Privacy
TextTheCaller Privacy Policy
Last updated 31 July 2026
Last updated: 26 July 2026
Overview
This Privacy Policy explains how TextTheCaller ("we", "us", "our") collects, uses, stores, shares, and protects personal information when you visit our website, create an account, subscribe to a plan, call one of our numbers, or otherwise interact with our service. It applies to people who have no account with us as well as to customers — including anyone who calls the demo line advertised on our website, which is covered in its own section below.
TextTheCaller is a service that automatically sends a text message to callers when you miss their call. Because the service involves phone numbers and messaging, some personal data is necessary for the platform to operate.
By using TextTheCaller, you acknowledge that your information will be handled in accordance with this Privacy Policy.
Information We Collect
Information you provide
When you create an account or use the service, you may provide:
- Your name and email address
- Your mobile phone number
- Your business or company name
- Your mobile network provider
- Your text-back message content and preferences
- Any other information you submit through forms, settings, or support requests
Information generated through the service
When someone calls your forwarded number and the service processes a missed call, we collect:
- Caller phone numbers — processed to deliver the text message. Caller numbers are not stored in their original form. We store a masked version (with middle digits hidden) in service logs, and a one-way cryptographic hash (HMAC-SHA-256 with a server-side secret) used solely to prevent duplicate messages to the same caller and to check against your skip list. The full number is passed to our SMS provider so the message can be delivered, and we instruct that provider to delete its copy 60 minutes after sending — see Retention by our SMS provider.
- Call event identifiers — unique references for each call, used to prevent duplicate messages and maintain accurate logs.
- Message delivery records — including the message content sent, delivery status, and any errors.
- Timestamps — when calls were received and messages were sent.
We only send text messages to UK mobile numbers. Calls from landlines, international numbers, withheld numbers, or anonymous callers are not processed and no caller data is stored for those calls.
To protect your usage, we limit messages to the same caller to once every seven days per account. This deduplication uses cryptographically hashed data (HMAC-SHA-256) and does not require us to store raw caller phone numbers.
Account and billing data
- Your subscription plan, billing status, trial status, and renewal dates
- Payment confirmations and invoice records
- Partial payment metadata provided by our payment processor
We do not store your full payment card details. Card information is handled entirely by our third-party payment processor.
Technical data
When you access our website or platform, we may automatically collect your IP address, browser type, device information, operating system, referring pages, session activity, and cookie identifiers.
Bot and abuse prevention
We use Cloudflare Turnstile on certain forms, including signup, sign-in, and email preference forms, to distinguish people from automated bots and protect the platform against abuse. When Turnstile runs, Cloudflare may process technical signals such as your IP address, browser and device characteristics, operating system, user agent, country, and information about how your browser interacts with the challenge.
We use Turnstile under our legitimate interests in securing the platform and preventing fraud and abuse. Cloudflare processes these signals on our behalf to provide Turnstile and also describes certain processing it carries out as a controller to improve its bot-detection capabilities. For more information, see the Cloudflare Turnstile Privacy Addendum.
If You Call Our Demo Line
We publish a demo phone number on our website so people can experience the service from the caller's side before signing up. This section is for you if you have called that number. It applies whether or not you have an account with us.
When you call the demo line, we are the controller of your data. This is different from the rest of the service, where someone calls a customer's own number and we handle the call on that customer's behalf. The demo number belongs to us, so we are directly responsible for what happens to your information.
Our legal basis is your consent, and calling is how you give it. The page carrying the number states, before you dial, that calling means you will receive one text at the number you call from. Dialling the number is the affirmative action that gives permission. You are free not to call, and nothing on our site is withheld if you don't.
What we process when you call
- Your phone number. We pass it in full to our SMS provider so the text can reach you, and instruct them to delete their copy 60 minutes later. We never keep it in that form ourselves. What we retain is a masked version showing only the country code and last four digits (for example
+44******1234), together with a one-way hash — SHA-256, then HMAC-SHA-256 with a secret held separately from the database — which lets us recognise a repeat call without ever storing the number itself. - Call and message records. The call identifier supplied by our telephony provider, the time of the call, the message we sent, and whether it was delivered.
- Nothing at all, in some cases. We only text UK mobile numbers. If you call from a landline, an international number, or with your caller ID withheld, no text is sent and no record of your number is created.
Our telephony provider also holds its own record of the call, as any phone network does, under its own retention terms.
What we do not do
We do not call you back, add you to a mailing list, use your number for marketing, sell it, or pass it to anyone other than the providers who carry the call and deliver the text. You will receive one message. Because we limit messages to the same number to once every seven days, calling again within a week will produce nothing.
Removing your record
Email us at [email protected] from any address and tell us the number you called from. We will match it against the stored hash and delete the record. You do not need an account, and we will not ask you to create one.
