Vox Rail LLC ("Vox Rail," "we," "us," or "our") provides business communications services, including hosted voice services, messaging, voicemail, call recording, transcription, equipment configuration, consulting, customer support, and related services.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with our website, communications services, customer portals, support systems, payment processing, and other interactions with Vox Rail.
1. Scope of This Policy
This Privacy Policy applies to personal information associated with:
- Visitors to the Vox Rail website.
- Prospective and current business customers.
- Customer administrators, employees, contractors, and other authorized users.
- Individuals who call, receive calls from, send messages to, or receive messages from a Vox Rail customer.
- Individuals whose information is included in call records, recordings, voicemail messages, transcriptions, text messages, support requests, or other communications processed through the Service.
- Individuals who receive or pay a Vox Rail invoice.
A business customer may separately determine how and why its employees, callers, message recipients, and other users interact with the Service. In those circumstances, the customer is responsible for providing legally required notices and obtaining legally required permissions for its collection and use of personal information. Individuals associated with a Vox Rail business customer may need to direct certain privacy requests to that business.
This Policy does not govern third-party websites, applications, or services that maintain their own privacy policies, including payment services or applications that a customer independently connects to the Vox Rail platform.
2. Personal Information We Collect
The information we collect depends on how a person interacts with Vox Rail and which services a customer selects.
A. Customer and Business Information
We may collect:
- Business names, trade names, and organizational information.
- Business, service, billing, and emergency-service addresses.
- Names, job titles, departments, and organizational roles.
- Email addresses and telephone numbers.
- Authorized account administrators and contacts.
- Customer security passcodes and authentication information.
- Service selections, quotes, Service Orders, contracts, and account preferences.
- Purchased, assigned, or customer-provided device information.
- Tax-exemption information and other information reasonably necessary for billing, accounting, or regulatory purposes.
- Full legal business name and any applicable trade or assumed business names.
- Federal Employer Identification Number, tax-identification number, business-registration number, or another government-issued business identifier.
- Business type, industry, jurisdiction of formation, operating regions, and business-registration status.
- Physical business address and business website address.
- The name, title, business email address, and telephone number of an owner, manager, authorized representative, or other business contact.
- Documentation or information reasonably necessary to verify the existence, identity, authority, ownership, or operations of a business.
- Telecommunications compliance-profile identifiers, registration identifiers, verification status, rejection reasons, and related carrier or regulatory review results.
- Telephone numbers, brands, calling names, messaging campaigns, and communications use cases associated with a verified business profile.
Vox Rail may collect this information to create, submit, maintain, and update business or compliance profiles with telecommunications providers. These profiles may be used to verify a customer's business identity and authority to use telephone numbers and to support services such as CNAM registration, STIR/SHAKEN caller authentication, branded calling, caller-reputation management, toll-free verification, and application-to-person messaging registration.
B. Website and Inquiry Information
When someone submits a website form, requests a callback, contacts us, or requests information, we may collect:
- Name.
- Email address.
- Telephone number.
- Preferred contact method.
- Service of interest.
- Information included in a submitted message or request.
- The date, time, and technical details associated with the submission.
Please do not include passwords, payment-card information, bank-account information, protected health information, or other unnecessary sensitive information in a general website contact form.
C. Account and Authentication Information
We may collect or generate:
- Usernames and account identifiers.
- Password hashes or other authentication credentials.
- Multifactor-authentication settings.
- Customer security passcodes.
- Login dates, times, IP addresses, and access history.
- Session, authentication, and security tokens.
- Authorized-user roles and permissions.
- Records of account, configuration, and support changes.
Passwords are protected using safeguards appropriate to the applicable system, such as one-way hashing or encryption. Vox Rail personnel generally do not have access to a user's original portal password.
D. Communications and Service-Usage Information
We may collect or process information generated when the Service is used, including:
- Calling and called telephone numbers.
- Message sender and recipient numbers.
- Call and message dates and times.
- Call duration, disposition, routing, and termination information.
- Extension numbers, device assignments, and telephone-number assignments.
- Caller-identification and calling-name information.
- Trunk, queue, ring group, voicemail, conference, and routing activity.
- Call-detail records and call-event records.
