Legal
Privacy Policy
Last updated: 2026-08-11
RingDispatch (the “Service”) is operated by RingDispatch LLC, a Virginia limited liability company. This policy explains what we collect, why we collect it, who we share it with, and the rights you have over your data. For questions email privacy@ringdispatch.com.
What we collect
From business owners (you): name, email, phone, business name and type, hours, languages, services and pricing, optional team member names + schedules, and your billing details (handled by Stripe — we never see your card number).
From callers to your AI: phone number, anything they say during the call (transcribed to text), the time of the call, and any details they share to book or message you (name, address, appointment reason).
Automatic: minimal server logs (IP, timestamp, route, response code) for debugging and security; cookies described below.
How we use it
- Answer calls and book appointments on your behalf — the core function of the Service.
- Show you a dashboard of what the AI did (transcripts, bookings, messages).
- Send you operational notifications (failed payment, etc.).
- Detect and stop abuse (rate limiting, fraud, prompt injection attempts).
We do not sell your data. We do not use your call data or transcripts to train AI models that other customers benefit from.
Who we share it with
- Anthropic— we send conversation context to Claude to generate responses. Anthropic’s data policy applies; they do not retain enterprise API content beyond 30 days unless we opt in for abuse monitoring (we have not).
- ElevenLabs — we send response text to ElevenLabs to generate spoken audio. Audio is streamed and not retained.
- Twilio (when telephony is wired) — provides the phone line and routes audio to/from your AI.
- Stripe — handles all subscription payments. We never see or store full card numbers.
- Fly.io — hosting (iad-region machines, edge-cached static assets, SQLite for owner-dashboard data).
- Resend — transactional email (booking summaries, daily digests, payment-failure notices).
- Sentry — anonymized client + server error monitoring so we catch issues before customers report them.
Biometric data (voice clones) — BIPA + state-law compliance
Voice cloning processes biometric identifiers (your unique voiceprint) and is regulated by the Illinois Biometric Information Privacy Act (BIPA), Texas CUBI, Washington biometric law, New York City's biometric ordinance, and similar state regimes. Our practice:
- Written notice + informed consent at recording. The voice-clone flow at Settings → Voice (or onboarding) presents a consent screen explicitly identifying the data collected (your voiceprint), the purpose (training a personal TTS voice for your AI receptionist), the storage location (ElevenLabs Professional Voice Clone service + RingDispatch database), and the retention schedule (below). You must check the consent box before recording can start.
- Retention schedule (public, BIPA Sec 15(a)): Voiceprints are retained for the duration of your active subscription. Upon account cancellation, the voiceprint identifier is deleted from our database within 30 days and ElevenLabs is requested to permanently destroy the cloned voice within 90 days (subject to their retention policy). In any case, voiceprints are destroyed not later than 3 years from your last use of the cloned voice on a call — the BIPA statutory cap.
- Destruction-at-purpose policy: your voiceprint is destroyed as soon as it is no longer needed for the purpose you consented to. Three actions trigger that today, each of them yours to take:
- Record a new clone(Settings → Voice) — the previous voiceprint is deleted at ElevenLabs before the replacement is created.
- Switch your AI to a stock voice(the voice step of “Edit my AI”) — the cloned voiceprint you moved away from is queued for destruction and retried until ElevenLabs confirms.
- Cancel your subscription — the voiceprint is destroyed and its identifier is removed from our database.
- What the Erase tool does NOT cover. Settings → Privacy → Erase deletes the records we hold about a caller — the call logs, bookings, messages and contact details tied to one phone number or email address. It does not touch your own voiceprint, which is destroyed by the triggers above instead. We say so explicitly because a policy that promised otherwise would leave you believing a biometric identifier had been destroyed when it had not.
- No third-party voiceprint sales. We do not sell, license, lease, or otherwise disclose your biometric data to any third party other than ElevenLabs (the sub-processor that hosts the cloned voice model) — itself bound by their own BIPA-compliant retention policy (publicly documented at elevenlabs.io/privacy).
- Caller-side biometrics:the speech-to-text engine that transcribes caller speech does NOT extract or persist a voiceprint of the caller. By default only the textual transcription is retained; if a business turns on optional call recording (off by default), the call audio is also kept — see “Call recordings” below. We do not perform voice-biometric speaker identification on inbound callers, and we do not sell or share caller audio with third parties for voiceprint extraction. (If we ever change this, callers will be notified via an updated recording disclosure on every call.)
- Call recordings (optional, off by default): a business may enable call recording in its settings. Recording starts only after the spoken recording notice at the top of the call, in a language the caller understands; a caller who objects during the call has the recording deleted automatically, and if consent rules suppress a call’s transcript the audio is deleted with it. Recordings are stored with our telephony sub-processor (not on our application servers), are playable only by the business owner through an authenticated dashboard, follow the same retention and deletion schedule as transcripts, and are never available to businesses in HIPAA mode.
