The short version. We do not sell your personal information. We do not sell or share Customer Proprietary Network Information. We do not listen to your calls, and we do not record them unless you switch recording on yourself. We use the data we hold to carry calls, bill accurately, stop fraud, and meet our legal obligations as a carrier — and for very little else.
1. Introduction and scope
CarrierLinkTel (“CarrierLinkTel”, “we”, “us” or “our”) provides voice origination, termination, telephone numbering and call tracking services to business customers in the United States. This Privacy Policy explains how we handle personal information when you:
- visit carrierlinktel.com or contact us through the site, by email or by telephone;
- are an authorised user of an account with us, or an employee or representative of a customer;
- place or receive a call that traverses our network; or
- interact with a telephone number that one of our customers has provisioned through our call tracking platform.
This policy does not apply to the privacy practices of our customers. If you called a business and that business uses our services, the business — not CarrierLinkTel — decides what happens to the information about that call, and its own privacy notice governs. We explain that division of responsibility in Section 2.
2. Our role: controller and processor
Our obligations differ depending on whose data we are handling and why.
| Context | Our role | What that means |
|---|---|---|
| Our website, marketing and sales activity | Controller | We decide what we collect and why. This policy governs in full. |
| Managing your account, billing and support | Controller | We hold business contact and account data to run the commercial relationship. |
| Carrying calls and generating call records | Carrier / controller for regulated purposes | We must create and retain certain records by law, and handle CPNI under federal rules. |
| Call tracking data, recordings and transcripts belonging to a customer | Processor / service provider | We act on our customer’s documented instructions. The customer is responsible for having a lawful basis, giving notice and obtaining any consent. |
3. Information we collect
3.1 Information you give us
- Business contact details — name, job title, company, work email, work telephone number, and the content of enquiries you send us.
- Onboarding and Know Your Customer information — legal entity details, business address, ownership and control information, authorised signatories, a description of your intended use and traffic profile, and evidence of your right to use calling numbers. We collect this because we are required to know who is originating traffic on our network.
- Account and credential data — usernames, hashed passwords, API keys, SIP credentials, authorised IP addresses and multi-factor authentication settings.
- Billing information — billing contact, billing address, tax identifiers, purchase orders and payment method details. Card details are captured and stored by our PCI-DSS compliant payment processors; we do not store full card numbers on our systems.
3.2 Information generated when calls are carried
Operating a voice network necessarily creates records about calls. For each call traversing our network we process call detail records (CDRs) and signalling data, which may include:
- calling and called telephone numbers, and any charge number or redirecting number;
- date, time, duration and time zone of the call;
- call direction, disposition, release cause and whether the call was answered;
- routing information — trunk, carrier, jurisdiction, LRN, rate centre and route taken;
- STIR/SHAKEN attestation level and identity headers;
- technical quality metrics such as jitter, packet loss, latency and codec; and
- the IP addresses of the signalling endpoints involved.
We process the metadata of calls. We do not process the content of calls except in the limited circumstances described in Section 6.
3.3 Information collected automatically from our website
- IP address, approximate city-level location derived from it, browser and device type, operating system, and referring URL;
- pages viewed, time on page, and links clicked;
- cookie and similar identifiers, as described in Section 8.
3.4 Information from third parties
- numbering and routing data from the North American Numbering Plan Administrator, number portability databases and our underlying carriers;
- fraud, sanctions-screening and creditworthiness signals from screening providers;
- traceback and reputation data from the industry traceback process and analytics providers; and
- business contact data from public sources and reputable business-information providers, used only for business-to-business marketing.
4. Customer Proprietary Network Information
Some of the data we hold is Customer Proprietary Network Information (CPNI) — a category protected under Section 222 of the Communications Act and FCC rules. CPNI includes information about the quantity, technical configuration, type, destination, location and amount of use of the telecommunications services you buy from us, together with related billing information.
Our commitments on CPNI:
- We do not sell CPNI. Not to data brokers, not to marketers, not to anyone.
- We use CPNI to provide the services you have purchased, to bill for them, to protect our network and other customers from fraud and abuse, and where the law requires or permits.
- We do not use CPNI to market services outside the category you already purchase without first obtaining the consent that FCC rules require.
- We authenticate callers before discussing CPNI. We will not release call detail information over the telephone to an unauthenticated caller, and we notify the account of record of password, address and authentication changes.
- We maintain internal CPNI training, access controls and record-keeping, and we report unauthorised disclosure of CPNI to law enforcement and affected customers as FCC rules require.
To request access to CPNI associated with your account, or to set your CPNI marketing preference, contact legal@carrierlinktel.com from the email address on the account of record.
5. Call tracking data and callers
Our call tracking platform lets a business understand which of its marketing activities produced a genuine inbound conversation. When our customer uses this platform, we may process on that customer’s behalf:
- the caller’s telephone number and the tracking number dialled;
- date, time, duration and outcome of the call;
- the marketing source attributed to the call — for example campaign, keyword, referring website or landing page — and, where the customer has deployed our dynamic number insertion script on its own website, the visitor identifiers, session data and UTM parameters needed to make that attribution;
- where the customer has enabled it, call recordings, transcripts and conversation analytics.