- Messaging delivery status and carrier responses.
- Device registrations, IP addresses, network information, and connection status.
- Service configuration, feature usage, and diagnostic information.
- Fraud, abuse, security, and authentication events.
- Approximate, registered, or dispatchable service-location information where required to provide the Service.
Some communications and service-usage information may constitute Customer Proprietary Network Information, commonly called CPNI, under federal law.
E. Communications Content
Depending on the customer's selected services and configuration, we may collect or process:
- Call recordings.
- Voicemail messages and voicemail attachments.
- Automated or manually generated transcriptions.
- SMS, MMS, or other message content and attachments.
- Audio prompts, announcements, greetings, and music supplied by the customer.
- Contact lists and address-book information.
- Fax or other communications content if a supported service is provided.
- Information voluntarily communicated during a support call or recorded communication.
Communications content may contain personal, confidential, or sensitive information about people who do not have a direct relationship with Vox Rail. The customer is responsible for determining when recording, monitoring, transcription, and messaging features may lawfully be used and for providing required notices and obtaining required consent.
F. Emergency-Service Information
To support emergency calling and E911, we may collect and disclose:
- Customer and user names.
- Assigned telephone numbers.
- Registered physical addresses.
- Building, suite, floor, room, or other dispatchable-location information.
- Callback information.
- Records of location registrations and changes.
- Information generated or provided during an emergency call.
Customers are responsible for keeping emergency-service information accurate and promptly notifying Vox Rail when a device, extension, user, or service is moved or reassigned.
G. Device, Network, and Technical Information
We may collect:
- Device manufacturer, model, serial number, and MAC address.
- Firmware and software versions.
- IP addresses and network identifiers.
- SIP registration and authentication status.
- Connection, encryption, VPN, and certificate information.
- Browser type, operating system, device type, and session information.
- Error reports, server events, diagnostic records, and security logs.
- Network performance and service-quality information.
H. Payment and Transaction Information
Vox Rail uses Square or another designated third-party payment processor to issue invoices and process electronic payments.
When a customer receives or pays an invoice, we may receive or maintain:
- Customer name and billing contact information.
- Billing address.
- Invoice number, description, amount, due date, and payment status.
- Payment date and transaction identifier.
- Payment method type, such as credit card, debit card, or ACH.
- Limited payment-method information, such as the card brand, expiration information, or last four digits of a payment method.
- Records showing whether a payment method has been saved or authorized for automatic payment.
- Failed, declined, pending, completed, returned, reversed, refunded, or disputed payment status.
- Chargeback, ACH-return, fraud-review, and payment-support information.
Complete payment-card numbers, bank-account numbers, and banking login credentials are generally collected and processed directly by Square and its financial-service or bank-verification providers rather than stored by Vox Rail. Square may use service providers such as Plaid when a payer links a bank account.
Choosing to save a payment method or authorize automatic payment is optional unless an applicable Service Order states otherwise. Removing a saved payment method or revoking automatic-payment authorization does not cancel the underlying Service or eliminate amounts owed.
I. Support and Business Communications
We may collect and retain:
- Support tickets and correspondence.
- Email, telephone, and portal communications.
- Troubleshooting information and diagnostic results.
- Records of requested and completed configuration changes.
- Customer satisfaction information and feedback.
- Communications relating to billing, collections, disputes, cancellation, and number porting.
Telephone support calls may be documented or recorded when permitted by law and after any legally required notice.
3. How We Collect Information
We may collect information:
- Directly from customers, users, website visitors, and payers.
- From a customer's administrators, employees, contractors, or IT providers.
- Automatically from devices, servers, applications, websites, and communications systems.
- From payment processors, banks, card networks, and fraud-prevention providers.
- From telecommunications carriers, messaging providers, emergency-service providers, and number-portability systems.
- From cloud-hosting, security, support, transcription, backup, and other service providers.
- From public records or other lawful sources when reasonably necessary to prevent fraud, verify information, collect an account, or comply with law.
- From business registries, government records, identity-verification providers, telecommunications compliance databases, and other lawful verification sources.
4. How We Use Personal Information
We may use personal information to:
- Establish, provision, maintain, and terminate customer accounts.
