callstracking.com
Privacy Policy
Effective July 12, 2026
1. Who we are
callstracking.com is operated by Altic LLC (“we,” “us,” or “callstracking.com”). We provide a call-attribution SaaS platform that helps advertisers measure which paid-ad clicks generate inbound phone calls, and upload those calls as conversions to ad platforms.
This policy explains what data we collect from three groups: advertiser customers (people who subscribe to our service), visitors to those advertisers’ websites (whose traffic is measured), and callers (people who call tracked numbers).
2. Data we collect from advertiser customers
- Account information: name, email address, hashed password, workspace name.
- OAuth tokens for connected ad platforms (Google Ads, Meta, TikTok, Microsoft Ads, LinkedIn). Refresh tokens are encrypted at rest.
- Configuration data: campaign names, forwarding phone numbers, qualification rules, integration preferences.
- Billing information is handled by Stripe. We store a Stripe customer ID and subscription status; we do not store card numbers.
- Usage logs: IP address, browser user-agent, request timestamps, feature usage — used for security, debugging, and product improvement.
3. Data we collect from visitors to advertiser sites
When a visitor lands on an advertiser’s site that uses our tracking snippet, we collect:
- Session identifier (a first-party cookie or local-storage value scoped to the advertiser’s domain).
- Referrer URL and UTM parameters.
- Ad-platform click identifiers (GCLID, fbclid, ttclid, msclkid, li_fat_id) if present in the URL.
- IP address (used to derive the visitor’s region for local-presence number matching; not stored beyond 30 days).
- The tracked phone number assigned to that visitor’s session.
We do not track visitors across advertiser sites. Each session is scoped to a single advertiser.
4. Data we collect from callers
When a caller dials a tracked number, we collect:
- Caller phone number (from the carrier).
- Call start time, duration, and result (answered / voicemail / no answer).
- Call recording (audio file), if recording is enabled for that campaign.
- Transcript of the call, where transcription is enabled.
Call recording notice: before a call connects, callers hear a recorded notice (default: “This call may be recorded for quality assurance.”) in jurisdictions that require two-party consent (including many U.S. states and EU/UK jurisdictions). Advertisers are responsible for ensuring recording is legal in the jurisdictions they operate in.
5. How we use data
- To assign each visitor a unique tracked phone number (Dynamic Number Insertion).
- To route calls from tracked numbers to the advertiser’s real phone number via Twilio.
- To match calls back to the ad click that generated the visit, and upload the resulting conversion to the corresponding ad platform.
- To bill advertisers for their subscription.
- To send transactional emails (billing, security alerts).
- To debug and improve the service.
Phone numbers uploaded to ad platforms are hashed (SHA-256) before transmission when the platform accepts hashed identifiers.
6. Third parties we share data with
- Twilio — telephony provider (call routing, recording).
- Vercel — application hosting.
- Neon — Postgres database hosting.
- Stripe — payment processing.
- Google Ads, Meta, TikTok, Microsoft Ads, LinkedIn — for offline conversion uploads and, in some cases, campaign metadata retrieval, initiated on the advertiser’s behalf under the advertiser’s OAuth authorization.
We do not sell personal data. We do not share data with advertisers other than the advertiser who owns the campaign in question.
7. Data retention
- Call recordings and transcripts: retained for 90 days unless the advertiser requests longer retention.
- Call metadata (duration, timestamps, attribution): retained for the life of the advertiser’s account, plus 12 months for financial-record purposes.
- Visitor IP addresses: retained for 30 days, then deleted.
- Advertiser account data: retained until account deletion is requested.
8. Your rights (GDPR / CCPA / similar)
If you are a resident of the EU/EEA/UK, California, or another jurisdiction with data-protection rights, you may request:
- Access to a copy of your data.
- Correction of inaccurate data.
- Deletion of your data (subject to legal-record retention requirements).
- Portability of your data.
- To object to or restrict certain processing.
To exercise these rights, email support@alticllc.com. For visitor / caller data, requests should generally be routed through the advertiser whose campaign produced that data; we will help facilitate.
9. Security
- All traffic is served over HTTPS.
- OAuth refresh tokens and other sensitive fields are encrypted at rest using AES-256-GCM.
- Passwords are hashed with bcrypt.
- Access to production data is restricted to authorized personnel.
No online service is 100% secure. If we become aware of a security incident affecting your data, we will notify you as required by applicable law.
10. Children
The service is not directed at children under 16. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email or in-app notice at least 14 days before they take effect.
12. Contact
Altic LLC
support@alticllc.com