If you are a caller, not a customer. When you call a business that uses our platform, we handle your information as that business’s service provider. We do not use it for our own marketing, we do not sell it, and we do not build advertising profiles from it. To ask what a particular business holds about your call, or to ask for it to be deleted, contact that business directly. If you cannot identify or reach them, write to legal@carrierlinktel.com and we will route your request to the correct customer and support them in responding.
Our customers are contractually required to provide any notice and obtain any consent that applicable law requires for call tracking, dynamic number insertion and recording — including, where relevant, consent under state wiretap and all-party-consent recording statutes.
6. Call recording and transcription
CarrierLinkTel does not listen to, record or transcribe calls as a matter of course. Recording occurs only where:
- a customer has expressly enabled a recording or transcription feature on its own account, in which case the customer is responsible for announcements, consent and lawful use; or
- we are compelled to assist with lawful interception under a valid legal process, as described in Section 10.
Recordings enabled by a customer are stored encrypted, are accessible only to that customer’s authorised users and to the minimum CarrierLinkTel personnel needed to support the service, and are deleted according to the customer’s configured retention period or on request.
7. How and why we use information
| Purpose | Information used | Basis |
|---|---|---|
| Routing, completing and troubleshooting calls | CDRs, signalling and technical data | Performance of contract; provision of a telecommunications service |
| Rating, invoicing and dispute resolution | CDRs, account and billing data | Performance of contract; legal obligation |
| Fraud prevention, traffic quality and AUP enforcement | CDRs, traffic metrics, authentication logs | Legitimate interests in protecting our network, our customers and consumers |
| Know Your Customer, sanctions screening and traceback response | Onboarding data, CDRs | Legal and regulatory obligation |
| Customer support and service communications | Contact and account data, support correspondence | Performance of contract |
| Providing the call tracking platform | Call tracking data | On documented instructions of our customer, as processor |
| Security monitoring and incident response | Logs, IP addresses, authentication events | Legitimate interests; legal obligation |
| Business-to-business marketing about our services | Business contact data, website analytics | Legitimate interests, subject to your right to opt out at any time |
| Improving network performance and capacity planning | Aggregated and de-identified traffic data | Legitimate interests |
We do not use call content, CDRs or CPNI to train advertising models, to build consumer profiles, or to make automated decisions producing legal or similarly significant effects about individuals.
8. Website, cookies and analytics
Our website uses a small number of cookies and similar technologies:
- Strictly necessary — session integrity, load balancing, security and form protection. These cannot be switched off.
- Preference — remembering your light or dark theme choice. This is stored in your own browser and is never transmitted to us.
- Analytics — aggregate measurement of how the site is used, so we can improve it.
You can block or delete cookies through your browser settings; strictly necessary cookies are required for the site to function correctly. We honour the Global Privacy Control (GPC) signal as a valid opt-out of sale and sharing where applicable law recognises it, and we do not use cross-context behavioural advertising.
9. How we share information
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose information only as follows:
- Underlying and terminating carriers — call signalling and the calling and called numbers must be passed to other carriers in order to complete a call. This is inherent to how the telephone network functions.
- Service providers — data centre and cloud hosting, payment processing, fraud and sanctions screening, email delivery, customer support tooling and professional advisers. Each is bound by contract to use the information only to provide services to us.
- Numbering and porting administrators — where required to assign, port or maintain telephone numbers.
- Regulators, the industry traceback process and law enforcement — as described in Section 10.
- Our customers — where you are a caller and the data belongs to the customer whose tracking number you dialled.
- Corporate transactions — in connection with a merger, acquisition, financing or sale of assets, subject to the acquirer honouring this policy for information transferred.
- With your consent — in any other case, we ask first.
10. Law enforcement and lawful access
As a telecommunications carrier we receive legal demands for subscriber and call record information. Our approach:
- We require valid legal process. A subpoena, court order, warrant or other lawful instrument appropriate to the data sought must be served properly and must be facially valid.
- We disclose the narrowest set of data the process actually compels, and we push back on overbroad, vague or improperly served requests.
- We comply with the Communications Assistance for Law Enforcement Act (CALEA) and with the Stored Communications Act.
- Where we are legally permitted to notify the affected customer of a demand, our practice is to do so, unless notice is prohibited by the process itself or would create a risk to life or to an investigation.
- Emergency disclosures are made only where there is a good-faith belief of an imminent danger of death or serious physical injury.
Law enforcement requests should be directed to legal@carrierlinktel.com.
