Privacy Policy
Last updated JUNE 2026
Giant Pea Ltd T/A MyFone® Communications (“we”, “us”, “our”) is a UK Limited company (registration number 06491992) registered at 4 Latimer Street, Romsey, Hampshire, SO51 8DG.
This privacy policy covers how we will use, collect and process any personal information provided to us.
Summary
- We are MyFone® Communications, and you can contact us at support@myfone.tel
- We process your data to provide our services to you, to meet our legal obligations, and for our legitimate interests
- We only process your data for as long as we need to, and then we delete it
- We do not sell or share your data with others unless they are providing a service to us (such as payment service providers), or unless you ask us to share your data
- We do not market to you without your consent and, if you give us your consent, you can withdraw it at any time
How we process your data
Throughout your interactions with us we will collect only the data that we require in order to provide you with the service that you are requesting. The key information that we process is shown below for your information:
Records of the calls you make and receive
When you make or receive calls using our service, we process data about them for the purposes of routing the traffic, billing you, calculating what we owe our suppliers, and to attempt to detect and prevent fraud. These are all necessary to provide our service to you. We may also retain these records where we are required by law to do so.
Retention: we retain these records for until such time as you delete the data yourselves, unless we are required by law to retain them for a longer period.
Call recordings and voicemail
If you have configured call recordings and voicemail, we operate these services on your behalf.
Retention: Data stored in the services you have with us will be kept until such time as you delete the data yourselves or you cancel your account. Upon cancellation of an account, we may keep the data for up to 7 days at which point it will be purged from our partners databases.
IP Addresses
When you access any of our websites or our partners servers we will store a record of your IP address along with details of your request in our logs. This information is stored and used by our system team to ensure the integrity of our services.
Retention: This information is stored in rotating logs, which are kept for a minimum of 6 months.
Authorisation & session data
Whenever you login to one of our websites we will use at least two cookies that will identify your session to our services. This is necessary to provide our service to you.
The browser_id cookie is a permanent cookie that uniquely identifies your browser to us and allows us to ensure that previous sessions from that browser are invalidated when logging in again. This is only used for the purposes of invalidating these sessions as well as allowing us to notify you when new sessions are created in new browsers. It is not used for any tracking whatsoever.
The user_session cookie is, initially, a session-only cookie that contains a unique token that identifies your specific session. This data is not stored on our end and is only stored in a hashed form. If you choose to persist your login session, this cookie will be converted to a more permanent cookie with an expiry time at some point in the future. The actual time will depend on the service you are using.
In addition to these cookies, we also store an IP addresses & user agent with your backend session. This allows us to look for anomalies in its use to help us protect your account and our systems.
Retention: This data is stored until such time as the associated user account is deleted.
Your name
We will store the names of individuals who are authorised to access a MyFone® account. Your name may be shared with other contacts on the same account. This is necessary to provide our service to you.
Retention: Your name will be retained until your user account is deleted.
Email addresses
We will store your email address for the purposes of managing your account with us. This will be used for transactional emails that relate directly to your MyFone® account or services. This information is required in order to ensure you are informed about your account and can take appropriate actions in various situations. This is necessary to provide our service to you.
We may also use your email address to send you messages about our services which may include notifications about newly launched features & tools, improvements to existing services, upcoming maintenance as well as information about our services that you we believe you’ll find useful. If you would rather not receive these messages, please let us know or click the unsubscribe link in any of these emails.
We will not send you any other marketing messages unless you subscribe to our newsletter which you can do through our website or our portal. When you do this, you will be consenting with us to use your email address for this purpose. You may withdraw this consent at any time by unsubscribing from the messages or contacting us.
Outgoing emails
If we send you transaction emails (for example: invoice notifications, payment confirmations/ receipts , balance warnings etc…), these will be passed through our partners internal mail server and stored for a period of time to assist with debugging delivery problems and ensuring messages are appropriately delivered to their destinations.
The information stored includes the contents of the message sent, the email addresses of the recipients and any other headers.
Retention: The contents of messages are stored for a period of 30 days from the date the message is received by our mail system. The meta data for any messages is kept for 60 days from this date.
Company name & your postal address
We require your postal address in order to provide you with an invoice for your services. This information is collected as a legal obligation and will be stored on our systems along with invoices for a minimum period of 7 years.
If you order products from us (such as phones), we will use your address to post the items to you. This is necessary to fulfil our contract with you.
Payment cards
We do not store full payment card details on our own servers. We work with an external PCI compliant payment processor who handles this.
We may store the last 4 digits of your card and the card type of our systems so that you can identify which card was used for your payments.
Bank account details
We do not store your full payment card details on our own servers. We work with a third party, Stripe, to securely process payments. When you cancel your account, your Stripe subscription will be cancelled and no further charges will be made once any outstanding balance has been collected.
Your personal data stored with us
When you use our services, you have some options that will allow you to upload personal data that you control. For example, you may add contacts or may use personal data in extension configuration.
In addition to data that is uploaded, you will also be generating personal data in the form of call logs & recordings.
You are the data controller in respect of these personal data, and you are responsible for ensuring that you are compliant with appropriate laws & regulations (for example the General Data Protection Regulation) for all personal data that is stored within any of your MyFone® services or accounts.
Retention: Data stored in the services you have with us will be kept until such time as you delete the data yourselves or you cancel your account. Upon cancellation of an account, we may keep the data for up to 7 days at which point it will be purged from our databases.
