← RingFloor

How your data
is handled

Last updated 13 September 2026

You are being asked to hand over a list of merchants and let us call them. That is a lot of trust, and "your data is safe with us" is not an answer. Here is how the system is actually built.

One client, one database

Every client runs their own installation with their own database. Not a shared database with a client column — a separate database.

Practically, that means your list cannot appear in another client's search results, cannot be used to enrich another client's records, and cannot be exported by anyone operating a different installation. The isolation is structural rather than a filter somebody has to remember to apply, which is the kind that fails quietly.

Your carrier account stays yours

Where you bring your own carrier account, it stays in your name and under your control. The numbers we provision for your territory belong to your account, so if you ever leave, your numbers go with you and keep ringing — you are not renting your own phone numbers back from us.

Credentials are encrypted, per installation

Carrier and voice-provider credentials are not stored in plain text. They are encrypted with AES-256-GCM, using a key derived from a secret unique to your installation.

The consequence worth understanding: a copy of your database, on its own, does not let anyone spend money on your carrier account — and a credential stored for one client cannot be decrypted by another client's installation, even though both run the same software on the same server.

Calls, recordings and transcripts

What our AI agents will and will not say

Agents we build are configured to say plainly that they are automated when somebody asks whether they are a bot, an AI, or a real person. They are configured not to claim a referral, an approval, or a lender relationship that does not exist.

This is a data-handling matter as much as a compliance one: an agent that invents a fact about the person it is calling has put wrong information into your CRM, and you will make decisions on it later.

Who can see your installation

Access to production is limited to the people who operate it. When we help you tune a script we listen to calls on your installation with you, not by taking copies away. We do not use your lists, your call recordings, or your transcripts to train models, and we do not use them to build anything for another client.

Sub-processors

ProviderWhat they touch
TwilioCall audio in transit, phone numbers, call metadata
ElevenLabsAudio and transcripts for AI voice calls
OpenAIText of AI conversations, where used for agent reasoning
Amazon Web ServicesHosts servers and databases
CloudflareDNS and traffic routing for the web layer

If you need a signed data processing agreement, or a sub-processor list as a document for your own compliance file, ask and we will provide it.

If you leave

You get your data. On request we export your contacts, call history, and recordings in a usable format, and delete them from our systems. Your numbers stay on your carrier account. There is no export fee and no hold-back — a platform that makes leaving painful is telling you something about how confident it is.

What we are not claiming

We are not SOC 2 certified, we do not hold ISO 27001, and we are not going to imply otherwise with a badge. We are a small team running a focused system, and the description above is what we can actually stand behind.

If your business requires a certified processor, say so early and we will tell you straight whether we are a fit rather than waste your time.

Getting in touch

Questions about any of this, or about a setup for your business — use the form on the home page or call (224) 207-4084.

Talk to us ↗