Privacy Policy
Last Modified: August 27, 2026
Dialfyne ("Dialfyne," "we," "our," and/or "us") values the privacy of individuals who use our websites (including dialfyne.com and app.dialfyne.com) and any other websites, applications, or services that link to this Privacy Policy (collectively, our "Services"). This Privacy Policy explains how we collect, use, and share personal information from users of our Services ("Users"). By using our Services, you agree to the collection, use, disclosure, and procedures this Privacy Policy describes.
Introduction
Dialfyne is usage-based sales software headquartered in Vancouver, Washington, USA. The Services include AI roleplay, a human-led power dialer, platform email, analytics, optional CRM and calendar integrations, and an optional Managed Outbound engagement.
This Privacy Policy covers personal information about:
- Visitors to dialfyne.com and related marketing pages
- Customers (and their authorized users) who purchase or use the Services
- End Users — prospects, leads, customers, and other contacts of our Customers who are called, emailed, recorded, transcribed, or otherwise processed through the Services
Roles. Dialfyne acts as a Processor (or "service provider" under the CCPA) on behalf of our Customers when they use the Services to manage their own sales workflows, call recordings, transcripts, email sequences, roleplay rooms, and customer data. For certain activities — operating our websites, our own sales and support, billing, security, product analytics, and generating Aggregated Data as described below — Dialfyne acts as a Controller(or "business").
Where we process End User data for a Customer, that Customer is responsible for providing required notices and obtaining required consents. Our Data Processing Addendum and subprocessor list form part of how we process that data.
What Information Do We Collect?
A. Information You Provide to Us
Registration and account. When you create an account, we collect your name, email address, job title, company name, phone number, and related workspace settings. If you invite teammates, we collect their name and email.
Payment. When you purchase Services, we collect billing contact information, purchase history, and payment amount. Card details are provided to Stripe, our payment processor. We do not store full payment card numbers. Stripe's privacy policy governs card data.
Communications. If you contact us, we receive your name, email, phone number, the contents of the message, and any recordings of support calls.
Marketing forms and surveys. When you complete a form or survey, we collect the fields you submit (typically name, email, job title, company, phone, and how you plan to use the Services), plus anti-abuse signals such as form-fill timing and CAPTCHA tokens.
Customer-uploaded content. Customers may upload lead lists, CRM fields, call transcripts (including from Gong, Chorus, or another dialer), roleplay scripts, voicemail audio, and similar business content. That content may include End User personal information.
B. Information We Collect When You Use Our Services
Location and device. We infer general location from IP address and receive device and software information (browser type, operating system, and similar).
Usage. We receive information about how you use the Services, such as pages visited, features used, click paths, session duration, and dates and times of visits.
Cookies and similar technologies. We and our partners may collect information using cookies, pixels, or similar technologies. Details and opt-out options are in our Cookie Policy.
Dialer call recordings, transcripts, and metadata. If a Customer records a call, we may collect the recording, live and post-call transcripts, dispositions, answering-machine and screener detections, duration, caller ID, and related coaching or scorecard data. The Customer is responsible for complying with call-recording laws and obtaining required consents. Recordings and transcripts are used to provide the Services (playback, coaching, scoring, CRM write-back, practice rooms). Customers may opt out of Dialfyne using their recordings or transcripts to improve Dialfyne's own product (for example skip-detection phrases) by emailing [email protected]. Opting out does not stop processing needed to run the Customer's workspace.
Roleplay. We collect participant names, emails, microphone audio, transcripts, scorecards, room settings, and session metadata. Avatar roleplays, when enabled, transmit realtime audio and avatar video through service providers so the participant can interact with an AI buyer. In the current version, Dialfyne does not store participant webcam video and does not score eye contact, posture, or camera presence.
Email and sequencing. When you use platform email or Managed Outbound, we collect email body content, subject lines, replies, message metadata, engagement data (opens, clicks, bounces), send times, unsubscribe status, mailbox and domain configuration, and related suppression records.
