Opens in a new tab
Privacy Policy

How We Handle Your Data

This page explains what personal data we collect across three relationships as a merchant, as a shopper or caller, and as a website visitor. Why we process it, who we share it with, and how long we keep it. Covers your rights in the EU, the UK and the United States.

GDPR-compliant · DPA included automatically · Full rights disclosure

Ruleinside LLC (trading as RuleInside)

Wyoming filing ID 2023-001209068  ·  30 N Gould St, Ste 32376, Sheridan, WY 82801, United States of America

Privacy contact: info (at) ruleinside.com

Questions about your personal data from the European Union: write to info (at) ruleinside.com.

Last Updated: 6 October 2026 Version: 4.5

RuleInside provides AI voice and chat agents for online stores. This policy explains what we do with personal data.

1. Three different relationships: please read this first

How we handle personal data depends on who you are.

If you are a merchant: you have a RuleInside account and pay us for the service. For your own account information we are the data controller: we decide why and how it is used, and this policy governs it.

If you are a shopper or caller: you spoke to an AI agent on a store's website or by telephone. For your data, the store is the data controller and we are its processor. We hold and process your data only on that store's instructions. This policy tells you what we hold and who to contact, but the store decides how your data is used and its own privacy policy governs. You may exercise your rights through either of us; if you contact us we will pass your request to the store and act on their instruction.

If you are visiting our website: you are browsing ruleinside.com, whether or not you are a merchant or a shopper. For that visit we are the data controller and this policy governs it. What we collect depends on the cookie choice you make, and section 2 sets it out in full.

2. What we collect

If you are a merchant

  • Your name and email address
  • Billing information, processed by Stripe; we hold a customer reference, not your card number
  • Records of administrative actions taken in your account, including who took them
  • Ordinary technical data such as your browser's user agent when verifying sign-in

If you are a shopper or caller

  • What you said. We store the recording and the text of your conversation with the agent, both your words and the agent's.
  • When the call began and ended, which agent handled it, and an identifier for the conversation
  • Contact details where the store holds them: name, email address, telephone number, country
  • An automatically generated summary of the call and its outcome
  • Where relevant to the store's use: your product interests, communication preferences, notes, and any opt-out you have given
  • If you ask the agent for a refund: your request, the reason you gave, and the order it concerns. The store receives it by email and you receive an email confirming it was passed on.
  • Sentiment analysis of the call, which includes short excerpts of what you said
  • If you were contacted as part of an outbound campaign: the record of your consent, or the record that we declined to contact you and why

We do not ask for or intentionally store special-category data (health, beliefs, biometrics and similar). We do not create a voiceprint. We hold recordings of what you said; we do not derive a biometric template that identifies you by your voice.

Because a conversation is open-ended, you may mention something sensitive without being asked. We do not solicit it and cannot reliably prevent it. Anything you say is subject to the same retention and deletion rules as everything else on this page.

If you are visiting our website

When you arrive at ruleinside.com we set only what is needed to make the site work and to remember your cookie choice. Everything in the table below runs only if you accept the relevant cookie category, and you can withdraw that at any time from the cookie settings link in the footer.

ToolWhat it does with your visit
Google AnalyticsCounts visits and pages, so we can see what people actually read
Microsoft ClarityRecords how you move through a page (mouse movement, scrolling, clicks) and can replay that session
Meta PixelMeasures whether our advertising on Facebook and Instagram reached you
LinkedIn Insight TagMeasures whether our advertising on LinkedIn reached you
ApolloAttempts to identify the organisation your visit comes from
BrevoRuns the chat window. If you write in it, we receive your message and any contact details you give us

Apollo deserves a plain explanation, because it is not ordinary analytics. It is a business-to-business sales tool. If you accept advertising cookies, it tries to work out which company you are visiting from, and can show us your visit alongside business contact details it already holds independently of this website, typically a work email address or job title. We use it to see which companies are interested in RuleInside. If you would rather that did not happen, decline advertising cookies and it will not run. You can also object at any time under section 7, and we will stop.

Separately from any cookie, our web host records ordinary server data such as your IP address and browser version. That is needed to deliver the page and keep the site secure, and it is not used to advertise to you.

