Privacy, CASL and where the data goes loaded

Privacy, and what we actually do

Most of this page describes mechanisms rather than intentions, things the software enforces whether or not anyone is watching. Where that is not true, it says so.

Last updated 25 September 2026

Whose data this is

When someone rings your business, we handle their information on your behalf. You decide what happens to it; we hold it so your assistant can answer, book and follow up. We do not sell it, share it between businesses, or use it to train anything.

What we keep about a caller: their phone number, the name and address they give, what they said they need, and, depending on your setting below, a recording and transcript of the call.

We also keep a short record of every email we send for a business: the address it went to, the subject line, what kind of email it was and whether our provider accepted it. Never the body. That covers both the notices we send a business about its own account and the confirmations its assistant sends its customers, and it is there so a business can see what went out in their name. It is deleted after a year.

Our email provider keeps whether each email was delivered or bounced, for 30 days, so we can tell a business whether a message arrived. It does not track whether an email was opened or which links were clicked.

Every email we send for a business says who it is from, gives a postal address and has an unsubscribe link. If you use it, we keep your email address on that one business's do-not-email list so nothing more goes to you from it, and we keep it for as long as that business uses us, because deleting it is how email would start again. Unsubscribing from one business does not affect another. Emails you ask for yourself, like a password reset, still arrive.

Texts work the same way. If you reply STOP to a business's number, our telephony provider stops every further text from that number, and we keep your number on that business's list so it can see why you no longer get its booking and callback confirmations and reminders. Reply START to undo it, and we remove you from the list.

If a business lists people to be told when a caller asks to be rung back, we keep those email addresses on its profile and use them for that notice and for a short daily summary of the business's own calls, and nothing else. The business can change or remove them, or turn the daily summary off, at any time, and with none listed we email the owners at the address they sign in with.

A business can also give us up to two backup phone numbers for an emergency, such as a partner or whoever is on call. We keep them on its account and ring them only to put an emergency caller through, never for anything else.

A business can add a mobile number for each person or van that does its jobs. We prove it first, by texting it a code, and then use it for one thing only: about half an hour after a job is due to end, we text that person a link to confirm the job is done, from the business's own number. That text names the customer's first name and street, and nothing else about them. The number is deleted as soon as the business removes it, or removes that person or van. Nothing is sent to it while the business's account is not active, and when a business leaves us it is removed with the rest of that business's records, the same as everything on this page.

And we keep a short record of where each person who signs in is signed in: what their browser says it is, a shortened version of their internet address with the last part removed, and when it was last used. In that list, never the full address, and we do not look up a location from it.

That exists so somebody can open their own account page, see their own devices, and end one of them without ending all of them, which is what you want on the day a phone goes missing. It is theirs to read and theirs to clear, nobody sees anybody else's, and a device you stop using is forgotten after thirty days.

Every account uses two-step sign-in: a passkey or an authenticator app, never a code by email or text. For a passkey we keep only its public half and the name you gave it; the private half never leaves your device or your phone. For an authenticator app we keep the shared secret it was set up with, and your recovery codes, both encrypted.

We also keep a security log of sign-ins: each attempt, whether it worked, the email address that was typed, the full internet address and what the browser says it is, and changes to two-step sign-in. Unlike the device list above, the address is kept whole, because the log exists to spot and investigate somebody trying to break in. It is deleted after ninety days.

The owners of a business can see their own team's part of that log: when each person signed in or failed to, how (password, passkey or recovery code), what the browser says it is, and the shortened address, with the last part removed. They see only the people on their own team, never anybody else's, and never the full address, which stays with us for investigating an attack.

When an owner signs our Terms of Service and Customer Service Agreement, we keep a record of that signature: the name they typed, the account they signed with (its name and email at the time), the date and time, their full internet address and what their browser says it is, and a fingerprint of exactly what was signed. Unlike the sign-in record above, the address is kept whole, because this is evidence of where a contract was signed. The record cannot be edited or deleted, a copy is emailed to every owner of the business and to our own records mailbox, and a copy is kept in our backup storage in Canada.

Texting people: CASL

Canada's anti-spam law is strict about commercial messages, and the way we satisfy it is structural rather than procedural:

  • We only ever text a customer who contacted you first. Their call to your number is the consent. There is no other way to start a conversation: the software has no facility for sending to a customer's number that has not rung you. The only other numbers it texts are your own: your emergency alerts, and the mobile of somebody on your team, proved by a code, for the link that confirms a job is done.
  • STOP always works, and it is honoured upstream at our telephony provider rather than by our own code remembering to check. Nothing we could get wrong can override it.
  • Every email can be stopped. Each one carries an unsubscribe link, and an address that uses it is checked before every email that business sends, by the one piece of our software every email passes through.
  • No cold outreach, no purchased lists, no marketing blasts. Not as a policy we follow, but as a thing the product cannot do. There is no feature for sending a promotion and no way to export your customer list out of the system, so a number given for a reminder stays a number for a reminder.

