1. What this policy covers
This policy explains what Nexgen Call does with personal information. It covers two different groups of people, and the answer is different for each.
- Visitors to nexgencall.com and our customers. Here we decide why and how the data is used. We are the controller.
- The callers, message recipients and website visitors of our customers. That data arrives because a customer configured a tracking number or installed the tracking script. The customer decides why it is collected; we process it on their instructions. We are the processor, and the customer's own privacy notice governs it.
If you called a business and want your record removed, contact that business. If you cannot reach them, write to us at [email protected] and we will pass the request to the customer who holds the data.
2. What we collect
From our customers
- Account details: company name, your name, work email, hashed password, time zone, role, and the plan you chose.
- Billing details: subscription status, plan, renewal dates and Stripe identifiers. Card numbers go to Stripe and never reach our servers.
- Usage and security records: sign-in times, IP address at sign-in, actions taken in the workspace, and API key usage. We keep these to run the service and to investigate account compromise.
On our customers' behalf
- Call records: caller number, tracked number, time, duration, ring and answer outcome, and the routing that applied.
- Recordings and transcripts, where the customer has turned recording on for that source.
- Message records: SMS content, sender and recipient numbers, delivery status and opt-out status.
- Website session data from the tracking script on a customer's site: page URL, referrer, UTM parameters, Google click identifier, an anonymous session identifier, and the tracked number shown to that session.
- Contacts the customer uploads for outbound calling or texting.
From visitors to nexgencall.com
Our own marketing page loads no third-party scripts, sets no advertising cookies and runs no analytics tag. Our servers keep standard web logs (IP address, user agent, requested path) for security and troubleshooting.
3. Cookies and the tracking script
Inside the application we set one cookie, the session cookie that keeps you signed in. It is strictly necessary, marked HttpOnly and Secure, and it is not used for advertising.
Our tracking script, which customers install on their own websites, stores a first-party session identifier in the visitor's browser so the same visitor keeps the same tracked number for the length of their visit. It does not read data from other sites and it does not follow the visitor across the web. Customers are responsible for disclosing it in their own cookie or privacy notice.
4. How we use it
- To provide the service: route calls, swap numbers, record where enabled, transcribe, score, report and deliver events to the customer's CRM or webhook.
- To bill for the service and collect payment.
- To secure accounts: rate limiting, fraud and abuse detection, audit trails.
- To support customers who write to us, and to send service notices such as trial expiry and failed payments.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use the contents of calls or messages to train machine learning models.
5. Who we share it with
We use the following subprocessors. Each one is bound by contract to protect the data and to use it only to provide its service to us.
| Subprocessor | What it does | Location |
|---|---|---|
| Twilio | Telephone numbers, call carriage, recording storage and SMS delivery. | United States |
| Stripe | Subscription billing and card processing. Card numbers reach Stripe directly and are never stored by us. | United States |
| DigitalOcean | Application servers, database and object storage. | United States |
| Cloudflare | DNS, TLS termination, CDN and edge filtering. | United States |
| Backblaze B2 | Encrypted off-site backups of the database and stored files. | United States |
| Deepgram | Speech-to-text transcription of call recordings, when call transcription is enabled for the account. | United States |
Beyond that list, we disclose personal information only when a customer instructs us to (for example, sending call events to a CRM the customer connected), when the law requires it, or to establish or defend a legal claim. If we are ever compelled to hand over customer data, we will tell the customer unless we are legally barred from doing so.
We will post changes to this list on this page before a new subprocessor starts handling customer data.
6. How long we keep it
- Call and message records, including transcripts we generate: for as long as the customer's workspace is active.
- Recordings: stored in the customer's own Twilio account under the retention settings the customer controls; we keep the reference with the call record.
- Website session data: 13 months, so year-on-year attribution reporting works.
- Account and billing records: for the life of the account, then as long as tax and accounting law requires.
- After an account closes: the workspace is kept for 30 days and then deleted.
Recordings that live in a customer's own Twilio account are also subject to Twilio's retention settings, which the customer controls.
7. Your choices and rights
Whoever you are, you can ask us to tell you what we hold about you, correct it, or delete it. Write to [email protected]. We answer within 30 days. We will ask you to verify your identity before acting on a request, and we will not treat you differently for making one.
California residents. Under the California Consumer Privacy Act you have the right to know the categories and specific pieces of personal information collected, the right to delete, the right to correct, and the right to opt out of sale or sharing. We do not sell or share personal information as those terms are defined in the Act, so there is no opt-out to exercise. The categories we collect are listed in section 2. You may use an authorized agent, and we will verify their authority.
Recorded calls. If you were recorded on a call with one of our customers and you want the recording deleted, tell us the phone number you called from and the approximate date. We will locate it and pass the request to the customer who controls it, and we will delete it on their instruction or where the law requires us to act directly.
8. Security
How we protect the data is described in plain language on our security page. In short: everything travels over TLS, secrets such as your Twilio auth token are encrypted at rest with AES-256-GCM, passwords are salted and iterated rather than stored, backups are encrypted and held off site, and access to production is limited to the people who operate the service.
If we become aware of a breach affecting your personal information, we will notify affected customers without undue delay and give them what they need to meet their own notification duties.
9. Children
Nexgen Call is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child's information reached us, write to us and we will delete it.
10. Changes to this policy
We will post any change here and update the effective date at the top. If a change materially affects how we handle personal information, we will email the account owner at least 30 days before it takes effect.
11. Contact
Nexgen Call, a product of Nexgen Business Solutions. Privacy questions and requests: [email protected].