1. Who We Are
Rojo Services LLC, a Puerto Rico limited liability company doing business as Rojoring.com (“Rojo Ring,” “we,” “us,” or “our”), operates the Rojo Ring ringless voicemail platform and the website at rojoring.com (collectively, the “Platform”). This Privacy Policy explains how we collect, use, share, and protect information about visitors to our website, applicants to our private beta, and the businesses (“Customers”) who use the Platform to deliver direct-to-voicemail messages to their own contacts.
This policy applies to information processed by Rojo Services LLC as a business / controller. When we process data on behalf of a Customer (for example, the contact lists a Customer uploads), we act as a service provider / processor under the Master Services Agreement and Data Processing Addendum with that Customer. End recipients of voicemail messages should direct privacy inquiries first to the Customer that contacted them, and may also contact us as described in Section 13 below.
Our four operating commitments— the spine of the program these documents describe:
- Opt-in only. No voicemail is rendered without prior express consent on file, producible on 24-hour notice.
- One contact per recipient per week. A hard platform-wide cap, enforced across every operator.
- IVR opt-out + platform-wide blacklisting. Opt-outs propagate everywhere within ten minutes and are permanent.
- 24-hour traceback. Full per-call provenance returned to any carrier, ITG, FCC, or state-AG request within 24 hours.
See the plain-language summary at rojoring.com/#compliance.
Contact for privacy requests
Rojo Services LLC dba Rojoring.com
J-5 Calle J, Guaynabo, PR 00966
Phone: (636) 346-2037
Email: [email protected]
2. Information We Collect
2.1 Information you give us directly
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, company name, title, business email, business phone, mailing address | Application form, account creation, contracts |
| Verification & KYC | EIN / business registration, government-issued ID for principals, website URL, description of intended use, sample scripts, list-source attestations | Beta application and onboarding |
| Account & billing | Username, hashed password, billing contact, payment method (processed by our payment processor), invoicing history | Account portal |
| Communications | Email and ticket correspondence, sales/onboarding call notes, recorded calls (where lawful and disclosed) | Support and sales interactions |
2.2 Information Customers upload or generate through the Platform
| Category | Examples | Purpose |
|---|---|---|
| Recipient contact data | Phone numbers and, optionally, names and metadata associated with the Customer's own contact list | Required to deliver voicemails the Customer instructs us to deliver |
| Consent records | Timestamp, source, IP address, opt-in language, channel of consent (web form, SMS keyword, signed agreement), and other proof Customers provide for each recipient | Required to verify the Customer has prior express consent under the TCPA |
| Voicemail audio | Audio files the Customer uploads or generates, including any AI-generated voice content | Required to render and deliver the voicemail |
| Campaign metadata | Send windows, throttle settings, caller ID assignments, A/B-test configuration | Required to operate the campaign |
| Delivery telemetry | Per-attempt delivery status, carrier responses, error codes, completion timestamps | Reporting, billing, and compliance audit |
| Suppression data | Recipient opt-outs (STOP/opt-out responses), DNC matches, internal suppression entries | Required to honor opt-outs and DNC obligations |
2.3 Information we collect automatically
- Website analytics: pages visited, referrer, browser, device, approximate location derived from IP, session duration.
- Cookies and similar technologies: see Section 9 and our Cookie Policy.
- Security and abuse logs: IP addresses, login attempts, API request metadata, and audit-trail events on the Platform.
2.4 Information from third parties
- Identity verification and sanctions screening providers used during KYC.
- DNC scrubbing services (National DNC Registry, state DNC registries, and litigator-flag lists).
- Call-analytics and reputation services used to detect anomalous traffic patterns.
- Marketing and enrichment for business contact data used in B2B outreach (no consumer data is enriched this way).
3. How We Use Information
We use information for the following real-world purposes:
- Operate the Platform: render audio, deliver voicemails per Customer instructions, return delivery telemetry, bill for usage.
- Vet Customers: confirm identity, business legitimacy, intended use, and consent posture before activation and on an ongoing basis.
- Enforce compliance: scrub against DNC and suppression lists, apply quiet-hours and throttling rules, monitor traffic for anomalies, respond to industry traceback requests within 24 hours.
- Respond to legal process: comply with subpoenas, court orders, regulator inquiries (including FCC tracebacks and state-AG inquiries), and lawful requests.
- Secure the Platform: detect and prevent fraud, unauthorized access, abuse, and credential stuffing.
- Communicate with Customers: service updates, billing, security advisories, policy changes.
- Improve the Platform: aggregate, de-identified analytics on delivery performance and reliability.
- Sales and marketing, only to business contacts and only as permitted by applicable law.
4. AI and Algorithmic Processing
We disclose AI use plainly:
- A/B-testing analytics use deterministic statistical methods, not generative AI.
