Privacy policy
Last updated 7 October 2026
In short. We collect what we need to run a business phone service: your account, your calls and texts, and, only when your team turns them on, recordings and AI notes. We use a small number of named providers, keep data in the United States, and do not sell it or use it for advertising. You can see, export, correct or delete your data by emailing support@redstonecastles.com.
1. Who we are and what this policy covers
Presence is a business phone service run by Redstone Castle LLC, a New York limited liability company (“we”, “us”). This policy explains what personal information we collect, why, who else handles it, how long we keep it, and your rights. It is written to be read, not skimmed past.
- Our customers’ account information, and visitors to our website. For this information we decide how it is used. In data-protection terms we are its “controller” or “business”.
- What our customers put through Presence: their calls, recordings, voicemails, transcripts, AI notes, texts, contacts and the like (“Customer Content”). We handle it on the customer’s behalf and under its instructions, as its “processor” or “service provider”. Our Data Processing Addendum governs that.
If you called, were called by or texted with a business that uses Presence, that business decides what happens to your information. Please contact it first. If you contact us, we will pass your request on and help the business answer it.
2. What we collect
About you and your business
- Account details. Your name, email address, a hashed password (or, if you sign in with Google, your Google account identifier, name and email address), the name of your business, and your role on its team.
- Sign-in and security. Session records, the browsers and phones signed in to your account, two-step sign-in settings (the authenticator secret is stored encrypted), and a log of significant account actions, such as changes to settings and team.
- Payment. Handled by Stripe. Your card details never reach our servers; we hold a Stripe customer reference, your plan, the number of people on it, and your invoices and payment status.
- Emergency address. The address you give at checkout, which US rules require before a number can be activated, with a record of who acknowledged the emergency-calling notice and when. Presence cannot call 911 today; see Emergency calls.
- Texting registration. If you register for texting: your business’s display and legal names, address, tax number if it has one, website, contact email and phone number, a description of the texts you send, sample messages and how people agree to receive them. If you choose the policy pages we host for you, your business name, legal name, email address, business number and city, state and country are published on them.
- Moving a number. If you move a number to Presence: the name, service address, account number and PIN on your current provider account, the billing number, a bill if you upload one, and the letter of authorization you sign, with the time and IP address of signing.
- Support. The emails you send us and our replies.
- How you found us. When you sign up, the campaign tags, referral code, referring website and first page from your first visit, if any (see Cookies). If we contacted your business about Presence ourselves, we may note that you signed up.
Customer Content, held for our customers
- Phone numbers and call records. The numbers your team uses, and for every call the numbers involved, the time, the duration, who on your team answered, the outcome you record and the cost. We need these to run the service, show your call history and stop fraud.
- Call audio. Live call audio passes through our servers to connect the call, and is not kept unless the call is recorded.
- Recordings and transcripts. Only when your team has turned recording on. Every recorded call announces the recording before the call is connected. Recordings are transcribed, and the transcript is used to write a short summary and notes for you.
- Voicemails. When a caller leaves a message, we keep the recording, transcribe it and write a short summary, so your team can read it as well as listen.
- AI notes. Summaries, notes, next steps, and a profile of the caller drawn from what was said (such as their industry, role and what they want), produced automatically from transcripts.
- Text messages and consent records. The texts your team sends and receives, their delivery status, and for each contact whether and how they agreed to receive texts or opted out.
- Contacts and work. Names, numbers and details your team saves or imports (including call lists), notes, tasks and inbox state.
- Call-quality ratings your team gives after calls.
From devices and the website
- The iPhone and Android apps. Each phone’s name, model, system and app version, and an installation identifier the app creates, so you can see which phones are signed in; and a push token from Apple or Google, so the app can ring when it is closed. The caller’s number and name in that push are encrypted, so Apple and Google cannot read them. The microphone is used only during a call. The apps contain no advertising, analytics or tracking code, and do not read your location, your phone’s address book or its call log.
- Technical logs. IP addresses, browser type and request logs, kept to keep the service working and secure. We do not use them to work out where you are.
- Cookies, described in Section 3.
- CRM connections. If you connect HubSpot or Apollo, we store your credentials encrypted and write your call records to that CRM on your behalf, looking up the matching contact by phone number. We do not read anything else from it.
