Your privacy, our responsibility.
This policy explains what data Ringflow collects, why we collect it, how we protect it, and what rights you have over it. We've written it in plain language — no unnecessary jargon.
Last updated: May 9, 2026
1. Who We Are
Ringflow Inc. ("Ringflow", "we", "our", or "us") operates the website ringflow.com and provides cloud communications services including Cloud Phone, AI Contact Center, AI Sales Platform, SMS/MMS messaging, HD Video Meetings, and related APIs and integrations (collectively, the "Services").
Our registered address is: Ringflow Inc., 1 World Trade Center, New York, NY 10007, United States. If you have any questions about this Privacy Policy or how we handle your data, you can reach our Privacy Team at privacy@ringflow.com.
2. Information We Collect
We collect information in the following ways:
Account & Contact Information
When you register for a Ringflow account, we collect your name, email address, phone number, company name, job title, and billing address. This information is necessary to create and manage your account and deliver our Services.
Usage & Communications Data
As you use our Services, we collect call detail records (CDRs), message logs, recording metadata, AI session transcripts, and analytics data. This data is used to provide, operate, and improve the Services.
Device & Technical Information
We automatically collect IP addresses, browser type and version, operating system, device identifiers, referral URLs, and session duration when you access our website or platform. This helps us maintain security and diagnose technical issues.
Payment Information
Billing details including credit card numbers are processed directly by our PCI-DSS-certified payment processor. Ringflow does not store full card numbers on its own systems.
Support Communications
When you contact our support team, we retain records of that correspondence — including chat transcripts, email threads, and call recordings — to resolve issues and improve our service quality.
Cookies & Tracking Technologies
We use first-party and third-party cookies, pixel tags, and similar technologies. See Section 5 for full details.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery — to provision phone numbers, route calls, send messages, run AI agents, and fulfil all features of your subscription.
- Billing & payments — to process subscription fees, issue invoices, handle refunds, and detect fraud.
- Product improvement — to analyse usage patterns, diagnose bugs, measure feature adoption, and inform our roadmap.
- Security & compliance — to detect and prevent abuse, enforce our Acceptable Use Policy, and meet legal obligations including STIR/SHAKEN call authentication and TCPA compliance.
- Customer communications — to send transactional emails (receipts, password resets, incident alerts), product announcements, and — with your consent — marketing updates. You can opt out of marketing emails at any time via the unsubscribe link.
- AI model improvement — aggregated and anonymised call and message data may be used to improve our AI Receptionist and transcription models. Identifiable customer data is never used for model training without explicit opt-in consent.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, our legal basis for processing your personal data is one of the following:
- Contractual necessity — processing required to deliver the Services you have subscribed to.
- Legitimate interests — processing for fraud prevention, security monitoring, and product analytics, where those interests are not overridden by your rights.
- Legal obligation — processing required to comply with applicable law (e.g., retaining call records for regulatory audits).
- Consent — for marketing communications and optional data uses where we ask for your explicit agreement.
You have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent given before withdrawal.
6. How We Share Your Data
Ringflow does not sell your personal data. We share data only in the following limited circumstances:
Service Providers
We engage vetted third-party processors — cloud infrastructure providers, payment processors, customer support tools, and analytics platforms — under data processing agreements that restrict them to processing data solely on our instructions.
Telecommunications Partners
To route calls and messages, we transmit necessary call metadata (originating number, destination number, call duration) to licensed carrier partners. These partners are bound by applicable telecommunications law.
Business Transfers
If Ringflow is acquired, merges with another company, or undergoes a similar corporate transaction, your data may be transferred to the successor entity. We will notify you via email and a prominent notice on our website before any such transfer takes effect.
Legal Requirements
We may disclose your data if required by law, court order, or lawful government request, or if we believe disclosure is necessary to protect the rights, property, or safety of Ringflow, our customers, or the public.
With Your Consent
We will share your data with any other third party only with your explicit consent.
