Legal

Privacy Policy

Last updated: September 6, 2026

Short version: we collect the minimum data needed to run your account, we store it on our own infrastructure (no advertising trackers, no data brokers), and you can have it exported or deleted at any time.

01Data we collect

Account data: your email address, company name, phone number, and a bcrypt hash of your password. We never store passwords in readable form.

Billing data: BTCPay invoice identifiers, amounts, plan and settlement status. We never see or store card numbers — there is no card rail — and we do not custody your Bitcoin.

Operational data: call metadata (numbers, direction, duration, sentiment classification, AI-generated summaries) and agent configurations. Until the OpenClaw engine is attached, dashboard call data is sample data, not real calls.

Support data: messages you send through the contact form.

Server logs: standard reverse-proxy logs (IP address, user agent, timestamps) kept for security and abuse prevention, rotated automatically.

02What we deliberately do not do

No advertising or cross-site tracking: the site sets no third-party marketing cookies and loads no ad scripts.

No sale of data: your information is never sold, rented or shared with data brokers.

No unnecessary processing: analytics are aggregated counts, not per-caller profiling beyond what the service requires.

03Where your data lives

All data is stored on our self-hosted PostgreSQL infrastructure in the European Union, fronted by our own Nginx reverse proxy. We do not push customer data to third-party cloud processors. Payment metadata is additionally mirrored inside your own BTCPay Server instance.

04Cookies

We set strictly-necessary cookies only: the NextAuth session cookie that keeps you signed in, and a CSRF-protection cookie. Both are HttpOnly and Secure. There are no consent banners because there is nothing to consent to — no analytics or marketing cookies exist.

05Your rights

Access, export, correction and deletion: request any of these from your dashboard settings or by contacting support. Deletion removes your account, subscriptions, invoices, agent configurations, call metadata and contact messages; minimal billing records may be retained where financial law requires it.

If you are in the EU/EEA, you additionally have the right to lodge a complaint with your national data-protection authority.

06Security

Transport is TLS-encrypted everywhere. Passwords are bcrypt-hashed; password-reset tokens are stored only as SHA-256 hashes and expire within one hour. Payment webhooks are HMAC-verified. The platform is protected by fail2ban, strict firewall rules and schema-validated APIs.

07Contact

Privacy requests and questions: privacy@voipclaw.com or via the contact page. We respond within one business day.

Questions about this document? Contact us.