https://myphoneflow.com/legal/privacy/v1.0/
PhoneFlow Privacy Notice
Version 1.0 · Effective: 2026-09-27 · Last updated: 2026-09-26
Summary (not a substitute for the terms below):
- This notice covers website visitors, prospects and trial signups, people who use PhoneFlow accounts, and people who call or use the web widget of businesses that use PhoneFlow.
- When you contact a business that uses PhoneFlow, that business controls your information. PhoneFlow handles it for the business as its service provider, and the business's own privacy notice applies.
- AI-handled calls and widget conversations are recorded (unless the business turns recording off), transcribed and processed by our service providers, including AI providers. PhoneFlow does not train AI models on that content.
- We do not sell personal information, and we do not share mobile numbers with third parties or affiliates for their marketing.
- We keep account and call data while the account is open unless it is deleted sooner on request. Deletion after a request or after an account closes is done within 60 days.
- To ask for access, correction or deletion, email [email protected].
1. Who we are and what this notice covers #
1.1 About PhoneFlow #
PhoneFlow is operated by Electric Software LLC, a Michigan limited liability company doing business as PhoneFlow ("PhoneFlow", "we", "us"). We provide an AI receptionist and business phone platform to organizations through https://myphoneflow.com and https://app.myphoneflow.com.
This notice explains what personal information we collect, how we use and disclose it, how long we keep it, and your choices. It is a notice, not a contract. How we handle data for our business customers is governed by the PhoneFlow Master Customer Agreement (https://myphoneflow.com/legal/customer-agreement/) and the PhoneFlow Data Processing Addendum (https://myphoneflow.com/legal/dpa/). If this notice and those documents conflict about Customer Data, those documents control.
1.2 Who this notice covers, and our role #
| If you are… | For example | Our role |
|---|---|---|
| A website visitor | You browse myphoneflow.com, fill in a form, book a meeting, or try the demo voice widget on our site | We decide how your information is used (controller) |
| A prospect or trial signup | You ask for a demo or start a free trial | Controller |
| A Customer User | You sign in to a PhoneFlow account your organization set up | Controller for your account, sign-in and billing details; service provider for the Customer Data in the account |
| A Caller or Widget Visitor of a Customer | You call or text a business that uses PhoneFlow, receive a call or text from it, or talk to its website voice widget | Service provider (processor) for that business, which controls your information |
| Someone contacting PhoneFlow directly | You call a PhoneFlow number, such as our sales and support line, or use the voice widget on our own site | Controller |
1.3 Words we use #
These terms mean the same here as in the PhoneFlow Master Customer Agreement:
- Customer: an organization with a PhoneFlow account. Customer Users are its personnel with PhoneFlow logins.
- Callers: people who call or text a Customer's PhoneFlow numbers, or receive calls or texts from them. Widget Visitors: people who use a Customer's web voice widget. Together they are End Users.
- Customer Data: what the Customer or its End Users put into the Services (such as call audio, recordings, transcripts, Caller details, knowledge-base content, configuration and integration credentials), plus what the Services produce from it (such as AI responses, summaries, extracted fields and classifications).
- Telemetry: non-content operational data, such as counts, durations, timestamps, latency, error codes, feature usage and billing records. Telemetry never includes audio, transcripts, message bodies or knowledge-base content.
- Services: the PhoneFlow platform, including the AI receptionist, phone numbers, call handling, messaging, web widget, integrations and dashboard.
2. Information we collect #
2.1 Website visitors #
- What you give us: name, work email, phone number, company, job title, website, and anything you write in a form or meeting request.
- Collected automatically: IP address, browser and device type, pages viewed, referring page, and whether you arrived from one of our ads (see Section 8).
- Our demo voice widget: see Section 2.5.
2.2 Prospects and trial signups #
- Contact and business details from our trial and demo forms, your answers to setup questions, and your marketing choices.
- To build a trial agent, we may review your business's public website and public business listings. These can include names, titles and contact details of your staff.
2.3 Customer Users #
- Account: name, email, phone number, role, organization and department.
- Sign-in and security: your password (never stored in readable form), sign-in times, IP address, browser details, and an audit record of important account actions.
