Privacy Policy
Last updated: July 29, 2026
This policy explains what personal data CallRadar ("we", "us") collects, why we collect it, and the choices you have.
Two roles: our site, and our customers' data
CallRadar handles personal data in two distinct roles:
- As a controller for data about our own website visitors and account holders: when you browse this site, sign up, or contact us, we decide how that data is used.
- As a processor for data our customers collect through the CallRadar service: calls, form submissions, and visitor attribution captured on their websites. The customer is the controller of that data; we process it on their instructions under our data processing terms.
If you called or submitted a form to a business that uses CallRadar and want your data corrected or deleted, contact that business first. We support them in fulfilling your request.
Data we collect
Account data
- Name, work email, and password when you create an account
- Billing details, handled by our payment provider; we do not store card numbers
- Support conversations and emails you send us
Data collected by the tracking script
When a customer installs the CallRadar script on their site, it collects, for that customer:
- Referrer, UTM parameters, campaign, keyword, and landing page
- IP address and approximate location (city level)
- Browser and device type
- Pages visited during the session that led to a call or form submission
Call and form data
- Caller phone number, call time, duration, and outcome
- Call recordings and transcripts, where the customer has enabled recording
- Form submission contents, including any personal details the visitor enters
Call recording
Call recording is off by default. When a customer enables it, the customer is responsible for complying with the recording-consent laws that apply to their calls, including announcing recording where required. CallRadar provides a configurable consent announcement and per-number recording controls to support this.
How we use data
- To provide the service: routing calls, matching leads to sources, generating reports
- To operate accounts, billing, and support
- To secure the service, prevent fraud and abuse, and debug faults
- To improve the product, using aggregated or de-identified usage data
We do not sell personal data, and we do not use our customers' call or form data for advertising.
Cookies
Our own website uses only cookies necessary for the site to function. The tracking script sets a first-party cookie on customers' sites to connect a visitor's session to their call or form submission; it is not used for cross-site advertising.
Data processing and legal bases
Where the GDPR or similar laws apply, we process account data on the basis of contract performance and legitimate interest, and our customers' visitor data as a processor under Article 28 terms.
Subprocessors and sharing
We share data only with providers needed to run the service:
- Telephony carriers, to provision numbers and route calls
- Cloud hosting and storage providers
- A payment processor, for billing
- An email provider, for transactional email
We may also disclose data where the law requires it, or as part of a merger or acquisition, in which case this policy continues to apply to data collected before the change.
Retention
- Call recordings: deleted automatically after the retention period the customer configures, 90 days by default
- Call metadata and form submissions: kept while the customer's account is active, deleted within 30 days of account closure
- Account and billing records: kept as long as required by tax and accounting law
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to processing, and to complain to a supervisory authority. These rights come from laws such as the GDPR in Europe and the CCPA in California. To exercise them, email support@callradar.com. We respond within 30 days, and we will never treat you differently for exercising a privacy right.
We do not sell or share personal data as those terms are defined by the CCPA, so there is no sale to opt out of.
Do Not Track and Global Privacy Control
Our website does not use advertising cookies or cross-site tracking, so there is nothing for a Do Not Track signal to switch off. Where a browser sends a Global Privacy Control signal, we treat it as an opt-out request, which our practices already satisfy since we do not sell or share personal data.
Security
Data is encrypted in transit and at rest. Access to customer data is limited to staff who need it to operate the service, and access is logged.
If a security incident affects personal data, we notify affected account holders without undue delay, and where we act as a processor we notify the affected customer so they can meet their own notification duties.
International transfers
Where data is transferred outside its region of origin, we rely on standard contractual clauses or equivalent safeguards.
Children
The service is for businesses and is not directed at children under 16. We do not knowingly collect their data.
Changes
If we make material changes to this policy, we will notify account holders by email before the changes take effect. The date at the top reflects the latest revision.
Contact
Questions about privacy: support@callradar.com