Privacy policy
Last updated 23 September 2026
Sonaline is a business texting and calling service. A business (a workspace) signs up, and its staff use Sonaline to text and call the business's customers. This page explains what information Sonaline handles, why, and what control you have over it.
Who is responsible for what
For the conversations a workspace has with its customers, the business that owns the workspace decides what is sent and kept; Sonaline processes that information on its behalf. For the accounts of the people who sign in, and for this website, Sonaline is responsible.
What we collect
- Account details: the name, email address and phone number of each person with an account, and how they sign in — a password (stored only as a salted hash), passkeys, an authenticator-app secret, or a Google account.
- Messages: the texts, pictures and voice notes sent and received through a workspace's numbers, the phone numbers involved, and when they were sent, along with the notes, assignments and saved replies staff add.
- Calls: call history (numbers, times and durations), voicemail, and recordings where a workspace uses them.
- Contacts: the names and numbers a workspace saves in its contact book, including any brought in from Google Contacts (below).
- Devices: push-notification tokens so the app can alert you to a new message or call, and, if you turn it on, a phone's diagnostic log and crash reports.
- Service logs: the address a request came from, which page or API it asked for, and whether it succeeded, used to keep the service running and secure.
How we use it
Only to provide the service: delivering messages and calls, showing a workspace its own conversations, sending notifications, keeping accounts secure, preventing abuse and runaway spending, and billing the workspace. We do not sell personal information, we do not use it for advertising, and we do not build profiles of the people a workspace texts.
Voice-note transcription and reply suggestions run only when someone asks for them, on the same cloud platform Sonaline runs on, and not through an outside AI company.
Signing in with Google and Google Contacts
If you sign in with Google, we receive your name, email address and profile picture from Google and use the verified email address only to find and open your existing Sonaline account.
If you choose to connect Google Contacts, Sonaline reads your Google contacts' names, phone numbers and organisations so they appear in your workspace's contact book and stay up to date, and writes a contact's name and organisation back to your Google account when someone in your workspace saves or edits it. Sonaline never changes a Google contact's phone numbers, never copies your team's internal notes to Google, and never deletes anything from your Google account. The access Google grants is stored encrypted, and you can disconnect at any time from the app's settings, which revokes it at Google and, if you ask, removes the contacts it brought in.
Sonaline's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the features described above, is not shared except as needed to provide them, and is never used for advertising or to train AI models.
Who we share it with
Only the service providers needed to run Sonaline, and only for that purpose:
- Cloudflare, which hosts the service, its databases and its file storage.
- Telephone carriers and messaging providers, which must carry a text or call to be able to deliver it.
- Google (Firebase Cloud Messaging) and the push service of your browser, to deliver notifications. A notification carries a signal to look for something new, not the message itself.
- Systems a workspace connects, such as its CRM, which receive the workspace's own messages because the workspace set them up to.
We may also disclose information when the law requires it.
How long we keep it
Each workspace sets how long its messages are kept; older messages, their attachments and related notes are deleted automatically every night. Signed-out sessions and expired sign-in links are cleared on the same schedule. When a workspace closes its account, its data is deleted.
Security
All connections are encrypted. Passwords are stored only as hashes, secrets such as connected-account tokens are stored encrypted, and staff can protect their accounts with passkeys or an authenticator app.
Your choices
- If you text a Sonaline business number, reply STOP and that number will not text you again. Reply START to undo it.
- To see, correct or delete information a business holds about you, contact that business; we will help it respond.
- If you have a Sonaline account, you can change your details and disconnect Google in the app, or contact us to have your account deleted.
Children
Sonaline is a service for businesses and is not directed at children under 13.
Changes
When this policy changes, we will update the date at the top of this page, and tell workspaces of any significant change before it takes effect.
Contact
Questions about this policy or your information: hello@sonaline.com.