Privacy Policy

Last updated: July 24, 2026

1. Introduction

PBXClaw LLC (“PBXClaw,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our phone system platform and website at pbxclaw.com.

2. Data We Collect

Account Information

  • Name, email address, phone number
  • Company name
  • Street address, address line 2, city, state, province or region, postal code, and country
  • Selected plan and application, checkout, approval, or denial status
  • Terms acceptance and your optional marketing consent choice, including related timestamps
  • Payment method and billing identifiers processed by our payment processor; PBXClaw does not store your full card number

Usage Data

  • Activation credential usage and authentication logs
  • IP addresses and approximate geolocation
  • Browser type and user agent
  • Feature usage patterns

Telephony Data

  • Call detail records (CDRs): caller ID, destination, duration, timestamp
  • Phone provisioning data: device model, MAC address, firmware version
  • Voicemail recordings (stored on your on-premise server, not our cloud)

3. How We Use Your Data

  • To review, approve, or deny applications for the Service
  • To provide, maintain, and improve the Service
  • To save a payment method, process payments, and manage subscriptions after approval
  • To send transactional emails about checkout, application decisions, account setup, billing, and security
  • To send PBXClaw product news, offers, and promotions only when you separately and expressly opt in
  • To detect and prevent fraud, abuse, and security incidents
  • To comply with legal obligations
  • To provide customer support

Marketing consent is optional, is not required to apply for or use PBXClaw, and is separate from accepting our Terms of Service and this Privacy Policy. This rule also applies if your checkout expires or your application is denied. You can withdraw consent at any time by using the unsubscribe link in a promotional email or by contacting us. Transactional checkout, pending-review, approval, denial, account, billing, and security messages are separate from promotional email.

We do not sell your data. We do not serve ads. We never will.

4. Data Retention

  • Account data: Retained for the life of your subscription plus 90 days
  • Application and checkout data: Denied applications and applications marked checkout_expired are not automatically deleted solely because of that status. We may retain them in our cloud-hosted systems for application history, fraud and abuse prevention, compliance, dispute handling, and, only with separate marketing consent, follow-up offers
  • Marketing choices: We retain consent and unsubscribe records as needed to honor your preferences and demonstrate compliance
  • Authentication logs: 12 months
  • Call detail records: 12 months
  • Payment records: 7 years (tax compliance)
  • Support tickets: 24 months after resolution

We periodically review retained applicant records and manually delete or anonymize them when they are no longer needed. Retained application data may be used for promotions only while separate marketing consent remains active. Withdrawing marketing consent stops promotional email but does not by itself delete the application record. You may request deletion at any time (see Section 8). We may retain limited records where required by law or reasonably necessary for tax, fraud-prevention, security, or dispute purposes.

5. Data Sharing

We share data with service providers only as needed for the purposes described in this Policy, including:

  • Payment processor: Secure checkout, payment-method storage, payment processing, and subscription billing
  • Identity and authentication provider: Account creation, password setup, sign-in, and organization membership after approval
  • Email delivery provider: Transactional email and promotional email for recipients who expressly opted in
  • Infrastructure provider: Website hosting, API delivery, database storage, security, and CDN services
  • Address autocomplete provider: Address suggestions and place details when you use the optional address-search feature

We do not sell personal information or share it with data brokers. We may disclose data if required by law, subpoena, court order, or other valid legal process.

6. GDPR Compliance (EEA Customers)

If you are in the European Economic Area, you have the following rights under GDPR:

  • Right of access: Request a copy of your personal data
  • Right to rectification: Correct inaccurate data
  • Right to erasure: Request deletion of your data
  • Right to restrict processing: Limit how we use your data
  • Right to data portability: Receive your data in a machine-readable format
  • Right to object: Object to certain processing activities

Legal bases for processing include steps taken at your request before entering a contract and contract performance (application, billing, and providing the Service), legitimate interests (security and fraud prevention), legal obligations, and your consent for marketing communications.

To exercise your rights, use the contact form and select privacy request. We will respond within 30 days.

7. CCPA Compliance (California Residents)

Under the California Consumer Privacy Act, California residents have the right to:

  • Know what personal information is collected and how it is used
  • Request deletion of personal information
  • Opt out of the sale of personal information (we do not sell personal information)
  • Non-discrimination for exercising these rights

To make a CCPA request, use the contact form and include “CCPA Request” in the subject.

8. Deletion Rights

You may request deletion of an application or account at any time through the contact form or, if you have access, through your account dashboard. Upon verified request:

  • Applicant and account data will be deleted within 30 days, including denied and checkout_expired application records
  • Payment records may be retained for up to 7 years for tax compliance
  • Limited security, fraud-prevention, dispute, and suppression records may be retained where legally permitted or required
  • Aggregated, anonymized analytics data may be retained indefinitely
  • Backups containing your data are purged within 90 days

9. Cookie Policy

PBXClaw uses minimal cookies:

  • Essential cookies: Session authentication, CSRF protection. Required for the Service to function. Cannot be disabled.
  • Preference cookies: Dashboard settings, language preferences. Expire after 1 year.

We do not use: Tracking cookies, advertising cookies, third-party analytics cookies, or any cookie-based profiling. No consent banner is required because we only use essential cookies.

10. Security

We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest, regular security audits, and access controls. Activation credentials are available only through the authenticated dashboard and are not sent by email. However, no method of transmission over the internet is 100% secure.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email at least 30 days before they take effect. The “Last updated” date at the top reflects the most recent revision.

12. Contact

For privacy-related questions or requests:
Contact the privacy team

PBXClaw LLC
Privacy Team
pbxclaw.com