Back to Home

Privacy Policy

Effective Date: April 16, 2026Version: 2.0

NumeraLoop ("we," "our," or "us") is committed to protecting your privacy and handling your personal data with transparency and care. This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights regarding your personal information.

1. Introduction

NumeraLoop operates a cloud-based telecommunications management platform that enables users to manage Twilio phone numbers, send and receive SMS and MMS messages, conduct browser-based voice calls, run bulk SMS campaigns, and integrate telephony workflows into their business operations.

This Privacy Policy applies to all users of our website at numeraloop.com and our web application, including individuals accessing the platform on behalf of a business or organization.

By using NumeraLoop, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of our services.

2. Information We Collect

2.1 Account and Identity Information

  • Full name and email address (required for account creation)
  • Password (stored as a secure cryptographic hash; never in plain text)
  • Profile settings and user preferences
  • Account creation date and last login timestamp

2.2 Payment and Billing Information

Payment processing is handled exclusively by Stripe, Inc. We do not collect, store, or have access to your full credit card number, CVV, or other sensitive payment card data. We retain only:

  • Stripe Customer ID (a reference token assigned by Stripe)
  • Subscription plan, status, and renewal dates
  • Billing history and invoice records
  • Last 4 digits of payment card (as provided by Stripe for display purposes)

2.3 Twilio Credentials and Telephony Configuration

  • Twilio Account SID
  • Twilio Auth Token (encrypted at rest using AES-256 encryption via pgcrypto)
  • Twilio API Keys and secrets (encrypted at rest)
  • TwiML Application SIDs
  • Connected phone numbers and their configurations
  • Call forwarding destinations, whisper messages, and routing rules
  • Webhook URLs and integration settings

2.4 Communications and Activity Data

  • Inbound and outbound call logs (originating number, destination number, duration, timestamp, status)
  • SMS/MMS message logs (sender, recipient, message content, media URLs, delivery status, timestamp)
  • Bulk SMS campaign configurations, recipient lists, and delivery reports
  • Auto-reply rules, canned messages, and keyword triggers
  • Browser calling session data (WebRTC connection metadata)
  • Contact records you create or import (names, phone numbers, custom fields)
  • Inbox conversations and message threads

2.5 Technical and Usage Data

  • IP address (used for security, fraud prevention, and compliance)
  • Browser type, version, and operating system
  • Device type and screen resolution
  • Pages visited, features used, and time spent on the platform
  • Error logs and diagnostic data
  • Referral source (how you arrived at our site)

2.6 Third-Party Contact Data You Provide

When you upload contact lists, import CSV files, or input recipient phone numbers for campaigns, you are providing us with personal data belonging to third parties. You represent and warrant that you have obtained all necessary consents to provide such data and to contact those individuals using our platform.

3. How We Use Your Information

We use the data we collect for the following purposes:

  • Service Delivery: To provide, operate, and maintain the NumeraLoop platform and all its features
  • Authentication and Security: To verify your identity, protect your account, and detect fraudulent activity
  • Telephony Operations: To process call forwarding, SMS delivery, campaign sends, and other telephony functions on your behalf using your Twilio credentials
  • Billing and Subscriptions: To manage your subscription, process payments, and send billing-related communications
  • Customer Support: To respond to your support requests, diagnose technical issues, and resolve disputes
  • Service Improvement: To analyze usage patterns, identify areas for improvement, and develop new features
  • Legal Compliance: To comply with applicable laws, respond to lawful requests from authorities, and enforce our Terms of Service
  • Communications: To send service-related notices, security alerts, and (where consented) product updates or newsletters

We do not sell your personal information to third parties, use your data for behavioral advertising, or share your data with data brokers.

5. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:

5.1 Service Providers

We work with trusted third-party vendors who process data on our behalf under strict data processing agreements. See Section 6 for details on each integration.

5.2 Legal Requirements

We may disclose your information when required by law, court order, subpoena, or valid legal process. We will notify you of such requests where legally permitted to do so.

5.3 Business Transfers

If NumeraLoop undergoes a merger, acquisition, or sale of all or substantially all assets, your data may be transferred to the acquiring entity. We will notify you prior to any such transfer, and the acquiring entity will be bound by this Privacy Policy.

5.4 Protection of Rights

We may disclose information where necessary to protect the rights, property, or safety of NumeraLoop, our users, or others, including for fraud prevention purposes.

6. Third-Party Integrations

Twilio, Inc.