3. Cookies
We set only our own cookies. There are no advertising or third-party analytics cookies, and our fonts are served from our own servers.
| Cookie | What it does | How long |
|---|---|---|
| bp_session | Keeps you signed in | 30 days, renewed while you use Presence |
| bp_2fa | Holds a two-step sign-in in progress | 10 minutes |
| bp_known | Remembers a browser that completed two-step sign-in | 180 days |
| google_oauth, hubspot_oauth_state | Protect Google sign-in and connecting HubSpot | 10 minutes |
| wanted_number_search | Carries your number search through signup | 1 hour |
| src | Where your first visit came from (campaign tags, referral code, referring site, first page), saved to your business if you sign up | 90 days |
| vid, exp | A random visitor identifier and which version of our website’s wording you see, so we can compare versions | 1 year |
| bp_preview | Lets our own staff see the site before launch | 90 days |
You can block or delete cookies in your browser. Signing in needs the session cookie; the others are optional.
4. Where it comes from
From you and your team; from the people who call and text your numbers; from your browsers and phones; from Stripe (payment status); from Google if you sign in with Google; from our carrier and the carrier registry (call, delivery and registration status); and from CRMs you connect (the matching contact for a call).
5. Why we use it, and our legal bases
If you are in the European Economic Area, the United Kingdom or Switzerland, the law requires us to state a legal basis for each use of your personal information. The bases are in brackets.
- To provide Presence: connect calls and texts, take voicemails, record and transcribe when your team chooses, write AI notes, show history and sync your devices (performing our contract with your business; our legitimate interest in serving its team).
- To bill you and keep financial records (contract; legal obligation).
- To keep Presence secure and stop fraud, toll fraud and unlawful calls and texts, including answering carrier and industry traceback requests (legitimate interests; legal obligation).
- To meet telecommunications rules, such as collecting your emergency address and registering your business for texting (legal obligation; contract).
- To answer support requests and send you service notices, such as changes to these policies or your plan (contract; legitimate interests).
- To understand how Presence is used and improve it, using usage statistics, call-quality ratings and comparisons of website wording (legitimate interests).
- To learn which of our marketing and our own sales calls brought customers to us (legitimate interests).
- To comply with the law, and to establish, exercise or defend legal claims (legal obligation; legitimate interests).
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
6. AI features
AI runs only after a call has ended, never during it. Deepgram turns recordings and voicemails into transcripts, and Google’s Gemini API reads transcripts to write notes and summaries. Under Google’s paid API terms, this data is not used to train Google’s models. We do not use Customer Content to train AI models of our own. AI notes can be wrong; your team should check them before relying on them.
7. Who else handles it
We use a small number of providers, each for one job, under contracts that limit them to that job. The full list, with what each handles and where, is on our sub-processor page.
- Telnyx carries calls and text messages to and from the public phone network, provides numbers, moves numbers and submits texting registrations. It sees the numbers and audio of every call and the content of every text, as any carrier must.
- The Campaign Registry and the mobile carriers receive your texting registration through Telnyx, and other carriers handle calls and texts on their way to the people you reach.
- Hetzner hosts our servers, in Ashburn, Virginia, United States. Recordings are stored there.
- Cloudflare stores our off-site backups, which are encrypted before they leave our servers, so Cloudflare cannot read them.
- Stripe takes payment.
- Deepgram transcribes recordings and voicemails.
- Google writes call notes (Gemini API), provides Google sign-in if you use it, carries app notifications to Android phones, and hosts our support email.
- Apple carries app notifications to iPhones. Call details in those notifications are encrypted.
- HubSpot or Apollo, only if you connect them.
We also disclose personal information:
- within your business’s account: your team shares calls, contacts and texts, and managers can play teammates’ recorded calls;
- when the law requires it, such as a court order or subpoena, or to protect someone from serious harm (we tell the customer first unless the law forbids it);
- to a buyer or successor if Presence or Redstone Castle LLC is sold, merged or reorganized, under this policy; and
- with your permission.
We do not sell personal information, and we do not share it for cross-context behavioral advertising or use it for targeted advertising. We have not done so in the last 12 months.
8. Text messages
Your team can text people from your Presence number once the number is registered with the US carriers, which they require for business texting. Registration sends your business’s name, address, tax number if it has one, and a description of the messages you send to The Campaign Registry and the carriers, through Telnyx.
