Skip to main content
Talkala logo
Start calling
Policy

Talkala Privacy Policy

Talkala uses personal data to run accounts, browser calling, prepaid billing, Talkala numbers, received SMS, support, security checks, and public contact forms. The details below explain what is used, why it is needed, who helps process it, and when records may need to be kept.

Effective date:
September 9, 2026

The short version

Account, calling, wallet, and SMS records
Stripe, Twilio, hosting and backend infrastructure providers, Cloudflare, Google, and email providers
Privacy rights and support paths

Controller and privacy contact

Ruben Ruiz Rodriguez, based at C/Los lirios, 23, 03160 Almoradi, Alicante, Spain, is the current controller for Talkala. Talkala has not designated a separate data protection officer. Privacy questions and rights requests should go to the legal contact email.

  • Controller: Ruben Ruiz Rodriguez
  • Address: C/Los lirios, 23, 03160 Almoradi, Alicante, Spain
  • Privacy/legal email: me@rubenruiz.dev
  • General support email: hello@talkala.com

Account, profile, and sign-in data

Talkala keeps the data needed to create, secure, and operate your account. Email/password accounts store password hashes, never plain-text passwords. Google sign-in is optional when configured and stores the Google identity details needed to connect that sign-in to your Talkala account.

  • Account identity, email address, email-verification state, accepted policy versions, and account status.
  • Password hashes, secure password-reset and email-verification records, and hashed request signals used for security limits.
  • Display name, avatar, notification preferences, country and layout preferences, and account settings.
  • Google sign-in identity, name, email, and verified-email state when you choose Google sign-in.

Calling, wallet, number, and caller-ID records

Each call or balance change creates a dated record so Talkala can show your history, calculate charges, handle disputes, and match events with its calling and payment partners. Earlier records are kept instead of being silently overwritten.

  • Call records typically include the destination dialed, timing, outcome, call setup details, billed amount, and reference numbers from Talkala's calling partner when support needs them.
  • Balance records typically include added credit, charges, refunds, amounts set aside during active calls, and related Stripe payment references where applicable.
  • Talkala-number records can include the number, Stripe subscription status, setup reference numbers from Talkala's phone partner when support needs them, received-SMS readiness, and number status.
  • Caller-ID records can include numbers you authorize, verification results, reference numbers from verification calls, status, and failure reasons.

Contacts, inbound SMS, referrals, and notifications

Talkala stores user-facing content when that content is part of an app feature. That includes contact-book entries, text-message bodies for inbound SMS, referral records, and notifications or email summaries needed to operate those features.

  • Contacts can include names, phone numbers, company, email, website, city, notes, tags, favorite status, initials, avatar data, and last-contacted metadata.
  • Received-SMS records can include sender and recipient numbers, message body, timestamps, delivery status, partner reference numbers needed for troubleshooting, message-length details used for billing, and billing totals.
  • Referral records can connect a referrer, referred account, referral code, reward status, qualifying wallet top-up, and the credited reward linked to qualifying activity.
  • Notifications can include category, title, body, whether you marked them read, links, outbound email progress, troubleshooting references from Talkala's mail provider where needed, bounce or spam-report signals from providers, and delivery errors.

Contact, support, and email content

Public contact forms and signed-in support requests process the information needed to route and answer the request. Contact and support emails pass through whichever transactional mail provider Talkala configures for outbound delivery.

  • Public contact forms collect name, reply email, topic, message, bot-check result, and hashed request information used to limit repeated submissions.
  • Signed-in support requests collect topic, priority, subject, reply email, message, signed-in identity, account email, and hashed request information used to limit repeated submissions.
  • Account and notification emails can include operational details such as top-up results, caller-ID events, number events, referral rewards, low-balance warnings, and failed-call notices.
  • Email delivery records can include provider reference IDs, whether the message succeeded, bounced, or prompted a spam complaint, error messages providers return, and whether Talkala attempted follow-up retries.

Browser, device, analytics, and anti-abuse data

Talkala processes browser and request data to keep sessions alive, remember preferences, measure aggregate public-page traffic, prevent abuse, and protect account flows.

  • Essential cookies and browser storage support signing in, accepting policies during account creation, restricted operator-access checks, themes, layouts, profiles, dialer-country preferences, and how public pages behave when you already have a signed-in session.
  • Hashed request signals and rate-limit events help limit repeated sign-up, sign-in, password reset, contact, support, calling, number, wallet, and caller-ID attempts.
  • Optional Cloudflare Turnstile checks on public and account-security forms may use approximate connection details (such as IP address) and typical browser indicators required to distinguish real visitors from scripted abuse.
  • Vercel's hosted analytics records aggregate page-view and navigation data without adding third-party analytics cookies.
  • After you allow optional analytics, Talkala can remember the first public page recorded with your permission and a broad traffic source, such as Google or direct. If you create an account within 30 days, that page and source are saved with your account to measure signups, first connected personal calls, and first successful personal wallet top-ups. Raw search queries, contact details, phone numbers, and payment identifiers are not included in this attribution data.
  • If you choose Accept in the privacy banner, Google Analytics can process page views, interactions, approximate location, and browser or device information. Talkala keeps Google advertising storage and personalization off and does not intentionally send contact details, payment identifiers, call or message content, or account secrets.
  • Coarse country signals can come from request context, calling context, payment context, or operational pricing context. Account records may keep first-seen and latest request country at the country-code level for support and security review; Talkala does not store raw IP addresses for that account-country feature.

