Privacy Policy
Last Updated: September 13, 2026
This Privacy Policy explains what data we collect, how we use it, and your rights in relation to it. By using the Service, you agree to the practices described in this policy.
1. Who We Are
non-voip.com (“non-voip.com,” “we,” “us,” or “our”) values your privacy. This Privacy Policy describes how we collect, use, disclose, and protect information collected through www.non-voip.com and our related online services (the “Services”).
support@non-voip.com2. Data We Collect
We collect only the minimum data necessary to operate the Service securely and effectively.
2.1 — Account Data
- First and last name (required for every account)
- Email address — used for sign-in, account verification and account emails (optional for accounts created with Telegram)
- Password, if you set one — stored only as a one-way (bcrypt) hash, never in readable form
- Passkeys, if you add any — we store the public key, the credential ID, the name you give it and when it was last used; never your private key or biometric data
- Linked Google and Telegram accounts (see Sections 3 and 4)
- Account creation date, sign-in times and active sign-in sessions (tied to your account and device; the session secret is stored only in hashed form)
- Credit balance, top-up and payment records, and referral activity
2.2 — Device Data
When you use our mobile application, we collect the following device information:
- Device manufacturer and model (e.g., Xiaomi Poco F8 Ultra)
- Operating system type and version (e.g., Android 17)
- App version
- Firebase Cloud Messaging (FCM) token — used to deliver push notifications to your device
2.3 — Usage and Technical Data
- IP address
- Browser or app type
- Pages visited and actions taken within the platform
- Verification history (service, country, server, result, timestamp, credit cost)
2.4 — Support Communications
If you contact us through our support system (Zoho Desk), we may retain the content of your messages and any attachments you provide, for the purpose of resolving your request.
3. Information from Google
You can create a non-voip account, or sign in to one, with your Google account. This section explains what we receive from Google when you do, and how we use, share, protect, keep and delete it (“Google user data”).
3.1 — What We Access
When you use Sign in with Google, Google sends us a signed identity token for your Google account. From it we read:
- Your Google account ID (a unique identifier Google assigns to your account)
- Your email address, and whether Google has verified it
- Your name as shown on your Google account (full name, first name and last name)
- The web address (URL) of your Google profile picture
Of this, we store your Google account ID, email address, name and profile picture URL, together with when you linked Google and when you last used it to sign in. We use Google only to confirm who you are: we do not ask for access to your Gmail, contacts, files, calendar or any other Google service, and we never receive or store a Google access token or refresh token. The identity token is checked and then discarded; it is not stored.
3.2 — How We Use It
We use Google user data only to provide sign-in and account features that you can see and control:
- Creating your account: your Google email address becomes your account email (treated as verified, because Google has verified it), and your first and last name become your account name
- Signing you in: your Google account ID identifies your account each time you use Sign in with Google
- Linking Google to your account, either from your account settings or when you sign in with Google using an email address you have already verified on an existing non-voip account
- Showing the connected Google account (name, email address and profile picture) in your account settings, and sending you a security notification when Google is linked to or unlinked from your account
Google user data is not used for advertising, is never sold, and is not used for any purpose other than these features.
3.3 — How We Share It
We do not sell, rent or trade Google user data, and we do not share it with advertisers or data brokers. We share it only:
- With the service providers listed in Section 8, only as far as needed to operate your account and respond to your requests — for example, to send emails to your address, deliver notifications to your devices, or pass an account deletion request to our staff
- With law enforcement or regulatory authorities, only when required by applicable law or a valid legal order
3.4 — How We Protect It
- It is transmitted only over encrypted connections (HTTPS/TLS)
- Before using it, we verify the identity token’s signature with Google’s public keys, check that it was issued for non-voip and has not expired, and accept it only if Google reports the email address as verified
- It is stored in our database under access controls that limit access to authorised personnel
- Repeated failed sign-in attempts are rate-limited to prevent abuse
3.5 — Retention and Deletion
- We keep Google user data for as long as Google is linked to your account.
- When you unlink Google in your account settings, it can no longer be used to sign in, with immediate effect. The record of the former link is kept as part of your account information for the retention period in Section 9.
- To have your Google user data deleted — on its own (for example, after unlinking Google) or together with your account — email legal@non-voip.com from the email address on your account; you can also request deletion of your account from your account settings. After your account is deleted, Google user data is kept no longer than the retention period for account information in Section 9.