Aggregated Data. We may create aggregated or de-identified statistics about how the Services are used (for example product reliability, feature adoption, or billing meters) that do not identify a Customer or a specific End User. Aggregated Data is not used to reconstruct call recordings, prospect names, or which Customer workspace a phone number came from. We do not operate a cross-workspace "pickup score" marketplace that publishes a phone number's reputation to other Customers.
C. Information We Receive from Third Parties
- Platform sign-on. If you register or log in with a third-party account (for example Google), we receive name, email, and profile information the provider shares.
- Payment processor. Stripe provides payment status and billing metadata.
- Website intelligence. Apollo.io and RB2B may enrich business-visitor data on our marketing site for Dialfyne's own sales.
- Advertising. Google Ads and the LinkedIn Insight Tag may provide conversion, campaign, and retargeting measurement data.
- Integrations and data providers. When a Customer connects a CRM, calendar, or similar system, or licenses contact data into the workspace, we process that data on the Customer's instructions.
How Do We Process Your Information?
We may use the personal information we collect:
- To create and authenticate accounts and otherwise manage workspaces
- To deliver, maintain, debug, improve, and enhance the Services
- To communicate with you, including support, onboarding, invoices, and service notices
- For marketing about Dialfyne, where permitted. Our trial and inquiry forms offer separate, optional choices for marketing email and human sales calls where a phone number is collected. We retain your choices, the consent wording and version, contact details, and submission timestamp as evidence. Declining does not prevent trial access or a response to your inquiry. Withdraw by replying to an email, asking the caller to stop, or emailing [email protected]. You will still receive necessary administrative messages
- To understand how the Services are used and to develop new features
- To protect the Services, including fraud monitoring, abuse prevention, and security investigations
- To facilitate third-party integrations the Customer connects
- To generate Aggregated Data as described in Section 2
- To provide sequencing, email, dialer, coaching, scoring, and roleplay features
- For compliance, including enforcing our Terms, responding to lawful requests, and meeting tax and accounting obligations
- For other purposes for which we provide specific notice at collection
What Legal Bases Do We Rely On?
If you are located in the EEA or UK, GDPR and UK GDPR require us to explain the legal bases we rely on. We may rely on:
- Consent. Where we ask for permission (for example non-essential cookies in the EEA/UK). You may withdraw consent at any time.
- Performance of a contract. To provide the Services you or your organization requested, including billing.
- Legitimate interests. For example B2B sales outreach to business contacts, product analytics, security, improving skip-detection and coaching quality using de-identified patterns, and generating Aggregated Data — where those interests are not overridden by your rights.
- Legal obligation. Tax, accounting, law-enforcement requests, and similar duties.
- Vital interests. Rare cases involving someone's safety.
When we act as a Processor, the Customer (as Controller) is responsible for ensuring it has a lawful basis to instruct us to process End User data.
Calls, Recordings, and Voice Data
The Dial product records and transcribes calls when a Customer enables those features. We comply with applicable recording laws as follows, and the Customer remains responsible for its own compliance:
- In one-party consent jurisdictions, recording may proceed with the consent of the Customer's user on the call.
- In all-party consent jurisdictions, including California, callers should be notified of recording before substantive conversation. Customers are responsible for configuring and confirming those disclosures.
Call recordings and transcripts are stored so the Customer can review, coach, score, write back to CRM, and (if the Customer chooses) build roleplay rooms from real calls. Default retention is 12 months unless the Customer requests earlier deletion or a longer period is agreed in writing.
Live greeting audio may also be processed in real time to detect voicemail, AI call screeners, silence, or a human answer so the rep is not connected to a machine. That processing is part of providing the Dial product.
Do We Offer AI-Based Products?
The Services use AI to transcribe conversations, score and coach calls, build practice rooms, draft and analyze email, and detect voicemail or screeners. We use a mix of third-party models and Dialfyne-operated logic.
- Third-party models (including speech-to-text and large language models) are used for inference to provide the feature you asked for. Our subprocessors are contractually prohibited from using Customer Data to train, fine-tune, or otherwise develop their general-purpose AI models.