- Anomaly detection uses traffic-pattern heuristics and reputation feeds; alerts are reviewed by humans before any automated restriction.
- Voice rendering: when a Customer chooses to use an AI-generated voice, the Customer is solely responsible for having lawful rights in the voice, the script, and the recipients' consent. We do not clone third-party voices without the rightsholder's consent and do not use recipient audio to train any model.
- No training on Customer data: we do not train AI models on Customer-uploaded recipient data, consent records, or voicemail content.
If we add additional AI processing in the future, we will update this section before deployment and notify Customers.
5. How We Share Information
We share information only as follows:
- With service providers under written contract: cloud hosting, telecom carriers and routing partners, DNC and reputation providers, identity-verification providers, payment processor, email and CRM tooling, error-monitoring, and customer-support tooling. A current vendor list is available on request.
- With downstream carriers and intermediate providers as required to deliver voicemail traffic the Customer instructs us to deliver, signed where supported by STIR/SHAKEN.
- With regulators and industry bodies when required by law or in response to an FCC traceback, Industry Traceback Group (ITG) inquiry, state-AG request, or court order.
- In a business transaction such as a merger, acquisition, or financing, with the same protections under the successor entity.
- With Customer consent or at Customer direction.
We do not sell personal information, and we do not “share” personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA and analogous state laws.
6. International Data Transfers
Our infrastructure is operated primarily in the United States, including U.S. territories. If you access the Platform from outside the U.S., your information will be transferred to and processed in the U.S. Where required (e.g., for EEA/UK transfers), we rely on Standard Contractual Clauses.
7. Data Retention
| Data category | Retention |
|---|---|
| Account, KYC, and contracting records | Duration of account + 7 years |
| Consent records (Customer-provided) | Duration of account + 5 years after the last campaign using that consent |
| Campaign metadata and delivery telemetry | 5 years (FCC traceback / Form 499 substantiation) |
| Voicemail audio files | 90 days after last campaign use, unless retained or deleted at Customer request |
| Suppression / opt-out records | Indefinitely |
| Website analytics | 14 months |
| Security and audit logs | 13 months |
When retention ends, we delete or de-identify the data, subject to legal-hold obligations.
8. Your Rights and Choices
Depending on where you live, you may have rights to: confirm whether we process information about you and obtain a copy; correct inaccurate information; request deletion; opt out of “sale” or “sharing” (we do neither); limit use of sensitive personal information; withdraw consent; data portability; not be discriminated against for exercising these rights; appeal a denial.
To submit a request, email [email protected] or write to the address in Section 1. We will verify your identity before fulfilling. We respond within applicable legal timeframes (45 days under most U.S. state laws; one month under GDPR).
Authorized agents may submit on your behalf with appropriate authorization.
9. Cookies
- Necessary cookies keep you signed in and protect against fraud (cannot be disabled).
- Analytics cookies help us understand site usage.
- Marketing cookies enable limited B2B retargeting.
A cookie banner offers granular consent. You can change preferences anytime at rojoring.com/cookies. We honor Global Privacy Control (GPC) signals.
10. Security
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control with least-privilege defaults and audit logs.
- MFA required for staff access to production systems.
- Annual penetration testing and continuous vulnerability scanning.
- Documented incident-response plan with breach notification per applicable law.
11. Children
The Platform is not directed to anyone under 18 and we do not knowingly collect information from children.
12. Notice for California Residents (CCPA/CPRA)
In the last 12 months we have collected the categories of personal information listed in Section 2, from the sources listed in Section 2.4, for the business purposes in Section 3, and disclosed those categories to the service providers listed in Section 5. We have not sold or shared personal information for cross-context behavioral advertising, and we have not knowingly disclosed personal information of minors.
You have the rights described in Section 8. We will not discriminate against you for exercising them.
13. Notice for Recipients of Voicemail Messages
If you received a voicemail through the Rojo Ring platform:
- The voicemail came from a Rojo Ring Customer, not from us directly. The Customer is the controller of the contact list and is responsible under the TCPA for having your prior express consent.
- The Customer should be identified by name and callback number at the start of the message.
- To stop messages from that Customer, follow the opt-out instructions in the voicemail or contact the Customer.
- To stop messages from any Customer through the Rojo Ring platform, email [email protected] with the phone number; we will add it to our platform-wide suppression list within 24 hours.
- To dispute consent, email [email protected] and we will require the Customer to produce the consent record.
14. Changes to This Policy
We will post any update to this policy with a new Effective Date. Material changes will be notified to Customers by email and via a banner on the site at least 30 days before they take effect.
15. Contact
Rojo Services LLC dba Rojoring.com
J-5 Calle J, Guaynabo, PR 00966
Phone: (636) 346-2037
Email: [email protected]