Legal

Privacy Policy

Last updated: October 7, 2026

1. Introduction

Meridal Group LLC, doing business as Rinqly ("Rinqly," "we," "our," or "us"), provides the Rinqly platform at rinqly.ai (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, in compliance with the General Data Protection Regulation (GDPR) and applicable data protection laws.

By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Password (stored only as a one-way hash)
  • Business name and contact details

2.2 Business Data

To configure your AI receptionist, we collect:

  • Business information (name, phone number, website URL, location)
  • Knowledge base content (FAQ questions and answers, and documents you upload)
  • AI receptionist configuration (greeting, system prompt, voice selection)

2.3 Call Data

When your AI receptionist handles calls, we collect:

  • Call recordings
  • Call transcripts
  • Caller phone numbers
  • Call duration and timestamps
  • Call summaries generated by AI
  • Text messages we send to callers for you (a booking confirmation, and a missed-call text if you turn it on), the replies to them, and any other text sent to your Rinqly number

Calls may be recorded and transcribed for quality purposes. Every call, inbound and outbound, opens with the notice "This call may be recorded and transcribed for quality purposes." This notice is always on and cannot be switched off. Call recordings are stored with our telephony provider, Twilio; call transcripts and summaries are stored in our database. Payment card numbers, card security codes and US Social Security numbers that a caller says out loud are masked before the transcript is stored, summarised or sent to any connected CRM; the last four digits of a card are kept so a payment can be matched. This masking applies to the transcript; a call recording holds the audio as it was spoken. How long recordings and transcripts are kept is set out in section 6.

2.4 Data We Process on Your Behalf

When you use the Service with your own customers, we process their data for you, under your instructions:

  • Messages that visitors type into your website chat widget, the contact details they leave, and any files they upload in the chat
  • Contact lists you upload for outbound calling (names, phone numbers and any other columns you include), the outcome of each call, and the numbers on your do-not-call list

2.5 Website Data

If you use our website analysis feature, we scrape publicly available content from the URL you provide to auto-generate your AI receptionist configuration. We do not scrape websites without your explicit request.

2.6 Calendar Data

If you connect Google Calendar, we access only the calendar data necessary to book and manage appointments on your behalf. We request the minimum scopes required:

  • Google Calendar: read and write calendar events for appointment booking

We do not access, store, or share any other Google account data. You can revoke access at any time through your Google Account settings. If you connect a Microsoft Outlook calendar instead, the same applies: we read and write only the calendar events needed to book appointments, and you can revoke access in your Microsoft account.

3. How We Use Your Information

We use collected information to:

  • Provide, operate, and maintain the Service
  • Configure and improve your AI receptionist
  • Process and manage phone calls on your behalf
  • Book appointments via connected calendar integrations
  • Generate call logs, summaries, and analytics
  • Send service-related communications
  • Detect and prevent fraud or abuse

4. Third-Party Services

We use the following third-party services to operate the platform:

  • OpenAI: The voice on calls Rinqly places for you (outbound campaigns and callbacks); call summaries, sentiment and quality scoring; knowledge-base search; reading your website during setup; web search and voice dictation in the setup builder
  • Anthropic: AI language model for website chat, the setup builder and the dashboard assistant
  • Supabase: Database, file storage and authentication
  • Vercel: Application hosting
  • Stripe: Payment processing
  • Resend: Transactional and onboarding email delivery
  • LiveKit: Real-time audio for phone and browser calls, and hosting of the voice agent
  • Twilio: Phone numbers, call connectivity, call recordings and text messages
  • Zyte: Fetching the public website you enter during setup or in the homepage demo
  • Firecrawl: Fetching website pages you add to your knowledge base
  • Cohere: Ranking knowledge-base search results, when that feature is switched on
  • Google: The voice on calls your receptionist answers (Gemini Live, for your phone line, the website demo and dashboard test calls); website analytics (Google Analytics); and Google Calendar when you connect it
  • Microsoft: Outlook calendar, when you connect it
  • Ahrefs: Website analytics (Ahrefs Web Analytics)
  • Telegram: Internal alerts to our own operators

When you connect an integration of your own choosing (for example a CRM, Slack, Zapier, Mailchimp or Shopify), we send it the call and chat details that integration is set up to receive, or read from it what the agent needs, such as an order status.

Each third-party service has its own privacy policy governing the use of your information. We only share the minimum data necessary for each service to function.

5. Data Storage & Security

Your data is stored securely using Supabase with row-level security (RLS) policies, ensuring that each user can only access their own data. We implement industry-standard security measures including:

  • Encrypted data transmission (TLS/SSL)
  • Encrypted passwords (bcrypt hashing)
  • Row-level security on all database tables
  • Secure API key management

6. Data Retention

While your account is active we keep the personal content of calls, chats and messages (call transcripts and summaries, caller names and numbers, website chat conversations and visitors' contact details, taken messages, booking details and text messages) for 365 days, and then delete it; counts, durations and billing records stay so your reports and invoices remain correct. Call recordings stored with our telephony provider are deleted after 90 days. Records of outbound calls are kept for five years, as telemarketing rules require. You can download the data we hold for your account at any time as a single file from your dashboard (Settings → Download my data). Numbers on your do-not-call list are kept for as long as the account exists so that they are never called again.