- Agreement records: when you accept or acknowledge our legal documents, we record which documents and versions you saw, the checkbox and button wording, the time, your IP address and browser, and the organization name and title you entered.
- Billing: billing contact, purchases, Wallet balance and Auto-Pay settings. Stripe handles card payments; we never receive full card numbers.
- Support: your emails, calls and messages with our team.
- Usage: Telemetry.
2.4 Callers and Widget Visitors of our Customers #
For a Customer that uses PhoneFlow to answer calls, send texts or run a web voice widget, we process on its behalf:
- phone numbers, caller ID name, and call times, durations and routing;
- call and widget audio, recordings (unless the Customer turned recording off), voicemail and transcripts;
- what you say or type, such as your name, contact details, address, reason for calling and appointment details;
- AI summaries, classifications and extracted details, and the emails, texts or tickets the Customer has set up;
- text messages to and from the Customer's PhoneFlow numbers, and opt-out requests; and
- for the widget, the page address, IP address and browser details.
This is Customer Data. The Customer decides what its agent asks, whether calls are recorded, and where results go. Please read that business's privacy notice.
2.5 People who contact PhoneFlow directly #
If you call a PhoneFlow number, such as +1 947 777 7449, or use the voice widget on myphoneflow.com, you are talking with PhoneFlow's own AI assistant. We collect your phone number, the recording and transcript, what you tell us, and, for widget sessions, technical details such as your IP address. We use this to respond, follow up on your enquiry, provide support, and review and improve how our own assistant handles calls.
2.6 Information we ask you not to give us #
Please do not give PhoneFlow, or any AI assistant running on PhoneFlow, payment card numbers, Social Security or other government ID numbers, bank account or routing numbers, or health information. Customers agree not to collect this "Prohibited Data" through the Services. PhoneFlow does not currently sign business associate agreements, so the Services are not intended for protected health information.
PhoneFlow does not create voiceprints and does not use voices to identify or authenticate speakers.
3. Where we get information #
- From you: forms, signup, use of the Services, calls, and support requests.
- From Customers: account setup, user invitations, contact imports, knowledge-base uploads and connected integrations.
- From Callers and Widget Visitors: during calls, texts and widget sessions with our Customers.
- Automatically: our systems, cookies and similar tools.
- From service providers: for example, call and message records from our carrier, and payment status from Stripe.
- From public and commercial sources: business websites, public business listings, mapping services and business contact databases. We use these mainly to research a business and build its agent during setup, and to understand which companies visit our website.
4. How we use information #
4.1 Information we control #
We use information about website visitors, prospects, Customer Users and people who contact us directly to:
- provide, operate, support and secure the Services and our websites;
- create and manage accounts, verify identities and email addresses, and record acceptance of our legal documents;
- perform Setup Services, meaning building and configuring agents on a Customer's instructions;
- process payments, Auto-Pay and billing, and prevent fraud and abuse, including duplicate trial accounts;
- respond to enquiries and send service, security and legal notices;
- send marketing where the law allows, and measure how our advertising and website perform;
- improve our websites, features and support using Telemetry and feedback; and
- comply with law, enforce our agreements, and establish, exercise or defend legal claims.
4.2 Customer Data #
We use Customer Data only to provide, maintain, secure and support the Services for the Customer it belongs to. That includes answering and routing calls, transcription and AI responses, sending the messages the Customer has set up, Setup Services, reports the Customer asks for, calculating fees, preventing fraud and abuse, and complying with law. We do not use one Customer's call content to serve another Customer, and we never use Customer Data for advertising.
4.3 Telemetry #
We use Telemetry to run, secure, bill for and improve the Services, and may use it in aggregated or de-identified form that does not identify any person or Customer.
5. AI processing #
5.1 What the AI Features do #
On an AI-handled call or widget session, speech is converted to text. An AI language model then reads the conversation with the Customer's instructions and knowledge base and writes a reply, which is converted back to speech. After the call, AI may write a summary, classify the reason for the call, pick out details such as a callback number, and transcribe voicemail. Knowledge-base content is converted into a searchable form so the assistant can find relevant answers.
