Home / Privacy Policy

Privacy Policy

How Ringmere handles personal data, in plain English.

Who we are

Ringmere is an AI phone receptionist for UK service businesses, operated by Peoplely Ltd (company no. 16386277), registered office 71-75 Shelton Street, London, England, WC2H 9JQ, and registered with the UK Information Commissioner’s Office (registration ZC192829). For call data processed on behalf of a business customer, that business is the data controller and Ringmere (Peoplely Ltd) acts as a data processor.

What we process

Account details for business customers, and, on their behalf, caller phone numbers, names, booking details and call transcripts (plus, where the business chooses to enable call recording, audio recordings), needed to answer calls and make bookings. If you ask for a missed call calculator report by email, we also process the email address and the figures you enter, so that we can send it and, only if you ticked the box, follow up once.

Why

To answer calls, book appointments, capture enquiries, prevent spam/fraud, and provide the dashboard and support. By default, callers are told at the start of a call that it is handled by an automated assistant, and that it may be recorded where the business has enabled call recording. A business can switch the automated-assistant disclosure off in its settings, and is responsible for its callers being told.

Who we share data with

We use a small number of vetted sub-processors to run the service, and none of them may use your data for their own purposes, for advertising, or to train general-purpose AI models: Twilio (telephony, SMS/WhatsApp, call recording), OpenAI (real-time voice AI and transcription), Google (Calendar API, for businesses that connect Google Calendar, and for people who sign in with Google), Microsoft (Calendar and Graph API, for businesses that connect Outlook or Microsoft 365, and for people who sign in with Microsoft), Resend (transactional email), Stripe (billing), Fly.io (hosting and database), Cloudflare R2 (encrypted offsite backup storage, EU jurisdiction), Sentry (error monitoring), Meta (WhatsApp Business Platform, for businesses that connect WhatsApp), Google Ads (conversion measurement on our own sign-up), Beds24 (for hotels that connect it as their channel manager: the guest name, phone, email and stay dates needed to hold the room), Cloudbeds (for hotels that connect it as their channel manager: the guest name, phone, email and stay dates needed to hold the room) and postcodes.io (delivery-radius lookup, for food businesses only). Each of them except postcodes.io, which receives only a postcode, is covered by a data-processing agreement: Twilio, Google, Microsoft, Resend, Stripe, Fly.io, Cloudflare R2, Sentry, Meta, Google Ads, Beds24 and Cloudbeds incorporate one into the terms we have accepted, and our agreement with OpenAI is executed. We do not sell personal data to anyone. Every sub-processor above except Google Ads, which receives no customer or caller data, is listed, with what each one receives and where, in Annex B of our Data Processing Agreement.

Where data is processed

Your data is stored in the UK (Fly.io, London region), with backups held in the EU (Cloudflare R2, EU jurisdiction) and encrypted at rest and in transit. Some of the sub-processors above process data outside the UK: Twilio, OpenAI, Resend, Stripe and Sentry operate from the United States; Google, Microsoft, Meta and Google Ads operate globally; Cloudflare R2 holds data in the EU; and where Beds24 and Cloudbeds process data is not yet confirmed. Those transfers rely on UK GDPR transfer safeguards (the UK International Data Transfer Addendum or Standard Contractual Clauses) under each provider’s data-processing agreement. If your organisation needs processing restricted to a particular region, contact info@ringmere.com before you go live so we can tell you what is currently possible.

How we protect it

Data is hosted in the UK (Fly.io, London region), encrypted in transit with TLS and at rest. Sensitive credentials, including Google Calendar and Outlook / Microsoft 365 refresh tokens, are separately encrypted with AES-256-GCM and are never exposed to the browser or to our AI provider. Every business account is tenant-isolated, so access is enforced per authenticated owner on every request, and internal access to personal data is limited to what is needed for support, security or legal purposes.

Google Calendar data

When a business connects Google Calendar, Ringmere requests two scopes: calendar.readonly, to check free/busy availability, and calendar.events, to create, update or cancel the bookings it makes on the business’s behalf. We do not read or store the content of unrelated calendar events. Availability and booking details derived from your calendar are shared with OpenAI, our voice AI provider, only so it can quote available times and confirm bookings during a live call; OpenAI never receives your Google account, credentials or refresh token, and does not use this data to train its models. We do not use Google user data for advertising or sell it. The use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. If a business disconnects Google Calendar, its stored token is deleted immediately and, unless the same Google account is still connected to Ringmere elsewhere, the access it granted is revoked at Google.

Outlook and Microsoft 365 calendar data

When a business connects Outlook or Microsoft 365, Ringmere requests delegated Microsoft Graph permissions: Calendars.ReadWrite, to check free/busy availability and to create, update or cancel the bookings it makes on the business’s behalf, and offline access so it can keep doing so. We do not read or store the content of unrelated calendar events. Availability and booking details derived from your calendar are shared with OpenAI, our voice AI provider, only so it can quote available times and confirm bookings during a live call; OpenAI never receives your Microsoft account, credentials or refresh token, and does not use this data to train its models. Signing in with Microsoft uses only your name, email address and Microsoft account identifier to create or access your Ringmere account. We do not use Microsoft data for advertising or sell it. If a business disconnects its calendar, the stored token is deleted immediately.

Cookies and advertising

This website works without cookies. For visitors in the UK and Europe, no advertising cookie is set unless you accept the optional measurement cookie in the banner; if you decline, Google may still receive an aggregated, cookieless signal that a sign-up happened. For visitors elsewhere, where no consent banner is required, measurement is on by default. The cookie lets Google Ads tell us which of our adverts led to a sign-up; it does not identify you to us and is not used to follow you around other websites. You can change your mind by clearing this site's data in your browser. The signed-in app carries the same measurement tag on the same terms, so that a sign-up can be matched to the advert that led to it; apart from that it uses only the cookies needed to keep you signed in, and one that recognises a browser you have signed in from before, so we can tell you when your account is signed in from a new one.

Your rights

Under UK GDPR you can request access, correction, deletion, restriction or portability of your data. Business customers can action caller requests from the platform. Email info@ringmere.com to exercise your rights.

Retention

Call data is retained only as long as needed for the service and your configured retention period, then deleted. Calculator report requests are kept for up to 12 months and deleted on request.

Contact

For any privacy question or request, contact info@ringmere.com.

Last updated 3 October 2026. This is a plain-English summary; contact info@ringmere.com for our full policy. Our Data Processing Agreement is published at ringmere.com/dpa.