Privacy policy
Effective 15 September 2026 · Rung Pty Ltd (ACN 000 000 000), Australia
Rung provides an AI phone receptionist for Australian trades and service businesses. This policy explains what personal information we collect, why, how it is stored and protected, and the choices you have. It is written to comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).
1. Who we are
Rung Pty Ltd ("Rung", "we", "us") operates runghq.com and the Rung voice agent service. We are the app provider; when you connect third-party tools (ServiceM8, Xero, Twilio, Stripe) those systems process data under their own policies as described below.
2. Information we collect
- Account details — your name, business name, email address, password (stored hashed), business address and ABN.
- Billing details — plan selection and payment status. Card details are captured by Stripe; Rung never stores your full card number or CVC.
- Call data — for the phone numbers we answer on your behalf: caller phone number, call recordings, speech-to-text transcripts, and the bookings/quotes the agent creates.
- Integration data — OAuth tokens for ServiceM8 and Xero (encrypted at rest) and the job/invoice records those tools return.
- Technical data — IP address, browser type and pages visited when you use the website or dashboard.
3. Why we collect it
- to answer your business calls and create bookings on your behalf (the core service);
- to sync bookings and invoices with tools you connect (ServiceM8, Xero);
- to bill your subscription (Stripe);
- to contact you about your account, outages and billing;
- to detect and prevent fraud and abuse.
We do not sell personal information, and we do not use your customers' call recordings to train models without your opt-in.
4. Calls are recorded — notice to your callers
Every call Rung answers on your behalf is announced as recorded ("This call is recorded for quality and training") before the conversation proceeds. You are responsible for any additional notice duties that apply to your own industry (for example, state-based surveillance laws for private conversations). Recordings and transcripts are retained for 24 months by default, then deleted.
5. Who we share data with
- Twilio — call and SMS transport (telephony carrier functions).
- Stripe — payment processing (PCI-DSS compliant).
- ServiceM8 / Xero — only the data needed to create the jobs, quotes and invoices you approve.
- Hosting — Australian-region cloud infrastructure; backups are encrypted.
We may disclose personal information where required by Australian law or a valid legal process.
6. Overseas disclosure
Some of the providers above (Twilio, Stripe) process data outside Australia, including in the United States. Where that happens we take reasonable steps to ensure the recipient handles it consistently with the APPs (APP 8).
7. Security
Passwords are stored hashed; integration credentials are encrypted at rest (Fernet); dashboard access is password-gated; transport is TLS throughout. We apply the notifiable-data-breach scheme (Part IIIC of the Privacy Act): if an eligible data breach occurs we notify affected individuals and the OAIC as required.
8. Your choices
- Access or correct your personal information, or request deletion of your recordings, via privacy@runghq.com or the in-app settings.
- Disconnect ServiceM8/Xero at any time in Settings; disconnecting removes the stored tokens.
- Close your workspace: we delete account and call data within 30 days of closure, except where we must keep records (e.g. tax).
9. Complaints
Contact us first at privacy@runghq.com — we respond within 30 days. If you are not satisfied you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
10. Changes
We will post any updated policy on this page and, for material changes, email workspace owners before it takes effect.