Sharing data with the emergency services
When you acquire an incoming phone number from us we will ask you to provide a name & address (known as “Subscriber Information”). We will share this information with BT so they may share it with the emergency services in the event that it is required. If you do not provide subscriber information, we may also disclose other contact details we store on your account in the event that it is requested by the emergency service operator. This is necessary to comply with our legal obligations.
Website analytics
We use Google Analytics to help us track the details of visitors browsing our public websites. We do not use Google Analytics on any URLs once you have been authenticated. We do not send any personal data to Google’s services through Google Analytics and we configure our tracking codes to anonymise any IP addresses. This is necessary for our legitimate interests of understanding the use made of our websites.
Support by email
If you contact us by email or through one of our websites, you will be sharing your contact details (email address and/or phone number) with us for the purposes of responding to your query. This is necessary to provide our service to you.
Retention: We retain all support requests (including the name & contact details of the recipient) that we receive for the purposes of auditing and training of staff.
Support by live chat
If you chat with us on our live chat service, you will be sharing your email address with us for the purposes of sending you a transcript as well as identifying yourself to our support team. This is necessary to provide our service to you.
We also use records of live chats for staff training, to make sure we can offer you the best possible service.
In addition to this information, our live chat system will place a cookie in your browser (named tidio_state_*) which will persist until you quit your browser. This is required to ensure that your live chat can continue between separate page requests to our website.
Retention: We retain transcripts of all live chats (including the name & contact details of the website visitor) for the purposes of auditing and training of staff.
Emails directly to/from our team
If you communicate with our employees directly by email (i.e. not using our normal support channels), we may retain your name & email address in the mailboxes of the employee(s) that you communicate with. This is necessary to provide our service to you.
Retention Employee emails are kept indefinitely. Any emails that contain sensitive data that are delivered by accident will be removed immediately.
MyFone Softphone App
If you use the MyFone Softphone mobile application, we process the following additional data:
SIP credentials and authentication: Your SIP username and password are stored locally on your device to keep you signed in. These credentials are sent securely to our servers to generate session tokens for making and receiving calls. Session tokens expire after one hour and are refreshed automatically.
Device contacts: With your permission, the app reads your device’s contact list to display caller names for incoming and outgoing calls. Contact data is only accessed locally on your device and is not uploaded to or stored on our servers.
Push notification tokens: To deliver incoming call alerts, we register your device with our push notification provider (Apple Push Notification service for iOS, Firebase Cloud Messaging for Android). This involves storing a device-specific token with our telephony provider, Twilio. These tokens do not contain personal information and are used solely to route incoming call notifications to your device.
Microphone access: The app requires microphone access to make and receive voice calls. Audio is transmitted in real time during active calls and is not recorded or stored by the app unless you have separately enabled call recording on your account.
Call history: A record of your recent calls (number, contact name, time, duration, and whether the call was answered or missed) is stored locally on your device. This data is not uploaded to our servers. You can clear your call history at any time by logging out of the app.
Device and platform information: When you sign in, the app sends your device platform (iOS or Android) to our server so we can deliver incoming call notifications via the correct channel. No other device information is collected.
Retention: SIP credentials and call history stored on your device are deleted when you log out of the app. Push notification tokens are deregistered with our telephony provider when you log out.
Cancellation of accounts
When your MyFone® account is cancelled, we will store your account details for a period of 1 month before they are fully removed from our systems.
Correcting your personal data
It is important to us that the information we store is up to date and accurate. You may update your details at any time through our website or by contacting us.
Removal of your personal data
In some cases, you may be able to request that we remove your personal data from our systems. As with correcting your data, you can often delete your data yourselves through our website. In other cases, though, please feel free to contact us.
Your rights
You have a lot of rights, including right to request access to and rectification or erasure of your personal data or restriction of processing of it. You also have the right to object to our processing of your data in some situations, as well as the right to data portability.
Notification of data breaches
Upon discovering any data breaches, we will notify any affected individuals as soon as it’s practical following our data breach notification policy. This policy dictates that in the event of a data breach concerning personal data, the affected parties will be notified by email to the main email address we store with your account.
Electronic storage of data
No method of electronic storage can be 100% secure, however, our partners have sophisticated and detailed security & development policies that govern our systems & applications to help ensure your data is as secure as it can be.
Use of our services by persons under the age of 16
We do not allow anyone under the age of 16 to signup, use or store any personal data with us on any of our services. If we discover or are notified about the presence of a user under this age, we will remove their data from our systems without notice.
Changes to our privacy policy
We may need to make changes to this privacy policy from time to time. All changes will be published to our websites and we recommend reviewing it to stay up to date. If we make any changes that we feel may affect your privacy rights, we will notify you by email or by displaying the information within our customer portal.
Our lawful basis for data processing
Under the General Data Protection Regulation, unless we have otherwise specified above, we will be processing your data in our legitimate interest. These interests include staff training, ensuring the security of our systems and to allow us to operate our business in an efficient manner.
Where our processing is based on consent, you may withdraw consent at any time.
Where our processing is necessary for us to perform our contract with you, or to take steps to enter into a contract with you, we will not be able to enter into a contract with you or deliver our services to you if you do not give us the data in question.
Disclosure of information to law enforcement agencies
We may disclose your information if we are requested to by any law enforcement agency where we believe we are required to comply with the request under any applicable laws.
Data protection authority
You may have the right to lodge a complaint with your local data protection authority or the Information Commissioner’s Office (ICO) in the United Kingdom (our authority).
The ICO can be contacted at: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Other information can be found on their website at ico.org.uk.
Contacting us
If you have any questions about our privacy policy or any other aspects of our services, you may contact us by email on support@myfone.tel