- Minor accounts:the voice-clone add-on is unavailable to accounts where the operator is under 18 unless a parent submits a separate written biometric consent form. See “Children + minor business owners” below.
BIPA enforcement: violations carry $1,000 (negligent) to $5,000 (intentional or reckless) statutory damages per violation with a private right of action. If you operate in Illinois and have specific BIPA compliance concerns for your own business, this disclosure is our public retention policy per Sec 15(a); the per-clone consent screen captures the Sec 15(b) written-informed-consent step. Email hello@ringdispatch.com for a copy of our internal biometric-data destruction policy.
Children + minor business owners
RingDispatch is not designed for use by children. We don’t knowingly collect personal information from children under 13 (COPPA) or biometric data (including voice clones) from anyone under 18 without verifiable parental consent under BIPA (Illinois), Texas CUBI, Washington biometric law, and similar state regimes.
If you’re a minor running a business and a parent/guardian wants to set up RingDispatch on your behalf: the parent must create the account, agree to the Terms, provide their own payment method, and act as the contracting party. The minor can be named as the “business operator” in the dashboard; the parent remains the account holder for billing, data-rights, and biometric-consent purposes. The voice-clone add-on is unavailable for accounts where the operator is under 18 unless the parent submits a separate written biometric-consent form (request via hello@ringdispatch.com).
If we discover a minor signed up without parental involvement, we’ll close the account, refund any charges, and erase any biometric data (cloned voice IDs) collected.
Data residency + foreign-national handling
Your business data (transcripts, bookings, audit logs) is stored on US-based infrastructure (Fly.io iad region) and processed in the United States. Our subprocessors (Anthropic, ElevenLabs, Twilio) operate from US-based platforms with global support teams.
For federal contractors / defense / CUI workloads: RingDispatch is a commercial small-businessproduct. We are NOT FedRAMP-authorized, NOT DFARS 252.204-7012 attested, NOT CMMC-certified, and NOT ITAR-aware. If you handle Controlled Unclassified Information (CUI), classified-adjacent contract data, or data subject to ITAR, do not route those calls through RingDispatch. We’d rather tell you that upfront than have you discover it in a security review. Email hello@ringdispatch.com if you have a federal-track use case you’d like us to consider.
Legal process — how we respond to subpoenas, warrants, government requests
We treat call recordings and transcripts as your business records, not ours. If we receive a valid subpoena, court order, or other compelled-disclosure request targeting your business’s data:
- We notify you first. Unless we are gagged by court order (rare, narrowly applies to grand-jury subpoenas under specific statutes), we email you with the request, scope, and a copy of the document within 24 hours of receipt so you can object, quash, or assert privilege through your own counsel before we respond.
- We require the request be specific.Blanket fishing expeditions (“all calls in your system”) get rejected; requests must name your business by account ID + identify the specific call(s) or date range with reasonable specificity.
- Attorney-client privilege + clergy-penitent + therapist- patient + journalist’s privilege + traditional-medicine / Indigenous-clergy communicationsare protected: if your business is a law firm, mental-health practice, clergy, newspaper / magazine / independent journalism org, or Indigenous medicine practitioner (hataałíi, curandera, wičháša wakˈáŋ, Faith-Keeper, di'yin), we will not voluntarily produce these records and will assert privilege on your behalf pending your counsel’s direction. Journalist’s privilege references: NY Civ. Rights §79-h, CA Evid. Code §1070, IL 735 ILCS 5/8-901, NJ 2A:84A-21, OH 2739.04, federal Branzburg v. Hayes (1972) + proposed PRESS Act. On an anonymous-source call our AI vetoes the call recording and the stored transcript, and does not capture your name. It does nothide the number you called from — our phone carrier logs that on every call, so if the number itself is sensitive, call from a blocked or different line. Indigenous-clergy references: AIRFA (American Indian Religious Freedom Act) 42 USC §1996, tribal-court evidentiary privilege, ICRA (Indian Civil Rights Act) 25 USC §1301 et seq.
- We push back on overbroad ICE / DHS / immigration-enforcement requests.Immigration attorneys’ client intake is privileged. If we are served, we notify you and assert attorney-client privilege before producing anything.