5.2 Who provides the AI #
Calls are carried by Twilio. Our AI providers are:
- Deepgram for speech-to-text and ElevenLabs for text-to-speech, both provided through Twilio;
- OpenAI (our default) or Anthropic (if the Customer chooses it) for the language model; and
- OpenAI for voicemail transcription and knowledge-base search.
The current full list, including hosting, email and payment providers, is the PhoneFlow Subprocessor List (https://myphoneflow.com/legal/subprocessors/). We use these providers' business services under contract. If a Customer connects its own AI provider account, that provider processes the data under the Customer's own agreement with it.
5.3 No training #
PhoneFlow does not use Customer Data to train, fine-tune or otherwise improve any AI model.
5.4 Accuracy and decisions #
AI can mishear, misunderstand or produce inaccurate text, and summaries and transcripts may contain errors. The Customer decides how results are used. PhoneFlow does not use AI to make decisions about people that have legal or similarly significant effects. The PhoneFlow Acceptable Use Policy (https://myphoneflow.com/legal/aup/) forbids Customers from using the AI for decisions about matters such as credit, housing or employment without human review.
5.5 What Callers and Widget Visitors are told #
- Phone calls: when the business has recording on, PhoneFlow plays the business's recording notice at the start of AI-answered calls that are recorded. When recording is off, there is no recording notice. PhoneFlow does not add a spoken statement that the call is answered by AI. A business may add its own wording about AI to its greeting, and a business's AI assistant must not claim to be a person.
- Web widget: a business's web voice widget may show or speak a notice before or when the conversation starts. What it shows depends on the business's widget placement and version.
Customers are responsible for any further notices and consents their callers' laws require, including any disclosure that the caller is talking with an AI.
6. How we disclose information #
We disclose personal information only as follows:
- Service providers and subprocessors. These include carriers, AI providers, hosting (Supabase and Amazon Web Services), email delivery (Amazon SES), payments (Stripe), website delivery and security (Cloudflare), mapping and address services (Google), and business contact research. They may use the information only to serve us, except for limited uses their contracts allow, such as security or legal compliance. Providers that handle Customer Data are listed at https://myphoneflow.com/legal/subprocessors/.
- Carriers. Calls and texts pass through Twilio and the networks it connects to, which handle call and message records under telecommunications law.
- The Customer, and where it sends data. Customer Users with access can see their Customer's data. A Customer may set PhoneFlow up to send call details to its email, text recipients, CRM, calendar, ticketing system or webhooks. Those transfers follow the Customer's instructions and are the Customer's own disclosures.
- Partners. Authorized PhoneFlow partners that resell the Services to a Customer or support it may access that Customer's account, including Customer Data such as recordings and transcripts, to provide that support. A Customer may ask us to remove a partner's access.
- Legal and safety. We disclose information when we believe in good faith the law requires it, for example in response to a subpoena, court order, or lawful regulator or carrier request. We also disclose it to protect the rights, safety or property of PhoneFlow, our Customers or others, to investigate fraud or abuse, or to enforce our agreements. Before disclosing Customer Data, we notify the Customer unless the law or circumstances prevent it.
- Business transfers. Information may be transferred in a merger, acquisition, financing, reorganization, or sale of all or part of our business, including to a PhoneFlow affiliate or successor. The recipient must handle it consistently with this notice.
- With your direction or consent.
No sale; no cross-context behavioral advertising. We do not sell personal information, and we do not share it for advertising based on your activity across other companies' websites. We never sell or share Customer Data or information about Callers or Widget Visitors.
7. Text messages #
- Mobile information is not shared for marketing. We do not share mobile phone numbers, text-message opt-in data or consent records with third parties or affiliates for their marketing or promotional purposes. We share them only with providers that help deliver messages, such as our carrier, and as the law requires.
- Texts for Customers. Texts from a Customer's PhoneFlow number, such as confirmations and appointment reminders, are sent for that Customer, which is responsible for having consent to send them.
