Privacy Policy
How AgentPhone collects, uses, and protects personal information from customers, end users, and visitors.
This Privacy Policy explains how Relay Innovations, Inc. (d/b/a AgentPhone) ("AgentPhone," "we," "us," or "our") collects, uses, shares, and protects personal information when you use our website, dashboard, APIs, MCP server, and related services (the "Service"). It applies to customers who sign up for an account, end users who call or message numbers operated through the Service, and visitors to our public website.
If a written agreement we have with you says something different, that agreement controls for that data.
1. Information We Collect
We collect information in three ways: you give it to us, it is generated automatically as you use the Service, and we receive it from third parties.
Information you give us
- Account information — name, email, organization, billing address, payment information (handled by our payment processor — we never store full card numbers), and the credentials you set on the account.
- Customer Data — call audio, transcripts, message bodies, attachments, contact lists, agent prompts, and webhook configuration that you submit through the Service.
- Support and sales information — anything you send us in email, support tickets, surveys, or sales conversations.
Information generated when you use the Service
- Telephony metadata — the phone numbers (yours and the other party's), call start and end times, duration, message direction, delivery status, error codes, carrier identifiers, and other signaling needed to route the call or message.
- Recordings and transcripts — when you enable recording or live transcription on a number or call. We process these only because you asked us to.
- Product telemetry — log lines, request and response metadata, IP address, device and browser information, dashboard click events, and crash reports. We use this to operate, secure, and improve the Service.
- Cookies and similar technologies — see Section 8.
Information from third parties
- Carriers and number providers — number registration data (CNAM, line type, portability), STIR/SHAKEN attestation results, deliverability and spam-likelihood signals.
- Identity and compliance vendors — the data they return when we verify a brand registration, a campaign, or a sender for messaging.
- Authentication providers — basic profile data when you sign in with a third-party identity provider.
2. How We Use Information
We use information to:
- Provide the Service — provision numbers, route calls and messages, generate transcripts, deliver webhooks, run the dashboard.
- Bill you and pay carriers, taxes, and regulatory fees.
- Secure the Service — detect fraud, abuse, spam, brute-force attempts, and traffic that violates carrier rules.
- Communicate with you — service announcements, security notices, and (with your consent where required) product updates.
- Comply with law — including TCPA, CAN-SPAM, GDPR, CCPA, and lawful requests from carriers and regulators.
- Improve the Service — understand how features perform, debug issues, and prioritize work.
We do not sell personal information. We do not use Customer Data to train shared AI models. SMS opt-in and consent information is not shared with or sold to third parties. Any data collected as part of the SMS opt-in process (such as a phone number and consent status) is used solely to send the messages you have consented to receive.
3. Legal Bases for Processing (EEA, UK, Switzerland)
Where the GDPR applies, we process personal information on these legal bases:
- Contract — to provide the Service to you or to a customer who has a number that interacted with you.
- Legitimate interests — to secure the Service, prevent fraud, and improve our products, balanced against your rights.
- Legal obligation — to comply with telecom, tax, and other applicable law.
- Consent — for marketing emails where required, and any other processing we say is consent-based at the time we ask.
4. How We Share Information
We share personal information only as described below.
- Service providers — cloud hosting, telecom carriers, number providers, payment processing, fraud detection, transcription, customer support, and analytics. They may only use the data to perform services for us under written contracts.
- Carriers and regulators — to route calls and messages, register brands and campaigns, and respond to lawful requests.
- Other parties at your direction — when you instruct the Service to forward, copy, or send data to a destination you choose (for example, your webhook endpoint or a tool you connect via MCP).
- In a corporate transaction — in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality.
- To comply with law or protect rights — when we believe in good faith that disclosure is necessary to comply with legal process, enforce our agreements, or protect AgentPhone, our customers, or the public.
5. International Transfers
We are based in the United States and process data there and in other countries. When we transfer personal information from the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) or another lawful transfer mechanism. We will provide a copy of the SCCs on request to [email protected].
6. Data Retention
We retain personal information only as long as needed for the purpose it was collected, plus a reasonable period after.
- Account data — for the life of the account, plus up to 24 months after deletion for billing reconciliation, dispute resolution, and audit.
- Customer Data (calls, messages, recordings, transcripts) — retained while your account is active. We delete Customer Data upon your request, following our data retention and disposal procedures.
- Telephony metadata — for up to 24 months, to support carrier reconciliation and security investigations.
- Logs and product telemetry — generally 30–90 days, and longer when an investigation is open.
You can ask us to delete Customer Data sooner; some metadata may need to be retained to comply with carrier or legal obligations.
7. Your Rights and Choices
Depending on where you live, you may have rights including:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct information that is inaccurate.
- Deletion — ask us to delete personal information, subject to legal retention obligations.
- Portability — receive your information in a portable format.
- Objection / restriction — object to or restrict certain processing.
- Opt out of "sale" or "sharing" under the CCPA / CPRA — we do not sell or share personal information for cross-context behavioral advertising.
- Withdraw consent — where we rely on consent, you can withdraw it without affecting prior processing.
To exercise these rights, email [email protected] from the address on your account, or use the privacy controls in the dashboard. If you are an end user contacting an AgentPhone customer's number, you should contact that customer first — they are the controller of their conversation with you, and we act on their instructions.
You can lodge a complaint with a supervisory authority. EEA residents may contact their national data protection authority; UK residents may contact the ICO; California residents may contact the California Privacy Protection Agency.
8. Cookies and Analytics
Our website uses a small number of cookies and similar technologies:
- Strictly necessary — to keep you signed in, remember your dashboard preferences, and protect against CSRF.
- Analytics — Google Analytics and PostHog, to understand how visitors use the site.
You can control cookies through your browser. Blocking strictly necessary cookies will break the dashboard.
9. Security
We maintain a written information security program with administrative, technical, and physical controls. Highlights include encryption in transit, encryption at rest (256-bit AES), multi-factor authentication with least-privilege access, audit logging, and vendor risk reviews. We completed a SOC 2 Type 1 examination covering the Security, Availability, and Confidentiality Trust Services Criteria (report as of July 30, 2026), and a SOC 2 Type 2 examination is in progress. See our Trust & Security page for details. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify you in accordance with applicable law.
10. Children's Privacy
The Service is not directed to children under 13 (or the age of digital consent in your country) and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact [email protected] and we will delete it.
11. Changes to this Policy
We may update this Privacy Policy from time to time. If the changes are material, we will notify you by email or in the dashboard at least 30 days before they take effect, except where a shorter period is required by law. The "Last updated" date at the top of this page always reflects the current version.
12. Contact
For privacy questions, requests, or complaints:
- Email — [email protected]
- Mail — Relay Innovations, Inc. (d/b/a AgentPhone), Attn: Privacy, San Francisco, California, USA
- Security issues — [email protected]
If your country requires us to designate an EU or UK representative under Article 27 of the GDPR, we will publish their contact details here once appointed.