- Gender-affirming care + reproductive health + LGBTQ+ youth shelter + immigrant-rights + abortion-rights + journalism business records get extra protection.Several US states have launched investigations into providers of gender-affirming care, abortion services, LGBTQ+ youth shelters, immigrant-rights orgs, abortion-rights legal orgs, and journalism orgs serving those communities. R14 expansion: the state-AG raid posture below extends BEYOND healthcare businesses to ALL of these business categories. If we receive a state-AG subpoena, civil investigative demand, or warrant targeting any of these business’s call records, we notify the business within 24 hours (unless gagged), assert HIPAA + state-shield-law + journalist’s-privilege + LGBTQ+-services + immigrant- advocacy protections (CA, CO, NY, IL, WA, MN, MA, NJ, NM, OR, VT, MD, CT, RI have shield laws for gender-affirming and reproductive care providers as of 2026; NY §79-h, CA §1070, IL 5/8-901, federal Branzburg / proposed PRESS Act for journalists; AIRFA + ICRA + ICWA for Indigenous practitioners + tribal-court evidentiary privilege), and refuse to produce care-type / source-identity / shelter- resident / client-identity information without a court order specifically addressing the relevant exception. We push back on jurisdictional fishing expeditions, parental-coercion attempts, donor-enumeration fishing, and state-CPS investigators (Alabama / Texas / Florida / Idaho using CPS against trans- kid-affirming families; AZ / OK / NM using CPS against Indigenous traditional-medicine families). See also /help → Special situations.
- Tribal sovereignty + Indigenous practitioner protection (R14 expansion).If you operate as a federally-recognized tribal business on sovereign trust land, a Native Hawaiian Organization (NHO, per Apology Resolution PL 103-150), a tribal-medicine practitioner (hataałíi, curandera, wičháša wakˈáŋ, Faith-Keeper, di'yin, kahuna), tribal newspaper, tribal clinic / hospital, BIA-jurisdiction service, tribal cannabis cultivator / dispensary, or any business operating under tribal-court jurisdiction: jurisdiction over disputes about your data is preserved under your sovereign framework. We do not assert that VA arbitration is exclusive against tribal-court or Native-Hawaiian-Affairs jurisdiction. We assert AIRFA (American Indian Religious Freedom Act, 42 USC §1996) + RFRA (Religious Freedom Restoration Act, 42 USC §2000bb — applies to minority religion of every kind, not just federally-recognized tribal practitioners; protects Hmong shaman / txiv neeb, Lukumí / Santería / Vodou houngan, Sikh + Jain + Zoroastrian + Bahá'í + Wiccan + pagan clergy + queer-affirming clergy + sex-positive religious practitioners + ex-Christian + LDS-leaver pagan clergy under Church of Lukumi Babalu Aye v. Hialeah, 508 U.S. 520, 1993) + ICRA (Indian Civil Rights Act, 25 USC §1301) + ICWA (Indian Child Welfare Act, 25 USC §1901) + tribal-court evidentiary privilege as applicable. IGRA (Indian Gaming Regulatory Act, 25 USC §2701 et seq.) + NIGC oversight (25 CFR Part 542/543) + tribal-state Class III compacts framing applies to tribal- owned IGRA Class III casinos + sports-betting + racinos + cardrooms operating on sovereign trust land. AML Title 31 BSA casino CTR/SAR-C filing obligations + OFAC SDN-list screening + high-stakes wire reporting are casino-as- financial-institution responsibilities (31 USC §5318 + 5324); we do not discuss specific cage-credit / SAR-C details over phone (safety.ts rule 21j MSB-equivalent posture). State CPS / state AG investigators fishing for “is this Diné child seeing a traditional medicine person?” or “is this tribal family in ceremony?” get the same hostile- fishing refusal as state-shield-law-protected medical practices. Vienna Convention-equivalent tribal-government notification applies for tribal-member deaths in BIA / IHS / tribal-correctional custody (safety.ts rule 11i). See /terms section 10.
- We never voluntarily discloseyour customer data to law enforcement absent valid legal process. We do not honor informal requests, “courtesy” requests, or non-statute-backed agency demands.
- Annual transparency report: we keep a running count of legal requests received, complied with, partially complied with, and rejected. We have not published a report yet — the first one covers 2026 and will be posted at /transparency, and we will say so here when it is live. Until then you can request the current counts by emailing privacy@ringdispatch.com.
This policy is independent of HIPAA mode or any other privacy toggle — it applies to every business by default.
Recording and AI disclosure
Your AI is required to disclose that it is an AI and that the call may be recorded, on every call, before collecting any information. This satisfies California SB 1001 (Bolstering Online Transparency), Colorado HB24-1139, Utah HB 140, and the EU AI Act transparency rules.
The AI’s opening greeting on every connected call identifies it as an AI assistant for your business and includes the recording notice — for example: “Hi, this is {your AI's name}, an AI assistant for {your business}. This call may be recorded for quality.” (Your chosen voice name and business name are substituted in.) This greeting is spoken before any substantive turn and cannot be disabled from the dashboard.
