Privacy, and what we actually do
Most of this page describes mechanisms rather than intentions, things the software enforces whether or not anyone is watching. Where that is not true, it says so.
Last updated 25 September 2026
Whose data this is
When someone rings your business, we handle their information on your behalf. You decide what happens to it; we hold it so your assistant can answer, book and follow up. We do not sell it, share it between businesses, or use it to train anything.
What we keep about a caller: their phone number, the name and address they give, what they said they need, and, depending on your setting below, a recording and transcript of the call.
We also keep a short record of every email we send for a business: the address it went to, the subject line, what kind of email it was and whether our provider accepted it. Never the body. That covers both the notices we send a business about its own account and the confirmations its assistant sends its customers, and it is there so a business can see what went out in their name. It is deleted after a year.
Our email provider keeps whether each email was delivered or bounced, for 30 days, so we can tell a business whether a message arrived. It does not track whether an email was opened or which links were clicked.
Every email we send for a business says who it is from, gives a postal address and has an unsubscribe link. If you use it, we keep your email address on that one business's do-not-email list so nothing more goes to you from it, and we keep it for as long as that business uses us, because deleting it is how email would start again. Unsubscribing from one business does not affect another. Emails you ask for yourself, like a password reset, still arrive.
Texts work the same way. If you reply STOP to a business's number, our telephony provider stops every further text from that number, and we keep your number on that business's list so it can see why you no longer get its booking and callback confirmations and reminders. Reply START to undo it, and we remove you from the list.
If a business lists people to be told when a caller asks to be rung back, we keep those email addresses on its profile and use them for that notice and for a short daily summary of the business's own calls, and nothing else. The business can change or remove them, or turn the daily summary off, at any time, and with none listed we email the owners at the address they sign in with.
A business can also give us up to two backup phone numbers for an emergency, such as a partner or whoever is on call. We keep them on its account and ring them only to put an emergency caller through, never for anything else.
A business can add a mobile number for each person or van that does its jobs. We prove it first, by texting it a code, and then use it for one thing only: about half an hour after a job is due to end, we text that person a link to confirm the job is done, from the business's own number. That text names the customer's first name and street, and nothing else about them. The number is deleted as soon as the business removes it, or removes that person or van. Nothing is sent to it while the business's account is not active, and when a business leaves us it is removed with the rest of that business's records, the same as everything on this page.
And we keep a short record of where each person who signs in is signed in: what their browser says it is, a shortened version of their internet address with the last part removed, and when it was last used. In that list, never the full address, and we do not look up a location from it.
That exists so somebody can open their own account page, see their own devices, and end one of them without ending all of them, which is what you want on the day a phone goes missing. It is theirs to read and theirs to clear, nobody sees anybody else's, and a device you stop using is forgotten after thirty days.
Every account uses two-step sign-in: a passkey or an authenticator app, never a code by email or text. For a passkey we keep only its public half and the name you gave it; the private half never leaves your device or your phone. For an authenticator app we keep the shared secret it was set up with, and your recovery codes, both encrypted.
We also keep a security log of sign-ins: each attempt, whether it worked, the email address that was typed, the full internet address and what the browser says it is, and changes to two-step sign-in. Unlike the device list above, the address is kept whole, because the log exists to spot and investigate somebody trying to break in. It is deleted after ninety days.
The owners of a business can see their own team's part of that log: when each person signed in or failed to, how (password, passkey or recovery code), what the browser says it is, and the shortened address, with the last part removed. They see only the people on their own team, never anybody else's, and never the full address, which stays with us for investigating an attack.
When an owner signs our Terms of Service and Customer Service Agreement, we keep a record of that signature: the name they typed, the account they signed with (its name and email at the time), the date and time, their full internet address and what their browser says it is, and a fingerprint of exactly what was signed. Unlike the sign-in record above, the address is kept whole, because this is evidence of where a contract was signed. The record cannot be edited or deleted, a copy is emailed to every owner of the business and to our own records mailbox, and a copy is kept in our backup storage in Canada.
Texting people: CASL
Canada's anti-spam law is strict about commercial messages, and the way we satisfy it is structural rather than procedural:
- We only ever text a customer who contacted you first. Their call to your number is the consent. There is no other way to start a conversation: the software has no facility for sending to a customer's number that has not rung you. The only other numbers it texts are your own: your emergency alerts, and the mobile of somebody on your team, proved by a code, for the link that confirms a job is done.
- STOP always works, and it is honoured upstream at our telephony provider rather than by our own code remembering to check. Nothing we could get wrong can override it.
- Every email can be stopped. Each one carries an unsubscribe link, and an address that uses it is checked before every email that business sends, by the one piece of our software every email passes through.
