Privacy Policy
LAST UPDATED · MAY 20, 2026
Contents
1. Who we are
DialerSeat™ ("we", "us", "our") is an outbound calling platform for sales teams, call centers, and solo agents. We operate the website dialerseat.com and the DialerSeat application. This Privacy Policy explains how we handle information when you visit our website, sign up for an account, or use our platform.
When you use DialerSeat, you act as the data controller for the lead information you upload — you decide what to collect, why, and how long to keep it. We act as the data processor, storing and processing that data on your behalf according to your instructions.
2. What we collect
Account information
When you sign up, we collect:
- Your email address
- Your name (if provided)
- Your password (handled by our authentication provider Clerk — we never see or store passwords directly)
- Your IP address and browser user-agent (for session security)
Payment information
Payments are processed by Stripe. We never see or store your full card number. Stripe gives us back a customer ID, subscription status, and the last four digits of your card for display purposes only. Card data is handled entirely by Stripe under their PCI DSS Level 1 certification.
Lead and contact data you upload
When you upload a CSV or add leads to a campaign, we store:
- Contact names, phone numbers, email addresses, mailing addresses
- Any custom fields you include in your CSV (notes, tags, statuses, etc.)
- The campaign and team the leads belong to
You are responsible for the legality of the lead data you upload. You must have a lawful basis (consent, legitimate interest, prior business relationship, etc.) to call the people on your lists. DialerSeat enforces TCPA calling-window rules on outbound calls, but consent and DNC compliance for the leads themselves is your responsibility.
Call activity data
When you make calls through DialerSeat, we store:
- The phone number dialed
- The outbound caller-ID number used
- Call start time, duration, and disposition
- Agent who made the call
- Any notes you add to the call
- Call recordings (see Section 5)
Usage and technical data
We collect technical information to operate and improve the service:
- Pages you visit on dialerseat.com
- Buttons clicked and features used in the application
- Browser type, device type, screen resolution
- Errors and crash reports (via Sentry)
- IP address (for security and rate limiting)
3. How we use your data
We use the data we collect to:
- Operate the product: Place outbound calls, store your campaigns and dispositions, render dashboards, send your invoices.
- Authenticate you: Log you in, keep your session secure, enforce subscription access.
- Bill you: Charge your card for your weekly subscription, send receipts, handle refunds.
- Support you: Respond when you email us, investigate bugs you report.
- Improve the product: Aggregate, anonymized usage data informs what we build next. We do not analyze individual user behavior for marketing purposes.
- Comply with the law: Respond to lawful subpoenas, court orders, and government requests.
We do not:
- Sell your data to anyone, ever
- Share your data with advertisers
- Train AI models on your call recordings or lead data
- Use your data to compete with you
- Read your call recordings unless you specifically ask us to for support
4. Who we share data with (subprocessors)
We use a small number of trusted providers to run DialerSeat. Each one only receives the minimum data needed to perform their role:
- Supabase (database hosting) — stores all your account, lead, and call data. Privacy policy
- Vercel (application hosting) — runs the DialerSeat web application. Privacy policy
- Clerk (authentication) — handles login, sessions, and password storage. Privacy policy
- Stripe (payments) — processes your subscription billing. Privacy policy
- SignalWire (telephony) — connects your outbound calls and stores call recordings. Privacy policy
- Sentry (error monitoring) — receives error reports with stack traces. PII is scrubbed before transmission. Privacy policy
We may add or change subprocessors as we grow. Material changes will be reflected on this page. We do not share your data with any third party not listed here without your explicit consent or a legal obligation to do so.
5. Call recordings and consent
DialerSeat records outbound calls by default. Recordings are stored in SignalWire's infrastructure and accessible to you in your dashboard.
You are responsible for obtaining consent to record calls in accordance with the laws of the jurisdictions you and your contacts are in. The United States has both one-party-consent and two-party-consent states. International jurisdictions have varying requirements (the EU generally requires two-party consent under GDPR).
We recommend that your call scripts include an early disclosure such as: "This call may be monitored or recorded for quality and training purposes." If a contact requests that recording be stopped, you must comply.
Recordings are retained for 30 days by default, then automatically deleted. You can download recordings before that period expires. We do not analyze the content of your recordings.
6. Data retention
Different types of data have different retention rules:
- Account data: Retained as long as your account is active. If you cancel and don't resubscribe, your data is preserved (we call this "lapsed user data preservation") so you can return later. You can request full deletion at any time — see Your rights.
- Lead and call data: Same as account data — preserved through cancellation, deleted on your request.
- Call recordings: 30 days, then automatically deleted.
- Billing records: Retained for 7 years as required by tax law.
- Error logs and security logs: Retained for 90 days then automatically purged.
7. Security
We protect your data with:
- Encryption in transit: All data flows over TLS 1.3.
- Encryption at rest: Supabase encrypts all stored data at rest using AES-256.
- Authentication: Clerk-managed sessions with industry-standard security.
- Access controls: Only you (and team members you authorize) can access your account data.
- Webhook signature verification: All inbound webhooks (Stripe, SignalWire) are signature-verified to prevent forgery.
- PII scrubbing in error reports: Sentry receives stack traces but not request bodies or headers containing tokens.
- Idempotent payment processing: Stripe events are deduplicated to prevent double-charging.
No system is perfectly secure. If we become aware of a data breach affecting your data, we will notify you without undue delay as required by applicable law.
8. Your rights
Depending on where you live, you may have the following rights regarding your data:
- Access: Request a copy of the data we hold about you.
- Correction: Ask us to correct inaccurate data.
- Deletion: Ask us to delete your account and all associated data.
- Portability: Export your data in a machine-readable format (CSV export of leads and calls is built into the dashboard).
- Objection: Object to specific uses of your data.
- Withdrawal of consent: Withdraw any consent you previously gave.
To exercise any of these rights, email us at privacy@dialerseat.com. We'll respond within 30 days. We may need to verify your identity before processing certain requests.
California residents (CCPA): You have the right to know what categories of personal information we collect, the right to delete it, and the right to opt out of its "sale" (we don't sell data, so this last right is moot — but it's still your right).
EU/EEA/UK residents (GDPR): You have the same rights listed above plus the right to lodge a complaint with a supervisory authority.
9. Cookies and tracking
We use cookies sparingly. The cookies set by dialerseat.com are:
- Authentication cookies (Clerk): Required to keep you logged in. Cannot be disabled without logging out.
- Functional preferences: Stored in localStorage (not cookies) to remember your campaign selection, sidebar state, etc.
We do not use third-party advertising cookies. We do not use Google Analytics, Meta Pixel, or other ad-network trackers on our marketing pages. Internal product analytics are server-side only.
10. Children
DialerSeat is a business tool. It is not directed to children under 16. We do not knowingly collect personal information from anyone under 16. If we learn that we have collected such information, we will delete it. If you believe a minor has used DialerSeat, please contact us at privacy@dialerseat.com.
11. International users
DialerSeat is operated from the United States. If you access the service from outside the US, your data will be transferred to and processed in the US. By using DialerSeat, you consent to this transfer.
For EU/EEA/UK users, transfers rely on either Standard Contractual Clauses with our subprocessors or the user's explicit consent under GDPR Article 49.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we'll update the "Last updated" date at the top of this page. Material changes will be communicated by email to registered users at least 30 days before they take effect.
Your continued use of DialerSeat after a policy update constitutes acceptance of the updated terms.
13. Contact us
Questions about this Privacy Policy, or want to exercise a data right? Email us at privacy@dialerseat.com.
For general support, email support@dialerseat.com.
See also: Terms of Service.