All telephony services — including voice calls, SMS/MMS, and number provisioning — are delivered through Twilio. We transmit your Twilio credentials and configuration data to Twilio solely to execute your instructions. Your use of telephony features is additionally governed by Twilio's Acceptable Use Policy and Privacy Policy.

Data may be processed in the United States and other countries where Twilio operates. Twilio maintains Standard Contractual Clauses for EEA transfers.

Stripe, Inc.

Payment processing is handled exclusively by Stripe. When you enter payment information, it is transmitted directly to Stripe's servers over an encrypted connection. NumeraLoop never receives or stores your raw card data. Stripe is certified as a PCI DSS Level 1 Service Provider. Your use of payment features is governed by Stripe's Privacy Policy and Terms of Service.

Stripe processes payments globally. Stripe maintains Standard Contractual Clauses and a Data Processing Agreement for GDPR compliance.

Supabase, Inc.

We use Supabase for our database infrastructure, user authentication, and file storage. Your account data, telephony configuration, contacts, and message logs are stored in a Supabase-hosted PostgreSQL database. Supabase employs row-level security (RLS) to ensure data isolation between users.

Supabase infrastructure is hosted on AWS. Supabase is GDPR compliant and offers a Data Processing Agreement.

7. Cookies and Tracking Technologies

7.1 Types of Cookies We Use

Cookie TypePurposeRequired
Authentication (session tokens)Maintain your logged-in session and verify your identityYes
Security (CSRF tokens)Protect against cross-site request forgery attacksYes
PreferencesRemember your UI settings and preferencesNo
Analytics (anonymized)Understand how features are used to improve the productNo

7.2 What We Do Not Use

  • We do not use third-party advertising or retargeting cookies
  • We do not use social media tracking pixels
  • We do not sell data derived from cookies to data brokers

7.3 Cookie Management

You can control non-essential cookies through your browser settings. Disabling essential cookies will impair your ability to log in and use the platform.

8. Data Retention and Deletion

Data CategoryRetention Period
Account and profile dataFor the duration of your active account
Call and SMS activity logs90 days (rolling), then automatically purged
Bulk campaign dataFor the duration of your active account
Contact recordsUntil you delete them or close your account
Billing records and invoices7 years (legal and tax compliance requirement)
Security and access logs12 months for fraud prevention purposes
Data after account deletionPermanently deleted within 30 days of request
Encrypted database backupsUp to 90 days before being overwritten

To request account deletion, use the "Delete Account" option in your Settings page, or contact us at support@numeraloop.com. Billing records may be retained for the legally required period even after account deletion.

9. Security Measures

We implement industry-standard technical and organizational measures to protect your data:

  • Encryption at Rest: Sensitive credentials (Twilio Auth Tokens, API keys) are encrypted using AES-256 via PostgreSQL pgcrypto before storage
  • Encryption in Transit: All data in transit is protected by TLS 1.2 or higher (HTTPS enforced on all connections)
  • Row-Level Security: Database access is enforced at the row level, ensuring each user can only access their own data
  • Authentication: Secure password hashing (bcrypt/argon2) and support for session-based authentication with automatic expiry
  • Credential Isolation: Your Twilio credentials are never exposed to the client browser; they are only used server-side in Edge Functions
  • Access Logging: Sensitive operations are logged for audit and security monitoring purposes
  • Payment Security: Payment card data is handled exclusively by Stripe (PCI DSS Level 1 certified) and never passes through our servers

Despite our best efforts, no system is 100% secure. In the event of a data breach affecting your rights and freedoms, we will notify you and relevant supervisory authorities as required by applicable law (within 72 hours under GDPR).

10. International Data Transfers

NumeraLoop is operated from the United States. Your data is stored and processed primarily in the United States via Supabase and AWS infrastructure. If you are located in the EEA, UK, Switzerland, or other regions with data transfer restrictions, please be aware of the following:

  • Standard Contractual Clauses (SCCs): Where required, we rely on SCCs approved by the European Commission as a lawful transfer mechanism
  • Adequacy Decisions: Where applicable, we transfer data to countries deemed adequate by the European Commission
  • Data Processing Agreements: All sub-processors (Stripe, Supabase, Twilio) have executed DPAs that include appropriate transfer safeguards

By using NumeraLoop, you consent to the transfer of your data to the United States and other countries where we or our service providers operate.

11. Your Rights Under GDPR (EU / EEA / UK)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) or UK GDPR:

Right to Access (Art. 15)

Request a copy of your personal data. Use "Export My Data" in your account Settings, or contact us directly.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete personal data through your account settings or by contacting us.