- Dialfyne-operated features such as greeting skip-detection currently rely on phrase lists, silence, and beep detection — not a model trained on your raw call recordings. We may still use de-identified examples to improve those rules unless you opt out as described in Section 2.
- Some optional research or live-context features may call additional model providers, including providers outside the United States. See the subprocessor list for current locations.
AI outputs (drafts, summaries, coaching tips, scores) require human review before they are relied on for business decisions. Dialfyne does not make solely automated decisions that produce legal or similarly significant effects about End Users. We:
- Keep a human in the loop for outbound email send (approval before send on Managed Outbound and reviewable sequences on the platform)
- Do not use Customer Data to train third-party generative models
- Limit sensitive personal information in AI processing to what is needed to provide the requested feature
Questions about AI processing: [email protected].
Outbound Communications to End Users
When a Customer uses Dial, Email, or Managed Outbound, Dialfyne may place calls, drop voicemail, or send email or SMS to End Users. Those communications are initiated by or configured by the Customer. The Customer is responsible for consent, DNC, TCPA, CAN-SPAM, and similar laws. Dialfyne provides features designed to support compliance (consent gates, calling hours, suppressions) but does not warrant the Customer's compliance.
Research and generated content. To make outbound email relevant, Dialfyne may research the recipient's employer using public web sources. Drafts may be produced by large language models and, for Managed Outbound, reviewed by a person before send. Research targets the business and professional role. We do not seek special-category data under GDPR to generate communications. Sources of facts used in a draft are recorded so a recipient asking where something came from can be told.
If you received a communication from a Dialfyne-powered system and wish to opt out:
- Reply STOP to any SMS
- Use the unsubscribe link in any email
- Contact the business that originally collected your information
- Email [email protected] and we will help route the request to the relevant Customer
Connected Accounts and Integrations
Google. If you connect Google Calendar (or another Google product we offer) through OAuth, we request only the scopes needed for that feature. We do not use Google user data for Dialfyne advertising or to train third-party AI models. You can disconnect Google in your Google Account settings. Cached calendar data associated with the connection is deleted within 7 days after disconnect, unless a longer period is required by law.
CRM and other connectors. You may connect HubSpot, Pipedrive, Salesforce, Attio, Jobber, webhooks, or similar systems. Those connectors access workspace data scoped to your permissions. Data that transits a third-party platform is subject to that platform's terms and privacy policy. You may disconnect a connector at any time in product settings.
If you connect a browser extension we publish in the future, we will describe that collection here before it is used.
Supplemental Information for the EEA, Switzerland, and the U.K.
Dialfyne is headquartered in the United States. Personal data is stored and processed in the United States using cloud infrastructure (including Supabase) and the subprocessors listed publicly. If you access the Services from outside the United States, your information may be transferred to the United States and other countries that may not have the same data-protection laws as your country.
For transfers from the EEA, UK, or Switzerland to the United States, we rely on appropriate safeguards, including Standard Contractual Clauses (Module Two or Module Three as applicable), the UK International Data Transfer Addendum, and the Swiss addendum, as described in our DPA. We use supplementary measures such as TLS in transit, encryption at rest, and access controls.
Your rights, where applicable, include: access, portability, rectification, objection, restriction, erasure, withdrawal of consent, and the right to lodge a complaint with your supervisory authority (ICO in the UK; your Member State authority in the EEA; FDPIC in Switzerland). We do not use the types of solely automated decision-making described in GDPR Article 22. Exercise rights at [email protected]. We will respond within one month of a verifiable request, or as otherwise required by law. We may refuse requests in limited cases (for example where access would infringe someone else's rights).
If you are an End User, contact the Customer whose workspace processed your data first. We will assist that Customer as required by the DPA.
As of this Policy, Dialfyne has not appointed a separate Article 27 EU or UK representative. EEA and UK individuals should contact us directly using Section 19.
Customers who need a signed DPA can rely on the online DPA at dialfyne.com/dpa, which is incorporated into our Terms, or request a countersigned copy at the same email.