- Opting out. Reply STOP to a text from a PhoneFlow number to opt out. We record the opt-out, and automated appointment-reminder texts honor it. Reply START to opt back in. Message and data rates may apply.
- Stopping automated calls. To stop automated or AI calls from a business that uses PhoneFlow (such as appointment reminders or AI callbacks), tell that business. The business is responsible for honoring your request, including for any live calls from its staff.
- PhoneFlow's own marketing. We place marketing calls or texts using automated or AI voices only with your prior express written consent, which is never a condition of purchase. Withdraw it any time by replying STOP, saying so on a call, or emailing [email protected].
8. Cookies and similar technologies #
On myphoneflow.com we use:
- essential storage, so the site works and remembers your cookie choice;
- a Google Ads tag, which tells us when someone who clicked our ad later submits a form;
- HubSpot forms and meeting booking, which may set cookies linking your visits to what you submit;
- ZoomInfo, only if you accept marketing cookies, which helps identify the companies, and sometimes the people, visiting our site for business-to-business marketing; and
- Cloudflare, which processes IP addresses to deliver the site and block attacks.
Our cookie banner lets you accept or reject marketing cookies, such as ZoomInfo, and change that choice later. The Google Ads tag and HubSpot scripts may load when a page loads, before you make a choice. You can also block cookies in your browser and manage ad personalization in your Google account. Our site does not respond to "Do Not Track" signals.
In the PhoneFlow app (app.myphoneflow.com), browser storage keeps you signed in for your session and remembers your settings. The app uses no third-party advertising or analytics tools.
9. How long we keep information #
Apart from widget rate-limiting records (below), we do not run automatic deletion schedules. Instead:
- Customer Data is kept while the Customer's account is open, unless the Customer deletes it or asks us to. We delete it within 60 days of a written deletion request, or within 60 days after the account closes (the 30-day export window runs within that period). This includes recordings stored with our carrier. After closing, the Customer has 30 days to ask for a copy before deletion.
- Customer User account information follows the same timeline. It is deleted sooner if the Customer removes the user and asks us to delete it.
- Leads, prospects, enquiries, and calls to PhoneFlow's own lines and widget are kept until you ask us to delete them or we no longer need them for the purposes in Sections 2.5 and 4.1.
- Agreement-acceptance, billing, payment and opt-out records are kept as legal and business records while the account exists and for 6 years after it closes, or longer if the law requires or a claim is pending.
- Backups and providers. Backup copies are removed as backups expire on our hosting providers' schedules. Some providers keep limited copies briefly for security and abuse monitoring under their own terms.
- Widget rate-limiting. IP addresses used to limit widget abuse are deleted once they are more than 24 hours old, the next time a widget session is requested.
We may keep information longer where the law requires, to resolve disputes, or to enforce our agreements.
10. Your choices and rights #
10.1 Choices everyone has #
- Marketing emails: use the unsubscribe link, or email us.
- Marketing calls and texts: see Section 7. Cookies: see Section 8.
- Account details: Customer Users can update their profile in the app or ask their administrator.
10.2 Your rights #
Depending on where you live, you may have the right to:
- know and access the personal information we hold about you, including a copy in a portable format;
- correct it;
- delete it;
- opt out of its sale or sharing, targeted advertising and certain profiling. We do not do these as those laws define them, but you may still send an opt-out request;
- limit use of sensitive personal information. We use it (for example, account passwords) only to provide and secure the Services; and
- not be treated differently for using these rights.
These rights come from laws such as the California Consumer Privacy Act and similar laws in other US states. Some apply only to businesses above size or data-volume thresholds. We describe them so you know how we respond, not to concede that any particular law applies to us.
State-law disclosures. In the last 12 months we collected these categories of personal information:
- identifiers;
- customer records;
- commercial information;
- internet activity;
- approximate location;
- audio and electronic information (recordings and transcripts);
- professional information; and
- sensitive personal information limited to account login credentials.
Sections 3, 4, 6 and 9 describe their sources, purposes, recipients and retention. We disclose each category for business purposes to the recipients in Section 6.
10.3 How to make a request #
- Contact: email [email protected] or call +1 947 777 7449.
