What we collect, why, how long we keep it, and what you can ask us to do with it. A phone company necessarily holds sensitive information about who you called and when, so this document is specific rather than general.
What we collect
Information you give us
- Name, email address, and optionally company name and phone number
- Country, for tax and routing purposes
- Anything you write in a support request or contact form
Information created by using the service
- Call detail records — the number called, the number calling, the time, the duration, and the outcome. This is how you are billed and how faults are diagnosed.
- Registration data — the IP address your device registers from and the software it reports.
- Sign-in records — the address and browser used, successful or not, so you and we can spot unauthorised access.
- Voicemail recordings, and call recordings if you have switched them on.
What we do not collect
We do not record the content of your calls unless you have explicitly enabled call recording on an extension. We do not sell personal data, and we run no advertising on this site.
Analytics
This website loads Google Tag Manager, which we use to measure how the site is used — which pages are visited, which links are followed, and roughly where visitors come from. It sets cookies in your browser and shares your IP address and browsing activity on this site with Google. It runs on every page, including the customer portal.
You can block it with any content blocker, or with Google's own opt-out browser add-on. Blocking it has no effect on the service: every part of the site works with it refused.
Why we hold it
To provide the service you asked for, to bill you accurately, to detect fraud and toll abuse, to support you when something breaks, and to meet legal obligations where they apply. We do not sell personal data, and we do not share it for marketing.
How long we keep it
- Call detail records — 24 months, for billing disputes and fault analysis
- Invoices and financial records — 7 years, as accounting practice requires
- Voicemail — until you delete it; recordings are removed with the message
- Sign-in records — 90 days
- Support conversations — 24 months after closure
- Account details — until you close the account, then anonymised while financial records are retained
Who else sees it
Carrier partners receive the minimum needed to route a call — typically the destination number and caller ID. Payment providers receive what is needed to take a payment; we never store full card numbers. Law enforcement receives data only on a lawful, properly served request, and we will tell you unless legally prohibited.
Security
Passwords are hashed and cannot be read by us or recovered. SIP secrets are encrypted at rest with AES-256-GCM. Traffic to this site is encrypted in transit, and SIP signalling can be encrypted with TLS. Access to customer data by our staff is limited by role and recorded in an append-only audit log.
No system is perfectly secure. If a breach affects your data we will tell you what happened, what it affects, and what to do, without waiting to have a complete story first.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to a particular use. Some data we must keep — a paid invoice cannot be deleted on request because accounting law requires it — and we will say so plainly rather than quietly ignoring part of a request. Write to info@voip.so and we will respond within 30 days.
Cookies
One cookie, named voipso_session, keeps you signed in. It is HTTP-only, marked
Secure in production, and SameSite=Lax. It expires when the session ends.
Google Tag Manager and the analytics tags it loads set their own cookies, which we do not control and which are governed by Google's privacy policy. We set no advertising cookies of our own.
Contact
Privacy questions go to info@voip.so, or by post to Behind 21 November School, Howl-Wadaag District, Mogadishu, Somalia.