Right to Erasure / "Right to be Forgotten" (Art. 17)

Request deletion of your personal data. Use "Delete Account" in Settings. Note: billing records may be retained for legal compliance.

Right to Restriction of Processing (Art. 18)

Request that we limit how we process your data in certain circumstances (e.g., while a dispute is resolved).

Right to Data Portability (Art. 20)

Receive your personal data in a structured, machine-readable format (JSON/CSV) for transfer to another service.

Right to Object (Art. 21)

Object to processing based on legitimate interests, including profiling and direct marketing.

Right to Withdraw Consent (Art. 7(3))

Withdraw consent for processing based on consent at any time without affecting prior lawful processing.

Right to Lodge a Complaint

File a complaint with your national supervisory authority (e.g., the ICO in the UK, or your local DPA in the EU).

To exercise any of these rights, contact us at support@numeraloop.com. We will respond within 30 days. We may request identity verification before processing your request.

12. Your Rights Under CCPA (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purposes for collection, and the categories of third parties we share it with
  • Right to Delete: Request deletion of personal information we have collected from you, subject to certain exceptions
  • Right to Correct: Request correction of inaccurate personal information we maintain about you
  • Right to Opt-Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is required, but you may contact us to confirm this practice.
  • Right to Limit Use of Sensitive Personal Information: Limit our use of sensitive personal information to what is necessary to provide our services
  • Right to Non-Discrimination: We will not discriminate against you for exercising any CCPA rights

To submit a CCPA request, email support@numeraloop.com with the subject line "CCPA Request." We will respond within 45 days. You may submit a request up to twice per 12-month period.

13. Your Rights Under PIPEDA (Canada)

If you are a Canadian resident, the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws grant you the following rights:

  • Right to Access: Request access to your personal information held by us and information about how it has been or may be used and disclosed
  • Right to Correction: Challenge the accuracy and completeness of your personal information and have it amended as appropriate
  • Right to Withdraw Consent: Withdraw consent to the collection, use, or disclosure of your personal information at any time, subject to legal or contractual restrictions
  • Right to Challenge Compliance: Challenge our compliance with PIPEDA by contacting our Privacy Officer or filing a complaint with the Office of the Privacy Commissioner of Canada (OPC)

We collect, use, and disclose personal information only with your knowledge and consent, and only for purposes that a reasonable person would consider appropriate. Contact us at support@numeraloop.com to exercise these rights.

14. Children's Privacy

NumeraLoop is a business-oriented telecommunications platform intended exclusively for adults aged 18 and older. We do not knowingly collect personal information from individuals under 18 years of age.

If we become aware that we have inadvertently collected personal information from a child under 18, we will take immediate steps to delete such information. If you believe we have collected data from a minor, please contact us immediately at support@numeraloop.com.

15. Voice and Communications Data

15.1 Call Recording

NumeraLoop does not record calls by default. If you enable call recording through your Twilio account configuration, recordings are stored by Twilio, not by NumeraLoop. You are solely responsible for complying with all applicable laws regarding call recording consent, including:

  • State wiretapping and eavesdropping laws (including two-party consent states such as California, Florida, Illinois, and others)
  • Federal Electronic Communications Privacy Act (ECPA) requirements
  • GDPR requirements for processing voice data in the EEA

15.2 Browser-Based Calling (WebRTC)

Browser calling uses the Twilio Voice SDK and WebRTC technology. Voice data is transmitted directly via Twilio's infrastructure. We store call metadata (duration, timestamps, status) but do not record or store audio content of browser-based calls.

15.3 SMS and MMS Content

Message content from inbound and outbound SMS/MMS is stored in your account database for operational purposes (inbox management, reporting). Message content is retained as described in Section 8. You are responsible for the content of all messages sent using our platform and for ensuring recipient consent.

16. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Effective Date" at the top of this page
  • Post a notice in the platform for at least 14 days prior to the change taking effect
  • Email registered users when changes materially affect their rights or our data practices

Your continued use of NumeraLoop after the effective date of any updated Privacy Policy constitutes your acceptance of the changes. If you do not agree, please discontinue use and delete your account.

17. Contact and Data Protection Officer

For any questions, concerns, or requests related to this Privacy Policy or the handling of your personal data, please contact us:

Company:NumeraLoop
General Inquiries:support@numeraloop.com
Data Deletion:Use Settings → Delete Account, or email us
Data Export:Use Settings → Export My Data
Response Time:Within 30 days for data subject requests

This Privacy Policy is effective as of April 16, 2026 (Version 2.0). By using NumeraLoop, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.