Skip to content
Markets open
Legal

Privacy Policy

What personal data PacketExchange collects, why, who it is shared with, how long it is kept and the rights you have over it.

Last updated
14 September 2026
Version
2026-09-14
Applies to
Members, visitors and people whose calls we carry

Who we are

Minutes Network FZ-LLC, registered in the Ras Al Khaimah free zone, United Arab Emirates (Licence No. 47016932), runs the PacketExchange platform (the “Platform”) and is the controller of personal data about account holders, their team members, website visitors and people who contact us. Our UK and EU contact is Minutes Network Limited, Leeds, United Kingdom (company no. 13955776).

When we carry calls and messages for a member, or store recordings, messages and contact lists for them, we act on that member’s behalf as their processor under our Data Processing Addendum. If your question is about how a member uses your data, for example a call you received from them, contact that member. We will help them respond.

For anything in this policy, contact support@packetexchange.io.

What we collect

CategoryWhat it includesWhere it comes from
Account detailsName, email address, company, phone number, country, profile photo, tax ID and tax country.You and your team
Sign-in and securityYour password (stored only as a one-way hash), two-factor settings, your Google account ID if you sign in with Google, sign-in times, IP addresses and browser details.You, your browser and Google
PaymentsTop-ups, invoices and withdrawals, the wallet address or bank details you give for payouts, and blockchain transaction IDs. Our card payment processor collects card details; we keep only a reference to the card.You and our payment providers
Call and message recordsCalling and called numbers, caller ID, times, duration, route, price, IP addresses, call signalling and call quality measurements.Created as traffic passes through the Platform
Message contentThe text of SMS messages sent or received through the Platform.Members and the people they message
Content members storeCall recordings, voicemails, call menu prompts and audio files, dialer contact lists, do-not-call lists, AI agent instructions and rate sheets.Members
Activity on the PlatformAPI requests (endpoint, time, IP address and result) and account actions such as purchases, settings changes and approvals.Created as you use the Platform
CommunicationsSupport requests, emails with us and status page subscriptions.You
Website visitsThe pages you view, the site or campaign that sent you, your country (looked up from your IP address, which is not stored), your device type (computer, phone or tablet) and a code that changes every day, so we can count visitors without storing an identifier in your browser. If you allow Analytics, also a random visitor ID. If you sign up, the campaign that brought you is kept with your account.Your browser

How we use it

PurposeLegal basis under the UK and EU GDPR
Providing the Platform: running your account, carrying and billing traffic, storing your content and paying out earningsPerforming our contract with you
Protecting the Platform and the telephone network: detecting fraud, artificial traffic and account takeover, blocking abusive traffic and enforcing our policiesOur legitimate interests, and those of other members and carriers, in security and fraud prevention
Meeting legal obligations: tax and accounting records, sanctions rules, lawful requests from authorities and US voice complianceLegal obligation
Communicating with you: service, billing and security emails, status updates you subscribe to and replies to support requestsPerforming our contract with you, or your consent for status subscriptions
Improving the Platform: understanding how features are used, fixing faults and producing market statistics that identify no oneOur legitimate interests in running and developing the Platform
Measuring our website and marketing: counting visits, and seeing which pages and campaigns lead to signupsOur legitimate interests, for counts that store nothing in your browser; your consent, for the Analytics visitor ID and for Advertising

We do not sell personal data. If you allow Advertising cookies, the ad platforms we use learn that you arrived from one of their ads and whether you then signed up, verified your email, created an API key, made a first API call or topped up (with the amount), so we can see which ads work. Without that permission nothing about you is shared with them. We do not use call audio, recordings or message content to train AI models.

AI features

Some features use AI. When you use one, the content it needs is sent to an AI provider to produce the result:

  • AI voice agents. The live audio of the call is converted to text, answered by an AI model and converted back into speech.
  • Imports. Rate sheets and contact lists you upload are read by an AI model so they can be imported.
  • Assistants. The support assistant and the assistants in the dialer and the Switch read your questions and the account information needed to answer them.

