Legal

Data Security Overview

A detailed overview for clients and prospective clients. Read this alongside our Privacy Policy and Terms of Service.

Effective and last updated August 15, 2026.

We believe you should be able to see exactly how your business's information is handled, with nothing hidden. This page explains our current security practices in plain language. Write manish@getringline.com if something is not covered here.

2. Information Security Program

Our approach is built around three principles: collect only what is needed to operate the Service, restrict access to the minimum necessary, and give Clients meaningful control and visibility over their own data at all times.

3. Data We Classify as Sensitive

Sensitive data gets extra handling care, including restricted access and, where applicable, restricted-scope credentials rather than full account access.

  • Call recordings and transcripts
  • Any credentials, API keys, or account access shared with us
  • Business and Caller contact information

4. Technical and Organizational Safeguards

  • Encrypted storage of credentials and API keys used to operate the Service
  • Restricted-scope API keys wherever a provider supports them, so GetRingLine cannot access a Client's funds, account settings, or unrelated data
  • Industry-standard encryption in transit between GetRingLine and our service providers
  • Access to Client and Caller data is limited to what is operationally necessary. As we grow, access stays need-to-know only

5. Payment Security

GetRingLine does not directly handle or store full payment card or bank account details. Subscription payments are processed through PayPal. If a Client uses our optional payment-collection add-on, it connects to the Client's own payment account (such as the Client's own Stripe account) with a restricted key that can create payment requests only — it cannot access funds, balance, or account settings.

6. Access Control

  • Access to production data and credentials is limited to people who need it to operate or support the Service.
  • Credentials for third-party providers (such as Retell AI, PayPal, and Google) are stored in our automation platform's credential management, not in plain-text files or shared documents.
  • When we add team members or contractors, each person gets access only to the systems needed for their role, and access is revoked when it is no longer needed.

7. Vendors and Third-Party Providers

Before we rely on a new provider, we consider their security reputation and the sensitivity of any data that would be shared. We favor restricted-scope access over full account control. Our current Sub-processors are listed in the Privacy Policy: Retell AI (voice), PayPal (payments), and Google (email). We do not store data with any provider beyond what is necessary to deliver the Service.

8. Infrastructure, Monitoring, and Continuity

As GetRingLine grows, we are moving automation infrastructure to dedicated, always-on cloud hosting to improve reliability. Clients will be notified of any material change to how or where their data is hosted.

We periodically review workflows and credentials for unnecessary access. As the Service grows, we intend to adopt more formal monitoring and periodic security testing appropriate to our scale.

We maintain reasonable backups for Client data at the current scale of the Service, and we are working toward more formal business continuity practices as we grow.

9. Data Minimization

We collect only the information reasonably necessary to operate the Service a Client has signed up for. We do not request access beyond what a given feature requires.

10. Incident Response

If we suspect a security incident, we: (1) contain and assess the scope as quickly as possible, (2) determine what data, if any, was affected, (3) notify affected Clients without undue delay and consistent with applicable law, and (4) take corrective action. We will share reasonably available information about the incident and the steps being taken.

11. Your Number, Retention, and Export

A Client's business phone number is never transferred to GetRingLine. Call forwarding is a setting on the Client's existing line and can be switched off at any time.

Data is retained consistent with the Privacy Policy. Clients may request deletion at any time. A full export is prepared within 48 hours of a confirmed cancellation, at no cost, typically as CSV or PDF.

12. Compliance Alignment

GetRingLine does not currently hold formal third-party certifications such as SOC 2 or ISO 27001, given our stage as a small, individually operated service. Our practices follow the principles behind those frameworks — restricted access, data minimization, and clear incident response. We intend to pursue formal certification as the Service scales.

13. Reporting a Security Concern

If you believe you have found a security issue affecting GetRingLine, write manish@getringline.com immediately. We take every report seriously and will respond promptly.