Dial.Work

PRIVACY

What we collect, and why.

The personal data Dial.Work holds, what it is used for, who it is shared with, and how to get it back or have it deleted.

In effect from 7 September 2026. Written to be read, so if a sentence here is doing something you did not expect, tell us at legal@dial.work.

On this page

  1. Who is responsible
  2. What we collect
  3. Why we use it, and what allows us to
  4. Cookies
  5. Who else sees it
  6. Where it goes
  7. How long we keep it
  8. Your rights
  9. Security
  10. Children
  11. Changes

Who is responsible

Dial.Work is the controller of the personal data described here. That means we decide what is collected and why, and we are the people to complain to if you think we have it wrong.

Write to privacy@dial.work about anything on this page. We answer privacy requests within 30 days, and within 45 days where California law sets that limit instead.

What we collect

Three ways, and no others.

What you give us
Your email address, and a wallet address if you sign in with one. Which kind of customer you are, which you choose on the sign-in screen. What you put in a number registration or a delegation application. Anything you write to support. Whether you have agreed to marketing email, and when.
What your use of the service produces
The numbers, prefixes and names delegated to you, how they are configured to route, what is in your cart, and what you have bought. Sign-in events and the security cookies described below.
What is collected automatically
Pages viewed, approximate location from IP address, and browser and device type, through our analytics. This is described in the cookies section, along with how to turn it off.

We do not collect card numbers. When you pay, the card details go directly from your browser to Stripe. What comes back to us, and all we store, is the card brand, its last four digits, and a Stripe reference we can charge again with your agreement.

We do not ask for, and do not want, special category data: health, race, religion, politics, sex life, biometrics or trade union membership. Please do not put any of it in an application or a support message.

Why we use it, and what allows us to

Under the GDPR every use of personal data needs a lawful basis. Ours are these, in full.

To run the service — performance of a contract
Signing you in, issuing a number, holding and delegating a prefix or a name, taking payment, renewing, and answering support.
To keep it working and stop abuse — legitimate interests
Security, rate limiting, fraud and spam prevention, debugging, and understanding in aggregate which parts of the product people use. We have weighed this against your interests; it is limited to what running a network safely requires, and you can object at any time.
To send you marketing email — consent
Only if you ticked the box, only for what the box described, and only until you untick it or unsubscribe. Never a condition of buying anything.
To meet our obligations — legal obligation
Tax and accounting records, telecoms and registry requirements for who holds a number, and responding to a lawful request from a regulator or a court.

Cookies

The portal sets as few as it can, and none of them follow you to other sites.

Strictly necessary
A signed session cookie that keeps you signed in for seven days, and a short-lived cookie holding the one-time value that proves a wallet signature is fresh. Without these you cannot sign in, so they are set without asking.
Analytics
PostHog, loaded through our own domain so an ad blocker does not silently break it, recording page views and product events. Your browser's Do Not Track or Global Privacy Control signal is honoured, and blocking the cookie does not affect anything you have bought.

We do not run advertising trackers, and nothing on this site is sold to a data broker.

Who else sees it

We share personal data with the companies that run parts of the service for us. Each is bound by a contract to use it only on our instructions.

Stripe
Payments, cards, and payment plans.
Resend
Sending sign-in links and email.
PostHog
Product analytics.
Cloudflare
Object storage for account records, and the network in front of the site.
Vercel
Hosting and delivery.

Beyond those, we disclose personal data only when a law, a court, or a telecoms regulator requires it, when it is needed to establish or defend a legal claim, or to a buyer if the business is sold — in which case you will be told before your data moves.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in California law. We have never done so.

Where it goes

Our processors are based in the United States, so personal data from the EEA and the UK is transferred there. Those transfers are covered by the European Commission's standard contractual clauses, with the UK addendum where the UK GDPR applies. Ask us and we will tell you which mechanism covers a particular processor.

How long we keep it

Your account
For as long as it exists, and for 30 days after you ask us to close it, so the deletion can be reversed if it was a mistake.
Numbers, prefixes and names
For as long as they are delegated to you, and afterwards in the registry record of who held what, which we are expected to be able to produce.
Payments and invoices
Seven years, because tax law says so.
Marketing consent, and unsubscribes
Kept after you withdraw consent, not deleted with it. A record that you opted out is the only way to make sure you stay opted out, and the only way to show we honoured it.
Analytics
Retained by PostHog under its own schedule, in a form not tied to your account.

Your rights

Wherever you live, you can ask us to do all of the following, and we will not treat you differently for asking.

  • Get a copy of what we hold about you, in a portable format.
  • Correct anything that is wrong.
  • Delete it, except where we are required to keep it.
  • Restrict or object to a use that relies on our legitimate interests.
  • Withdraw consent to marketing email, at any time, without giving a reason.
  • Know what we have collected, where it came from, and who we disclosed it to.

Email privacy@dial.work to exercise any of them, or use the unsubscribe link in any marketing email, which takes effect immediately and needs no account. An authorised agent may act for you if you confirm it in writing.

If you are in the EEA or the UK you can also complain to your data protection authority, and if you are in California to the California Privacy Protection Agency. We would rather you came to us first.

We do not make decisions about you by automated means that produce legal or similarly significant effects. Applications for a number or a delegation are reviewed by a person.

Security

Traffic is encrypted in transit, session cookies are signed and HTTP-only, sign-in links expire in fifteen minutes, and card details never touch our servers. No system is perfect; if we ever have a breach that puts you at risk we will tell you and the relevant regulator within the time the law allows.

Children

The service is for adults and for organisations. It is not directed at children, we do not knowingly collect data from anyone under 16, and if we learn we have, we delete it.

Changes

If we change this policy in a way that matters, we will email account holders before it takes effect rather than quietly changing the date at the top. Every version keeps its effective date.

Dial.Work

Read the terms document · privacy@dial.work