Presence records, for each contact, whether they have agreed to receive texts, and does not send to anyone who has not or who has opted out. Anyone can reply STOP to stop all texts from that number, or HELP for who is texting them and how to reach them.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
9. Where it is stored
We store personal information in the United States, on our servers in Ashburn, Virginia. Our providers process it in the United States, and some, such as Google and our carrier, operate globally under their own safeguards. If you are in the European Economic Area, the United Kingdom or Switzerland, your information is transferred to the United States; for Customer Content we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum to them, incorporated in our Data Processing Addendum, and for account information on the necessity of the transfer to provide the service you asked for.
10. Security
- Our website and apps use encrypted connections (HTTPS) only, and the apps check our certificate so that a hostile network cannot pretend to be us.
- Call audio between your browser or app and our servers is encrypted. Between our servers and other phone networks, calls travel over the carrier network as any phone call does, without end-to-end encryption.
- Passwords are hashed. Two-step sign-in with an authenticator app is available to every user. Repeated failed sign-ins are slowed down.
- CRM credentials and two-step sign-in secrets are encrypted with keys kept outside the database. Push notifications are encrypted with a key for each phone.
- Each customer’s data is kept separate in our software, and recordings are served only to members of the business they belong to.
- We back up nightly. Off-site backups are encrypted before they leave our servers.
- Only the two people who run Presence can reach production systems.
No system is perfectly secure. If a breach affects your personal information, we will tell you and the authorities as the law requires.
11. How long we keep it
| Information | Kept for |
|---|---|
| Account and billing records | While your account exists, and as long afterwards as tax and accounting rules require |
| Call records, text messages, contacts and consent records | While your account exists |
| Recordings, voicemails, transcripts and notes | Until you ask us to delete them, or 30 days after your account closes |
| Emergency address and acknowledgment | While your account exists |
| Number-move paperwork | While your account exists |
| Technical logs | 90 days |
| Backups | 14 days after the data is deleted from the live system |
| Support emails | While your account exists |
We may keep information longer where the law requires it or for a legal claim, and keep protecting it while we do.
12. Your rights
You can see, correct, export or delete your data. Email support@redstonecastles.com and we will do it within 30 days. Admins can also download contacts and calls with their notes and transcripts at any time from Settings → Export your data. To delete your account, see Delete your account. Deleting your account releases your phone number.
US state privacy laws. Residents of California and of other states with privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas and Oregon) may have the right to know what personal information we hold and how we use it, to get a copy, to correct it, to delete it, and to opt out of its sale, of sharing for targeted advertising and of certain profiling. We do none of those three. We use sensitive personal information (your login credentials, and the content of messages we carry for customers) only to provide the service, so there is nothing to limit. We will not treat you differently for using your rights. We treat a Global Privacy Control signal as a request to opt out, though there is nothing to opt out of.
Europe and the UK. You also have the right to restrict or object to our use of your information (including uses based on our legitimate interests), to have it transferred, to withdraw any consent you gave, and to complain to your data-protection authority (in the UK, the Information Commissioner’s Office).
How to ask. Email support@redstonecastles.com. To protect your data, we check that the request comes from you, usually by replying to the email address on the account. Someone you authorize may ask for you, with your signed permission. If we refuse a request, we will say why, and you can appeal by replying to our answer with the word “appeal”; we will answer the appeal within the time the law allows. If you are not satisfied, you may contact your state attorney general.
13. Notice at collection for California residents
In the last 12 months we have collected these categories of personal information, from the sources in Section 4, for the purposes in Section 5, and disclosed them to the recipients in Section 7. We have not sold or shared any of them. We keep each for the periods in Section 11.
- Identifiers: name, email address, phone numbers, IP address, account and device identifiers.
- Customer records: business address, emergency address, billing details held by Stripe.
- Commercial information: plan, people on it, invoices and payments.
- Internet or network activity: request logs, cookies, signed-in devices.
- Audio and electronic information: call recordings and voicemails, when made.
- Professional information: your business and your role on its team.
- Inferences: caller profiles in AI notes, held for our customers.
- Sensitive personal information: account login credentials, and the content of calls, recordings and texts we carry for our customers.
14. Children
Presence is for businesses and is not for anyone under 18. We do not knowingly collect personal information from children. If you believe we have, tell us and we will delete it.
15. Changes
If we change this policy in a way that matters, we will email account owners before it takes effect, and change the date at the top.
16. Contact
Redstone Castle LLC, New York. Email support@redstonecastles.com.