PRIVACY POLICY
SwitchBoard Cloud-Based SaaS Phone System
Effective date: 20 August 2026 - Last updated: 21 August 2026
This policy explains what personal data STARTcloud, Inc. ("SwitchBoard", "we", "us") collects when you visit switchboard.cloud or use SwitchBoard Cloud™, why we collect it, who we share it with, and the choices you have.
01. Two different roles — please read this first
SwitchBoard Cloud is a business phone system that companies buy for their teams. That means we handle personal data in two distinct roles:
We are the controller for data about our own customers and visitors: the marketing site, sign-up and sign-in, billing, support requests, and how instances are provisioned. Sections 2 to 11 describe this.
We are a processor for the data inside a customer's phone system — call records, recordings, voicemail, transcripts, contacts, and the accounts of that customer's staff. The customer decides what is collected, what is recorded, and how long it is kept. We process it on their instructions. Section 12 describes this.
If you are an employee of a SwitchBoard customer, or someone who called them: the organisation that operates the phone system is responsible for that data. Please direct requests to them. We will help them respond.
​
02. Data we collect as controller
When you create a SwitchBoard ID: name, email address, mobile number, password (stored only as a salted hash), and email/phone verification status.
When you set up an instance: your company name, the subdomain you choose, the cloud region and time zone you select, and the identity of the person who launched it.
Billing: company name, billing contact, address, tax identifiers, plan and invoice history. Card and bank details are entered directly into Stripe's PCI-certified systems and are handled entirely by Stripe. Neither SwitchBoard nor Paythen sees, stores or processes card numbers or banking data.
Support and sales: the content of your emails and tickets, and notes from calls or demos.
Automatically, when you use our sites and services: IP address, browser and device type, pages viewed, referring page, timestamps, and diagnostic logs from the provisioning system and the instance's own server logs (for example sign-in attempts and errors).
Cookies: the onboarding and instance applications use a small number of strictly necessary cookies — session/authentication cookies, and short-lived security cookies for the sign-in exchange. The marketing site (hosted on Wix) may set analytics cookies; see section 10.
We do not deliberately collect special-category data (health, biometrics, political opinions and similar) as controller. Note that a customer's call recordings can contain anything a caller says, which is one reason recordings are the customer's data and not ours to use (section 12).
03. Why we use it, and our legal basis
• Creating your account, authenticating you, and running your instance — Legal basis: Performance of a contract
• Verifying your email address and mobile number (anti-fraud) — Legal basis: Legitimate interests; contract
• Billing, collections, tax and accounting records — Legal basis: Contract; legal obligation
• Support, incident response and troubleshooting — Legal basis: Contract; legitimate interests
• Keeping the Service secure, preventing fraud and abuse, enforcing usage limits — Legal basis: Legitimate interests
• Service notices (provisioning progress, instance ready, security and billing notices) — Legal basis: Contract
• Product and marketing email about SwitchBoard — Legal basis: Consent where required, otherwise legitimate interests — you can opt out at any time
• Improving the Service using aggregate, non-identifying usage data — Legal basis: Legitimate interests
We do not sell personal data, and we do not use the content of calls, recordings or transcripts to train machine-learning models.
04. Automated decisions
We do not make decisions about you by purely automated means that have a legal or similarly significant effect. A launch can be automatically held for human review when usage limits are exceeded; a person then approves or declines it.
05. Who we share data with
We use a small number of service providers ("subprocessors"). Each gets only what it needs.
-
Amazon Web Services — Hosts each customer's instance and our platform services · Data involved: Everything on the instance; platform data · Where: The region the customer chooses (see section 6)
-
Twilio — Voice and messaging connectivity; SMS verification codes · Data involved: Phone numbers, call metadata, message content, verification codes · Where: US / global
-
Amazon SES — Sends transactional email from switchboard.global (verification, magic links, instance notices) · Data involved: Name, email address, message content · Where: United States
-
Google Workspace — Our own sales and support mailboxes on switchboard.cloud · Data involved: Name, email address, correspondence content · Where: Global
-
Wix — Hosts the marketing website at switchboard.cloud · Data involved: Site analytics, contact-form submissions · Where: Global
-
Stripe — Takes payment and stores card details · Data involved: Billing contact, payment details · Where: Global (see Stripe's privacy centre)
-
Paythen — Subscription and payment-plan management, layered on our Stripe account. Does not receive card or bank details · Data involved: Billing contact, plan and invoice data · Where: Company based in Australia; data hosted on Heroku
-
Speech-to-text / AI providers — currently OpenAI and Amazon Web Services (Transcribe, Bedrock, Comprehend) — Transcription, summarisation, sentiment analysis — only when a customer enables them · Data involved: Call recording audio and the resulting text · Where: US / the configured region
-
Clio (and other CRMs we add) — Contact synchronisation — only when a customer connects it · Data involved: Contact names, phone numbers, email addresses · Where: Per that provider
We may also disclose data: to professional advisers under confidentiality; to authorities where legally required (we will notify the customer unless legally prohibited); and to an acquirer in a merger or sale, subject to this policy.