- No cold outreach, no purchased lists, no marketing blasts. Not as a policy we follow, but as a thing the product cannot do. There is no feature for sending a promotion and no way to export your customer list out of the system, so a number given for a reminder stays a number for a reminder.
Call recording
Callers are told at the start of the call, in the greeting itself, before they have said anything worth recording. You choose one of four settings, and the greeting changes to match:
Who else touches it, and where
We are a Canadian business and we would rather this table said Canada all the way down. It does not, and pretending otherwise would be the kind of claim that matters precisely when it is tested:
| Kind of service | What it handles | Processed in |
|---|---|---|
| Telephony | The phone number, the calls and the text messages | United States |
| Voice AI | The assistant that answers and speaks | United States |
| Language model | The assistant’s understanding and its replies | United States |
| Maps and addresses | The address of a job, to work out the drive between jobs at that time of day. Nothing about who the job is for or what it is | United States |
| Payments | Your subscription. Card details go to the processor and never reach us | United States |
| Email delivery | Email we send you: reports, password links, booking and callback confirmations. Keeps delivery status for 30 days | Canada |
| Our mailbox | Email you send us | Canada |
| Call recording storage | The recording of a call, once it is finished. This is the copy that lasts | Canada |
We will name them if you ask. This table says what leaves, why it has to and which country it lands in, which is what you need in order to decide whether to trust us. The specific companies are commercially sensitive, so we do not publish the list, but we give it in full, in writing, to any client, their lawyer or a regulator who asks. Write to hello@everyring.ca and you will get the names, what each one holds and how long.
Our own application and database run on servers in Beauharnois, Québec. The services above are the exception rather than the rule, and each one is there because the job genuinely requires it.
We do not currently use an error-tracking service. If we ever turn one on, it is configured to strip personal information before anything leaves our servers, and this page will say so.
What we notice about visits to this site
We measure how this website is used so we can tell which pages help and which lose people. It is our own, on our own servers, and it is deliberately built to work without identifying anybody.
What is recorded: which pages were opened, clicks on buttons we have labelled, how far down a page someone scrolled, how long they stayed on each page, how long the whole visit lasted, which site they arrived from, and roughly which town and country the visit came from.
About the town. Our content delivery provider works it out at their end and tells us the name ("London", "Kitchener") and nothing more precise. We never see or keep the address it came from. A town is only ever shown in our own reports when several different people visited from it; anywhere with fewer is pooled into "elsewhere", because one visitor from a small town is a person rather than a place. To be exact about what that is: the town of a visit is kept with it for the 90 days below, and the rule about several people is applied when we read the report, not when we write it down.
About the country. The same provider tells us the country, as a two-letter code. Unlike the town, every country is named in our reports however few people came from it, and the reason is that a country cannot give away more than the town inside it already would: one visitor from Germany is one of eighty million, where one visitor from a small town is somebody standing somewhere. It is kept for the same 90 days and deleted with everything else.
We stopped recording the kind of device. It answered nothing we would act on, and every extra detail kept beside a location narrows who it could have been. Anything previously recorded was deleted rather than left to expire.
What is not:
- No cookies, and nothing stored on your device. Not a cookie, not local storage, nothing. That is why this site has never asked you to accept cookies, there is nothing to accept.
- No IP address. It is used for a moment to work out a daily code that separates one visitor from another, and then discarded. It is never written to a database, a log or a metric.
- No web addresses beyond the page name. Anything after the question mark, the part that carries reset links and email addresses, is dropped before the page is recorded.
- Nothing you type. Buttons are recorded by a label we chose, never by what is written on or near them.
- Not the site you came from, only its name. We record google.com, never what you searched for.
Because nothing is kept on your device, a visit cannot be joined to a later one. The daily code changes every day and cannot be turned back into a person.
If your browser says not to, we do not. Do Not Track and Global Privacy Control are both honoured, and honoured in the browser, so nothing about your visit is sent at all rather than sent and then discarded at our end.
This applies to the public website and to the application you sign in to. Inside the application we record the same things and no more: which screens are used, not what is on them. Nothing about your customers is ever part of it.
Google Calendar, if you connect one
Connecting a calendar is optional and nothing here applies until you do it. You can disconnect at any time from your business profile.
What Google data we access
We ask for the narrowest permissions that do the job, and deliberately not the broad ones:
We do not request calendar or calendar.readonly, either of which would let us read everything in every calendar on the account.
How we use it
- Busy times decide which appointment slots the assistant offers a caller, so it does not offer one you are already booked for.
- Bookings the assistant makes are written into the calendar you chose, and moved or cancelled there when the customer changes their mind.
