Privacy, CASL and where the data goes loaded

Privacy, and what we actually do

Most of this page describes mechanisms rather than intentions — things the software enforces whether or not anyone is watching. Where that is not true, it says so.

Last updated August 2026

Whose data this is

When someone rings your business, we handle their information on your behalf. You decide what happens to it; we hold it so your assistant can answer, book and follow up. We do not sell it, share it between businesses, or use it to train anything.

What we keep about a caller: their phone number, the name and address they give, what they said they need, and — depending on your setting below — a recording and transcript of the call.

Texting people: CASL

Canada's anti-spam law is strict about commercial messages, and the way we satisfy it is structural rather than procedural:

  • We only ever text someone who contacted you first. Their call to your number is the consent. There is no other way to start a conversation — the software has no facility for sending to a number that has not rung you.
  • STOP always works, and it is honoured upstream at Twilio rather than by our own code remembering to check. Nothing we could get wrong can override it.
  • No cold outreach, no purchased lists, no marketing blasts. Not as a policy we follow — as a thing the product cannot do. There is no feature for sending a promotion and no way to export your customer list out of the system, so a number given for a reminder stays a number for a reminder.

Call recording

Callers are told at the start of the call, in the greeting itself, before they have said anything worth recording. You choose one of three settings, and the greeting changes to match:

Full
Audio and transcript kept. What most businesses want, because it is what lets you check what was promised.
Redact personal details
Audio and transcript kept, with personal details removed by the provider. For clinics and anyone handling health or financial information.
Keep nothing
No recording, no transcript, no summary. The call still happens and still books — nothing about what was said survives it.

Who else touches it, and where

We are a Canadian business and we would rather this table said Canada all the way down. It does not, and pretending otherwise would be the kind of claim that matters precisely when it is tested:

ProviderWhat it handlesProcessed in
TwilioThe phone number, the calls and the text messagesUnited States
Retell AIThe voice assistant that answers and speaksUnited States
Anthropic (Claude)The assistant’s understanding and its repliesUnited States
StripeYour subscription. Card details go to Stripe and never reach usUnited States
ResendEmail we send you — reports, password linksUnited States

Our own application and database run on servers in Beauharnois, Québec. The providers above are the exception rather than the rule, and each one is there because the service genuinely requires it.

We do not currently use an error-tracking service. If we ever turn one on, it is configured to strip personal information before anything leaves our servers, and this page will say so.

What we notice about visits to this site

We measure how this website is used so we can tell which pages help and which lose people. It is our own, on our own servers, and it is deliberately built to work without identifying anybody.

What is recorded: which pages were opened, clicks on buttons we have labelled, how far down a page someone scrolled, how long they stayed on each page, how long the whole visit lasted, which site they arrived from, and roughly which town the visit came from.

About the town. Our content delivery provider works it out at their end and tells us the name — "London", "Kitchener" — and nothing more precise. We never see or keep the address it came from. A town is only ever shown in our own reports when several different people visited from it; anywhere with fewer is pooled into "elsewhere", because one visitor from a small town is a person rather than a place. To be exact about what that is: the town of a visit is kept with it for the 90 days below, and the rule about several people is applied when we read the report, not when we write it down.

We stopped recording the kind of device. It answered nothing we would act on, and every extra detail kept beside a location narrows who it could have been. Anything previously recorded was deleted rather than left to expire.

What is not:

  • No cookies, and nothing stored on your device. Not a cookie, not local storage, nothing. That is why this site has never asked you to accept cookies — there is nothing to accept.
  • No IP address. It is used for a moment to work out a daily code that separates one visitor from another, and then discarded. It is never written to a database, a log or a metric.
  • No web addresses beyond the page name. Anything after the question mark — the part that carries reset links and email addresses — is dropped before the page is recorded.
  • Nothing you type. Buttons are recorded by a label we chose, never by what is written on or near them.
  • Not the site you came from, only its name. We record google.com, never what you searched for.

Because nothing is kept on your device, a visit cannot be joined to a later one. The daily code changes every day and cannot be turned back into a person.

If your browser says not to, we do not. Do Not Track and Global Privacy Control are both honoured — and honoured in the browser, so nothing about your visit is sent at all rather than sent and then discarded at our end.

This applies to the public website and to the application you sign in to. Inside the application we record the same things and no more: which screens are used, not what is on them. Nothing about your customers is ever part of it.

How long we keep things

Two of these are enforced by scheduled jobs, not by anyone remembering:

Website analytics — 90 days
Deleted automatically. A record of how someone moved around our own site is not worth keeping longer than that.
Change-log values — 90 days
We journal every change to every record, which is how a mistake gets traced. The values in that journal — a caller's name, their address — are stripped after ninety days, leaving who changed what and when.
Change-log metadata — 7 years
Who changed which record, when, and which fields moved. An ordinary business record, and it carries no personal information once the step above has run.
Calls, messages and bookings — while you are a customer
These are your business records and we do not delete them on a timer. If you leave, ask us and we remove them.

What we can see

Less than you might assume, and this one is worth spelling out because it is unusual. Our own staff administer plans, pricing, billing and the health of the platform. They cannot read your customers' details.

That is enforced in the database layer rather than by a policy or a login screen: the query that would return another business's callers has no administrative override to reach for. Our internal audit view shows which fields on a record changed, never what they changed to.

The one deliberate exception, during a 14-day trial: while we are setting your assistant up, we hold a working password for your account. That ends the moment we hand over — the password is reset to something nobody has seen and you set your own.

Asking us to delete something

Under PIPEDA you can ask what we hold about you and ask us to correct or remove it. If you are one of our customers' callers, ask the business you rang — it is their record and their decision — and we will act on their instruction.

This is a manual process today. There is no button; you email us and a person does it. We would rather say that than describe a self-serve feature we have not built.

privacy@everyring.ca