Scope of this Policy
Backstop Mobile (“Backstop,” “we,” “us,” or “our”) provides mobile voice, text, and data service together with AI-powered call handling, transcription, summaries, follow-up tools, and integrations. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use our websites, mobile applications, wireless service, AI features, integrations, sales and support channels, and related services (collectively, the “Services”).
This Policy applies to account owners, administrators, team members, website visitors, trial users, and other people whose information is processed through the Services, including callers, callees, contacts, and customers of a Backstop subscriber.
The Terms of Service govern your use of the Services. Third-party products and connected services have their own privacy practices, as explained below.
Who controls information
Backstop determines how personal information is used for account registration, mobile-service delivery, network operations, billing, security, fraud prevention, support, and compliance.
When a business or other organization uses Backstop to handle its calls, contacts, messages, calendars, email, CRM records, or other business information, that organization controls how it uses the Services and who may access its information. Backstop processes that information to provide the Services to the organization.
If you interact with a Backstop subscriber and want to exercise rights concerning information controlled by that subscriber, contact the subscriber first. We will assist the subscriber and respond directly where required by law.
Account owners and administrators may access and manage information associated with their account, including team-member information, shared-line activity, call records, transcripts, recordings, summaries, and integration activity, subject to role-based permissions.
Information we collect
Account and identity information
We collect information such as your name, business name, email address, phone number, service and billing address, account role, login credentials, communication preferences, and records showing your acceptance of applicable terms and notices.
We may collect information needed to verify your identity, phone number, account authority, or eligibility for a trial, promotion, number port, eSIM, or activation. This may include one-time verification status, porting account information, transfer PIN information, and authentication records.
Plan, billing, and transaction information
We collect information about your plan, lines, trial status, renewals, charges, credits, taxes, refunds, payment status, and transaction history.
Payment-card numbers and security codes are collected and processed by our payment processors, not stored directly by Backstop. We may receive a payment token, card type, expiration information, last four digits, billing address, digital-wallet identifier, and transaction status.
Mobile-service and network information
We and our mobile-network and connectivity partners collect information needed to provide voice, text, data, eSIM, Wi-Fi Calling, hotspot, roaming, porting, and emergency services. This may include:
- mobile services, lines, plans, and features associated with an account;
- phone numbers called or texted and numbers from which communications are received;
- call and message date, time, duration, destination, routing, delivery, and status;
- data and hotspot usage, network type, performance, congestion, and fair-use measurements;
- device and SIM information, including device model, operating system, IMEI, eSIM or SIM identifiers, carrier configuration, and activation status;
- approximate or precise device location when needed for connectivity, emergency calling, Wi-Fi Calling, fraud prevention, network operation, or a feature you enable; and
- number-porting, eSIM-transfer, suspension, and account-security activity.
Some of this information may be Customer Proprietary Network Information, or CPNI, under federal law.
Call, message, and AI content
Depending on the features and settings used, we collect and process:
- call audio when recording is enabled;
- call transcripts, which are created by default for AI-answered, user-answered, and outbound calls unless transcription is disabled using an available control;
- voicemail, SMS, MMS, and other message content;
- AI prompts, greetings, instructions, answers, and conversation context;
- AI-generated summaries, notes, classifications, urgency indicators, tasks, drafts, proposed actions, and follow-up records;
- corrections, edits, feedback, approvals, and automation settings provided by users; and
- information supplied by callers or callees during a communication.
Call recording is optional and separate from transcription. The AI identifies itself as a digital assistant by default, although the account owner can configure its introduction. Account owners must provide notices and obtain permissions required for recording, transcription, automated calling, messaging, and use of personal information. Backstop also provides notices and controls required of it by law.
Integrations and connected accounts
If you connect an email, calendar, contact, accounting, field-service, route-planning, supplier, CRM, or other third-party service, we receive the information and permissions needed to operate that integration. This may include account identifiers, authorization tokens, contacts, email messages, calendar events, availability, appointments, tasks, customer records, estimates, invoices, service history, metadata, permission scopes, and activity or error logs.