None of these features makes decisions about you that have legal or similarly significant effects. Fraud and traffic controls can block calls or hold funds automatically, and a person reviews any suspension or withheld payout if you ask.

Who we share it with

  • Service providers that run parts of the Platform for us, under contracts that limit what they can do with the data. They are listed by category below.
  • Carriers and other members. The carriers and sellers that carry a call or message receive the numbers, caller ID and signalling needed to connect it. Buyers and sellers see the records of traffic between them. If you exchange details with another member through Connect, we share what you choose to share.
  • The caller ID testing network. When you run a caller ID test, the caller ID and route under test go to the testing network, and the handset holder there receives the test call.
  • Payment networks. Card payments go through our card payment processor. Cryptocurrency payments are recorded on public blockchains, where wallet addresses and amounts are visible to anyone and cannot be erased.
  • Authorities. Law enforcement, regulators and courts, where the law requires it, as described in our Law Enforcement Guidelines.
  • Professional advisers, such as lawyers and accountants, under a duty of confidentiality.
  • A buyer of our business, if the Platform is sold or merged, with the same protections in place.
ServiceWhat it doesData involvedWhere
Data centre hostingRuns the Platform’s servers and databasesAll data held on the PlatformGermany
Phone numbers and messagingProvides phone numbers and carries the calls and SMS on themPhone numbers, call and message records, SMS content, and registration documents for numbers that need themEuropean Union
Speech processingTurns speech into text and text into speech for AI voice agentsLive call audio and the words spokenUnited States
AI modelsPowers AI voice agents and assistants, and reads uploaded rate sheets and contact listsConversation text, questions and the content of uploaded filesUnited States
Email deliverySends account, billing, security, number activity and status emailsEmail addresses, names and the content of the emailsUnited States
Caller ID testingPlaces test calls to real handsets and reports the caller ID receivedThe caller ID and route under testWorldwide
Card paymentsTakes card payments and Switch subscriptionsName, email address, card and billing details, payment amountsUnited States and European Union
Cryptocurrency paymentsSettles stablecoin payments made by wallets and software agentsWallet addresses and payment amountsPublic blockchain networks
Sign in with GoogleLets you sign in with a Google accountName, email address, profile photo and Google account IDUnited States

Members can ask for the named list of providers at support@packetexchange.io.

Where your data is

The Platform’s servers and databases are in data centres in Germany. The company that runs the Platform is established in the United Arab Emirates, some of our providers, including our email, payment and AI providers, process data in the United States and other countries, and calls and messages cross carrier networks in the countries they connect. When personal data leaves the UK or the European Economic Area for a country without an adequacy decision, the United Arab Emirates included, we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where relevant, or another transfer mechanism the law recognises.

How long we keep it

RecordHow long we keep it
Signalling traces for each call7 days, then deleted automatically
API request logs90 days, then deleted automatically
Call recordings and voicemailsThe period the member sets for each number (30 days by default), then deleted automatically
Call and message recordsWhile needed for billing, disputes, fraud prevention and legal obligations
SMS message contentWhile the member’s account is open, and after closure until deleted on request
Account detailsWhile the account is open. Name, email address, company, phone number and country are removed when it is closed
Financial recordsFor as long as tax and accounting law requires, including after the account is closed
Website visit statistics (page, referring site, campaign, country, device type)13 months, then only as daily totals that identify no one
Visitor ID records, if you allowed Analytics13 months after your last visit, then deleted automatically
Where an account came from (signup campaign, country and device type, and ad click IDs if you allowed it)For as long as the account record exists

Members can delete recordings, voicemails and contact lists from their dashboard at any time, and can set how long recordings are kept for each number.

Your rights

Depending on where you live, you can ask us to give you a copy of your personal data, correct it, delete it, restrict how we use it or transfer it to you in a portable format. You can also object to processing based on our legitimate interests, and withdraw consent where we rely on it.

  • Most account details can be changed in your settings, and call records can be exported from your dashboard.
  • You can close your account from your settings. We then remove your name, email address, company, phone number, country and two-factor settings, and keep only what the law, billing or an open dispute requires.
  • For anything else, email support@packetexchange.io from the address on your account. We reply within one month.