3.6 — Limited Use
non-voip's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data to develop, improve or train artificial intelligence or machine learning models.
4. Information from Telegram
You can also create an account or sign in with Telegram. We ask Telegram only for your basic profile, not for your phone number or email address. Telegram sends us a signed identity token, from which we read and store:
- Your Telegram user ID
- Your name (first and last name, where your profile has them)
- Your Telegram username
- The web address (URL) of your Telegram profile photo
We use this only to create your account (your name becomes your account name), to sign you in, and to show and manage the connected Telegram account in your settings. It is never sold, is not used for advertising, and is shared only as described in Section 8.
The identity token is verified with Telegram’s public keys and is not stored; only a one-way fingerprint of it is kept, until the token expires, to stop it being used twice. Telegram data is kept and deleted in the same way as Google user data (Section 3.5).
5. How We Use Your Data
We use your data to:
- Create and manage your account
- Deliver and operate the Service
- Process credit top-ups and verifications
- Send push notifications related to your account activity (via FCM)
- Detect and prevent fraud, abuse, and unauthorized access
- Monitor platform performance and identify technical issues
- Respond to support requests
- Improve the Service over time
6. Analytics Tools
We use the following third-party analytics tools to understand how users interact with the Service:
These tools may collect anonymized usage data including IP address, browser type, device type, and on-site behavior. They operate under their own privacy policies and data processing agreements.
You may opt out of analytics tracking by enabling "Do Not Track" in your browser settings or by using a privacy-focused browser extension.
7. Cookies
We use cookies and similar technologies to:
- Maintain your login session
- Store your preferences
- Support analytics platforms listed above
You can disable cookies through your browser settings. Note that disabling cookies may affect the functionality of the Service.
8. Data Sharing
We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.
We share personal data only with the service providers below, which process it to run the Service on our behalf, and with authorities where the law requires it. Each receives only what its part of the Service needs:
- Hosting and infrastructure providers that run our website, API and databases (including Vercel, which hosts our website) — any data that passes through or is stored on the Service
- Our email delivery (SMTP) provider — your email address and the content of the account and payment emails we send you, such as your first name and payment receipts
- Firebase Cloud Messaging (Google) — your device’s push token and the content of the notifications we send to it, which can include your name, email address, the phone number you rented, received codes and messages, and payment details
- Payment providers KazaWallet and CCPayments — only the payment amount, the currency or cryptocurrency and network, and a random payment reference. We do not send them your name, email address or account ID; when you pay, you deal with them directly under their own terms and privacy policies
- Phone number providers — only the service, country and maximum price of each order (and the rented number itself when you reuse it); never your name, email address, account ID or IP address
- Telegram — alerts to our staff about account deletion and API rate-limit increase requests (your account ID, name, email address and the reason you give), business waitlist submissions (name, email address, company, description and IP address), and some payments (your account ID and payment details)
- Notion — business waitlist submissions (name, email address, company and description)
- Zoho — our support chat and help desk (Zoho SalesIQ and Zoho Desk), which receive the messages and details you send us through them
- Analytics providers listed in Section 6, under data processing agreements
- Law enforcement or regulatory authorities, only when required by applicable law or a valid legal order
9. Data Retention
Retention periods for different data types:
10. Data Security
We implement reasonable technical and organizational measures to protect your data, including:
- Encrypted data transmission (HTTPS/TLS)
- Access controls limiting data access to authorized personnel only
- Regular monitoring for unauthorized access or anomalies
No system is completely secure. While we take security seriously, we cannot guarantee absolute security of your data.
11. Children's Privacy
The Service is not intended for users under the age of 18. We do not knowingly collect data from users below this age. If we become aware that a user is underage, their account and associated data will be deleted immediately.
12. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your account and associated data
- Withdraw consent for non-essential data processing (e.g., analytics cookies)
To exercise any of these rights, contact us at legal@non-voip.com. We will respond within a reasonable timeframe.
Note: some data may be retained beyond deletion requests where required by applicable law or for fraud prevention purposes.
13. Third-Party Services
The Service may link to or integrate with third-party platforms (e.g., payment processors, blockchain networks). This Privacy Policy does not apply to those third-party services. We encourage you to review their respective privacy policies before use.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. Continued use of the Service after changes are posted constitutes your acceptance of the updated Policy.
For significant changes, we will make reasonable efforts to notify you in advance through the platform or via email.