WhatsApp and messaging data

Where a client activates WhatsApp messaging, RuleInside acts as a processor on that client’s behalf and handles the following categories of personal data: the phone numbers of the people the client communicates with, the content of messages sent and received, delivery and read metadata, and, where the client’s WhatsApp Business app is connected in coexistence mode, copies of messages the client’s staff send manually from that app.

We use this data solely to deliver, receive and route messages on the client’s instructions, and to send service reminders the client has configured. We do not use message content to train models, and we do not use it for our own marketing.

Retention differs by what the data is, and section 6 sets out each period. In short: the text of every WhatsApp message is kept for 180 days, whether a shopper sent it, the store sent it through us, or the store’s own staff wrote it from their WhatsApp Business app and we received a copy; and the record that a message happened is kept for as long as the store’s account exists. A client may request earlier deletion at any time, and deletion of the client’s account removes all associated message data.

How the messages travel depends on how the store is set up, and there are two ways. Where the store has connected its own WhatsApp Business Account to RuleInside, messages pass directly between RuleInside and Meta, which operates the WhatsApp Business Platform; ElevenLabs is not in that path. Where the store has not connected its own account, ElevenLabs transmits the messages on our behalf and reaches Meta on our behalf. Both companies are listed in section 4, and each applies its own terms and privacy notice to the transmission.

3. Why we process it, and on what legal basis

PurposeWhose dataLegal basis
Providing the voice-agent serviceShoppers and callersThe store's basis as controller
Operating and billing your accountMerchantsPerformance of a contract
Keeping the service secure and reliableBothLegitimate interests
Proving an opt-out was honouredShoppers and callersLegal obligation
Outbound calls or messagesShoppers and callersConsent, recorded per recipient before contact (except the one message confirming a STOP or START)
Understanding how our website is usedWebsite visitorsConsent
Marketing our own service, and identifying which businesses visit usWebsite visitorsConsent
Replying to a message you send through website chatWebsite visitorsConsent for the chat storage; our legitimate interest in answering you
Delivering the website and keeping it secureWebsite visitorsLegitimate interests

We do not use your data to train AI models. Improving AI models is not a purpose of this service.

Outbound contact is refused unless the checks pass. Before any call or WhatsApp message we check opt-out status, do-not-call suppression and consent. Calls, and marketing messages sent automatically, also wait for the calling hours where you are; a marketing message a store's staff send to you by hand, a code you asked for within the last 24 hours, and messages that are not marketing are not held for the hours. Our AI Disclosure sets out each case. If any check cannot be completed, you are not contacted. The system deliberately fails towards not contacting you.

4. Who else sees the data

We use the following providers. Each processes data only to deliver its part of the service, on our instructions.

Engaged directly by us

ProviderWhat it handles
ElevenLabsRuns the voice agent. Holds the recordings and transcripts.
SupabaseHosts our database, in Ireland
OpenAIGenerates a search embedding when you ask the agent about a product
StripeMerchant payments
ResendSends our email. If you ask a store's agent for a refund, it carries your name, email address, order number, the amount and what you said to the store, and, unless the store has turned it off or you have opted out of its emails, sends you an email confirming the store has your request.
Better StackOperational monitoring and alerts, which can include a contact identifier
VercelHosts the merchant portal

Engaged by ElevenLabs, listed so you can see the whole chain

ProviderWhat it handles
TwilioTelephone connectivity
GoogleThe language model that composes the agent's replies, on some agents
AnthropicThe language model that composes the agent's replies, on other agents
OpenAIMay also compose replies

The language model is chosen per agent, and the platform may complete a reply on a different provider's model when the selected one is slow. The list above names every provider we have observed handling a conversation. A current list is kept at ruleinside.com/sub-processors, and we give at least 14 days' notice before adding or replacing a provider.

WhatsApp. WhatsApp messages are carried by WhatsApp, which is operated by Meta. Where the store has connected its own WhatsApp Business Account to RuleInside, the store has its own agreement with WhatsApp, and WhatsApp acts for the store; we send and receive the store's messages through it. Where the store's messaging runs through ElevenLabs, ElevenLabs reaches WhatsApp on our behalf. In both cases WhatsApp keeps message content for up to 30 days to deliver it.

For our own website only

These run on ruleinside.com, and only if you accept the relevant cookie category. They play no part in the service itself and never receive merchant or shopper data.