If you are in the UK or the EU, you can complain to your data protection authority. We would welcome the chance to resolve your concern first.

Security

  • Connections to the website, dashboard and API are encrypted with TLS.
  • Passwords are stored as bcrypt hashes and API keys as SHA-256 hashes, so neither can be read back.
  • Two-factor authentication is available on every account, and team members get only the permissions they are given.
  • Administrative access to production systems is limited to authorised staff and uses key-based authentication.

If a breach affects your personal data, we tell you and the relevant authorities as the law requires.

Cookies and browser storage

Necessary storage and your preferences are always used, because the site does not work without them. Analytics and Advertising storage is only set if you allow it in the cookie banner, and you can change your mind at any time: . Turning a category off deletes what it set on our site.

NameTypeCategoryPurposeHow long
refreshTokenCookie, HTTP-onlyNecessaryKeeps you signed in7 days, or until you sign out
wmmn_tokenLocal storageNecessaryA 15-minute access token for the dashboard, renewed while you stay signed inUntil you sign out
wmmn_portal_token, vendor_portal_tokenLocal storageNecessaryKeeps you signed in to the customer or supplier portal a member invited you toUntil you sign out
px_oauth_stateCookie, HTTP-onlyNecessaryProtects a Google or LinkedIn sign-in from being completed in someone else’s browser10 minutes
px_consentCookieNecessaryRemembers your cookie choices180 days
__stripe_mid, __stripe_sidCookie, set by StripeNecessaryFraud prevention for card payments, set only when you pay by card1 year and 30 minutes
px_attr_sSession storageMeasurement without an identifierThe campaign tags, referring site and landing page of this visit, sent with a signup so we know which page or campaign it came from. Holds no identifier and no ad click IDUntil you close the tab
px-workspace, px-switch-mode, px-guide, px.cdr.*, usage-view, px.tz.override, px.switch.listFilter.*, px-api-ref-lang, px-dev-lang, px.routeTest.cli, px.actionRequired.hidden.v1, switch-tour-v1-doneLocal storagePreferencesRemembers the product and mode you chose, your place in guided tours, table columns, saved views, your time zone, the code-sample language you picked and notices you dismissedUntil you clear your browser storage
icw:*, pkx:first-call:*, pkx:onboard-customer:*, px_route_draft_v1, wmmn.deck-import.v1, wmmn.add-trunk-wizard.v2.*, switch-ai-control-thread-v1, dialer-talk-thread-v1Local or session storagePreferencesKeeps unfinished forms, your place in setup guides and assistant conversations, so you can pick up where you left offUntil you finish, or clear your browser storage
wmmn.quick-upload.*, hideVerifyBanner, px-oauth-error-shownSession storagePreferencesCarries an upload between two steps and remembers a notice you closedUntil you close the tab
px_vidCookieAnalyticsA random visitor ID, set only if you allow Analytics, so a visit can be linked to an account if you later sign up13 months after your last visit
px_attrLocal storageAnalyticsThe first and latest campaign that brought you here and any ad click ID, set only if you allow Analytics or AdvertisingUntil you withdraw consent or clear your browser storage

Page visits are counted without cookies. Each visit is recorded with a code made from your IP address, browser and a random value that changes every day and is then deleted, so the code cannot be linked to you or to your other days. Your IP address is used only to look up your country in a database on our own servers and is not stored. Country data: IP Geolocation by DB-IP, licensed under CC BY 4.0.

No advertising cookies are in use at the moment. If we start using them, they will only load after you allow Advertising, and this table will list them. The only other third-party cookies are the fraud-prevention cookies our card processor, Stripe, sets when you pay by card.

Children

The Platform is for businesses and is not directed at anyone under 18. We do not knowingly accept children as account holders.

Changes to this policy

We post updates on this page with a new date and version. If a change materially affects how we use your personal data, we tell account holders by email or in the dashboard before it takes effect.

Contact

Legal notices, privacy, abuse reports, law enforcement requests and support
support@packetexchange.io