You can delete your account yourself from the same place, or by emailing support@rinqly.ai; a request by email is carried out within 30 days. When an account is deleted, its login and the Service are removed immediately. Rinqly keeps an archived copy of the account's records (calls and their transcripts, messages, campaigns, do-not-call requests and signed agreements) for up to five years to meet legal and record-keeping obligations, and then deletes it. The archive is not accessible from any account, including the deleted one.

7. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases as defined by the GDPR:

  • Contract performance (Art. 6(1)(b)): to provide and operate the Service you subscribed to
  • Legitimate interest (Art. 6(1)(f)): to improve our Service, prevent fraud, and ensure security
  • Consent (Art. 6(1)(a)): for optional integrations such as Google Calendar access
  • Legal obligation (Art. 6(1)(c)): to comply with applicable laws and regulations

8. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the following rights:

  • Right of access (Art. 15): obtain a copy of your personal data
  • Right to rectification (Art. 16): correct inaccurate or incomplete data
  • Right to erasure (Art. 17): request deletion of your personal data
  • Right to data portability (Art. 20): receive your data in a structured, machine-readable format
  • Right to restrict processing (Art. 18): limit how we use your data
  • Right to object (Art. 21): object to processing based on legitimate interest
  • Right to withdraw consent: revoke consent at any time (e.g., disconnect Google Calendar)

To exercise any of these rights, contact us at support@rinqly.ai. We will respond within 30 days as required by the GDPR. If you believe your rights have been violated, you have the right to lodge a complaint with your local data protection authority.

9. Email We Send You

We send two kinds of email, and you control them separately:

  • Service email: verification codes, password resets, call summaries, lead notifications, and billing notices. These are part of the Service and continue for as long as your account is open.
  • Onboarding and trial email, a short sequence during your first days that helps you finish setup and tells you when your trial is ending. Every one of these carries an unsubscribe link, and unsubscribing stops the sequence without affecting your account or your service email.

Occasionally we may also send product news: a new feature, a change to a plan, an offer for existing customers. Under US law (CAN-SPAM) we may send these to customers without a separate opt-in; every one carries an unsubscribe link, opting out is honored within ten business days, and it never affects service email. You agree to this when you create your account.

We do not sell your address, and we do not send you email on behalf of anyone else.

10. Text Messages (SMS)

Rinqly sends text messages under the program name Rinqly notifications, from Rinqly phone numbers, in two cases:

  • Verification codes from Rinqly. When you enter your phone number to have our demo receptionist call you, or to request a test call during a trial, we text you a one-time code and then call you. You agree to this text and call when you enter your number on that form, where the consent notice is shown next to the field.
  • Texts on behalf of businesses that use Rinqly. When you call a business that answers its phone with Rinqly, that business can have us text you a reply to a call it missed, a short follow-up after your call, and a confirmation of an appointment you booked on the call. These texts name the business and are about your own call. You give your consent by calling the business and, for a confirmation, by booking the appointment.

Message frequency varies: a verification code is a single text, and a business's texts follow only your own calls to it, with at most one missed-call text per hour. Msg & data rates may apply. Reply STOP to any text to opt out (STOPALL, UNSUBSCRIBE, CANCEL, END and QUIT also work); we confirm the opt-out and send nothing further unless you reply START. Reply HELP for help, or email support@rinqly.ai. An opt-out by text also puts your number on that business's do-not-call list. Carriers are not liable for delayed or undelivered messages. The full program terms are in section 17 of our Terms of Service.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. We do not sell or rent mobile numbers or text-message consent to anyone, including lead generators.

Your phone number and the texts are used only to send these messages and to answer your replies. Our telephony provider, Twilio, carries the messages as our service provider and does not receive them for its own marketing. A reply you send to a business's text is shown to that business.

11. Cookies

We use essential cookies for authentication and session management. Our public website also uses Google Analytics and Ahrefs Web Analytics to count visits and see which pages people read; Google Analytics sets its own first-party cookies for this. We use this analytics only for our own site and do not use advertising networks or advertising cookies.

12. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where our third-party service providers listed in section 4 operate. We ensure that such transfers are protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, or the service provider's participation in recognized data protection frameworks.

13. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

15. Data Controller

The data controller responsible for your personal data is Meridal Group LLC, doing business as Rinqly. For the data in section 2.4, the business that uses Rinqly is the controller and we process that data on its behalf. For any privacy matter, contact support@rinqly.ai.

16. Contact Us

If you have questions about this Privacy Policy, contact us at:

support@rinqly.ai