Privacy Policy
Last updated: 8/5/2026
1. Introduction
This Privacy Policy explains how RingBack ("we", "us") handles information when a business owner uses the RingBack service. RingBack is designed to help small businesses respond to missed calls with an automatic text message and manage the resulting conversations.
2. Information we collect
- Account information: email address, password (stored hashed by our authentication provider), business name, owner name, business type and address you provide during onboarding.
- Phone and messaging data: business phone number, missed-call metadata, and the SMS conversations sent and received through the service.
- Customer contact data: phone numbers of people who call your business and the messages they exchange with you through RingBack.
- Usage and technical data: log data, IP address, browser and device information used to keep the service secure and reliable.
3. Why we collect it
- To provide the RingBack service — sending automatic replies to missed callers and storing the conversations.
- To authenticate users and protect accounts.
- To display leads, statuses and reporting inside the dashboard.
- To improve the reliability, safety and quality of the service.
- To communicate with account holders about their account or the service.
4. How account data is stored
Account and application data is stored in a secure, access-controlled database. Access is restricted to authorised systems and personnel who need it to operate the service. Each business's data is separated so that one business cannot access another business's records.
5. How phone and message data may be processed
Missed-call metadata and SMS messages sent or received through RingBack are processed to deliver the service, display the conversation to the business owner, and generate lead and dashboard information. Messages may be transmitted through a telephony or messaging provider (see Subprocessors below).
6. Subprocessors
We use a small number of third-party service providers to run RingBack. The primary providers we intend to use are:
- Supabase — authentication and database hosting.
- Stripe (when paid subscriptions begin) — payment processing.
- Twilio (when telephony integration is enabled) — SMS and phone number connectivity.
These providers process data on our behalf under their own terms and security practices.
7. Data retention
We retain account and conversation data for as long as your account remains active or as needed to provide the service. On account closure, we will delete or anonymise personal data within a reasonable period, unless we are required to retain it for legal, tax or dispute-resolution reasons.
8. Your rights
Depending on your location, you may have rights to access, correct, delete or export personal data we hold about you, and to object to or restrict certain processing. You can exercise these rights by contacting us using the details below.
9. Contact
For privacy questions or requests, contact: privacy@ringback.io.
This document is a working draft prepared during pre-beta. It should be reviewed by a qualified legal professional before commercial launch. It does not constitute legal advice.