Backstop accesses connected information within the permissions granted through the integration and the instructions and automation settings selected by the account.
Website, app, device, and usage information
We collect IP address, browser type, device type, operating system, app version, language, time zone, pages or screens viewed, links or controls used, session and referral information, crash reports, diagnostic logs, and interactions with emails or notifications. We also use cookies, local storage, software-development kits, and similar technologies as described in this Policy.
We use PostHog as an analytics service provider to measure website use, diagnose errors and performance problems, and replay website sessions. A session replay can reconstruct page content shown, pointer movement, scrolling, clicks, navigation, and interface changes. We configure replay to mask all form inputs and selected sensitive status text, and not to record network request or response headers or bodies. We also avoid sending phone numbers, email addresses, one-time codes, authentication tokens, names, company details, and free-text form responses as analytics event properties.
When a visitor requests a verification code, completes signup, or sends a sales inquiry, we may store PostHog’s pseudonymous browser and session identifiers with that database record so authorized staff can locate the session replay that led to it. The identifiers do not contain form answers, but they become associated with the contact information in the related record within Backstop’s systems.
Support, sales, and communications
We collect information you provide in sales inquiries, support requests, surveys, calls, emails, chats, and other communications with us. This can include contact and company information, line count, industry, workflow descriptions, attachments, device information, and issue history.
Information about people without Backstop accounts
Subscribers may provide information about callers, callees, employees, customers, vendors, and contacts through calls, messages, uploaded contacts, connected services, or business records. A person does not need a Backstop account for their phone number, communication content, or other information to be processed through the Services.
Subscribers must have authority to provide this information and must use it in accordance with applicable law.
Sensitive and unsupported information
Depending on how the Services are used, personal information may include precise location, account credentials, communication content, call audio, CPNI, or other information considered sensitive under applicable law.
Where information comes from
We collect personal information:
- directly from you;
- from account owners, administrators, and other authorized users;
- from callers, callees, contacts, and people who communicate through the Services;
- automatically from devices, apps, websites, mobile networks, and use of the Services;
- from mobile-network operators, connectivity and roaming partners, number-porting providers, emergency-service providers, and eSIM or device partners;
- from payment processors, phone-verification providers, fraud-prevention providers, and support providers;
- from services you connect, such as email, calendar, contacts, CRM, accounting, and field-service platforms; and
- from public sources or business partners when needed to verify business information, prevent fraud, or provide a requested feature.
How we use information
We use personal information to:
- create, authenticate, secure, and administer accounts;
- verify phone numbers, identities, and account authority;
- activate and manage lines, eSIMs, devices, plans, trials, and number ports;
- route and complete calls and messages and provide mobile data;
- support 911, E911, Wi-Fi Calling, emergency alerts, fraud prevention, and network operations;
- measure usage and apply plan, congestion, fair-use, roaming, and network-management rules;
- transcribe and summarize calls and generate notes, tasks, notifications, and follow-up suggestions;
- operate the AI assistant according to prompts, routing rules, permissions, and approval settings;
- carry out actions a user approves or has configured to occur automatically;
- operate, secure, troubleshoot, and improve integrations;
- process charges, renewals, credits, refunds, and taxes and maintain financial records;
- provide sales, onboarding, porting, device, and customer support;
- detect and prevent spam, abuse, fraud, unauthorized access, account takeover, SIM-swap fraud, port-out fraud, unlawful activity, and security incidents;
- monitor performance, repair errors, develop features, and improve the quality, safety, and usefulness of the Services;
- create aggregated or de-identified information for analytics, forecasting, research, and service improvement;
- send account, billing, security, service, support, and permitted promotional communications;
- enforce our agreements, protect users and networks, comply with law, and respond to valid legal process; and
- complete a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.
We do not use Customer Content for third-party advertising.
AI, transcription, and recording
Backstop uses automated systems, including speech-recognition and generative-AI systems, to answer calls, create transcripts and summaries, identify follow-up, draft communications, retrieve connected business information, and carry out authorized actions.
AI-generated outputs are based on call content, account settings, business information, connected data, and user instructions. Users can review, edit, approve, reject, or delete supported outputs and can require approval before selected actions are taken.
