Privacy & Security
StartDialing, operated by TruITT. Last updated July 2026.
1. What we collect. Account details you give us (name, email, phone, company info), billing data, the contact lists and scripts you upload, and the calls and messages your agents make. We also log basic technical data (IP address, browser, timestamps) to keep the service secure.
2. How we use it. To operate the service — place your calls and texts, bill you, show your results, provide support, prevent abuse, and meet legal obligations. We do not sell your data, and we do not use your contact lists for any purpose other than running your campaigns.
3. Subprocessors. We rely on a small set of vendors to run the product: Supabase (database and authentication), Stripe(payments — we never see or store full card numbers), Twilio (phone numbers, call and message delivery), ElevenLabs (AI voice), and Vercel (hosting). Each processes only the data needed for its function. Any calendar, CRM, or commerce integration you connect is used only to power the agent tools you enable.
4. Cookies. We use a strictly-necessary cookie to keep you signed in — this is required for the service to work. Optional functional and analytics cookies are off by default and only set if you allow them in the cookie banner. You can change your choice at any time.
5. Your data rights. You own your data. From your account settings you can view and edit your information, export everything we hold about you as a file, and permanently delete your account and all associated data at any time. Deletion is immediate and irreversible.
6. Security. Data is encrypted in transit (TLS) and at rest. Access to your data is protected by row-level security so each account can reach only its own records. API access requires authentication, and sensitive third-party tokens are stored server-side and never exposed to the browser. We keep an audit log of significant account actions.
7. HIPAA. StartDialing is not intended for protected health information (PHI), and using it to transmit PHI is not permitted unless we have signed a Business Associate Agreement (BAA) with you in advance. We do not currently offer a BAA, so do not upload PHI. If your use case requires one, contact us before onboarding and we will tell you honestly whether we can support it.
8. SOC 2. We build to SOC 2 security principles — least-privilege access, encryption, audit logging, and vetted subprocessors — but we want to be straight with you: StartDialing has not completed a SOC 2 Type II audit and we do not claim certification. We will update this page and make the report available under NDA if and when that changes. We will never claim a certification we do not hold.
9. Data retention. We keep your data for as long as your account is active. When you delete your account, your records are removed. We may retain minimal billing records where law requires.
10. Contact. Questions about privacy, security, or a data request? Email privacy@startdialing.io.