Call recording

Callers are told at the start of the call, in the greeting itself, before they have said anything worth recording. You choose one of four settings, and the greeting changes to match:

Full
Audio and transcript kept. What most businesses want, because it is what lets you check what was promised.
Redact personal details
Audio and transcript kept, with personal details removed by the provider. For clinics and anyone handling health or financial information.
Written transcript, no audio
The words are kept and the voice is not. A transcript and a summary; no recording exists afterwards, here or at our voice provider. Callers are told a written record is kept, rather than that the call is recorded, because it is not.
Keep nothing
No recording, no transcript, no summary. The call still happens and still books. Nothing about what was said survives it.

Who else touches it, and where

We are a Canadian business and we would rather this table said Canada all the way down. It does not, and pretending otherwise would be the kind of claim that matters precisely when it is tested:

Kind of serviceWhat it handlesProcessed in
TelephonyThe phone number, the calls and the text messagesUnited States
Voice AIThe assistant that answers and speaksUnited States
Language modelThe assistant’s understanding and its repliesUnited States
Maps and addressesThe address of a job, to work out the drive between jobs at that time of day. Nothing about who the job is for or what it isUnited States
PaymentsYour subscription. Card details go to the processor and never reach usUnited States
Email deliveryEmail we send you: reports, password links, booking and callback confirmations. Keeps delivery status for 30 daysCanada
Our mailboxEmail you send usCanada
Call recording storageThe recording of a call, once it is finished. This is the copy that lastsCanada

We will name them if you ask. This table says what leaves, why it has to and which country it lands in, which is what you need in order to decide whether to trust us. The specific companies are commercially sensitive, so we do not publish the list, but we give it in full, in writing, to any client, their lawyer or a regulator who asks. Write to hello@everyring.ca and you will get the names, what each one holds and how long.

Our own application and database run on servers in Beauharnois, Québec. The services above are the exception rather than the rule, and each one is there because the job genuinely requires it.

We do not currently use an error-tracking service. If we ever turn one on, it is configured to strip personal information before anything leaves our servers, and this page will say so.

What we notice about visits to this site

We measure how this website is used so we can tell which pages help and which lose people. It is our own, on our own servers, and it is deliberately built to work without identifying anybody.

What is recorded: which pages were opened, clicks on buttons we have labelled, how far down a page someone scrolled, how long they stayed on each page, how long the whole visit lasted, which site they arrived from, and roughly which town and country the visit came from.

About the town. Our content delivery provider works it out at their end and tells us the name ("London", "Kitchener") and nothing more precise. We never see or keep the address it came from. A town is only ever shown in our own reports when several different people visited from it; anywhere with fewer is pooled into "elsewhere", because one visitor from a small town is a person rather than a place. To be exact about what that is: the town of a visit is kept with it for the 90 days below, and the rule about several people is applied when we read the report, not when we write it down.

About the country. The same provider tells us the country, as a two-letter code. Unlike the town, every country is named in our reports however few people came from it, and the reason is that a country cannot give away more than the town inside it already would: one visitor from Germany is one of eighty million, where one visitor from a small town is somebody standing somewhere. It is kept for the same 90 days and deleted with everything else.

We stopped recording the kind of device. It answered nothing we would act on, and every extra detail kept beside a location narrows who it could have been. Anything previously recorded was deleted rather than left to expire.

What is not:

  • No cookies, and nothing stored on your device. Not a cookie, not local storage, nothing. That is why this site has never asked you to accept cookies, there is nothing to accept.
  • No IP address. It is used for a moment to work out a daily code that separates one visitor from another, and then discarded. It is never written to a database, a log or a metric.
  • No web addresses beyond the page name. Anything after the question mark, the part that carries reset links and email addresses, is dropped before the page is recorded.
  • Nothing you type. Buttons are recorded by a label we chose, never by what is written on or near them.
  • Not the site you came from, only its name. We record google.com, never what you searched for.

Because nothing is kept on your device, a visit cannot be joined to a later one. The daily code changes every day and cannot be turned back into a person.

If your browser says not to, we do not. Do Not Track and Global Privacy Control are both honoured, and honoured in the browser, so nothing about your visit is sent at all rather than sent and then discarded at our end.

