Privacy Policy

Last updated: August 23, 2026

تتوفر هذه الوثيقة القانونية حاليًا باللغة الإنجليزية، وتكون النسخة الإنجليزية هي النسخة الحاكمة.

This Privacy Policy explains how Reframe CX, Inc., a corporation organized under the laws of Delaware, United States (“Reframe,” “we,” “us,” or “our”), collects, uses, stores, shares, and protects personal information when you visit our website, use our platform, interact with our AI voice services, communicate with us, or call a business that uses Reframe.

Reframe provides an AI voice platform that helps businesses answer calls, handle customer conversations, collect information, generate transcripts and summaries, route requests, and integrate with business tools such as calendars, booking systems, CRMs, point-of-sale systems, communication platforms, analytics tools, and payment providers.

This Privacy Policy applies to:

  • Visitors to our website.
  • Reframe customers and users, including business owners, admins, staff, and team members.
  • Callers and end customers who interact with AI voice agents powered by Reframe.
  • People who contact us for sales, support, partnerships, hiring, or other business purposes.

If you are calling or interacting with a business that uses Reframe, that business is usually responsible for deciding how and why your personal information is processed. Reframe processes your information on behalf of that business to provide our services.

This Privacy Policy should be read together with our Terms of Service and, where applicable, any Data Processing Agreement, customer agreement, order form, or service-specific terms.

1. Information We Collect

We collect different types of information depending on how you interact with Reframe.

1.1 Information from Reframe customers and users

When a business creates or uses a Reframe account, we may collect:

  • Name.
  • Business name.
  • Business address.
  • Email address.
  • Phone number.
  • Job title or role.
  • Login credentials or authentication information.
  • Billing and payment information.
  • Subscription plan and usage details.
  • Team member information.
  • Workspace settings and account preferences.
  • Business configuration data, such as opening hours, service descriptions, menus, prices, booking rules, escalation rules, FAQs, prompts, and AI agent instructions.
  • Support messages, feedback, and communications with us.

1.2 Information from callers and end customers

When a person calls or interacts with a business using Reframe, we may process information provided during the interaction, including:

  • Caller phone number.
  • Caller name, if provided.
  • Call audio, if recording is enabled.
  • Call transcripts, if transcription is enabled.
  • Conversation summaries.
  • Customer requests, questions, complaints, booking details, order details, appointment preferences, or service needs.
  • Date, time, duration, routing status, and technical metadata of the call.
  • Call routing, escalation, and outcome information.
  • Information submitted through connected channels, forms, messages, or integrations.

Depending on the customer's configuration and the nature of the call, callers may voluntarily provide additional information. Customers should avoid collecting sensitive personal information unless necessary, lawful, and supported by appropriate safeguards.

1.3 Website, product, and device information

When you visit our website or use our platform, we may automatically collect:

  • IP address.
  • Browser type and version.
  • Device type.
  • Operating system.
  • Pages visited.
  • Referring URLs.
  • Approximate location based on IP address.
  • Log data.
  • Cookie identifiers and similar technologies.
  • Usage events, clicks, sessions, and performance information.
  • Error, diagnostic, and security logs.

1.4 Information from third-party services

If a customer connects Reframe to third-party services, we may receive information from those services, including:

  • Calendar availability and booking data.
  • CRM records.
  • POS or order information.
  • Customer profiles.
  • Support tickets.
  • Messaging history.
  • Telephony metadata.
  • Authentication data.
  • Payment, billing, and invoice metadata.
  • Integration configuration and API responses.

The information we receive depends on the customer's settings, permissions, and the third-party service.

2. How We Use Information

We use personal information to provide, operate, secure, improve, and support Reframe.

This includes using information to:

  • Create and manage customer accounts.
  • Provide AI voice agent functionality.
  • Answer, route, transcribe, summarize, and analyze calls.
  • Process bookings, appointment requests, customer inquiries, and business workflows.
  • Generate call insights, analytics, reports, and operational summaries.
  • Connect Reframe with third-party tools and integrations.
  • Provide customer support and respond to requests.
  • Process billing, subscriptions, invoices, and payments.
  • Monitor usage, reliability, quality, security, and performance.
  • Detect, prevent, and investigate fraud, abuse, security incidents, and unauthorized access.
  • Improve our products, features, prompts, user experience, and documentation.
  • Communicate with customers about product updates, service notices, billing, support, security, and administrative matters.
  • Send marketing communications where permitted by law.
  • Comply with legal obligations, enforce our Terms, and protect our rights.

We do not use caller call recordings, transcripts, or customer conversation data to train general AI models unless expressly permitted by the customer, permitted by law, and supported by appropriate safeguards.

3. AI Processing

Reframe uses artificial intelligence and automated systems to help businesses handle conversations.

AI processing may include:

  • Speech recognition.
  • Text-to-speech generation.
  • Natural language understanding.
  • Call classification.
  • Intent detection.
  • Conversation summarization.
  • Sentiment or topic analysis.
  • Suggested next actions.
  • Automated responses based on customer-provided instructions and business data.