Transcription is on by default for AI-answered, user-answered, and outbound calls. Users can opt out particular calls or numbers and can turn transcription off during a live call. Recording is optional and may be disabled per call or for selected callers.
We may use aggregated or de-identified service telemetry, user feedback, and quality measurements to evaluate and improve the Services. Authorized personnel may review limited content when needed to provide requested support, investigate abuse or security issues, comply with law, or evaluate a feature with the account owner’s permission.
Where an organization uses Backstop, that organization decides why calls are handled, transcribed, recorded, summarized, or connected to other systems. The organization is responsible for required notices and consent from employees, callers, callees, customers, and other participants.
CPNI and telecommunications information
Customer Proprietary Network Information, or CPNI, can include information about the telecommunications services you purchase and how you use them, including call destinations, timing, duration, frequency, technical configuration, usage, billing, and certain location information. It generally does not include your name, postal address, or phone number when considered by itself.
We protect CPNI and use or disclose it only as permitted by applicable law. Permitted purposes may include providing and billing for Service, supporting and repairing Service, protecting users and networks, preventing fraud, responding to emergencies or lawful process, and offering communications-related services where permitted. We obtain customer approval when legally required and honor valid restrictions or withdrawals.
We do not sell CPNI. Access is limited to authorized personnel and service providers with a business need, and account information must be authenticated before CPNI is disclosed. To ask about or restrict marketing uses of CPNI, email [email protected].
How we disclose information
Mobile and communications partners
We disclose information to mobile-network operators, wholesale connectivity and roaming providers, number-porting providers, eSIM and device providers, messaging and voice providers, emergency-service providers, and other communications partners as needed to provide and protect mobile Service.
Service providers
We disclose information to providers that support cloud hosting, data storage, AI processing, speech recognition, communications, payment processing, identity and phone verification, security, fraud detection, analytics, software development, customer support, email delivery, and other business operations. They may process information only as needed to perform services for us and under applicable contractual and legal obligations.
Connected third-party services
When you enable an integration or direct Backstop to send information to another service, we disclose the information needed to complete that instruction. The third party’s own privacy policy applies to information it receives in its independent capacity. Disconnecting an integration stops new access by Backstop but does not delete information already sent to or retained by the third party.
Account owners, administrators, users, and subscribers
We disclose account information and Customer Content within an account according to roles, permissions, shared-line assignments, routing rules, and settings. An employer or business owner may be able to access information created by its team members through the Services.
If you call, message, or otherwise interact with a Backstop subscriber, we provide the subscriber with the resulting call record, transcript, recording if enabled, summary, contact details, and follow-up information.
Legal, safety, and security recipients
We may disclose information to courts, law-enforcement agencies, emergency responders, regulators, government authorities, auditors, insurers, or others when we reasonably believe disclosure is required or permitted to comply with law or legal process; respond to an emergency; support emergency communications; protect a person, account, device, network, or service; investigate fraud or abuse; or establish, exercise, or defend legal claims.
Corporate transactions, advisers, and your direction
We may disclose information to prospective or actual investors, lenders, buyers, sellers, advisers, or other parties involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality protections. We may also disclose information to attorneys, accountants, auditors, insurers, and other professional advisers.
We disclose information when you direct us to do so or consent to a particular disclosure.
Aggregated or de-identified information
We may disclose information that has been aggregated or de-identified so it cannot reasonably be linked to an individual. We maintain de-identified information in de-identified form and do not attempt to reidentify it except as permitted by law to test our methods.
Sale, sharing, and targeted advertising
We do not knowingly sell or share the personal information of anyone under 16. Disclosing information to a service provider, mobile-network partner, connected service at your direction, or another recipient described in this Policy is not treated as a sale where applicable law excludes that disclosure from the definition of sale.
Cookies and similar technologies
We use cookies, local storage, SDKs, and similar technologies to:
- keep users signed in and maintain sessions;
- remember settings and preferences;
- provide requested features;
- protect accounts and prevent fraud or abuse;
- diagnose errors and measure website and app performance; and
- understand how the Services are used and improve navigation and functionality.
