eTollFree, LLC (“eTollFree,” “we,” “us”) provides toll-free, VoIP, and business phone services. This page has two parts: our Privacy Policy, which explains how we collect, use, and protect your information, and our HIPAA Business Associate Terms, which apply to healthcare customers who share protected health information with us. This page is part of our Terms & Conditions.
Privacy at a Glance
- We don’t sell your personal information to anyone.
- If you opt in to text messages, that opt-in data is never shared with third parties for marketing purposes.
- We only collect what we need to set up your service, keep it running, and bill you accurately.
- We protect your data with encryption in transit and strict access controls.
- You can ask us to access, correct, or delete your information at any time.
- We use industry-standard verification to keep our network free of fraud and robocalls.
Information We Collect
Information you give us
When you sign up or work with our support team, you may give us your name, business name, email address, phone number, billing address, and payment card details (processed securely by our payment processor — we don’t store full card numbers). If you’re ordering certain numbers or services, we may also ask for identity verification (KYC) documents to comply with carrier and regulatory rules.
Information from using our services
Running your service generates call detail records, number usage data, and your routing settings. If you turn on voicemail, call recording, or transcription features, we collect that content too. We also keep a record of your conversations with our support team.
Information collected on our websites
Like most websites, ours collects your IP address, device and browser type, the pages you view, and information from cookies and similar technologies. See the Cookies & Analytics section below for details.
Information from others
We sometimes receive information about you from telecom carriers, number databases, identity and fraud verification services, and our credit and payment partners.
How We Use Your Information
- To provide and operate your numbers, routing, and other services
- To bill you and process payments
- To verify your identity and prevent fraud and robocalls, including KYC checks, STIR/SHAKEN caller ID authentication, and other FCC-required steps
- To provide customer support
- To send you service and account notices
- To send marketing messages, which you can always opt out of
- To improve our websites and services
- To meet our legal and regulatory obligations
How We Share Information
We do not sell or rent your personal information. We share it only in these situations:
- With service providers who work on our behalf, such as payment processors, telecom carriers and number administrators, cloud hosting providers, and CRM, email, SMS, analytics, and advertising partners. Each is bound to protect your information and use it only for the services they provide us.
- With carriers and regulators, as required to provision, port, or register your numbers.
- With law enforcement or in response to legal process, when required by law.
- With a buyer or successor, if eTollFree is involved in a merger or acquisition.
Text Messages (SMS)
If you give us a mobile number and opt in, we may text you about your account, verification codes, and support. Message frequency varies depending on your account activity. Message and data rates may apply. Reply STOP to opt out at any time, or HELP for help.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.
Cookies & Analytics
We use cookies and similar tools to make our site work, understand how it’s used (for example, with Google Analytics), measure advertising performance and support remarketing (for example, with Google, Meta, and LinkedIn), and improve the site with session-replay tools that show us where visitors get stuck.
You can control cookies through your browser settings, and opt out of interest-based advertising using the ad-choice tools offered by these providers. We don’t currently respond to browser “Do Not Track” signals.
How We Protect Your Information
We encrypt data in transit using HTTPS/TLS and limit access to information to staff who need it to do their jobs. Payment cards are handled by a PCI-compliant payment processor — we don’t store full card numbers ourselves. We monitor our systems for suspicious activity.
No system is 100% secure. If a breach occurs, we’ll notify you as required by law.
How Long We Keep Information
We keep your information while you’re a customer, and afterward for as long as needed for business, tax, legal, and regulatory purposes. Call detail records, in particular, have regulatory retention periods we’re required to follow. Once information is no longer needed, we delete or de-identify it.
Your Choices & Rights
You can ask us to access, correct, or delete your information, or opt out of marketing email (using the unsubscribe link) and marketing texts (by replying STOP). Some information must be kept for legal or regulatory reasons even after a deletion request.
To exercise any of these rights, email [email protected]. If you’re a California resident or covered by another state’s privacy law, we honor the rights those laws give you. We won’t discriminate against you for exercising any of these rights.
Children’s Privacy
Our services are built for businesses and adults. They aren’t directed to children, and we don’t knowingly collect information from anyone under 13.
HIPAA Business Associate Terms
These terms apply when a customer that is a HIPAA covered entity, or a business associate of one, uses our services in a way that involves protected health information (PHI). In that case, eTollFree acts as a business associate, and the terms below apply.
Definitions
Terms used here have the same meaning given to them in the HIPAA Rules (the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164). “Business Associate” means eTollFree, LLC. “Covered Entity” means the customer.
Our Obligations
As business associate, eTollFree agrees to:
- Not use or disclose protected health information other than as permitted by our agreement with you or as required by law
- Use appropriate safeguards, including compliance with Subpart C of 45 CFR Part 164, to prevent unauthorized use or disclosure of electronic protected health information
- Report to you any use or disclosure of protected health information not permitted by our agreement, including breaches of unsecured protected health information (45 CFR 164.410) and security incidents, as we become aware of them
- Require any subcontractors that create, receive, maintain, or transmit protected health information on our behalf to agree to the same restrictions and conditions that apply to us (45 CFR 164.502(e)(1)(ii) and 164.308(b)(2))
- Make protected health information available to you as needed to satisfy your obligations under 45 CFR 164.524
- Make amendments to protected health information as you direct, to satisfy your obligations under 45 CFR 164.526
- Maintain and make available the information needed for an accounting of disclosures under 45 CFR 164.528
- Comply with the requirements of Subpart E of 45 CFR Part 164 when carrying out any of your obligations under that subpart
- Make our internal practices, books, and records available to the Secretary of Health and Human Services for purposes of determining HIPAA compliance
Permitted Uses and Disclosures
As business associate, eTollFree may:
- Use or disclose protected health information only as necessary to perform the services set out in our agreement with you
- Use or disclose protected health information as required by law
- Use and disclose protected health information consistent with your minimum-necessary policies and procedures
- Use protected health information for our own proper management and administration, or to carry out our legal responsibilities
We will not use or disclose protected health information in a way that would violate Subpart E of 45 CFR Part 164, except for the uses described above.
Term and Termination
These terms take effect when you begin using our services in a way that involves protected health information, and continue until those services end or you terminate for cause as described below.
You may terminate for cause if we materially violate these terms and don’t cure the violation within 60 days of notice.
When these terms end, we’ll return or destroy any protected health information we hold, where feasible. Where it isn’t feasible to return or destroy it, we’ll keep the same safeguards required under Subpart C of 45 CFR Part 164 for as long as we retain it. Our obligations here survive termination.
Miscellaneous
We may amend these terms as needed to comply with the HIPAA Rules or other applicable law. Any ambiguity in these terms will be interpreted in a way that permits compliance with the HIPAA Rules.
Customers who need a signed Business Associate Agreement can request one at [email protected].
Changes to This Policy
We may update this policy from time to time. The “Last updated” date at the top of this page shows the latest version. If we make a material change, we’ll let you know by email or a notice on our site.
Contact Us
eTollFree, LLC
777 Main Street, Suite 600
Fort Worth, TX 76102
Privacy & compliance: [email protected]
Support: [email protected]
Phone: 1 (800) 233-0234
