restricted by law, we rely on the relevant provider’s standard contractual clauses or equivalent safeguards.
How long we keep it
Account data, call metadata, message content, contacts, and any call transcripts are kept while your account is open. Recordings and voicemail are kept until you delete them or the account closes.
When you close your account we delete or anonymise your personal data, except records we are required to retain — principally billing and transaction records for tax and accounting purposes, and the minimum needed to handle a dispute or prevent repeat abuse.
Your rights
Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, take it elsewhere in a portable form, and withdraw consent where processing relies on consent. If you are in the EEA or UK you can also complain to your data protection authority.
To exercise any of these, email support@callmins.com from the address on your account. We will respond within the period the applicable law requires. Note that deleting your account while a wallet balance or an active number remains may forfeit both — see the Terms.
Cookies and analytics
We set the cookies needed to keep you signed in and to keep the app secure; these cannot be switched off without breaking the service. Analytics and product-usage measurement run through Google Tag Manager and Firebase. Where the law requires consent for non-essential cookies, we ask before setting them.
Children
callmins is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, tell us and we will remove it.
Security
Passwords and app PINs are stored only as hashes. Session tokens are stored hashed. TURN credentials are short-lived and minted per session. Traffic is encrypted in transit. No system is perfectly secure, and we will notify you and the relevant regulator of a qualifying breach as the law requires.
Changes
We will update the date at the top of this page when this policy changes. For changes that materially affect your rights we will tell you by email or in the app before they take effect.