We do not use third-party cross-site advertising cookies. You can control cookies through browser or device settings, but blocking necessary cookies may prevent login, security, or other features from working correctly.
Website analytics and session replay use a first-party browser identifier so events from the same browser can be understood as one session. These tools are used for product analytics, troubleshooting, security, and service improvement, not cross-site advertising.
The Services do not respond to browser “Do Not Track” signals because there is no uniform standard for them. Where required by law, we recognize Global Privacy Control signals as an opt-out request. Because Backstop does not sell or share personal information for targeted advertising, such a signal does not otherwise change how the Services operate.
Retention and deletion
We retain personal information only as long as reasonably necessary for the purposes in this Policy, including providing the Services, maintaining security, meeting legal and regulatory obligations, resolving disputes, preventing fraud, and enforcing agreements.
- Call records, transcripts, recordings, messages, summaries, and connected data are retained according to account settings while an account is active.
- Users can delete individual call records and other supported Customer Content and can export supported records in CSV or ZIP format.
- If a trial ends and the user does not continue with paid Service, trial Customer Content is deleted.
- After cancellation, remaining Customer Content is scheduled for automatic deletion within 180 days.
- Payment processors retain payment-card information under their own policies. Backstop retains transaction, billing, tax, credit, and refund records as needed for accounting, disputes, fraud prevention, and law.
- Phone-verification request records, including the submitted phone number, consent record, verification status, and timestamps, are retained even if verification is not completed, unless deletion is required in response to an applicable privacy request or legal obligation.
- Pseudonymous analytics and replay-linkage identifiers stored with verification, signup, or sales records follow the retention and deletion treatment of the related record. Session replays stored by our analytics provider follow the replay-retention period configured for that service.
- We may retain limited account, security, consent, porting, regulatory, and legal records after Customer Content is deleted when required or permitted by law.
- Data in protected backups is removed or overwritten through the normal backup cycle and is not restored to active systems except for disaster recovery, security, or legal needs.
- Aggregated or de-identified information may be retained because it no longer reasonably identifies an individual.
Deleting information may not remove copies already sent to another user, an account owner, a connected third-party service, or another communication recipient.
Your settings and choices
- Transcription and recording. You can use available controls to opt out specific calls or numbers from transcription and turn transcription off during a live call. Recording is optional and can be disabled per call or for selected callers.
- Connected services. You can review or disconnect integrations through available account controls, through the connected service, or by contacting support.
- AI actions. You can require approval before supported actions occur or authorize selected actions to occur automatically. You can change those permissions and review completed actions through available controls.
- Access, correction, export, and deletion. You can access, edit, search, export, and delete supported account and call information through the Services or submit a request to support.
- Marketing communications. You may unsubscribe from marketing email using the link in the message and opt out of marketing texts by replying STOP where supported. Service, billing, security, legal, and transactional communications will continue as needed.
- Account closure. You may cancel Service and close your account through available controls or by contacting support. Closing an account does not immediately delete records that must be retained for billing, security, porting, regulatory, or legal purposes.
U.S. state privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- confirm whether we process your personal information and access that information;
- obtain a portable copy of information you provided;
- correct inaccurate information;
- delete personal information;
- learn about categories, sources, purposes, and recipients involved in our processing;
- obtain a list of specific third parties to whom information was disclosed where state law provides that right;
- opt out of a sale, targeted advertising, or sharing for cross-context behavioral advertising;
- opt out of qualifying profiling used for decisions with legal or similarly significant effects;
- limit certain uses or disclosures of sensitive information;
- withdraw consent where processing is based on consent;
- appeal a denial of a privacy request; and
- receive equal Service and not be discriminated against for exercising a privacy right.
Backstop does not sell personal information, use it for targeted advertising, or use sensitive personal information to infer characteristics for advertising.
To exercise a privacy right, email [email protected] with the subject “Privacy Request.” Describe the request and provide the email address or phone number associated with the information. Do not send a password, one-time code, full payment-card number, or other unnecessary sensitive information.