- The calendar list fills the picker, and the email address tells you which account is connected.
That is the whole of it. Google data is not used for advertising, not used to build a profile of you, and not used to create, train or improve any machine learning or AI model.
What we write into your calendar. An appointment we book carries the customer's name, the phone number to reach them, the address of the job where they gave one, and what they asked for. That is information about your customer going into your own calendar, which is the point of the feature, and it is worth knowing that it goes to Google along with it.
Who we share it with
We do not sell it, and we never share it between businesses. It is not disclosed to anybody for their own purposes. Two transfers happen and both are in order to run the feature you asked for:
- Our hosting provider, in Canada, where the connection and any booking we made are stored.
- The AI that answers your phone and texts receives the available times, so it can offer them out loud or in a message. It receives times and nothing else: no titles, no attendees, no locations, because we never hold those in the first place.
AI, and what it is never used for
Your assistant is built on AI services run by other companies: one answers text messages, another runs the voice assistant. Where anything derived from your calendar reaches either of them, it is the available times above and nothing more.
Nothing from your Google account is ever used to create, train or improve any machine learning or AI model. Not by us, and not by any provider we use: our contracts with them prohibit training on the content we send, and we have not opted in to any arrangement that would permit it.
We describe these providers by role rather than by name, for the reason set out under Who else touches it, and where: the list is commercially sensitive, so we do not publish it, and we give it in full and in writing to any client, their lawyer or a regulator who asks.
Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How it is protected
- The keys to your calendar are encrypted where they are stored, with a certificate kept outside the database. A copy of the database on its own does not open your calendar.
- Encrypted in transit, over HTTPS, every time.
- Held in Canada, with the rest of your data.
- Only the narrow permissions above, so what a mistake could reach is bounded by what we were able to ask for.
- Deleted when you disconnect. We remove the stored authorisation rather than blanking it, and stop listening for changes. You can also remove our access yourself at any time from your Google account permissions, which is the authoritative way to end it.
Other calendars, by link
Both of these are optional, only an owner can set them up, and neither involves another company of ours: the calendar service is one you already use.
How long we keep things
Every period below is enforced by a scheduled job, not by anyone remembering:
What is not on a timer, so that you know: the call record itself, the assistant's written summary of a call, your leads, your text messages and your bookings. Emails are the exception among the things we send for you: the text messages stay, and the record of an email goes after a year. Those are your business records and we keep them while you are a customer. Ask us and we remove them, at any time, and you can erase everything about one caller yourself from their page.
What we can see
Less than you might assume, and this one is worth spelling out because it is unusual. Our own staff administer plans, pricing, billing and the health of the platform. They cannot read your customers' details.
That is enforced in the database layer rather than by a policy or a login screen: the query that would return another business's callers has no administrative override to reach for. Our internal audit view shows which fields on a record changed, never what they changed to.
If you tell us a call went wrong, we receive your note, when the call was and what it was recorded as. Never the conversation, and never who rang. If we need to look at the call itself, we ask you.
While we are setting your assistant up, before your business goes live, one of our staff can be given access to your account to do it. We never see your password. You choose it yourself, from an invitation link that only reaches you, and there is nothing for us to hold or to hand back.
That access expires after two hours, and it is never anonymous: our staff member stays signed in as themselves, so every change made while we are setting you up appears in your own history under their name. It ends for good the day we hand the account over, or the day your trial ends or your paid subscription starts if either comes first, and after that we cannot get in at all.
Asking us to delete something
Under PIPEDA you can ask what we hold about you and ask us to correct or remove it. If you are one of our customers' callers, ask the business you rang, it is their record and their decision, and we will act on their instruction.
The business you rang can do it themselves, from the page that shows your conversation. It removes the conversation, the call, the recording and your details, from here and from the provider that carries the call and runs the voice assistant. We check afterwards that the recording has really gone rather than taking the provider's word for it.
Three honest limits. The provider keeps its own billing record of the call (that a call happened, when, and how long, never the audio or the words), and we cannot shorten that. A record of the deletion itself is kept: that somebody erased a record and who, without the details that were erased. That is what makes the deletion something we can stand behind rather than something nobody can check.
And the third, which is true of any system that takes backups and is worth saying plainly rather than leaving you to assume otherwise. We copy the database every night so that a failed disk is not a lost business, and those copies are kept for thirty days and then destroyed. A record you erase today is gone from the live system immediately and gone from the last backup within a month. We do not go into old backups to remove single records, because restoring and rewriting them is more likely to damage the data of every other person in there than to help.
If you would rather ask us directly, or the business is not reachable, email us and a person will do it.