11. How long we keep information
| Category | Typical retention | Reason |
|---|---|---|
| Call detail records | Up to 24 months | Billing, dispute resolution, traceback and regulatory obligations |
| Billing and financial records | 7 years | Tax, accounting and audit requirements |
| Know Your Customer records | Term of contract plus 5 years | Regulatory and traceback obligations |
| Call recordings and transcripts | As configured by the customer; default 90 days | Under customer control |
| Call tracking attribution data | As configured by the customer; default 13 months | Under customer control |
| Security and access logs | 12 months | Security monitoring and incident investigation |
| Website analytics | 14 months | Site improvement |
| Marketing contact data | Until you opt out, then suppression list only | Honouring your opt-out |
We may retain information longer where a legal hold, investigation, regulatory enquiry or dispute requires it. When retention ends, we delete or irreversibly de-identify the information.
12. How we protect information
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of carrier data, including: encryption of data in transit and at rest; TLS and SRTP for signalling and media where the endpoint supports it; role-based access control and least-privilege provisioning; multi-factor authentication for administrative access; network segmentation between signalling, media and business systems; centralised logging and continuous monitoring; vulnerability management and periodic penetration testing; vendor security review; personnel background checks, confidentiality obligations and security and CPNI training; and a documented incident response plan.
No system is perfectly secure. Where a breach affecting your personal information occurs, we will notify affected customers and regulators as required by applicable law, including the FCC breach notification rules applicable to CPNI and relevant state breach notification statutes. If you believe you have found a security vulnerability, please report it to support@carrierlinktel.com.
13. Your privacy rights
Depending on where you live, you may have the right to:
- Know and access — obtain confirmation of whether we process information about you, and a copy of it;
- Correct — have inaccurate information corrected;
- Delete — request erasure, subject to our legal retention obligations as a carrier;
- Portability — receive certain information in a portable format;
- Opt out — of sale, of sharing for cross-context behavioural advertising, and of profiling. We do not engage in any of these, so there is nothing to opt out of, but the right stands;
- Opt out of marketing — unsubscribe from our business marketing at any time;
- Non-discrimination — we will not deny service, charge a different price or provide a lesser quality of service because you exercised a privacy right;
- Appeal — ask us to reconsider a decision on your request.
To exercise any right, email legal@carrierlinktel.com with “Privacy Request” in the subject line. We will verify your identity in proportion to the sensitivity of the request — for CPNI and call records that verification is necessarily strict — and respond within 45 days, extending once by a further 45 days where reasonably necessary and telling you if we do. An authorised agent may act for you with written permission we can verify. There is no charge unless a request is manifestly unfounded or excessive.
If your request concerns data we process on behalf of a customer, we will forward it to that customer and support them in responding, since they decide the outcome.
14. US state privacy disclosures
This section supplements the above for residents of California and of other states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas and Oregon.
Categories of personal information collected in the past 12 months, using California Consumer Privacy Act terminology: identifiers (name, business email, telephone number, IP address); commercial information (services purchased, billing records); internet and network activity (website usage, CDR and signalling metadata); geolocation inferred at city level from IP or rate centre; professional or employment information (job title, employer); and audio information, only where a customer has enabled recording.
Sources, purposes and recipients are described in Sections 3, 7 and 9. We collect this information for the business purposes listed and disclose it only to the recipient categories listed.
Sale and sharing. We have not sold personal information and have not shared it for cross-context behavioural advertising in the preceding 12 months, and we do not do so today. We do not knowingly sell or share the personal information of consumers under 16.
Sensitive personal information. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit under the CCPA.
California residents may also request, under the “Shine the Light” law, information about disclosures to third parties for their direct marketing purposes. We make no such disclosures.
15. International users and transfers
CarrierLinkTel is based in the United States and our infrastructure is operated in the United States. If you contact us or use our services from outside the United States, your information will be transferred to and processed in the United States, where data protection law may differ from that of your jurisdiction.
Where we process personal information subject to the UK or EU General Data Protection Regulation as a processor for a customer, we do so under a data processing agreement incorporating the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, with supplementary measures as appropriate. Customers who need a signed data processing agreement should write to legal@carrierlinktel.com.
16. Children’s privacy
Our services are sold to businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact legal@carrierlinktel.com and we will delete it promptly.
17. Changes to this policy
We review this policy at least annually and update it when our practices, the services, or the law change. The effective date at the top of this page reflects the current version. Where a change materially affects how we handle your personal information, we will give notice by email to account contacts or by a prominent notice on this website before it takes effect.
18. How to contact us
For any privacy question, request or complaint:
- Privacy and legal: legal@carrierlinktel.com
- General enquiries: info@carrierlinktel.com
- Technical support: support@carrierlinktel.com
- Telephone: +1 (803) 721-4438
- Postal address: CarrierLinkTel, 223 W White St, Rock Hill, SC 29730, United States
If you are not satisfied with our response, you may lodge a complaint with your state attorney general, with the Federal Communications Commission, or — if you are in the UK or EU — with your local supervisory authority. We would ask that you raise it with us first so that we can put it right.