Privacy Policy
Effective 3 September 2026. This policy explains what RingTrunk collects when you visit ringtrunk.com, use the portal or developer API, or send calls through a RingTrunk trunk, and what we do with it. It is written to be read, not skimmed past — it is short because we collect little.
Who we are and what this covers
RingTrunk is operated by Zingaro AI Private Limited, a company registered in India (“RingTrunk”, “we”, “us”). We provide Indian phone numbers and SIP trunks that developers connect to their own voice platform. This policy covers the website at ringtrunk.com, the customer portal, the developer API at ringtrunk.com/api/v1 and the SIP service at sip.ringtrunk.com.
For the purposes of the Digital Personal Data Protection Act, 2023, Zingaro AI Private Limited is the data fiduciary for the data described here. Our customers are themselves responsible for the people they call and who call them — see If you are our customer.
What we collect
We collect only what the service needs to work, be billed and stay secure.
- Account data. Your name, email address, company name and sign-in identifiers. Passwords are handled by Firebase Authentication and are never visible to us.
- Early-access requests. The name, email, company and use-case you type into the request form, plus the IP address and browser identifier of the submission, used to prevent abuse of the form.
- Trunk configuration. Trunk names, the SIP credentials we issue (stored encrypted, shown to you once), the addresses of your SIP servers (origination URIs), IP allow-lists, forwarding numbers, channel and rate limits, and API keys (stored as hashes).
- Call detail records. For every call through a trunk: the calling and called numbers, the trunk it used, direction, start and end times, ring and talk duration, and the SIP result code. This is the record you see under Calls in the portal.
- Technical logs. SIP signalling logs, authentication attempts and failures, source IP addresses and portal access logs. These exist to keep the switch secure and to answer support questions.
- Billing data. Payments are processed by Razorpay. We receive the payment status, amount, method type and a payment identifier; we never receive or store your card, bank or UPI details.
- Support communications. Emails you send us, and our replies.
What we do not collect
We do not record or store call audio. On a RingTrunk trunk the media stream flows directly between the carrier and your SIP server; it does not pass through our servers. When you enable callback forwarding on a number, the audio is relayed in real time to the forwarding phone and is not stored. We do not transcribe calls and we do not analyse their content.
We do not use advertising trackers, we do not build marketing profiles, and we do not sell or rent data to anyone.
Why we use it
- To provide the service: authenticate your trunk, route calls to and from your numbers, deliver incoming calls to the servers you configure, and show you your call records.
- To comply with Indian telecom rules: presenting only caller IDs that belong to you, carrying domestic destinations only, and keeping the records our licensed carrier partners and regulators require.
- To bill you and to resolve billing disputes.
- To keep the platform secure: detecting brute-force attempts, fraud, spoofing and abuse, and enforcing per-trunk limits.
- To support you when you write to us.
- To understand usage in aggregate so we can plan capacity. This never involves call content.
We process account and configuration data because you asked us to provide the service, billing data to perform our contract with you, and logs and call records because the law and the security of the platform require it.
Who we share it with
- Licensed carriers. To connect a call, the calling and called numbers and the signalling for that call are sent to the Indian telecom operator that carries it. This is inherent in placing or receiving a phone call.
- Infrastructure providers. Google Cloud and Firebase (database, authentication, email), Amazon Web Services and Google Cloud (servers), and Cloudflare (DNS, content delivery and protection of the website). They process data on our behalf under their own security commitments.
- Razorpay. Our payment processor. Razorpay's own privacy policy governs the payment details you enter with them.
- Authorities. When Indian law, a court order or the licence conditions of our carrier partners require it, we provide the records we hold. We do not volunteer more than is required.
We do not share your data with anyone else, and we do not sell it.
How long we keep it
- Account and trunk configuration: for as long as your account exists, then deleted within 90 days of closure unless a legal obligation requires us to keep parts of it.
- Call detail records and SIP logs: for as long as applicable Indian telecom regulations require licensed operators and their partners to retain them, and as needed for billing disputes. They are then deleted.
- Early-access requests: until your request is handled and your account is created, or until you ask us to delete it.
- Billing records: for the period required by Indian tax and company law.
- Backups: encrypted backups age out on a rolling schedule; deleted data disappears from them within that cycle.
How we protect it
- All web, API and portal traffic is encrypted in transit (HTTPS/TLS).
- Trunk passwords are encrypted at rest and shown once at creation; API keys are stored as hashes.
- SIP authentication uses digest challenge-response, optionally restricted to the IP addresses you allow-list; repeated failures are blocked automatically.
- Access to production systems is limited to the people who operate them.
No system is perfectly secure. If you believe your credentials have been exposed, rotate them in the portal immediately and tell us at [email protected].
Your rights
Under the Digital Personal Data Protection Act, 2023 you may ask us what personal data we hold about you, ask us to correct it, ask us to erase it, withdraw consent where our processing relies on it, and nominate a person to exercise these rights on your behalf. Erasure is subject to the retention obligations above: we can close your account and delete your configuration, but call records required by law stay until their retention period ends.
Write to [email protected] from the email address on your account. We acknowledge every request and answer within the time the law allows. If you are not satisfied with our answer, you may approach the Data Protection Board of India.
Cookies
The portal uses the strictly necessary cookies and browser storage that keep you signed in. Cloudflare may set a security cookie to protect the site from automated abuse. We do not use analytics or advertising cookies, and there is nothing to opt out of.
If you are our customer
When you connect RingTrunk to your voice platform, you decide whom to call, what your system says, and whether your system records or transcribes calls. You are responsible for the notices, consents and legal requirements that apply to the people you call and who call you, including telemarketing rules and any recording disclosures. RingTrunk carries the call; it does not see or keep its content.
Where data is processed
Our switching infrastructure and our primary database run in Indian data-centre regions. Some of our providers (Google, Amazon, Cloudflare) may process or replicate data in other regions as part of their global operations; where a provider offers an Indian region we use it.
Children
RingTrunk is a developer service for businesses and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we have, tell us and we will delete it.
Changes to this policy
When we change this policy we update the effective date at the top. If a change materially affects how we handle your data, we email account holders before it takes effect.
Contact
Zingaro AI Private Limited, India. Privacy questions, data requests and grievances: [email protected]. A person reads every message.