PRIVACY
What we collect, and why.
The personal data Dial.Work holds, what it is used for, who it is shared with, and how to get it back or have it deleted.
In effect from 7 September 2026. Written to be read, so if a sentence here is doing something you did not expect, tell us at legal@dial.work.
Who is responsible
Dial.Work is the controller of the personal data described here. That means we decide what is collected and why, and we are the people to complain to if you think we have it wrong.
Write to privacy@dial.work about anything on this page. We answer privacy requests within 30 days, and within 45 days where California law sets that limit instead.
What we collect
Three ways, and no others.
- What you give us
- Your email address, and a wallet address if you sign in with one. Which kind of customer you are, which you choose on the sign-in screen. What you put in a number registration or a delegation application. Anything you write to support. Whether you have agreed to marketing email, and when.
- What your use of the service produces
- The numbers, prefixes and names delegated to you, how they are configured to route, what is in your cart, and what you have bought. Sign-in events and the security cookies described below.
- What is collected automatically
- Pages viewed, approximate location from IP address, and browser and device type, through our analytics. This is described in the cookies section, along with how to turn it off.
We do not collect card numbers. When you pay, the card details go directly from your browser to Stripe. What comes back to us, and all we store, is the card brand, its last four digits, and a Stripe reference we can charge again with your agreement.
We do not ask for, and do not want, special category data: health, race, religion, politics, sex life, biometrics or trade union membership. Please do not put any of it in an application or a support message.
Why we use it, and what allows us to
Under the GDPR every use of personal data needs a lawful basis. Ours are these, in full.
- To run the service — performance of a contract
- Signing you in, issuing a number, holding and delegating a prefix or a name, taking payment, renewing, and answering support.
- To keep it working and stop abuse — legitimate interests
- Security, rate limiting, fraud and spam prevention, debugging, and understanding in aggregate which parts of the product people use. We have weighed this against your interests; it is limited to what running a network safely requires, and you can object at any time.
- To send you marketing email — consent
- Only if you ticked the box, only for what the box described, and only until you untick it or unsubscribe. Never a condition of buying anything.
- To meet our obligations — legal obligation
- Tax and accounting records, telecoms and registry requirements for who holds a number, and responding to a lawful request from a regulator or a court.
Where it goes
Our processors are based in the United States, so personal data from the EEA and the UK is transferred there. Those transfers are covered by the European Commission's standard contractual clauses, with the UK addendum where the UK GDPR applies. Ask us and we will tell you which mechanism covers a particular processor.
How long we keep it
- Your account
- For as long as it exists, and for 30 days after you ask us to close it, so the deletion can be reversed if it was a mistake.
- Numbers, prefixes and names
- For as long as they are delegated to you, and afterwards in the registry record of who held what, which we are expected to be able to produce.
- Payments and invoices
- Seven years, because tax law says so.
- Marketing consent, and unsubscribes
- Kept after you withdraw consent, not deleted with it. A record that you opted out is the only way to make sure you stay opted out, and the only way to show we honoured it.
- Analytics
- Retained by PostHog under its own schedule, in a form not tied to your account.
Your rights
Wherever you live, you can ask us to do all of the following, and we will not treat you differently for asking.
- Get a copy of what we hold about you, in a portable format.
- Correct anything that is wrong.
- Delete it, except where we are required to keep it.
- Restrict or object to a use that relies on our legitimate interests.
- Withdraw consent to marketing email, at any time, without giving a reason.
- Know what we have collected, where it came from, and who we disclosed it to.
Email privacy@dial.work to exercise any of them, or use the unsubscribe link in any marketing email, which takes effect immediately and needs no account. An authorised agent may act for you if you confirm it in writing.
If you are in the EEA or the UK you can also complain to your data protection authority, and if you are in California to the California Privacy Protection Agency. We would rather you came to us first.
We do not make decisions about you by automated means that produce legal or similarly significant effects. Applications for a number or a delegation are reviewed by a person.
Security
Traffic is encrypted in transit, session cookies are signed and HTTP-only, sign-in links expire in fifteen minutes, and card details never touch our servers. No system is perfect; if we ever have a breach that puts you at risk we will tell you and the relevant regulator within the time the law allows.
Children
The service is for adults and for organisations. It is not directed at children, we do not knowingly collect data from anyone under 16, and if we learn we have, we delete it.
Changes
If we change this policy in a way that matters, we will email account holders before it takes effect rather than quietly changing the date at the top. Every version keeps its effective date.