- Provide voice, messaging, voicemail, recording, transcription, emergency calling, support, and related services.
- Route, connect, deliver, and troubleshoot calls and messages.
- Configure and manage telephones, softphones, applications, extensions, telephone numbers, and customer systems.
- Register and update E911 and dispatchable-location information.
- Generate invoices and process, reconcile, refund, or collect payments.
- Administer saved payment methods and automatic payments through our designated payment processor.
- Provide customer support and perform authorized configuration changes.
- Authenticate customers and authorized users.
- Detect, investigate, and prevent fraud, toll fraud, abuse, spam, cybersecurity incidents, and unauthorized access.
- Monitor service reliability, capacity, quality, and performance.
- Maintain records required for billing, taxation, accounting, regulatory compliance, and dispute resolution.
- Comply with court orders, subpoenas, warrants, government requests, and other legal obligations.
- Enforce our agreements and protect Vox Rail, our customers, and other persons.
- Communicate about invoices, outages, maintenance, security, service changes, and account administration.
- Improve our services using aggregated, deidentified, or otherwise lawfully processed information.
- Market communications-related services when permitted by law and, where required, after obtaining customer approval.
- Verify a customer's legal business identity, registration status, authorized representatives, and authority to use assigned telephone numbers.
- Create, submit, manage, renew, and update telecommunications business profiles, compliance profiles, trust products, number registrations, and messaging registrations.
- Support CNAM registration, STIR/SHAKEN caller authentication, branded calling, caller-reputation management, toll-free verification, and A2P messaging compliance.
- Respond to verification requests, correct rejected profiles, investigate inaccurate registrations, and satisfy carrier or regulatory due-diligence requirements.
We do not use the content of customer calls, recordings, voicemail messages, or text messages for unrelated advertising.
5. Customer Proprietary Network Information
Federal law provides customers with rights concerning Customer Proprietary Network Information, commonly called CPNI, and imposes a duty on covered telecommunications and interconnected VoIP providers to protect its confidentiality.
CPNI may include individually identifiable information about the quantity, technical configuration, type, destination, location, and amount of use of telecommunications services. Examples include telephone numbers called, incoming calling numbers, call dates, call times, call duration, call location, service features, and certain billing and usage records.
Vox Rail may use or disclose CPNI without additional customer approval when permitted by law, including when reasonably necessary to:
- Provide and maintain the services to which the customer subscribes.
- Bill for and collect payment for those services.
- Provide customer support and troubleshoot service.
- Protect Vox Rail, customers, users, and other providers from fraudulent, abusive, or unlawful use.
- Respond to lawful process or satisfy another legal obligation.
- Provide or market related communications features when permitted by applicable law.
When customer approval is legally required for another use or disclosure of individually identifiable CPNI, Vox Rail will request the applicable approval. A customer may deny or withdraw such approval without affecting the services to which the customer already subscribes, except where the information is necessary to provide a requested feature or service.
Vox Rail may require appropriate authentication before disclosing CPNI or completing account changes. Customers may contact Vox Rail using the information at the end of this Policy to ask questions about CPNI or withdraw a previously granted CPNI approval.
This Privacy Policy does not replace a separate CPNI notice, approval, authentication, or recordkeeping process when one is required by law.
6. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients for legitimate business, operational, security, and legal purposes.
A. Customer Administrators and Authorized Users
Information associated with a business account may be available to the customer's owners, administrators, managers, IT providers, or other authorized users. This may include call records, recordings, voicemail messages, messages, reports, configuration details, and user activity.
The customer determines who it authorizes to access its account. Individuals should contact their employer or the applicable business customer with questions about that access.
B. Telecommunications, Messaging, and Business-Verification Providers
We may disclose information reasonably necessary to provide and verify communications services to telephone carriers, messaging providers, number providers, mobile carriers, caller-identification providers, caller-reputation services, fraud-prevention providers, business-verification providers, telecommunications compliance databases, and interconnection partners.
Information disclosed for these purposes may include a customer's full legal business name, trade name, Employer Identification Number or other business-registration identifier, business type, industry, physical address, website, operating regions, communications use case, and the name, title, email address, and telephone number of an authorized representative.