This applies to the public website and to the application you sign in to. Inside the application we record the same things and no more: which screens are used, not what is on them. Nothing about your customers is ever part of it.

Google Calendar, if you connect one

Connecting a calendar is optional and nothing here applies until you do it. You can disconnect at any time from your business profile.

What Google data we access

We ask for the narrowest permissions that do the job, and deliberately not the broad ones:

When your calendar is busy calendar.freebusy
Start and end times only. This permission does not return titles, attendees, descriptions or locations, so we never see what your other appointments are, only that something is there.
The bookings we make calendar.events
Creating, moving and cancelling the appointments your assistant books.
Calendars this app created calendar.app.created
Making an extra calendar for each van, chair or person you can book, and managing events on those. It cannot read or change any other calendar.
The list of your calendars calendar.calendarlist.readonly
Their names, so you can choose which one to use. Not their contents.
Your email address openid email
So the profile can show which Google account is connected.

We do not request calendar or calendar.readonly, either of which would let us read everything in every calendar on the account.

How we use it

  • Busy times decide which appointment slots the assistant offers a caller, so it does not offer one you are already booked for.
  • Bookings the assistant makes are written into the calendar you chose, and moved or cancelled there when the customer changes their mind.
  • The calendar list fills the picker, and the email address tells you which account is connected.

That is the whole of it. Google data is not used for advertising, not used to build a profile of you, and not used to create, train or improve any machine learning or AI model.

What we write into your calendar. An appointment we book carries the customer's name, the phone number to reach them, the address of the job where they gave one, and what they asked for. That is information about your customer going into your own calendar, which is the point of the feature, and it is worth knowing that it goes to Google along with it.

Who we share it with

We do not sell it, and we never share it between businesses. It is not disclosed to anybody for their own purposes. Two transfers happen and both are in order to run the feature you asked for:

  • Our hosting provider, in Canada, where the connection and any booking we made are stored.
  • The AI that answers your phone and texts receives the available times, so it can offer them out loud or in a message. It receives times and nothing else: no titles, no attendees, no locations, because we never hold those in the first place.

AI, and what it is never used for

Your assistant is built on AI services run by other companies: one answers text messages, another runs the voice assistant. Where anything derived from your calendar reaches either of them, it is the available times above and nothing more.

Nothing from your Google account is ever used to create, train or improve any machine learning or AI model. Not by us, and not by any provider we use: our contracts with them prohibit training on the content we send, and we have not opted in to any arrangement that would permit it.

We describe these providers by role rather than by name, for the reason set out under Who else touches it, and where: the list is commercially sensitive, so we do not publish it, and we give it in full and in writing to any client, their lawyer or a regulator who asks.

Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How it is protected

  • The keys to your calendar are encrypted where they are stored, with a certificate kept outside the database. A copy of the database on its own does not open your calendar.
  • Encrypted in transit, over HTTPS, every time.
  • Held in Canada, with the rest of your data.
  • Only the narrow permissions above, so what a mistake could reach is bounded by what we were able to ask for.
  • Deleted when you disconnect. We remove the stored authorisation rather than blanking it, and stop listening for changes. You can also remove our access yourself at any time from your Google account permissions, which is the authoritative way to end it.

Both of these are optional, only an owner can set them up, and neither involves another company of ours: the calendar service is one you already use.

A private link to your bookings
An owner can create a private calendar link that shows their bookings, with the job, the customer's name and the job's address, to whoever holds the link. It is how the bookings appear in Apple Calendar, Outlook or another calendar app. It carries no phone numbers, notes or call transcripts. We keep only a scrambled fingerprint of the link, not the link itself, and the owner can reset it at any time, which stops the old link working immediately, or turn it off.
Busy times from a calendar you link
When an owner links another calendar by its sharing address, we read only the start and end times of its events, not their content: no titles, descriptions, places or guests are kept. We refresh them every 15 minutes, use them only to stop the assistant offering those times, and delete them when the link is removed. The link itself is stored encrypted and is never shown back.