How We Use Your Information
We use your information to:
- Create and manage your account
- Provide the automated text-back service, including processing missed calls and sending text messages to callers
- Manage your subscription, billing, and payments
- Enforce usage limits and prevent duplicate messages
- Detect and prevent fraud, abuse, spam, and misuse of the service
- Provide customer support and respond to enquiries
- Monitor service performance, diagnose issues, and improve the product
- Comply with legal obligations and enforce our terms
Marketing emails and signup reminders
When you provide your email address while creating an account or signing up for a trial, you can choose to receive occasional marketing emails about TextTheCaller. These may include signup or trial reminders, feature and product updates, service tips, small-business tips, invitations to return, and requests for feedback. We only send these emails if you actively opt in by selecting the separate marketing checkbox during signup.
Every marketing email includes a link to manage your email preferences or unsubscribe. The link may include your email address to pre-fill the preference form, but it does not open or change your preferences automatically. You must still complete our security check before accessing them. We remove the email query from the browser address bar after the page loads and do not run website analytics on the preference page.
You can withdraw your consent at any time using this preference link. If you unsubscribe, we stop sending marketing emails unless you later make a new choice to subscribe. Not opting in, or later unsubscribing, does not affect essential service messages such as requested sign-in links, security notices, billing messages, or important account communications.
If we do not have a recorded date showing that marketing emails were permitted, we treat the account as opted out. This includes accounts created before this preference was introduced.
We record the date and time marketing emails were permitted, later subscription or unsubscribe changes, and limited audit information about marketing emails sent from our administration system. This helps us respect your current choice, respond to complaints, and demonstrate compliance. These records are retained with your account for as long as reasonably necessary for those purposes.
Legal Bases for Processing
Where data protection law requires a legal basis, we rely on one or more of the following:
- Contract — processing necessary to provide the service, maintain your account, and handle your subscription.
- Legitimate interests — processing necessary for securing the platform, preventing abuse, improving the service, and enforcing our rights, where those interests are not overridden by your rights.
- Legal obligation — processing necessary to comply with tax, accounting, fraud prevention, or regulatory requirements.
- Consent — sending optional marketing emails when you actively opt in, sending the demo text to someone who calls our demo line, setting advertising cookies, and other activities where consent is required by law. You may withdraw consent at any time, though this will not affect processing that took place before withdrawal.
Cookies
Essential cookies. We use cookies and similar technologies to keep you signed in, maintain session integrity, remember preferences, and protect against abuse. These are necessary for the service to function, are not used for advertising, and cannot be disabled without affecting core functionality. They do not require your consent.
Advertising cookies. With your consent, we use the Meta Pixel, a tool provided by Meta Platforms Ireland Limited, on our public website pages. It tells us how many people who saw one of our adverts went on to visit the site or start a free trial, so we can judge whether our advertising is working. It sets cookies in your browser and shares information with Meta, including your IP address, the pages you view on our site, and an identifier Meta may use to recognise you if you have a Meta account.
We ask for your permission before any advertising cookie is set. If you decline, the Meta Pixel is never loaded and nothing is shared with Meta. The website works in exactly the same way whichever you choose, and declining does not restrict any part of the service.
You can change your choice at any time using the "Cookie settings" link in the footer of any page. Withdrawing consent stops any further sharing, but does not undo sharing that already took place while consent was in force. Meta acts as a separate controller for the data it receives; its own privacy information explains what it does with it.
You can also manage cookies through your browser settings, though blocking essential cookies may affect site functionality.
Sharing of Information
We do not sell your personal data.
We share personal data with third-party service providers who help us operate the service, including providers of cloud hosting, SMS delivery, payment processing, and security services such as Cloudflare Turnstile. These providers may only use the data as necessary to perform services on our behalf, except where a provider separately acts as a controller as explained in its own privacy information.
We may also share information where required by law, regulation, court order, or lawful request from a public authority, or where necessary to investigate fraud, prevent harm, protect our rights, or enforce our agreements.
If TextTheCaller is involved in a merger, acquisition, or sale of assets, personal data may be disclosed to relevant parties as part of that process.
International Data Transfers
Your information may be processed and stored in countries other than where you are located, where our service providers operate. Where personal data is transferred internationally and local law requires safeguards, we take reasonable steps to ensure appropriate protections are in place.
Data Retention
We retain personal data for as long as reasonably necessary to provide the service, maintain your account, comply with legal obligations, resolve disputes, and prevent fraud.
Caller data in service logs (masked phone numbers and anonymised identifiers) is retained for operational and abuse-prevention purposes. Call event identifiers are retained to prevent duplicate messaging.
Retention by our SMS provider
Delivering a text message requires us to give the recipient's full phone number to the provider that carries it. There is no way to send an SMS without this.
We instruct that provider to delete its own record of each message — including the recipient's full number and the message content — 60 minutes after sending. This is set on every message we send. Their systems keep deleted data recoverable in routine backups for a further five days, after which it is gone.