AI outputs may not always be accurate, complete, or appropriate. Businesses using Reframe are responsible for reviewing important outputs and deciding when human review or intervention is required.

Where required by law or reasonably expected by callers, customers using Reframe should disclose that callers may be interacting with an AI assistant and that calls may be recorded, transcribed, or analyzed.

4. Call Recording and Transcription

Reframe may enable businesses to record, transcribe, and summarize calls.

The business using Reframe is responsible for:

  • Deciding whether recording or transcription is enabled.
  • Providing legally required notices to callers.
  • Obtaining legally required consents or establishing another lawful basis.
  • Ensuring that its privacy notices explain how caller data is processed.
  • Responding to caller requests about recordings, transcripts, or personal information.

A sample call disclosure may be:

"This call may be answered by an AI assistant and may be recorded or transcribed to help us respond to your request."

The exact wording should be reviewed by legal counsel and adjusted for the customer's jurisdiction and use case.

5. Legal Bases for Processing

Depending on the jurisdiction and context, we may process personal information based on one or more of the following legal bases:

  • Performance of a contract with our customers.
  • The customer's instructions as data controller.
  • Consent, where required.
  • Legitimate business interests, such as operating, securing, and improving the Service.
  • Compliance with legal obligations.
  • Protection of rights, safety, and security.

When Reframe processes caller or end-customer data on behalf of a business customer, the business customer is usually responsible for determining the appropriate legal basis for collecting and using that data.

6. How We Share Information

We do not sell personal information. We may share information in the following circumstances:

6.1 With the business customer

If you call or interact with a business using Reframe, we share call details, transcripts, summaries, recordings, contact details, and related information with that business so it can respond to you and operate its services.

6.2 With service providers and subprocessors

We may share information with trusted vendors that help us provide Reframe, including cloud hosting providers, telephony providers, AI model providers, analytics providers, payment providers, monitoring tools, email tools, support tools, security vendors, and infrastructure providers.

These providers may process information only as needed to provide services to us and are expected to protect the information they process.

6.3 With connected third-party integrations

When a customer connects Reframe to third-party tools, we may send or receive information through those integrations according to the customer's configuration and instructions.

6.4 For legal, safety, and security reasons

We may disclose information if we believe it is necessary to:

  • Comply with law, legal process, court orders, or government requests.
  • Enforce our Terms of Service.
  • Protect the rights, property, or safety of Reframe, customers, callers, users, or others.
  • Detect, prevent, or investigate fraud, abuse, security incidents, or technical issues.

6.5 Business transfers

If Reframe is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to appropriate safeguards.

7. International Data Transfers

Reframe CX, Inc. is a company organized in the United States. We and our service providers may transfer personal information to, store it in, or process it in the United States and other countries, which may have privacy and data-protection laws that differ from those where the information was collected.

Where applicable law requires transfer safeguards, we use legally recognized mechanisms appropriate to the transfer, which may include contractual protections, data processing agreements, transfer assessments, consent, regulatory approvals, licenses, or permits.

Where local law assigns additional cross-border transfer responsibilities, Reframe and the relevant business customer will address those responsibilities under applicable law, the customer agreement, and any Data Processing Agreement.

8. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, to follow a customer’s documented instructions, or as required or permitted by law.

We determine retention periods based on factors including:

  • How long the customer account remains active and which services are requested.
  • The customer’s settings, documented instructions, and contractual requirements.
  • The nature, amount, and sensitivity of the information.
  • Legal, tax, accounting, audit, and regulatory obligations.
  • Security, fraud-prevention, abuse-prevention, and dispute-resolution needs.
  • Backup cycles, technical constraints, and business continuity requirements.

When personal information is no longer needed, we delete or de-identify it, subject to limited retention in backups and records that we must keep for legal, security, fraud-prevention, accounting, or dispute-resolution purposes.

Customers and account users can submit a verified request through our Data Deletion page or contact privacy@reframe.cx or support@reframe.cx. Callers and end customers should usually contact the relevant Reframe customer first. We may retain limited information where required by law or reasonably necessary for security, fraud prevention, dispute resolution, or legitimate business records.

9. Security

We use commercially reasonable administrative, technical, and organizational safeguards designed to protect personal information.

These safeguards may include:

  • Access controls.
  • Encryption in transit.
  • Encryption at rest where appropriate.
  • Logging and monitoring.
  • Role-based permissions.
  • Vendor review.
  • Secure infrastructure practices.
  • Backup and recovery controls.
  • Incident response procedures.

No method of transmission or storage is completely secure. Customers are responsible for protecting their own accounts, devices, passwords, API keys, integrations, and staff access.

10. Your Privacy Rights

Depending on your location and applicable law, you may have rights to:

  • Access your personal information.
  • Correct inaccurate information.
  • Delete your personal information.
  • Restrict or object to processing.
  • Withdraw consent where processing is based on consent.
  • Request data portability.
  • Object to direct marketing.
  • Lodge a complaint with a data protection authority.