7. How Long We Retain Your Data
We retain your data for as long as your account is active or as needed to provide the Services. Specific retention periods are:
- Account information — retained for the duration of your subscription plus 90 days after account closure, then deleted or anonymised.
- Call detail records — retained for 13 months by default; Enterprise customers may configure custom retention windows of up to 7 years for regulatory compliance.
- Call recordings — retained for 90 days by default. You can extend, download, or delete recordings at any time from the dashboard.
- AI transcripts — retained for 90 days by default; configurable per workspace.
- Billing records — retained for 7 years to meet financial reporting obligations.
- Support communications — retained for 3 years after resolution of the relevant ticket.
When data reaches the end of its retention period, it is securely deleted from all production and backup systems within 30 days.
8. Your Rights
Depending on your location, you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data, subject to our legal retention obligations.
- Right to restrict processing — ask us to limit how we use your data in certain circumstances.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise any of these rights, email privacy@ringflow.com with the subject line "Data Rights Request". We will respond within 30 days. We may ask you to verify your identity before fulfilling a request.
If you are in the EEA or UK and believe we are not handling your data lawfully, you have the right to lodge a complaint with your local data protection authority.
9. Data Security
Ringflow implements a layered security programme to protect your data:
- Encryption in transit — all data transmitted between your devices and our platform is encrypted using TLS 1.2 or higher.
- Encryption at rest — all stored data, including call recordings and AI transcripts, is encrypted using AES-256.
- Access controls — role-based access control (RBAC) ensures employees can only access data necessary for their job function. All access is logged and regularly audited.
- Security standards — Ringflow is STIR/SHAKEN certified for call authentication. Business Associate Agreements (BAA) are available on healthcare-aligned plans. Contact us for our full security documentation package.
- Vulnerability management — we conduct regular penetration tests and operate a responsible disclosure programme at security@ringflow.com.
- Incident response — in the event of a data breach that affects your personal data, we will notify you within 72 hours in accordance with applicable law.
10. International Data Transfers
Ringflow is headquartered in the United States and operates data centres in the US (East and West), EU-West (Ireland), and APAC-SE (Singapore). When we transfer personal data from the EEA, UK, or Switzerland to countries that do not provide an equivalent level of data protection, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- UK International Data Transfer Agreements (IDTAs) for UK data subjects.
- Binding Corporate Rules where applicable.
You can request a copy of our SCCs by emailing privacy@ringflow.com.
11. Children's Privacy
Ringflow's Services are intended for businesses and professionals aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us with personal data, please contact privacy@ringflow.com immediately and we will delete the relevant information promptly.
12. Third-Party Links & Embedded Content
Our website and platform may contain links to third-party websites, integration partner pages, or embedded content (such as YouTube videos or LinkedIn posts). These third parties operate under their own privacy policies, which we do not control. We recommend reviewing the privacy policy of any third-party site you visit through a link on our platform.
Our integration marketplace connects Ringflow to tools such as HubSpot, Zoho CRM, Salesforce, and Slack. When you enable an integration, the relevant third-party service may receive data from Ringflow in accordance with the permissions you grant. You can revoke integration access at any time from the Integrations section of your dashboard.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:
- Post the updated policy at ringflow.com/privacy-policy with a new "Last Updated" date.
- Send an email notification to the primary account holder of every active workspace.
- Display an in-app banner for 30 days after the change takes effect.
Your continued use of the Services after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree to the revised policy, you should stop using the Services and contact us to close your account.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Ringflow Privacy Team
Email: privacy@ringflow.com Address: Ringflow Inc., 1 World Trade Center, New York, NY 10007, United States
EU / UK Representative
For data subjects in the EEA or UK who wish to exercise their rights or raise a concern, you may also contact our EU representative at eu-privacy@ringflow.com.
We are committed to working with you to resolve any privacy concerns fairly and promptly.
Our Commitment
Your data stays yours.
Privacy at Ringflow is not a checkbox — it is an architectural decision. We collect the minimum data needed to run the service, encrypt everything, and give you full control to access, export, or delete it at any time.