These providers may include Twilio and other carriers or communications-service providers used to create and review business or compliance profiles, verify business identity, assign and port telephone numbers, complete calls, transmit messages, authenticate caller identification, detect fraud or abuse, and satisfy telecommunications compliance requirements.
Verified business information, verification status, calling-name information, and associated telephone numbers may be used to support CNAM registration, STIR/SHAKEN caller authentication, branded calling, caller-reputation management, toll-free verification, and application-to-person messaging registration. Calling-name or branded-calling information may be provided to downstream carriers, caller-identification services, and call recipients as part of the applicable service.
Submission of information does not guarantee approval of a compliance profile, a particular STIR/SHAKEN attestation level, successful CNAM display, removal of spam labeling, acceptance by every carrier, or approval of a messaging registration. Review and approval decisions may be made by Twilio, other carriers, business-verification providers, industry registries, or regulatory authorities under their respective requirements.
C. Cloud Infrastructure and Technology Providers
We may use service providers to host, secure, monitor, back up, and maintain the Service. These providers may include Akamai Cloud, formerly Linode, and providers of data storage, system monitoring, security, email, customer support, and backup services.
D. Payment and Financial-Service Providers
We may disclose billing, customer, invoice, and transaction information to Square, banks, card networks, ACH participants, bank-verification providers, fraud-prevention providers, collection providers, accountants, and other parties involved in processing or reconciling payments.
Payment processors may independently collect additional information directly from the payer and process it under their own terms and privacy policies. Information submitted directly to Square is subject to Square's applicable privacy notice.
E. Emergency-Service Providers
We may disclose registered location, telephone number, callback information, customer information, and other necessary data to emergency call-routing providers, public safety answering points, emergency responders, emergency databases, and underlying carriers.
F. Recording and Transcription Providers
When a customer enables transcription or another audio-processing feature, we may transmit applicable audio or communications content to a transcription or processing provider. These providers may include ElevenLabs or another provider selected by Vox Rail.
We submit only the content reasonably necessary to provide the enabled feature. Customers should not enable transcription for content they are not authorized to record, transmit, or process.
G. Professional Advisers and Contractors
We may disclose information to employees, contractors, attorneys, accountants, auditors, insurers, consultants, and other professional advisers who require access for legitimate business purposes and are subject to appropriate confidentiality or legal obligations.
H. Legal Compliance and Protection
We may preserve or disclose information when we reasonably believe doing so is necessary to:
- Comply with applicable law or lawful legal process.
- Respond to a court, government agency, law-enforcement authority, or regulator.
- Investigate fraud, abuse, security incidents, or violations of our agreements.
- Protect the rights, property, safety, or security of Vox Rail, our customers, service providers, emergency responders, or other persons.
- Establish, exercise, or defend a legal claim.
I. Business Transfers
Information may be disclosed or transferred in connection with a proposed or completed merger, financing, acquisition, reorganization, sale of assets, or transfer of all or part of Vox Rail's business. Any recipient will remain subject to applicable legal obligations concerning the information.
7. No Sale of Personal Information
Vox Rail does not sell personal information for monetary compensation. We do not share personal information for cross-context behavioral advertising and do not use CPNI, communications content, or payment information to create advertising profiles for unrelated third parties.
We may disclose information to service providers and communications partners as described in this Policy. Those operational disclosures are not intended as sales of personal information.
8. Call Recording, Monitoring, Voicemail, Messaging, and Transcription
Customers control whether many communications-content features are enabled and how their users employ them. Customers are responsible for:
- Determining whether call recording, monitoring, whispering, barging, voicemail transcription, and messaging may lawfully be used.
- Informing employees, callers, and message recipients as required.
- Obtaining all legally required consent.
- Establishing internal access and retention policies.
- Preventing unauthorized access to communications content.
- Avoiding unnecessary collection of sensitive or regulated information.
Vox Rail processes communications content to provide the features selected by the customer. Automated transcriptions may contain errors and should not be treated as authoritative records.
SMS and MMS messages may be processed by Vox Rail, Twilio, mobile carriers, carrier aggregators, and other messaging providers. Message delivery and filtering may depend on those providers. Message recipients may have legal rights to revoke consent or opt out of future messages. Customers are responsible for honoring those requests and complying with applicable calling and messaging laws.