ProviderWhat it handles
GoogleWebsite analytics
MicrosoftSession recording on our pages (Clarity)
MetaAdvertising measurement (Meta Pixel)
LinkedInAdvertising measurement
ApolloIdentifying which organisations visit our website
BrevoThe chat window on our website

We do not sell personal data. We do not use it to train our own models, and our providers are contractually restricted to processing it on our instructions.

One qualification, so this is not misread. The advertising tools on our website do pass details of your visit to the advertising platforms named above so we can measure whether our ads worked. United States privacy laws call that "sharing for cross-context behavioural advertising", and although we receive no money for it, we would rather name it than hide behind the word "sell". Declining advertising cookies stops it entirely. None of this applies to shopper or caller data, which is never used for advertising.

5. Where your data is held

Our database is in Ireland, inside the European Economic Area. It holds contact records, call details, our copy of the transcript, consent records and event history.

The voice service is processed in the United States. That is where the recordings and the primary transcript are handled.

Transfers outside the EEA and the UK are covered by the Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum where UK data is involved, or by a provider's certification under the EU-U.S. Data Privacy Framework where it holds one. ElevenLabs, who hold the recordings, are certified under the EU-U.S. Data Privacy Framework, the Swiss-U.S. Framework, and the UK Extension.

Where a website tool listed in section 4 processes data outside the EEA or the UK, the same safeguards apply to it.

You can ask us for a copy of the safeguards that apply, at info (at) ruleinside.com.

6. How long we keep it

Deletion runs automatically on a schedule, except where a row below says it is done on request.

WhatKept for
Conversation text (our copy)180 days
Text of a WhatsApp message: sent by a shopper, sent by the store through us, or written by the store’s own staff in their WhatsApp Business app and copied to us180 days, then deleted automatically
Record of a WhatsApp message (who, when, direction, type), without its textFor as long as the store’s account exists; deleted with it
Call records and interaction history365 days
Sentiment analysis365 days
Event history365 days
Delivery logs30 days
Call recordings held by ElevenLabs90 days
Conversation records held by ElevenLabs365 days. Where a store uses an ElevenLabs account of its own that it brought to RuleInside, ElevenLabs keeps them for the period set in that account, on the store’s instructions.
A merchant’s own RuleInside account (name, email address, billing details)While the account is open. When the merchant asks us to close it, deleted within one month, except the billing records below and the invoices issued through our Stripe account, which cannot be deleted and are kept with no end date. Closing the account also ends the service of any store it pays for; that store’s data is then deleted as described below the table.
A store’s billing records (minutes used and bought, the references to its invoices, agent orders), which hold no shopper dataDeleted 5 years after the rest of the store’s data

Cookies on our own website expire on the timescales shown in the cookie banner's preferences panel, which lists every cookie individually and is kept up to date automatically. Data already held by the website providers in section 4 is kept under each provider's own schedule; withdrawing your consent stops any further collection from that point.

If a store stops using RuleInside, it has 30 days to export its data. After that we permanently delete everything we hold on its behalf, including the conversation records held by ElevenLabs, unless the law requires us to keep something (its billing records, listed in the table above).

Two things we want to be straightforward about. First, ElevenLabs, not us, holds the primary copy of recordings and transcripts. When a retention period is reached we delete their copy first and our own record only after that succeeds. One exception: for a small number of conversations from early June 2026, made before each store had its own ElevenLabs account, we hold the transcript text and may no longer be able to reach the ElevenLabs copy. We are closing that gap, and you can ask us about any of them at info (at) ruleinside.com.

Second, while the store uses RuleInside, we keep three things longer, and only these: records of do-not-call requests, records of consent given or withdrawn, and records of when we declined to contact someone. We keep them precisely so we can prove your opt-out was honoured. Deleting them would destroy the evidence that protects you. They are always included when you ask what we hold. When the store stops using RuleInside, they are included in its export and deleted with the rest of its data after the 30 days.

7. Your rights

You may ask us to:

  • Tell you what we hold about you, and give you a copy
  • Correct anything inaccurate
  • Delete your data
  • Restrict or object to processing
  • Withdraw consent at any time, where processing is based on it
  • Receive your data in a structured, commonly used, machine-readable format

How deletion works in practice. We delete your data from our own database and from ElevenLabs. If ElevenLabs cannot be reached we keep our record rather than delete it, so that your data does not survive somewhere we can no longer point at, and the deletion is retried until it completes. We will tell you if this happens.