Why Talkala processes this data

The main legal bases under the General Data Protection Regulation (GDPR) are contract necessity, legal obligations, legitimate interests, and consent where a specific optional choice requires it. The exact basis depends on the activity.

  • Contract necessity: account access, calling, wallet balance, number subscriptions, inbound SMS, call history, support, and settings.
  • Legal obligation: tax, accounting, payment, regulatory, dispute, and fraud-prevention records where applicable.
  • Legitimate interests: service security, abuse prevention, rate limiting, operational diagnostics, routing controls, cookie-free aggregate analytics, and matching billing or call facts with contracted partners.
  • Consent or user choice: optional Google Analytics, starting-page conversion measurement, and other optional communications or feature choices where the app presents an opt-in or setting.

Providers and recipients

Talkala uses a small provider set to operate the product. These providers process data only where their role is needed for a feature, infrastructure, security, or answering support requests.

  • Stripe: hosted checkout, wallet top-ups, saved payment-method summaries, number subscriptions, invoices, receipts, and billing portal.
  • Twilio: browser voice connection, calls to ordinary landline and mobile networks, caller-ID validation, phone-number setup, inbound SMS delivery, status signals used to finalize durations and charges, and cost information needed for prepaid billing.
  • Application backend services: databases, server functions, and operational processing for accounts, wallets, calling, support, contacts, messages, notifications, pricing, and other product records.
  • Vercel: web hosting, application delivery, cookie-free aggregate traffic measurement, deployment infrastructure, and static asset delivery.
  • Cloudflare Turnstile: optional bot-detection checks on public and account-security forms.
  • Google: optional Google sign-in when configured and consent-based Google Analytics when you allow it.
  • Configured transactional email provider: transactional, support, contact, account-security, and notification email delivery.

International transfers

Talkala is operated from Spain, but the infrastructure and communications providers may process data in other countries, including outside the European Economic Area. Where required, those transfers should rely on the provider's published transfer mechanism, data processing agreement, adequacy framework, standard contractual clauses, or equivalent safeguards.

How long records are kept

Retention depends on the record type. Some app preferences can be cleared from your browser. Operational records can remain longer when needed for account access, billing integrity, tax or accounting duties, fraud prevention, dispute handling, security logs, aligning billed calls with carriers, or legal compliance.

  • Browser preferences generally last until you clear browser storage, they expire, or the app overwrites them.
  • Your optional analytics choice stays in local browser storage until you change it or clear that storage. The starting-page cookie lasts up to 30 days. A page link saved with an account remains until you withdraw it while signed in or the account closes. A decline made while signed out applies to that account on the next sign-in from the same browser. Clearing browser storage alone does not remove an account link; use Cookie settings while signed in. Already sent analytics events follow the analytics provider retention settings and are not recalled by this control.
  • Temporary policy-acceptance cookies expire quickly. Restricted operator-access cookies are short lived.
  • Expired email verification and password-reset request records are deleted after 30 days; rate-limit events after 7 days; signup-security events after 90 days.
  • Payment, wallet, call, number, SMS, referral, support, and security records can remain after a feature is disabled or an account is closed when they are needed for audit, billing, abuse prevention, or legal reasons.
  • Account closure disables access but is not the same as privacy erasure or permanent deletion. Some records can remain because billing, calling, messaging, support, audit, or legal history may still matter.

Your privacy rights

Depending on where you live, you may have rights to access, correct, erase, restrict, object to, or receive a copy of personal data. You can also object to some legitimate-interest processing or withdraw consent where processing is based on consent.

  • Start with the legal contact email or signed-in support when the request is account-specific.
  • Talkala may need to verify your identity before acting on a request.
  • Some records cannot simply be deleted on request because they are tied to billing integrity, fraud prevention, tax, dispute, phone-network records, or security obligations.
  • If you are in Spain or the European Union, you can also raise concerns with your data protection authority. For Spain, that is the Spanish Data Protection Agency (AEPD).

Children and special categories

Talkala is not designed for children, and it is not designed to collect special-category data such as health, religion, biometrics, or political views. Do not include that kind of information in contact notes, support messages, or SMS unless it is genuinely necessary for your own communication.

Automated decisions and fraud controls

Talkala uses automated checks for rate limits, verification gates, pricing availability, account state, route restrictions, caller-ID validation state, and abuse controls. These checks can block a call, form submission, number purchase, wallet action, or account feature. They protect the service, but you can contact support if you think a block is wrong.

Common questions

Related questions

Does Talkala store my full card number?

No. Card details go through Stripe. Talkala stores payment records and payment-method summaries such as brand, last four digits, expiry month/year, Stripe IDs, receipts, and invoice links when needed.

Does Talkala record my calls?

No. Call recording is not part of the product. Talkala keeps dependable call summaries, including timing, outcome, billed amount, and partner reference identifiers where needed for support. It does not keep call audio.

Does Talkala store SMS content?

Yes, for inbound SMS delivered to a number on your account. The inbox cannot function without the message contents and lightweight delivery facts. Outbound SMS is not available in this version.

How do I ask about my data?

Use the legal contact email for privacy requests. If the request depends on a specific account, call, payment, number, or SMS thread, sign in and use in-app support where possible.

Next step

Want the security and product-rules picture too?

Use Security for safeguards, Cookies for browser storage, and Help Center for the operational rules that affect calling, billing, numbers, and support.