Privacy Policy
SecretVoIP · Last updated {date} 1 February 2026
This Privacy Policy explains how SecretVoIP collects, uses, retains and protects personal data in connection with the customer portal and prepaid SIP voice service.
1. Data controller
SecretVoIP is the data controller responsible for the personal data described in this policy, collected through the customer portal and the underlying SIP voice service (the “Service”). Questions about this policy or your data can be directed to our support team through the customer portal or via Telegram at @SecretVoIPSupport.
2. Data we collect
We collect the following categories of data in connection with the Service:
- Account data — nickname, username, email address, Telegram handle, hashed password and account preferences such as language;
- SIP registration metadata — SIP line credentials, registration timestamps, client IP address, user agent of the registering device and registration status;
- Call detail records (CDRs) — calling and called number, caller ID used, call start and end time, duration, direction, disposition and cost, but not the content of calls unless call recording has been separately enabled and disclosed to you;
- Payment references — top-up amounts, timestamps, payment method type and transaction identifiers issued by our payment processors. We do not store full card numbers or wallet private keys;
- Support and security logs — sign-in events, credential rotations, session activity and Telegram support conversation content.
3. Why we process this data and our legal basis
- To create and administer your account and provision SIP lines (performance of a contract);
- To route calls, meter usage and deduct prepaid balance (performance of a contract);
- To detect and prevent fraud, abuse and unauthorised access (legitimate interest);
- To provide customer support and respond to enquiries (performance of a contract / legitimate interest);
- To comply with tax, accounting, telecommunications and law-enforcement obligations (legal obligation);
- To improve reliability and troubleshoot the network (legitimate interest).
4. Retention periods
We keep personal data only as long as necessary for the purposes above:
- Account data is retained for as long as your account is active, and for a limited period afterward to handle disputes, fraud investigation and legal obligations;
- Call detail records and payment references are retained for the period required by applicable telecommunications, tax and accounting law, typically between one and seven years depending on jurisdiction;
- Security logs (sign-ins, credential rotations, session activity) are retained for a limited operational window, after which they are deleted or anonymised;
- Telegram support conversation content is retained for as long as needed to resolve the matter and for a reasonable period afterward for quality and audit purposes.
5. Third parties and carriers
To deliver calls we share the minimum necessary call signalling and routing data (such as the dialled number, caller ID and call duration) with interconnected telecommunications carriers along the call path. We use payment processors to handle balance top-ups and may use infrastructure providers (hosting, monitoring, communications) that process data on our behalf under contractual confidentiality and data-protection obligations. We do not sell personal data to third parties, and we do not share call detail records with advertisers.
6. Security measures
We apply technical and organisational measures appropriate to the sensitivity of the data we hold, including encryption of data in transit between your device and the portal, hashed storage of passwords, access controls limiting internal access to personal data on a need-to-know basis, and logging of administrative actions for audit purposes. No system is completely secure; you should also take reasonable steps to protect your account, including using a strong password and keeping your SIP credentials confidential.
7. International transfers
Because the Service relies on an interconnected global telecommunications network, call signalling data may be transmitted through carriers located outside your country of residence in order to complete a call to its destination. Where we transfer personal data internationally to infrastructure or payment providers, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms recognised under applicable data-protection law.
8. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Request correction (rectification) of inaccurate or incomplete data;
- Request erasure of your data, subject to our legal retention obligations (see Section 4);
- Request a portable copy of the data you provided to us;
- Object to, or request restriction of, certain processing carried out on the basis of legitimate interest;
- Lodge a complaint with your local data-protection authority.
You can exercise most of these rights directly from the customer portal (updating account details, rotating credentials, closing your account) or by contacting support on Telegram. We may need to verify your identity before actioning a request.
9. Cookies and local storage
The portal uses strictly necessary cookies and browser local storage to keep you signed in, remember your language preference and protect against cross-site request forgery. We do not use third-party advertising or cross-site tracking cookies. You can control cookies through your browser settings, though disabling strictly necessary cookies may prevent you from signing in.
10. Contact
For privacy questions, data requests or complaints, contact us via Telegram at @SecretVoIPSupport. We aim to respond to legitimate privacy requests within 30 days.