- Verification: we will ask only for what we need to confirm your identity, such as proof you control the account email.
- Agents: an authorized agent may ask for you. We may require proof of the agent's authority and ask you to confirm your identity directly.
- Timing: we respond within the time the law requires, generally 45 days. Where the law allows, we may extend this once and will tell you.
- Appeals: if we decline, you may appeal by replying to our decision or emailing [email protected] with "Appeal" in the subject line. If you remain unsatisfied, you may contact your state attorney general.
- Limits: we may decline or limit a request where the law allows, for example to complete a transaction, keep required records, protect security, or defend legal claims.
10.4 Callers and Widget Visitors of our Customers #
The business you contacted controls your information, so please send requests to it directly. If you send one to us, we will pass it to the Customer where we can identify it and help the Customer respond as our agreement requires. The number you called or the website you visited helps us find the right Customer. We do not act on these requests ourselves unless the Customer instructs us or the law requires it.
10.5 Customer Users #
Your organization controls its account, including Customer Data and user access, and its administrators can see your account details and activity. For your own account information, contact your administrator or us. Export or deletion of a Customer's data must be requested by the Customer's authorized administrator by email to [email protected]. The app does not yet offer self-serve export or account deletion.
11. Security #
We use administrative, technical and physical safeguards suited to the information we handle:
- data is encrypted in transit, and at rest by our hosting providers;
- integration credentials are also encrypted in our database;
- database access controls keep each Customer's data separate from other Customers';
- PhoneFlow personnel have access to production systems only to operate, support and secure the Services; and
- Stripe handles card payments.
No system is completely secure, and we cannot guarantee security. If we learn of a security incident affecting your personal information, we will notify you, or the responsible Customer, as the law and our agreements require. Keep your password private, and tell us at [email protected] if you think your account has been compromised.
12. Children #
Our Services and websites are built for businesses and are not directed to children under 13. We do not knowingly gather personal information from anyone under 13. Customers may not place a PhoneFlow web voice widget on a website or page directed to children under 13, or use the Services to knowingly collect information from children under 13, unless they have verifiable parental consent as COPPA requires and PhoneFlow has approved the placement in writing.
If we learn we have a child's personal information without verifiable parental consent, we will delete it. We may also turn off a widget placed on a child-directed site. To tell us about a child's information, email [email protected].
13. Where information is processed #
PhoneFlow is based in the United States. Our databases are hosted in the United States, and real-time call processing runs in Amazon Web Services' US East (Ohio) region. Some providers may process information in other countries under their own safeguards.
The Services are intended for US and Canadian phone numbers and callers. If you are outside the United States, your information will be transferred to and processed in the United States, whose laws may differ from yours. US courts, law enforcement and national security authorities may be able to obtain access to it.
Where the Services handle personal data from the European Economic Area, the United Kingdom or Switzerland for a Customer, the PhoneFlow Data Processing Addendum (https://myphoneflow.com/legal/dpa/) applies, including the Standard Contractual Clauses and the UK Addendum.
14. Changes to this notice #
We may update this notice as our Services, practices or the law change. Each version has a number and an effective date, and earlier versions stay available at their own address (for example, https://myphoneflow.com/legal/privacy/v1.0/). Changes are listed at https://myphoneflow.com/legal/changes/.
- Housekeeping fixes (typos, contact details) are posted with a change-log entry.
- Other non-material changes, such as adding a service provider, are posted with at least 30 days' notice by email to Customer administrators and an in-app banner.
- Material changes to how we use data, or to AI training, come with at least 30 days' notice by email and in the app. Customers are then asked to review and acknowledge the change at their next sign-in.
- Changes apply going forward. We will not use information we already hold in a materially different way from what we said when we collected it without notice and, where the law requires, consent.
The current version is always at https://myphoneflow.com/legal/privacy/.
15. How to contact us #
For privacy questions, requests or complaints:
- Email: [email protected]
- Phone: +1 947 777 7449
- Mail: Electric Software LLC d/b/a PhoneFlow, Attn: Privacy, 120 N Washington Square, Suite 300, Lansing, MI 48933
For general support, email [email protected].
