Skip to main content
PortPuffin
  • Home
  • Features
  • Trust
  • Blog
  • Contact
  • Sign in

Privacy Policy

Effective Date: May 4, 2026

Table of contents

  • 1. Information We Collect
  • 2. How We Use Your Information
  • 3. Data Security
  • 4. Voice, Recording, and Transcription
  • 5. TCPA, DNC, and Per-Channel Consent
  • 6. Data Sharing
  • 7. Data Retention
  • 8. Your Rights
  • 9. Cookies and Analytics
  • 10. Changes to This Policy
  • 11. Contact Us

1. Information We Collect

When you use PortPuffin, we collect information you provide directly, including your business name, email address, phone numbers you provision, IVR configuration, and contact directory necessary to operate your business voice service.

When callers reach your phone numbers, we capture the call metadata required to route the call (caller phone number, dialed number, timestamp, duration, status), and — where you have enabled the relevant features — call recordings, voicemail audio + transcripts, and ASR transcripts of caller speech. Recording is gated by per-state two-party-consent law and surfaces a recorded announcement before audio is captured.

We also automatically collect usage data such as IP addresses, browser type, pages visited, and timestamps to improve our services and ensure security.

2. How We Use Your Information

We use your information to route inbound calls per your IVR configuration, deliver voicemails and transcripts, drive the AI receptionist (including ASR, intent classification, LLM orchestration, and TTS playback), generate analytics, and communicate service updates and recovered savings to you.

We may also use your information to send service updates, respond to inquiries, improve our routing and AI algorithms, detect emergency keywords for safety alerting, and comply with legal obligations.

3. Data Security

We implement industry-standard security measures including encryption in transit (TLS), AES-256-GCM encryption at rest for call recordings and transcripts, KMS-managed encryption keys, schema-per-tenant data isolation, access controls, append-only audit logging, and regular security audits to protect your call data and personal information.

4. Voice, Recording, and Transcription

When recording is enabled for a phone number, PortPuffin prepends a state-aware consent announcement to the call before audio is captured. We follow per-state law for two-party-consent jurisdictions (CA, FL, IL, MD, MA, MI, MT, NV, NH, OR, PA, VT, WA, plus DC) and one-party-consent jurisdictions (the remaining 37 states). Recordings are encrypted at rest and retained per your configured retention policy, with a default of 90 days.

Voicemail audio is transcribed via third-party transcription providers (Deepgram, AWS Transcribe). ASR transcripts of in-call caller speech are encrypted at rest using AES-256-GCM. Transcripts may be redacted or hard-deleted at any time via the PortPuffin admin console, subject to legal-hold guards.

Voice cloning is supported only with explicit attestation of rights and is watermarked with PerTH per industry best practice. Cloned voices are subject to DMCA hard-delete on rights challenge.

5. TCPA, DNC, and Per-Channel Consent

PortPuffin enforces TCPA + FCC compliance on outbound contact via a federated Do-Not-Call (DNC) list with five independent sources: the federal DNC registry, per-state registries for all 50 states + DC, your tenant-managed internal DNC list, customer-initiated stop requests, and SMS STOP-keyword enrollments. Before any outbound call or SMS is dispatched, a six-step gate algorithm checks every applicable source.

Consent records are stored per channel (voice, SMS, fax) and per trigger (purpose). Each consent record retains the disclosure language presented at capture time and a cryptographic snapshot of the consent form source, so consent claims are independently verifiable. Tenants who use the platform consent-capture builder (in-store kiosk, web widget, SMS-reply, verbal-recorded, paper-form, and widget-embed sources) cannot delete the disclosed language post-grant — the disclosed text is the customer-facing contractual record.

Every block decision logged by the six-step gate is recorded in an append-only audit trail and is exportable on subpoena within a 60-second response time. The platform supports GDPR Article-15 access requests, CCPA right-to-know + right-to-delete requests, and FCC / TCPA-plaintiff discovery requests via the same evidence-export endpoint. Tenants who explicitly disable DNC enforcement assume liability for the resulting outbound traffic.

Per Phase 20 privacy invariant: full E.164 customer phone numbers are stored only in durable, encrypted storage with strict access controls. On the observability bus (Loki / Mimir / Tempo) only the last four digits are emitted, with the remainder redacted as `customerE164Redacted`. This is enforced regardless of tenant configuration.

Outbound contact to recipients whose locale is unknown defaults to BLOCK (fail-OPEN flag default = false for unknown locales) — preventing accidental cross-border TCPA / GDPR / PECR violations. Tenants may opt in to international outbound dispatch per recipient locale.

6. Data Sharing

We do not sell your personal information. We share call data with CPaaS providers (Twilio, Telnyx) solely for the purpose of completing call routing and number provisioning. We share transcript data with transcription and AI providers (Deepgram, AWS, Anthropic, ElevenLabs) solely for the purpose of generating transcripts and AI receptionist responses. We may also share data with service providers who assist in operating our platform under strict confidentiality agreements.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide services. Call recordings and voicemails follow your configured retention policy (default 90 days). Transcripts default to 365 days for ASR sessions. Audit and operational metadata is retained per regulatory requirements.

8. Your Rights

You have the right to access, correct, or delete your personal information. You may also request a copy of your data, redact specific transcripts, or opt out of non-essential communications. To exercise these rights, contact us at the address below.

9. Cookies and Analytics

We use cookies and similar technologies to analyze site traffic and improve your experience. You can manage cookie preferences through our cookie consent banner. Analytics data is collected only with your consent.

10. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by email or through a notice on our website. Continued use of our services after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this privacy policy or our data practices, please contact us at privacy@portpuffin.com.

PortPuffin

Email: privacy@portpuffin.com

PortPuffin · © 2026 D Town Retail, LLC

Privacy PolicyTerms of Service

PortPuffin

Business phone, voice, and AI receptionist for shipping, mailbox, and print centers.

Product

  • Features
  • Contact

Legal

  • Trust & Security
  • Privacy
  • Terms

Connect

  • LinkedIn
  • X
© 2026 PortPuffin. All rights reserved.Privacy · Terms