1. Who we are and our role
CallBix is operated by CallBix (operated by Thinkbix Technologies Pvt. Ltd.), Sterling Tower, Pancard Club Road, Baner, Pune, Maharashtra, India (“we”, “us”). This policy covers our website (callbix.app), the CallBix web app and the CallBix Android app.
For call data, our customer is in charge. When a business uses CallBix to record and log its team's calls, that business decides what is captured and why. It is the data fiduciary (controller) for that data and we process it on its behalf, under our Terms. If you spoke to a business that uses CallBix, please contact that business about your data; we will help them respond.
For account, billing and website data, we decide how it is used, and this policy describes it.
2. What we collect
- Account data: name, work email, phone number, role, team, password (stored only as a bcrypt hash).
- Call data captured by the app: phone numbers called and calling, contact names from the phone or CRM, call direction, time, duration, SIM slot, and the outcome, notes, follow-ups and custom fields agents enter.
- Call recordings: audio files from the phone's call recorder or the CallBix recorder, when the customer turns recording on.
- CRM data: when a customer connects a CRM, the contact details and fields needed to match calls and show them to agents.
- Device data: phone model, Android version, app version, permission status, a device identifier, and a push notification token.
- Usage and crash data from the app: through Google Firebase Analytics and Crashlytics — which screens and features are used and technical crash reports, linked to an internal user id. We never send phone numbers, names, notes or recordings to analytics.
- Billing data: company name, billing email, GSTIN and invoices. Card and UPI details are handled by Razorpay or Stripe; we never see full card numbers.
- Website and support: what you send through our contact form or email, and basic server logs (IP address, browser, pages requested).
The app only reads calls on the SIMs a user chooses, and only while signed in. Calls on SIMs a user excludes are never read beyond identifying the SIM, and never leave the phone.
3. How we use it
- To provide the service: log and record calls, sync them to the customer's CRM, show caller ID, reports, call lists, targets and notifications.
- To secure accounts and the service, prevent abuse and keep audit records.
- To bill customers, send invoices and account emails (invitations, password resets, trial and daily-report emails).
- To fix bugs and improve the product, using aggregated usage and crash data.
- To answer support and sales enquiries.
- To meet legal obligations, such as tax records.
4. Legal basis
We process account and billing data to perform our contract with the customer and for our legitimate interests in running a secure, reliable service; call data on the customer's instructions; and crash/usage analytics on the basis of legitimate interest. Where the law requires consent — for example, for recording calls in some places — the customer is responsible for obtaining it (see our Acceptable use policy).
6. How long we keep it
- Call recordings are deleted automatically after the retention period of the customer's plan (for example 90 days on Starter), or sooner if the customer deletes them.
- Call history is kept while the customer's account is active, within their plan's history limits.
- When a customer closes their account, we delete their data within 30 days, except invoices and records we must keep by law (usually 8 years for tax records in India).
- Server logs are kept for up to 90 days; crash reports for up to 90 days.
7. Where data is stored
Data may be stored and processed in India and in other countries where our providers operate. When data leaves the country it was collected in, we use providers with appropriate safeguards (such as standard contractual clauses) and do not transfer data to any country the Government of India restricts.
8. Security
We use encryption in transit (TLS), AES-256-GCM encryption for stored CRM credentials, expiring signed links for recordings, role-based access and audit logs. See Security & data processing. No system is perfectly secure; if we learn of a breach affecting your data, we'll tell affected customers and authorities as the law requires.
9. Your rights
Depending on where you live, you can ask to access, correct or delete your personal data, object to or restrict some processing, withdraw consent, get a copy of your data, and nominate someone to exercise your rights if you can't. Signed-in users can update their profile in the app; for anything else, email hello@callbix.app. We reply within 30 days.
If your request is about call data held for a business, we'll pass it to that business. You may also complain to the Data Protection Board of India or your local data protection authority.
10. Grievance officer
In line with India's IT Rules and the DPDP Act: Sachin Yadav, Grievance Officer, Sterling Tower, Pancard Club Road, Baner, Pune, Maharashtra, India. Email hello@callbix.app. We acknowledge complaints within 24 hours and resolve them within 15 days.
11. Children
CallBix is a business tool and isn't meant for anyone under 18. We don't knowingly collect children's data.
12. Changes to this policy
We'll post any change here with a new date, and email account owners about significant changes before they take effect.
Questions about this policy? Write to hello@callbix.app. CallBix (operated by Thinkbix Technologies Pvt. Ltd.), Sterling Tower, Pancard Club Road, Baner, Pune, Maharashtra, India.