Privacy Policy
Last updated: April 2026
This Privacy Policy describes how CallMatrix("we," "us," or "our") collects, uses, stores, and protects information when you use our call routing and monetization platform, marketing website, APIs, and related services (collectively, the "Service").
1. Information We Collect
1.1 Account Information
When you register for an account, we collect your name, email address, company name, phone number, and billing address. This information is necessary to create and manage your account.
1.2 Billing and Payment Information
Payment information (credit card numbers, bank account details) is collected and processed by our third-party payment processor. We do not store full payment card numbers on our servers. We retain transaction records including amounts, dates, and payment method identifiers for billing and accounting purposes.
1.3 Call Data
When calls are routed through the Service, we collect and store call metadata including: caller phone number, called number (DID), call start time, end time, duration, call status, routing decisions, buyer assignment, revenue and cost data, IVR keypress responses, and collected digit inputs (e.g., zip codes). If call recording is enabled by you, audio recordings are stored as configured.
1.4 Website Visitor Data (Dynamic Number Insertion)
When you deploy our DNI snippet on your website, we collect data about your website visitors including: IP address, browser user agent, referrer URL, landing page URL, UTM parameters, Google Click IDs (GCLID, gbraid, wbraid), and the phone number assigned to each visitor session. This data is collected to enable call attribution and conversion tracking.
1.5 Lead Form and Widget Submissions
When visitors submit forms or request callbacks through your embedded forms and widgets, we collect the data they provide (name, phone number, email, address, and any custom fields you configure). This data is used to initiate outbound calls and is stored as part of your campaign records.
1.6 Google Ads Data
If you enable the Google Ads integration, we sync data from your Google Ads account including campaign structures, keyword performance, search terms, audience data, and call records. This data is used to power analytics and conversion upload features. We access this data using OAuth tokens you provide and do not share it with third parties.
1.7 Platform Usage Data
We collect data about how you use the Service including pages visited, features used, API calls made, and configuration changes. This data helps us improve the platform and provide support.
1.8 Marketing Website Data
When you visit our marketing website (https://callmatrix.io), we collect standard web analytics data through cookies and similar technologies including pages viewed, time on site, referral source, and device/browser information.
2. How We Use Your Information
- Provide the Service: Route calls, execute IVR trees, run ping-post auctions, assign tracking numbers, process lead forms, trigger callbacks, and deliver analytics dashboards.
- Process billing: Calculate usage charges, deduct from wallet balances, process subscription payments, and send billing notifications.
- Google Ads integration: Sync campaign data, run insight analyzers, and upload conversion data back to your Google Ads account as configured by you.
- Customer support: Investigate and resolve issues you report, including reviewing call records and routing logs.
- Platform improvement: Analyze aggregate usage patterns to improve performance, reliability, and features.
- Security: Detect and prevent fraud, abuse, and unauthorized access.
- Communications: Send transactional emails (billing alerts, usage notifications, system alerts) and, with your consent, product update emails.
3. Information We Do Not Collect or Sell
- We do not sell, rent, or trade your personal information or call data to third parties.
- We do not use your call data or campaign data to build advertising profiles.
- We do not listen to or review call recordings except when explicitly requested by you for support purposes.
- We do not share your Google Ads data with any party other than you and Google (via the conversion upload you configure).
4. Data Sharing
We share data only in the following circumstances:
- Telephony providers: Call routing data is shared with our telephony provider to complete calls. This includes caller and destination phone numbers and call control instructions.
- Payment processor: Billing data is shared with our payment processor to process payments.
- Google Ads: When you enable conversion upload, call conversion data (GCLID, conversion value, timestamp) is sent to your Google Ads account.
- Ping-post buyers: When ping-post auctions are enabled, anonymized lead data (state, zip code, vertical, area code) is sent to buyers you configure. Full lead data is sent only to the winning buyer after the call connects.
- Legal requirements: We may disclose information if required by law, subpoena, court order, or government investigation.
5. Call Recording and Consent
Call recording is an optional feature controlled entirely by you. When enabled, CallMatrix can play a configurable consent prompt at the beginning of each call. You are solely responsible for complying with applicable call recording laws, including obtaining necessary consent from call participants. Recording consent requirements vary by jurisdiction (one-party vs. two-party consent states).
6. Data Storage and Security
- Data is stored in encrypted databases hosted on secure, access-controlled infrastructure.
- All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.
- Database access is restricted to authorized personnel and automated systems via role-based access controls.
- We maintain regular automated backups with point-in-time recovery capability.
- API authentication uses bearer tokens and API keys with rate limiting.
- We conduct regular security reviews and promptly address identified vulnerabilities.
7. Data Retention
- Active accounts: Call records, analytics data, and campaign configurations are retained for the lifetime of your account.
- Closed accounts: Data is retained for 90 days after account closure to allow for reactivation or data export requests, then permanently deleted.
- Billing records: Transaction records are retained for 7 years to comply with tax and financial reporting obligations.
- Call recordings: Retained according to your configured retention period. You may delete recordings at any time.
- DNI visitor sessions: Expired sessions are batch-purged automatically based on your configured session expiry window.
8. Cookies and Tracking Technologies
8.1 Essential Cookies
We use essential cookies for authentication, session management, and security. These cannot be disabled while using the Service.
8.2 Analytics Cookies
Our marketing website uses analytics cookies to understand visitor behavior. You may disable these via your browser settings or cookie preferences without affecting your use of the platform.
8.3 DNI Snippet
The Dynamic Number Insertion snippet deployed on your websites uses JavaScript and sessionStorage (not cookies) to track visitor sessions and assign phone numbers. This is a first-party integration controlled by you.
9. Your Rights
9.1 Access and Export
You may access and export your data at any time using the platform's built-in export features (CSV, XLSX, Google Sheets) or via the API (Enterprise plans). You may also request a complete data export by contacting [email protected].
9.2 Correction
You may update your account information at any time through the platform settings. For corrections to other data, contact [email protected].
9.3 Deletion
You may request deletion of your account and associated data by contacting [email protected]. We will process deletion requests within 30 days, subject to legal retention obligations.
9.4 Data Portability
You may export your call records, campaign configurations, and analytics data in machine-readable formats (CSV, XLSX, JSON via API) at any time.
10. California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know: You may request details about the categories and specific pieces of personal information we collect.
- Right to delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to opt out of sale: We do not sell personal information. No opt-out is necessary.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, contact [email protected] with the subject line "CCPA Request."
11. European Residents (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following applies:
- Legal basis: We process your data based on contractual necessity (to provide the Service), legitimate interest (to improve and secure the Service), and consent (for marketing communications).
- Data transfers: Your data may be transferred to and processed in the United States. We implement appropriate safeguards for international transfers.
- Additional rights: You have the right to lodge a complaint with your local data protection authority, the right to restrict processing, and the right to object to processing based on legitimate interests.
To exercise these rights, contact [email protected] with the subject line "GDPR Request."
12. Children's Privacy
CallMatrix is a business-to-business platform and is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.
13. Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before they take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.
15. Contact Us
For privacy-related inquiries, data requests, or concerns, contact us at:
- Email: [email protected]
- Subject line: "Privacy Inquiry"
We aim to respond to all privacy-related requests within 30 days.