We set this deliberately. Left to the provider's own default, message records would be archived after 90 days and kept for seven years. The hour we allow is enough to investigate a delivery failure reported on the day, and no longer.
If you cancel your account, we may retain limited records for a period where necessary for billing, dispute resolution, legal compliance, or security purposes. Compliance review records, including records of extreme violations, may be retained for longer where required for regulatory, legal, or law enforcement purposes.
Security
We use reasonable administrative, technical, and organisational measures to protect personal data, including access controls, authentication protections, and secure infrastructure practices.
Caller phone numbers receive additional protection: they are masked before storage in logs and cryptographically hashed using HMAC-SHA-256 with a server-side secret for deduplication and skip list matching. Original caller numbers are not retained in our database. Even in the event of a database breach, stored hashes cannot be reversed without the server secret, which is stored separately from the database.
Contact import privacy
If you use the contact import feature to add numbers to your skip list, your phone numbers are processed entirely on your device. The import works as follows:
- Your device's native contact picker presents a system-level interface where you choose which contacts to share — we cannot access contacts you do not select.
- Selected phone numbers are hashed using SHA-256 on your device, then masked to hide middle digits. Only the hash and masked display value are sent to our server.
- Our server applies an additional HMAC layer with a server-side secret before storing the hash. The raw phone number never leaves your device and is never transmitted to or seen by us.
- We only request phone number data from the contact picker — no names, email addresses, or other contact information is accessed.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your login credentials.
Content Moderation and Account Suspension
We monitor text-back message content for potential abuse, spam, and violations of our Terms of Service and UK SMS regulations (including PECR). This involves multiple layers of review:
- Automated filtering — messages are checked against a list of prohibited words, phrases, and patterns before they can be saved.
- AI compliance review — an AI-assisted system analyses your message content, company name, and sender ID against UK SMS compliance rules. This check runs each time you save a text-back message.
- Manual admin review — every saved text-back message is logged and queued for human review by our team, regardless of whether it passed automated checks.
What happens when a message fails review
If the AI compliance check determines that your message does not meet our guidelines (for example, it contains promotional language that is not permitted in service messages), the message will not be saved and you will be asked to revise it.
Extreme violations and account suspension
In cases where the AI compliance check identifies an extreme violation — such as impersonation of a government body, authority, or official entity; threatening, intimidating, or coercive language; phishing or scam patterns; or hate speech — the following actions are taken automatically:
- SMS sending is paused — your account will no longer send text-back messages to missed callers until an admin has reviewed the violation.
- Text-back editing is blocked — you will not be able to save or modify your text-back message while the review is pending.
- Account deletion is temporarily restricted — to preserve evidence and allow for review, you will not be able to delete your account while a suspension is active. This restriction is necessary to comply with our legal obligations and protect the integrity of the platform.
- An internal incident report is generated — our team receives a detailed notification including your account details, the message content that triggered the violation, the AI's assessment, your IP address, and timestamp information. This allows us to review the incident promptly and take appropriate action.
These measures are taken under our legitimate interest in preventing misuse of the platform, protecting recipients of text messages, complying with UK telecommunications regulations, and cooperating with law enforcement or regulators if required.
A suspended account will remain in this state until an admin has reviewed and resolved the violation. If the flag was made in error, the suspension will be lifted and full account functionality restored. If you believe your account has been suspended incorrectly, please contact us.
Data collected during moderation
When you save a text-back message, we record the following for compliance review purposes:
- Your company name, sender ID, selected message preset, and the full rendered message
- Whether the message passed or failed automated and AI checks, and any reason provided
- The date and time the message was saved
In the event of an extreme violation, we additionally record:
- Your IP address and browser user agent at the time of the incident
- The identity of any admin who reviews or takes action on the violation
This data is retained for as long as necessary to fulfil our compliance, legal, and abuse-prevention obligations.
Your Rights
Depending on your location, you may have rights including:
- Requesting access to the personal data we hold about you
- Requesting correction of inaccurate information
- Requesting deletion of your information
- Restricting or objecting to certain processing
- Requesting portability of certain data
- Withdrawing consent where processing is based on consent
- Objecting at any time to the use of your personal data for direct marketing
These rights may be subject to legal exceptions. In particular, the right to deletion may be temporarily restricted where your account is under review for an extreme content violation, as described in the Content Moderation and Account Suspension section above. To exercise a privacy right, contact us using the details below. We may need to verify your identity before responding.
If you are in a jurisdiction with a data protection regulator, you may also have the right to lodge a complaint with them.
Children
TextTheCaller is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected information from a child, we will take steps to delete it.
Third-Party Links
Our website may contain links to third-party websites or services. We are not responsible for their privacy practices and your use of them is subject to their own terms and policies.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the policy on our website and, where appropriate, notify you by email. Your continued use of the service after changes are posted constitutes acceptance of the updated policy.
Contact
If you have questions about this Privacy Policy or a privacy-related request, contact us at [email protected].