An up-to-date subprocessor list is this table; ask us at support@switchboard.cloud if you need it confirmed in writing. We tell customers before a new subprocessor starts handling their data.
06. Where your phone system lives
Customers choose the cloud region when they launch an instance. We currently offer: Ohio, N. Virginia, Oregon (US); Canada (Central); London and Frankfurt (Europe); São Paulo; Mumbai; Singapore; Sydney.
The instance's data — including recordings and transcripts — is stored in the chosen region. Choosing London or Frankfurt keeps the phone system's data in the UK or the EU. Some platform functions (account sign-in, provisioning records, support) and some subprocessors operate from the United States regardless of that choice.
07. International transfers
Where we transfer personal data out of the UK, EEA or Switzerland, we rely on an adequacy decision where one applies, or otherwise on the European Commission's Standard Contractual Clauses (and the UK Addendum), together with additional safeguards where appropriate. Ask us at support@switchboard.cloud for a copy of the relevant mechanism.
08. How long we keep it
Account records: for as long as the account is active, then up to 24 months, unless you ask us to delete them sooner.
• Instance data: while the instance exists. After termination we keep it for 30 days so an export can be requested, then delete it. We also keep a short-lived copy of an instance, taken before releases and significant changes so that a faulty change can be reversed. A copy holds the data present when it was taken, so deleted data may remain in a copy until we remove it, normally within a month.
• Billing and tax records: as long as tax and accounting law requires (typically 7 years).
• Support correspondence: 24 months.
• Server and security logs: 90 days, longer where retained for an investigation.
• Recordings, voicemail and transcripts inside an instance: for the retention period the customer configures. We do not impose our own.
09. Security
-
Each customer gets a dedicated server with its own database. Customer data is not commingled in shared tables with other customers' data.
-
Traffic to the applications is encrypted with TLS. Credentials for third-party integrations are encrypted at rest with a key unique to each instance.
-
Passwords are stored as salted hashes, never in plain text. Two-factor authentication is available and we recommend enabling it.
-
Access to production systems is limited to staff who need it, and is logged.
-
We keep an audit trail of security-relevant events such as sign-ins and instance launches.
No system is perfectly secure. If a breach affects your personal data we will notify you and any relevant regulator as the law requires, without undue delay.
10. Cookies and the marketing site
The application uses strictly necessary cookies only: an authentication session cookie, and short-lived cookies that protect the sign-in exchange. Blocking these prevents sign-in.
​
The marketing site at switchboard.cloud is hosted on Wix, which may set analytics and functional cookies. We do not run advertising cookies.
11. Your rights
Depending on where you live you may have the right to: access your data; correct it; delete it; restrict or object to processing; receive it in a portable format; withdraw consent; and not be discriminated against for exercising these rights.
EEA/UK: you may also complain to your data protection authority.
California: we do not sell personal information and do not share it for cross-context behavioural advertising. You may request to know, delete, or correct your personal information, and may use an authorised agent.
To exercise a right, email support@switchboard.cloud. We will verify your identity and respond within the time the law allows (generally one month for GDPR, 45 days for CCPA). If your request concerns data inside a customer's phone system, see section 12.
12. If you are an end user, employee or caller
When an organisation uses SwitchBoard Cloud, that organisation decides what happens on its phone system: whether calls are recorded, whether transcription or sentiment analysis is switched on, who can listen to recordings, and how long anything is kept. It is the controller for that data; we are its processor and act on its instructions.
That means:
-
Requests to access or delete a recording, transcript, voicemail or contact record should go to the organisation that operates the phone system, not to us. If you contact us we will refer you to them and assist them in responding.
-
Whether you are told that a call is recorded is that organisation's responsibility, as is obtaining any consent the law requires. Our Terms of Service require customers to comply with recording and consent laws.
-
We do not use that data for our own purposes, and we do not sell it.
13. Children
The Service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided data, contact us and we will delete it.
14. Changes to this policy
We may update this policy. We will change the "last updated" date and, for material changes, notify customers by email or in the Service before the change takes effect. Earlier versions are available on request.
15. Contact us
STARTcloud, Inc. — 500 Westover Dr #4574, Sanford, NC 27330
Privacy: support@switchboard.cloud · Security: security@switchboard.cloud · General: support@switchboard.cloud