What survives a deletion request, and why: do-not-call entries, consent records, and records of contact we declined. Deleting these would lose the proof that you asked not to be contacted, and you could be contacted again. This is permitted under Article 17(3)(b) GDPR. When a merchant closes their own account, the billing records listed in section 6 and the invoices issued through our Stripe account are also kept. Everything else goes.

If you are a shopper or caller, the store you spoke to is the controller, so contacting them is usually fastest. You may contact us and we will act on their instruction.

To make a request, write to info (at) ruleinside.com. We respond within one month. If your request is complex we may extend that by up to two further months, and we will tell you within the first month if we do.

We may ask you for information to confirm your identity before we act, usually the telephone number or email address associated with the conversation. We use it only to check your identity and delete it afterwards.

8. AI and recorded calls

When you speak to one of our agents, you are speaking to software, not a person. The agent tells you this at the start of the conversation. It also tells you that the call is recorded: in the same opening words or, where the store has chosen it, in its second or third reply. If you tell the agent that you do not want to be recorded, we delete our recording and transcript of that call, normally within two days (a store that keeps its own copy of its calls is responsible for that copy). If you would rather not speak to an AI, end the call; you are never obliged to continue. You may also ask to be put through to a person.

More detail is at ruleinside.com/ai-disclosure.

9. Automated decisions

The agent can book appointments, look up orders and record what you asked for. It does not make final decisions about you. Refunds are never processed automatically: a person at the store approves them. You can always ask for a person to handle your request.

10. Security

Access is separated per store, so one store can never reach another's data. Credentials are held in a secrets vault rather than in code. Access to personal data requires a cryptographically signed token issued by our servers; a caller ID alone is never accepted as proof of identity, because it can be spoofed. Records of administrative actions cannot be altered or deleted by the systems that create them. Data is encrypted in transit and at rest.

If a personal data breach occurs, we notify the affected store without undue delay so that it can meet its own obligations, and we notify individuals directly where the law requires it.

11. Complaints

Please tell us first: write to info (at) ruleinside.com with "Complaint" in the subject line. We will acknowledge within 30 days and tell you what we intend to do.

You can also complain to a data protection authority, in particular in the country where you live or work, or where you believe the problem happened (Article 77 GDPR; in the United Kingdom, section 165 of the Data Protection Act 2018). In Italy that is the Garante per la protezione dei dati personali (garanteprivacy.it); in the United Kingdom, the Information Commission (ico.org.uk).

12. United Kingdom

For people in the UK this policy applies as written, read against the UK GDPR and the Data Protection Act 2018, with these additions:

  • Your rights are the same as those in section 7 and are exercised the same way.
  • You may complain to us directly and we will acknowledge within 30 days, under section 103 of the Data (Use and Access) Act 2025.
  • If you are not satisfied you may complain to the Information Commission.
  • Transfers out of the UK rely on the UK International Data Transfer Addendum, or on a provider's certification under the UK Extension to the EU-U.S. Data Privacy Framework.

13. United States

California. If you are a California resident, the California Consumer Privacy Act gives you the right to know what personal information we collect and why, to have it deleted, to correct it, to opt out of its sale or sharing, to limit the use of sensitive personal information, and not to be treated differently for exercising any of these rights. We do not sell or share personal information as those terms are defined by the CCPA. The categories we collect are in section 2.

Other states. Several other states give residents comparable rights. Rather than maintain a state-by-state list, we extend the rights described above to every resident of the United States.

To exercise a right, write to info (at) ruleinside.com with "US Privacy Request" in the subject line. We respond within 45 days and will tell you if we need the permitted extension.

Recorded calls. Some states require every party to a call to consent to it being recorded. Our agents announce the recording early in the call: in their opening words or, where the store has chosen it, in their second or third reply. Stores using our service are contractually required to comply with the recording laws that apply to the people they call.

14. Children

The service is not directed at children and we do not knowingly collect their personal data. If you believe a child's data has reached us, write to info (at) ruleinside.com and we will delete it.

15. Changes to this policy

We will post any change on this page and update the date at the top. We notify merchants of material changes directly, at least 30 days in advance. Adding or replacing a provider listed in section 4 follows the at least 14 days' notice given there instead.