9. Cookies and Website Technologies
The Vox Rail website uses cookies and similar technologies that are reasonably necessary to:
- Maintain website sessions.
- Protect forms against cross-site request forgery and other abuse.
- Preserve website security and functionality.
- Process submitted forms and requests.
- Diagnose website errors and maintain availability.
These technologies may include a session cookie and a cross-site request-forgery protection token. Essential cookies may be set automatically because the website cannot provide certain functions securely without them.
Browser settings may allow a visitor to block or delete cookies. Blocking essential cookies may prevent forms, logins, or other website functions from operating correctly.
If Vox Rail introduces nonessential analytics, advertising, or tracking technologies, this Policy and any legally required cookie controls will be updated accordingly.
10. Data Retention
Vox Rail retains personal information for the period reasonably necessary to provide the Service, maintain security, meet contractual and legal obligations, resolve disputes, collect amounts owed, and enforce our agreements.
Retention depends on the category of information:
- Customer, Account, and Business-Verification Records: Customer identity, account, service, configuration, business-registration, authorized-representative, compliance-profile, verification-status, and administrative records are generally retained while the account is active and may be retained for up to three years following termination. Particular records may be retained longer when reasonably necessary to maintain a carrier registration, document authorization or verification, respond to a regulatory inquiry, prevent fraud, resolve a dispute, or satisfy a legal, regulatory, accounting, or telecommunications-industry requirement. Telecommunications providers and verification services may retain their own copies according to their respective policies and legal obligations.
- Call-Detail Records: Call-detail records are generally retained throughout the active customer relationship and for up to three years following termination of the applicable account. These records may include calling and called numbers, call dates, times, durations, routing, disposition, and related billing information. Records may be retained longer when required by law, lawful process, an active investigation, or an unresolved dispute.
- Call-Event and Technical Logs: Detailed call-event, system, diagnostic, registration, and technical logs may be retained for a shorter operational or security period unless they are needed to investigate an incident, troubleshoot service, resolve a dispute, prevent fraud, or comply with law.
- Invoices and Payment Records: Invoices, payment status, transaction records, refunds, chargebacks, and accounting records may be retained for the period required by Vox Rail's accounting, taxation, collection, and legal obligations. Square, financial institutions, and payment networks maintain their own records under their respective policies.
- Recordings, Voicemail, Messages, and Transcriptions: Communications content is retained according to the customer's selected configuration, available storage, applicable Service Order, Vox Rail retention settings, and legal requirements. This content may be deleted before the three-year period applicable to call-detail records.
- E911 Records: Emergency-location and E911 records are retained while reasonably necessary to provide emergency calling and may be retained afterward for regulatory, billing, safety, investigation, or dispute-resolution purposes.
- Support Records: Support requests and related records may be retained for up to three years after termination or longer when reasonably necessary to document authorization, configuration history, troubleshooting, a dispute, or a legal obligation.
- Security and Fraud Records: Security logs, access records, fraud alerts, and investigation records are retained for as long as reasonably necessary to investigate incidents, prevent recurrence, protect affected persons, and satisfy legal obligations.
- Website Inquiries: Website inquiries are retained while reasonably necessary to respond, maintain business records, and follow up on requested services.
- Backups: Information in system backups is deleted through ordinary backup rotation. Information removed from active systems may remain temporarily in protected backups until those backups expire or are overwritten.
Customer content may be deleted after expiration of its configured retention period or following account termination. Customers are responsible for downloading information they are legally or operationally required to preserve before cancellation or deletion.
We may retain information longer when required by law, legal process, an unresolved dispute, an investigation, a security incident, or a valid preservation request. We may retain aggregated or deidentified information that no longer reasonably identifies an individual.
11. Data Security
Vox Rail uses reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure.
Depending on the Service and configuration, these safeguards may include:
- Access controls and authentication.
- Multifactor authentication.
- Password hashing or encryption.
- Network firewalls and access restrictions.
- Encrypted administrative connections.
- TLS-protected SIP signaling.
- SRTP-protected media.
- Encrypted OpenVPN or comparable network tunnels.
- Security logging and monitoring.