Supplemental Information for California Residents
This section supplements this Policy with CCPA/CPRA disclosures. Over the past 12 months we have collected:
- Identifiers: name, email, phone, IP address, account name
- Customer records: billing address, telephone, payment metadata (card numbers are handled by Stripe)
- Commercial information: purchase and usage history
- Internet/network activity: browsing and interactions with our sites and apps, cookies
- Geolocation: general location inferred from IP
- Professional information: job title, company
- Audio/electronic: call recordings and transcripts when Customers record calls; roleplay audio
- Inferences: product usage insights and coaching scores
- Sensitive personal information: account credentials; voice recordings, which California may treat as sensitive
Sources, purposes, and third-party categories are described in Sections 2, 3, and 9. We use this information to provide and improve the Services, support Customers, market Dialfyne, prevent fraud, and comply with law.
California rights: know, delete, correct, limit use of sensitive personal information, opt out of sale or sharing, and non-discrimination. Submit requests to [email protected] or via /do-not-sell. We verify identity before processing. You may use an authorized agent with written permission. We respond within 45 days of a verifiable request, or as otherwise required.
We do not sell personal information for money. We use third-party cookies and analytics on the marketing site that may constitute a "sale" or "sharing" under the CCPA (internet activity and identifiers with analytics providers and advertising networks). Opt out via Cookie Settings, GPC, or the Do Not Sell page. We will not ask you to reauthorize sale or sharing for at least 12 months after you opt out. We do not have actual knowledge that we sell or share personal information of consumers under 16.
You may request that we limit use of voice recordings to what is necessary to provide the Services you requested.
Supplemental Information for Other U.S. Residents
If you are a resident of a U.S. state with a comprehensive privacy law other than California (including Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Indiana, Kentucky, Maryland, Minnesota, and Rhode Island), you may have rights to know, delete, correct, opt out of sale/sharing/targeted advertising and certain profiling, portability, and non-discrimination, subject to exceptions in those laws.
Contact [email protected]. We will respond within the timeframe required by applicable law and will verify your identity. You may designate an authorized agent.
How Long Do We Keep Your Information?
We keep personal information only as long as needed to provide the Services, unless a longer period is required or permitted by law. Typical periods:
- Customer account data: duration of the relationship plus 3 years
- Call recordings and transcripts: 12 months from recording
- Call metadata: 24 months
- End User contact data in a workspace: 24 months from last interaction, or until the Customer deletes it
- Roleplay transcripts: 12 months; scorecards 24 months
- Website analytics: per Vercel Analytics and Ahrefs Analytics retention settings
- Payment records: 7 years
- Audit logs: 12 months
When we no longer need personal information, we delete or anonymize it. Backup copies may persist until the backup cycle expires, isolated from further use. You may request deletion at [email protected].
How Do We Keep Your Information Safe?
We implement technical and organizational measures designed to protect personal information, including TLS 1.2+ in transit, encryption at rest on our primary database, role-based access and workspace isolation, logging, and vendor due diligence. Our infrastructure providers maintain their own SOC 2 or equivalent programs; Dialfyne itself is not currently SOC 2 or ISO 27001 certified. No electronic transmission or storage is 100% secure. You should access the Services from a secure environment.
In the event of a personal data breach affecting Customer Personal Data, we will notify the affected Customer without undue delay and no later than 72 hours after becoming aware, as described in the DPA.
Do We Collect Information from Minors?
The Services are for business use and are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe we have, email [email protected] so we can delete it.
Links to Third-Party Sites
Our websites may link to third-party sites. We are not responsible for their privacy practices. Review their policies independently.
Do We Make Updates to This Policy?
We may update this Privacy Policy from time to time. The updated version is indicated by the "Last Modified" date. If we make material changes, we may notify you by posting a notice or by email. Continued use of the Services after changes take effect constitutes acceptance, except where applicable law requires additional consent.
How Can You Contact Us?
Questions or complaints about this Policy or Dialfyne's privacy practices:
Dialfyne
Attn: Privacy Team
Vancouver, Washington, USA
Email: [email protected]
Legal: [email protected]
Phone: +1 (971) 375-4740