If you are a caller or end customer of a business using Reframe, you should usually contact that business directly to exercise your privacy rights. Reframe will support our business customers in responding to valid privacy requests where required by law and contract.

To contact Reframe about privacy, email privacy@reframe.cx.

We may need to verify your identity before responding to a privacy request.

11. Children's Privacy

Reframe is not intended for use by children. We do not knowingly collect personal information directly from children through our website or platform.

Businesses using Reframe should not use the Service to knowingly collect children's personal data unless they have the required legal authority, parental consent where applicable, and appropriate safeguards.

If you believe a child's personal information has been processed through Reframe improperly, contact us at privacy@reframe.cx.

12. Sensitive Personal Information

Reframe is not designed to collect or process sensitive personal information unless expressly agreed, legally permitted, and supported by appropriate safeguards.

Sensitive information may include health information, biometric information, religious beliefs, political opinions, government identifiers, financial account details, precise location, information about children, or other legally protected categories.

Customers must not configure Reframe to collect sensitive information unless they are legally permitted to do so and have implemented appropriate notices, consents, safeguards, and contractual terms.

13. Marketing Communications

We may send marketing emails to business contacts who sign up, request information, attend events, download materials, or otherwise interact with us.

You can unsubscribe from marketing emails by using the unsubscribe link in the email or contacting us at support@reframe.cx. We may still send non-marketing messages related to your account, billing, security, support, or use of the Service.

Customers using Reframe for outbound communications, marketing, or customer engagement are responsible for complying with applicable consent, opt-out, anti-spam, telecommunications, and marketing laws.

14. Cookies and Similar Technologies

We may use cookies, pixels, local storage, and similar technologies to:

  • Keep you signed in.
  • Remember preferences.
  • Improve website functionality.
  • Analyze traffic and usage.
  • Measure marketing performance.
  • Improve security.

You can control cookies through your browser settings. Some features may not work properly if cookies are disabled.

If required by law, we will provide additional cookie notices or consent controls.

14.1 Browser Privacy Signals and Third-Party Tracking

Some browsers offer a “Do Not Track” (“DNT”) signal. Because there is no consistent industry standard for DNT, our website does not currently respond to Do Not Track signals.

We do not sell personal information or share it for cross-context behavioral advertising.

We do not knowingly allow third parties to collect personal information about your online activities over time and across different websites through Reframe for targeted advertising. Service providers may collect data about your use of Reframe for the operational and analytics purposes described in this Privacy Policy.

15. Customer Data Processing Role

For most caller and end-customer data, the business customer determines the purpose and means of processing, and Reframe acts as a service provider or processor.

For data relating to Reframe's own website, sales, billing, security, product analytics, and customer relationship management, Reframe may act as a controller.

Where required, Reframe and the customer may enter into a Data Processing Agreement that describes each party's responsibilities for personal data processing.

16. Data Processing Agreement and Subprocessors

Business customers may request a Data Processing Agreement by contacting privacy@reframe.cx.

We use subprocessors to help provide the Service. These subprocessors may process personal information only as needed to provide their services to Reframe and are expected to maintain appropriate confidentiality, security, and data protection safeguards.

ProviderPurposeLocationData Processed
Google CloudHosting and infrastructureGlobal / regional cloud infrastructure, based on Reframe configurationCustomer data, workspace data, logs, metadata, infrastructure data
Google GeminiAI processingGlobal / regional Google infrastructure, based on Reframe configurationPrompts, transcripts, conversation context, AI instructions, generated outputs
OpenAIAI processingGlobal / regional OpenAI infrastructure, based on Reframe configurationPrompts, transcripts, conversation context, AI instructions, generated outputs
TwilioCalls and call routingGlobal telecommunications infrastructurePhone numbers, call metadata, call routing data, audio where applicable
PostHogProduct analyticsGlobal / regional infrastructure, based on Reframe configurationUsage events, device data, product analytics, session and interaction metadata
StripeBilling and paymentsGlobal payment infrastructureBilling data, payment metadata, customer payment identifiers, invoice metadata
PaymobBilling and paymentsEgyptBilling data, payment metadata, customer payment identifiers, invoice metadata

Reframe may update this subprocessor list from time to time as the Service evolves. Where required by law or contract, Reframe will provide appropriate notice of material subprocessor changes.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by email, dashboard notice, website notice, or another reasonable method.

The updated Privacy Policy will be effective as of the "Last updated" date shown above. Continued use of Reframe after the updated policy becomes effective means you acknowledge the updated policy.

18. Contact Us

For privacy questions, requests, or complaints, contact us at:

Reframe CX, Inc.
Mailing address:
584 Castro St, Suite #4185
San Francisco, CA 94114

Email: privacy@reframe.cx

If required by applicable law, Reframe will appoint and publish details for a Data Protection Officer or designated privacy contact. Until then, privacy inquiries should be sent to privacy@reframe.cx and legal notices should be sent to legal@reframe.cx.