- Software, firmware, and certificate maintenance.
- Restricted infrastructure and administrative access.
- Protected backups and retention controls.
- Use of established payment processors rather than storage of complete payment credentials by Vox Rail.
Communications may need to be decrypted or processed within Vox Rail-controlled systems to provide routing, voicemail, recording, conferencing, transcription, call queues, supervisor monitoring, and related features.
Encryption between Vox Rail and a carrier applies to the applicable connection and cannot guarantee encryption after a communication enters the public telephone network, a mobile network, an emergency-services network, or another third-party system.
No method of electronic transmission or storage is completely secure. Vox Rail cannot guarantee that information will never be accessed, disclosed, altered, lost, or destroyed despite reasonable safeguards.
If Vox Rail discovers a qualifying breach involving protected information, we will investigate and provide legally required notifications to affected customers, individuals, government agencies, or law-enforcement authorities as applicable.
12. Privacy Rights and Choices
Depending on the person's relationship with Vox Rail and applicable law, a person may have the right to request:
- Access to personal information maintained about them.
- Correction of inaccurate information.
- Deletion of certain information.
- A copy of certain information in a portable format.
- Restriction of or objection to certain processing.
- Withdrawal of consent for processing based on consent.
- Information about categories of information disclosed to service providers.
- Review of a decision concerning a privacy request where applicable.
These rights are not absolute. Vox Rail may retain or continue processing information when permitted or required for service delivery, billing, security, fraud prevention, regulatory compliance, legal claims, record retention, or another lawful purpose.
Vox Rail may verify the requester's identity and authority before responding. Verification may require use of established customer credentials, a security passcode, an address or telephone number of record, or another method appropriate to the sensitivity of the requested information.
If information is controlled by a Vox Rail business customer, we may refer the request to that customer or ask the requester to contact the customer directly. Vox Rail will assist customers with appropriate requests when reasonably required by law or contract.
Requests may be submitted using the contact information at the end of this Policy.
13. Communications Preferences
Customers cannot opt out of communications reasonably necessary to provide or administer the Service, including invoices, payment notices, security alerts, outage notices, maintenance notifications, E911 notices, legal notices, and responses to support requests.
A recipient may opt out of nonessential promotional email by using the unsubscribe method included in the message or contacting Vox Rail. Opting out of promotional communications does not affect operational or transactional communications.
Message recipients may revoke consent or opt out of applicable text messages through methods provided in the message or by contacting the business that sent the message. Because business customers control their own messaging campaigns, requests concerning a customer's messages should ordinarily be directed to that customer.
14. Children's Privacy
Vox Rail's website and services are intended for businesses and organizations and are not directed to children under thirteen years of age. Vox Rail does not knowingly solicit personal information directly from children under thirteen through its website.
Communications processed through a business customer's telephone system may incidentally involve minors. The customer is responsible for ensuring that its use of the Service and its collection of communications involving minors complies with applicable law.
If a parent or legal guardian believes a child submitted personal information directly to Vox Rail through the website, the parent or guardian may contact us to request review and appropriate action.
15. Processing Locations
Vox Rail and its service providers may process or store information in the United States and in other jurisdictions where applicable providers operate. Privacy and data-protection laws may differ between jurisdictions. Vox Rail uses reasonable contractual, technical, and organizational measures appropriate to the nature of the information and services provided.
16. Third-Party Links and Services
The Vox Rail website and Service may contain links to or integrations with third-party websites and services. Vox Rail is not responsible for the independent privacy, security, or data-handling practices of third parties. Individuals should review the privacy policies of those providers before submitting information directly to them.
17. Changes to This Privacy Policy
Vox Rail may update this Privacy Policy to reflect changes in our services, technology, providers, business practices, or legal obligations.
The revised Policy will be posted on this page with an updated effective or revision date. When a change materially affects current customers or the handling of protected information, Vox Rail will provide additional notice when reasonably appropriate or legally required.
18. Contact Us
Questions, concerns, CPNI inquiries, and privacy requests may be submitted to:
Vox Rail LLCEmail: info@voxrail.com
Phone: (208) 996-8380
To protect customer information, Vox Rail may require identity and authority verification before discussing an account, disclosing records, or completing a request.