We will verify the request using information already associated with the account and may ask for additional information when reasonably necessary to protect the account. An authorized agent may submit a request where permitted by law, subject to proof of authorization and direct identity verification where appropriate.
If we deny a request, you may appeal by replying to our decision with the subject “Privacy Appeal.” Some information is governed by federal telecommunications laws, including CPNI rules, and may be exempt from particular state privacy-law provisions while remaining protected under federal law.
California privacy disclosures
During the preceding 12 months, Backstop may have collected these categories of personal information:
- identifiers, including names, addresses, email addresses, phone numbers, IP addresses, device identifiers, account identifiers, and SIM or eSIM identifiers;
- customer-record information, including contact, account, billing, and payment-related information;
- commercial information, including plans, transactions, purchases, renewals, credits, and support history;
- Internet, application, and network activity, including browsing, app usage, data usage, network performance, diagnostics, and security logs;
- geolocation used for wireless service, emergency service, security, and enabled features;
- audio, electronic, and communications information, including call audio when recorded, transcripts, messages, voicemail, prompts, and support communications;
- professional or employment-related information, including business name, industry, job role, team assignment, and workflow information;
- inferences, including summaries, classifications, urgency indicators, recommendations, and preferences;
- sensitive personal information, including precise geolocation, account credentials, communication content, and CPNI where applicable; and
- other information you provide or that appears in Customer Content.
The sources, purposes, and recipients for these categories are described throughout this Policy. We may disclose each category for the business purposes described here to service providers and other listed recipients. Backstop has not sold personal information or shared it for cross-context behavioral advertising during the preceding 12 months.
Backstop uses sensitive personal information only to provide requested Services, protect accounts and networks, maintain security, prevent fraud, comply with law, and for other purposes permitted without a right to limit under California law. We do not offer financial incentives or price differences in exchange for personal information.
Information for people outside the United States
Backstop is based in the United States, and personal information may be processed in the United States and in other countries where our service providers operate. Those countries may have privacy laws that differ from the laws where you live.
Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests in operating and protecting the Services, consent, compliance with legal obligations, or protection of vital interests in an emergency. Where required, we use approved contractual safeguards or another lawful transfer mechanism.
Subject to applicable law, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; and complain to a local data-protection authority. Email support to exercise those rights.
Security
Backstop uses administrative, technical, and organizational safeguards designed to protect personal information. Data is encrypted in transit and at rest. We also use access controls, authentication, logging, monitoring, network protections, vendor controls, and incident-response procedures appropriate to the information and Services.
Encryption in transit and at rest does not mean communications are end-to-end encrypted. Backstop and authorized providers must be able to process call, message, and integration content to provide requested features.
No system can be guaranteed completely secure. Protect account credentials and devices, use available security features, and contact support promptly if you believe an account, phone number, device, eSIM, or integration has been compromised. We provide security-incident notices where required by law.
Children
Backstop accounts may be opened only by adults with authority to enter the service agreement. The Services are not directed to children under 13, and we do not knowingly collect personal information directly from children under 13.
If you believe a child under 13 provided personal information directly to Backstop, email support. We will investigate and delete the information where required.
Information about a minor may appear incidentally in a subscriber’s calls, contacts, messages, or business records. The subscriber is responsible for having authority to process that information.
Third-party services
Third-party websites, applications, integrations, payment processors, digital wallets, mobile networks, and connected services have their own privacy practices. This Policy does not govern a third party’s independent collection or use of personal information.
Review the privacy settings and policies of a connected service before enabling it. Backstop is not responsible for a third party’s independent privacy or security practices.
Changes to this Policy
We may update this Policy as the Services, technology, or law changes. We will post the updated Policy and change the effective date. If a change materially affects how we use personal information, we will provide additional notice through the Services, by email, or through another appropriate channel and obtain consent where required by law.
For privacy questions, CPNI restrictions, requests, or appeals, email [email protected]. Do not email passwords, one-time authentication codes, full payment-card numbers, security codes, protected health information, or other unnecessary sensitive information.
Contact Backstop Mobile.
Privacy questions and requests can be sent to [email protected].