This policy explains what LineHQ collects, why we need it, and how we protect it. It covers account holders, business customers, callers and people who contact us for support.
1. Who we are
LineHQ ("we", "us") provides UK virtual phone numbers and inbound call handling to businesses. That includes call forwarding, voicemail, optional recording, schedules and virtual receptionist features. You can reach us through our contact form.
2. Controller and processor
For account, billing and support data, LineHQ is the data controller. For caller data that we process for a business customer, such as call metadata, voicemails and recordings, that customer is usually the data controller and LineHQ acts as their processor.
3. What we collect
- Account data - your name, business name, email address and login details.
- Billing data - your package, wallet balance, top-ups and Stripe payment references. We do not store card numbers.
- Number and routing data - the phone numbers you hold and how you route calls.
- Call data - caller and called numbers, timestamps, duration, call status, voicemail and, if enabled, recordings.
- Technical data - IP address, device, browser and log data needed to keep the service secure.
4. How we use it
- To provide the service, including number provisioning, routing, recording, voicemail and billing.
- To prevent fraud and misuse, including spend limits, destination allowlists and account suspension where needed.
- To meet legal and regulatory obligations, including telecoms and accounting requirements.
- To support you and notify you about your account.
- To understand how the website is used, where analytics cookies have been accepted.
5. Call recordings
Where a customer enables recording, callers hear an announcement before recording starts. Recordings are stored on private infrastructure, kept for the retention period set on the account, and deleted when that period ends. See our Call Recording Policy for more detail.
6. Transcription & AI processing
Optional call and voicemail transcription, and the AI summaries generated from those transcripts, are processed in-house on our own UK-based infrastructure. Your call audio, transcripts and summaries are not sent to any third-party AI provider and are not used to train anyone else's models. Transcripts and summaries follow the same retention and access controls as the underlying recording.
7. Sharing & sub-processors
We share data only with the providers needed to run the service, including:
- Wholesale carrier partners - number supply, call termination and porting.
- Stripe - payment processing for wallet top-ups and subscriptions.
- Hosting, email-delivery and error-monitoring providers under contract.
Transcription and AI summarisation are not in this list: we run those on our own infrastructure rather than through an external AI service.
8. International transfers
Some suppliers may process data outside the UK. Where that happens, we rely on UK adequacy regulations, International Data Transfer Agreements or Standard Contractual Clauses.
9. Retention
We keep account and billing records for as long as the law requires, usually six years for financial records. Call recordings follow the retention period set on the account and are then deleted.
10. Your rights
Under UK GDPR you have rights to access, correct, delete, restrict, transfer or object to the use of your personal data. If your request relates to a business customer's caller data, we may need to pass it to that business as the controller. To exercise your rights, use our contact form. You can also complain to the Information Commissioner's Office (ICO).
11. Security
Access is restricted and authenticated. Recordings are stored privately. Secrets are kept outside the codebase, and carrier traffic is limited to known carrier systems.
12. Changes
We will post any changes to this policy on this page and update the date above.