How long we keep things

Every period below is enforced by a scheduled job, not by anyone remembering:

Call recordings, 90 days
The audio of a call is deleted ninety days after it happened, from the storage we control, for every business on the service and for the ones that have left. Our voice provider's own copy goes much sooner: it is deleted once the call is settled, and we check afterwards that it has really gone. Open a call older than ninety days and the app tells you the recording was deleted, rather than leaving you pressing a button that will never work.
Call transcripts, 5 years
The written record of what was said is kept for five years, which is the period Canadian businesses are generally expected to keep their records for, and then removed. The call itself stays: when it was, how long it ran, and what it cost.
Website analytics, 90 days
Deleted automatically. A record of how someone moved around our own site is not worth keeping longer than that.
Change-log values, 90 days
We journal every change to every record, which is how a mistake gets traced. The values in that journal (a caller's name, their address) are stripped after ninety days, leaving who changed what and when.
A record of the emails we send, 1 year
When we send an email for a business, we keep who it went to, what the subject line said, what kind of email it was and whether our provider accepted it. We do not keep what the email said. This exists so a business can see what went out in their name and answer the question we used to have to answer for them, which was usually "did that invitation actually send". It is deleted after a year.
Addresses that unsubscribed, while the business uses us
Only the address and when, on that one business's do-not-email list. Kept rather than deleted on a timer, because deleting it would let email to that person start again.
Numbers that texted STOP, until they text START
Only the number and when, on that one business's list. Removed the moment the person texts START.
Where somebody is signed in, 30 days
A device that has not been used for a month is forgotten, whether it was signed out or simply abandoned. A list of the machines somebody used two years ago is a record of their movements, and it is not one we want to be holding about anybody's staff.
The security log of sign-ins, 90 days
Each sign-in attempt, the address typed, the full internet address and browser, and changes to two-step sign-in. Long enough to investigate an attack that was noticed late, and then deleted. A business's owners see their own team's sign-ins from it for the same ninety days, with the address shortened.
A signature on our agreements, permanently
The name typed, the account, the time, the internet address and browser, and a fingerprint of what was signed. Kept after a business leaves, because it is the record of what both sides agreed to, and it cannot be edited or deleted: that is what makes it worth anything as a record.
A team member's mobile, until it is removed
Kept while the business uses it to send the job link, and deleted, with the codes we sent to prove it, the moment it is removed from that person or van.
Busy times from a linked calendar, until the link is removed
Only start and end times, replaced every 15 minutes with what the calendar says now, and deleted the moment the owner removes the link.
Change-log metadata, 7 years
Who changed which record, when, and which fields moved. An ordinary business record, and it carries no personal information once the step above has run.

What is not on a timer, so that you know: the call record itself, the assistant's written summary of a call, your leads, your text messages and your bookings. Emails are the exception among the things we send for you: the text messages stay, and the record of an email goes after a year. Those are your business records and we keep them while you are a customer. Ask us and we remove them, at any time, and you can erase everything about one caller yourself from their page.

What we can see

Less than you might assume, and this one is worth spelling out because it is unusual. Our own staff administer plans, pricing, billing and the health of the platform. They cannot read your customers' details.

That is enforced in the database layer rather than by a policy or a login screen: the query that would return another business's callers has no administrative override to reach for. Our internal audit view shows which fields on a record changed, never what they changed to.

If you tell us a call went wrong, we receive your note, when the call was and what it was recorded as. Never the conversation, and never who rang. If we need to look at the call itself, we ask you.

While we are setting your assistant up, before your business goes live, one of our staff can be given access to your account to do it. We never see your password. You choose it yourself, from an invitation link that only reaches you, and there is nothing for us to hold or to hand back.

That access expires after two hours, and it is never anonymous: our staff member stays signed in as themselves, so every change made while we are setting you up appears in your own history under their name. It ends for good the day we hand the account over, or the day your trial ends or your paid subscription starts if either comes first, and after that we cannot get in at all.

Asking us to delete something

Under PIPEDA you can ask what we hold about you and ask us to correct or remove it. If you are one of our customers' callers, ask the business you rang, it is their record and their decision, and we will act on their instruction.

The business you rang can do it themselves, from the page that shows your conversation. It removes the conversation, the call, the recording and your details, from here and from the provider that carries the call and runs the voice assistant. We check afterwards that the recording has really gone rather than taking the provider's word for it.

Three honest limits. The provider keeps its own billing record of the call (that a call happened, when, and how long, never the audio or the words), and we cannot shorten that. A record of the deletion itself is kept: that somebody erased a record and who, without the details that were erased. That is what makes the deletion something we can stand behind rather than something nobody can check.

And the third, which is true of any system that takes backups and is worth saying plainly rather than leaving you to assume otherwise. We copy the database every night so that a failed disk is not a lost business, and those copies are kept for thirty days and then destroyed. A record you erase today is gone from the live system immediately and gone from the last backup within a month. We do not go into old backups to remove single records, because restoring and rewriting them is more likely to damage the data of every other person in there than to help.

If you would rather ask us directly, or the business is not reachable, email us and a person will do it.

privacy@everyring.ca