Frontcall

Privacy Policy

Last updated: June 2026

1. Data controller

Frontcall is operated by Guillaume-Amaury Debras, auto-entrepreneur (micro-entreprise), SIRET [SIRET — to be added once registered], [REGISTERED BUSINESS ADDRESS] ("we", "us"). We are the data controller for your account, usage and billing data. For any question about your data, contact us at [email protected].

2. Data we collect

We only collect data necessary for the service to function:

  • Email address (for account creation and login)
  • Account settings you provide (calling script, meeting link, timezone, goals)
  • Lead data you import (names, phone numbers, addresses of your prospects)
  • Payment information processed by Stripe (we never store card numbers)
  • Technical data strictly needed to run the service (session, CSRF)

3. Legal basis for processing

Under the GDPR, we process your data on the following legal bases:

  • Performance of a contract — to provide the service and manage your subscription and billing.
  • Legitimate interest — to keep the service secure and to send you periodic recap emails about your own activity (you can opt out at any time).
  • Consent — where you choose optional features such as Google sign-in.
  • Legal obligation — to retain billing and payment records for the period required by tax and accounting law.

4. How we use your data

Your data is used to:

  • Provide the Frontcall service
  • Manage your subscription and billing
  • Send you essential service notifications
  • Send you periodic activity recap emails (weekly and monthly digests of your own calling activity). You can opt out at any time via the unsubscribe link included in every recap email or from your account settings — no login required for the unsubscribe link.

Your data is never sold or shared for advertising purposes.

5. Leads you import — roles and responsibilities

Frontcall lets you import and manage your own prospect data (the businesses and people you contact). For this lead data, you are the data controller and Frontcall acts as your processor: we process it solely to provide the service to you, never for our own purposes.

As the controller of your prospect data, you are responsible for having a lawful basis to process it (for B2B prospecting in the EU this is typically legitimate interest), for informing the people concerned, and for honouring their rights — including the right to object to prospecting. Frontcall provides export and deletion tools to help you respond to such requests; contact us at [email protected].

6. Cookies

Frontcall only uses cookies strictly necessary for the service to function (session, CSRF). No advertising cookies or third-party trackers are installed.

7. Data retention

Your data is retained as long as your account is active. You can permanently delete your account and all your data at any time, directly from your account settings ("Delete account") — no request needed. Deletion is immediate and irreversible, and cancels any active subscription. You can also contact us by email if you prefer.

If your account stays inactive for an extended period (24 months), we may delete it and its data after notifying you by email. Billing and payment records are retained in anonymised form for the period required by applicable tax and accounting law.

8. Your rights

In accordance with the GDPR, you have the right to access, rectify, erase, restrict, port, and object to the processing of your data. You can erase your account and data yourself at any time from your settings, or contact us at [email protected]. You also have the right to lodge a complaint with your supervisory authority (in France, the CNIL).

9. International data transfers

Our servers are hosted in Europe. However, some of our service providers (see "Third-party services" below) are located outside the European Union, including in the United States. Where your data is transferred outside the EU/EEA, it is protected by appropriate safeguards — Standard Contractual Clauses (SCCs) approved by the European Commission and/or the providers' certification under the EU–US Data Privacy Framework. You can request more details about these safeguards at [email protected].

10. Data security

We implement industry-standard security measures to protect your data, including encrypted connections (HTTPS), hashed password storage, and strict per-account access controls. However, no method of transmission over the Internet is 100% secure. While we do our best to protect your personal information, we cannot guarantee its absolute security. In the event of a data breach that affects your rights, we will notify you in accordance with applicable law.

11. Third-party services

Frontcall uses the following third-party providers to deliver the service. Some are located outside the EU and rely on the safeguards described in section 9:

  • Railway — infrastructure hosting and deployment (United States)
  • Stripe — payment processing and subscription management (United States / Ireland)
  • Resend — email delivery: meeting invitations, weekly and monthly recap digests (United States)
  • Google — optional sign-in, if you choose to log in with Google (United States)

Each provider only accesses the data strictly necessary to perform their service on our behalf and is contractually obligated not to disclose or use it for any other purpose. We encourage you to review their respective privacy policies.