For two-party-consent jurisdictions (CA, FL, IL, MD, MA, MT, NV, NH, PA, WA), the spoken “may be recorded” disclosure is treated as implicit consent under standard telephone-recording doctrine when the caller continues the call. For HIPAA-regulated businesses or stricter compliance regimes, enable HIPAA mode in Settings: it requires explicit per-call consent before any transcript is stored, and optional audio call recording is disabled entirely (call audio is PHI — the consent-gated transcript is the record in HIPAA mode).
SMS / text messaging
When you (or your customers) opt into SMS from RingDispatch — for booking confirmations, daily digests, payment-failure notices, and emergency-route alerts — we collect and process mobile phone numbers + message content through Twilio, our SMS carrier provider. We will not sell mobile information to third parties under any circumstances. We will not share mobile information with third parties for marketing or promotional purposes — the only entity we share your mobile number with is Twilio, and only for the purpose of delivering the transactional messages you opted into.
Message frequency varies based on your activity. Message and data rates may apply from your wireless carrier. Reply STOP to any message to unsubscribe from further messages, or reply HELP for assistance. You can also email privacy@ringdispatch.com to opt out.
Cookies
Every cookie we set is first-party and strictly necessary — it exists to sign you in, keep you attached to the right business account, or finish a step you started. There are no analytics cookies, no advertising cookies, no third-party cookies, and nothing that follows you to another site. None of them are readable by JavaScript (all are HttpOnly), and all are marked Secure in production.
phoneai_owner— your signed owner session. SameSite=Lax, expires after 30 days.phoneai_tenant— a signed pointer to which business account this browser is working in, so we load and write the right data. SameSite=Lax, expires after 1 year.phoneai_delegate— the signed session for a team member you invited to view your dashboard. Set only when such an invite is accepted. SameSite=Lax, expires after 30 days.phoneai_admin— the session for our own internal operator console. It is only ever issued to a RingDispatch staff browser that presented our operator secret; a customer never receives it. SameSite=Strict, expires after 12 hours.phoneai_oauth_nonce_googleandphoneai_oauth_nonce_microsoft— set only while you are connecting a calendar, to prove the consent screen was finished in the same browser that started it. SameSite=Lax, expires after 10 minutes, and cleared the moment the connection succeeds or fails.
A few things are kept in your browser’s own local storage rather than in a cookie — that you dismissed the cookie banner, an unfinished onboarding draft so you don’t lose your place, and whether you muted the in-dashboard demo. These are functional, stay on your device, and are never sent to us or to anyone else.
Your rights (GDPR / CCPA)
If you are an owner, you can export or delete your data from Settings. If you are a caller and want your data redacted from a business’s records, ask the business owner — they can erase your phone number, name, and transcript via their dashboard. We respect “right to be forgotten” requests (irreversible PII redaction; booking row stays for accounting).
Retention
Active booking data is retained while the owner’s account is active. Booking records are retained for about 18 months, after which the personal details are redacted (soft-deleted) and the record is permanently removed roughly 30 days later. HIPAA-mode businesses retain records for 6 years as required, and once a business has ever operated in HIPAA mode that longer window continues to govern its existing records. Transcripts follow the booking they belong to. Server logs are kept 30 days.
Backups: we keep encrypted, offsite snapshots of the database so we can recover from a disaster — daily snapshots for 30 days and monthly snapshots for 12 months, after which each snapshot is deleted. Deletion and redaction happen on the live records on the timeline above; a snapshot taken beforehand still contains the older copy until that snapshot ages out. Snapshots are encrypted at rest, used only to restore the Service after data loss, and never shared or used for any other purpose.
Security
Data is encrypted in transit (TLS). Owner sessions are cryptographically signed. Webhook signatures from Stripe, Twilio, and Resend are verified before processing. We rate-limit destructive endpoints.
Not every route is guarded the same way, and that is deliberate — a page we ask your customer to open cannot require your password. What actually protects each kind of route:
- Your dashboard and every action that changes your business’s data require the signed owner-session cookie, which is compared in constant time on every request.
- A team member you invite gets their own signed cookie. It lets them view the bookings you shared and receive emergency pages; it cannot write anything, and revoking the invite locks them out immediately.
- The pages we hand to your customers — your public booking page, the link to reschedule or cancel their own appointment, an estimate to approve, a waitlist slot to claim, and your private calendar feed — carry no session cookie at all. Each is reached through a long, unguessable, signed link that is verified in constant time and is good for that one purpose only.
- The callbacks Twilio, Stripe, and Resend send us belong to no browser, so they are accepted only when their cryptographic signature verifies against our shared secret.
Underneath all of it, every route runs inside a per-business boundary and each business’s records live in their own separate database — so no cookie or link issued for one business can read another business’s data.
International transfers
Data is processed in the United States. EU/UK customers consent to international transfer when they sign up. We use Standard Contractual Clauses where required.
Changes
We’ll update the date above when this policy changes. Material changes will be emailed to active customers.
Questions: privacy@ringdispatch.com