PRIVACY
What we hold,
and why we hold it
Running a telecom platform means holding records of what was used and when. This page says exactly what those are, what they are for, and what we do not do with them.
WHAT WE HOLD
Sixteen kinds of record, and what each is for
Each exists because the platform cannot work without it, not because it might be useful later.
- Account details
- The email address and business name used to create the account, and the people who are members of it.
- Sign-in links
- A one-time link is emailed to sign you in. We store a hash of it, never the link itself, and it is deleted once it has been used or has expired.
- Sign-in sessions
- Signing in sets one cookie, __Host-tel_session, which is how the site knows it is still you. It holds no personal data, only a reference to a session record we can end from our side. There is no analytics or advertising cookie of any kind.
- Usage records
- What was used, by which resource, when and where, because that is what the platform meters, rates and invoices.
- API logs
- The requests made against the account and the responses returned, so a failure can be diagnosed rather than argued about.
- Waiting-list emails
- An address, used once to tell you production access has opened, and then only if you ask for more.
- Contact requests
- What you sent us through the contact form and the address to reply to, kept while the answer might still matter.
- Business checks
- Which checks your business has satisfied, when each was settled and by whom, and the history of those results changing. We hold the outcome and a reference to it, not the documents you sent to the checking provider, which stay with them.
- UK service address
- The UK address a service is provided from. Required by Ofcom for UK geographic numbers, held only for accounts that ask for one, and separate from the registered company address.
- Payment records
- What you topped up, what was charged for each capability, and the running balance those add up to. If a payment is refunded, the refund is recorded here too, with the reason, and it appears on your own balance history. If a price is agreed for your account rather than the published one, that figure is held here as well. Card details are never held here: they go to Stripe, and what we keep is their reference to the payment, not the card.
- Service controls
- Whether each capability is available to you: on sale, orderable, being provisioned, and whether a service you already have keeps running. Normally there is no record here at all, because nothing has been set. A record appears when somebody at Telyne changes one of those for your account specifically, and it holds what was changed, when, who changed it and why.
- Developer credentials
- The API keys on your account, and where your webhooks are delivered. A key's secret is never stored: we keep a one-way hash of it, its first eight characters, its last four, what you named it and when it was last used. That is enough to show you which key is which and not enough to use as one. That is why a secret is shown once, at creation, and cannot be shown again by us or by anyone who obtained the database. Also here: which API version your account is pinned to, and the secret we sign your webhooks with, which you can read back in order to verify them.
- Test and sandbox records
- What you created in the sandbox with a test key: simulated eSIMs, the orders that made them, and the usage you drove against them. None of it is real service, none of it is charged for, and none of it touches a network. It is kept so that a test you ran yesterday is still there today.
- Events and their delivery
- Every asynchronous thing that happened on your account, such as a profile activating, a threshold being crossed or a key being issued, with the object it was about as it was at the time, so a replay tells you what was true then rather than what is true now. Alongside it, each attempt we made to deliver it to your endpoint and what your endpoint answered. Test and live are kept apart. And when a call of yours carried an idempotency key, the answer we gave it, so that repeating the call returns the same answer instead of doing the thing twice.
- eSIM records
- Which data bundles you bought, what each cost and what you paid for it, the eSIM profiles issued to you and how much data each has left. The profile identifiers we hold are what let an eSIM be installed and managed, so they are shown only to the account that owns them and are never put in a link. Usage readings come from the supplier that carries the data.
- Staff and administration records
- Records about the people who run Telyne, not about customers. Who has an administrator account and what they are allowed to do, the second factor that secures it, and an append-only record of every privileged action taken: who did it, when, and what changed. That record cannot be edited or deleted by anyone, including the founder, which is the point of keeping it. It also holds occasions when an administrator viewed an account as its owner sees it, always read-only and always with a recorded reason, and changes proposed to page titles and descriptions before they are published.
WHAT WE DO NOT DO
Not sold, not shared, not advertised against
These are commitments about the records above, in plain terms.
YOUR CONTROL
You can see it, export it and end it
The same records the platform bills from are the ones you can read.
- See it
- Usage, logs and account details are queryable through the API and visible in the dashboard.
- Export it
- Anything you can query you can export, in the same resolution it is held at.
- Correct it
- Account and contact details are editable by you rather than by request.
- End it
- Close the account and the records that are not required for billing or legal reasons go with it.
- Ask
- Write to us and a person answers. Contact details are in the footer of every page.
QUESTIONS
Privacy at Telyne
Do you sell or share my data?
No. Not to anybody and not for any purpose. There is no advertising business here, no profiling and no targeting, and the records exist to run the platform rather than to be an asset.
Do you contact my customers?
No. If you resell, your customers are yours. We do not contact them, we do not appear in front of them, and we hold what the platform needs to meter and bill rather than a relationship with them.
Why do you keep API logs?
So a failure can be diagnosed. When a platform and an integration disagree about what was sent, a shared record is the only thing that settles it quickly, and it is the same record you can query.
How long is anything kept?
For as long as it is needed to run the account, meter usage and meet legal obligations, and no longer. Close the account and what is not required for those reasons goes with it.
How do I ask a question about my data?
Write to us. A person answers, and the contact address is in the footer of every page on this site.
Be told when it opens
Join the waiting list and we will email you once, when it opens, with the capabilities that are ready first.
One email at launch. Nothing else, and unsubscribe in one click.
We send a link to confirm the address. Unconfirmed addresses are deleted after 30 days.
Complex requirement or an existing estate to move? Talk to us.