Privacy and cookies

Privacy policy and cookie notice

This notice explains how Creotec Limited processes personal data when you use WordFone. Last updated: 30 June 2026.

1. Controller and contact

Creotec Limited operates WordFone and is the controller for personal data processed through the service. Contact hi.there@wordfone.com for privacy matters. The operator must add its legal identity, postal address, and any required representative details before public launch.

2. Information we process

We process account email, password hash, email-verification status, display name, calling alias, primary number, country selection, visibility, pronunciation hint, address-style entry data, private access link settings, required private link labels, usage counts, last-used times, and support correspondence. Private access link tokens are stored as hashes, not as the raw link token. We also process security and service data, including account-activity records, IP addresses, limited hashed network identifiers for rate limiting, normalised device information, verification and notification records, and report and appeal records.

If you enable an authenticator app, we store its secret encrypted. If you add a passkey, we store the credential identifier, public key, counter, and label needed to validate it; we do not receive or store your biometric information. Recovery codes are stored as one-way hashes.

3. Payments and billing data

When you publish or renew an alias, we process billing-related records such as the selected alias, pricing tier, amount, currency, discount state, subscription status, renewal dates, payment provider identifiers, invoice or checkout references, and payment confirmation status.

Stripe processes payment details such as card or wallet information under its own role as payment provider. WordFone does not store full card numbers or security codes. We use webhook events from the payment provider to publish aliases, update renewal status, send confirmations, manage grace periods, and release unpaid aliases where required.

4. Why we use data and our legal bases

We use account, identity, billing, reporting, and support data to provide the service and perform our contract with you. We use verification, account security, moderation, audit, renewal, expiry, release, and rate-limiting data for our legitimate interests in preventing fraud, abuse, unpaid use, and unauthorised access and protecting users. We may also process data where necessary to meet a legal obligation or establish, exercise, or defend legal claims.

5. Address visibility, private links, and reporting

Private active identities can appear only as active but private in normal directory queries. Owners can create revocable private access links that reveal the telephone number, and optionally the display name, to people who have the link. Private links are shown once only, are identified by required labels, and successful uses are recorded in owner account activity with timestamp, IP address, and device string. Public active identities can resolve exact address-style entries and can appear in directory queries with registration date, renewal date, verified status, and the telephone number after a confirmation step, but without the display name. Listed active identities can show the same public details plus the display name. Anyone can submit a report for a name.tld identity, but the report form does not expose private owner information. Address-style destinations are marked as unverified.

6. Service, billing, and renewal emails

We send operational emails, such as email verification, password recovery, sign-in alerts, account-change alerts, payment confirmations, renewal reminders, expiry and grace-period notices, moderation notices, and re-verification reminders, using authenticated mail delivery. The email provider processes recipient address, message metadata, and message content only to deliver the email on our instructions. We do not sell personal data or use advertising trackers in these messages.

7. Cookies

WordFone uses essential cookies only: a secure session cookie to keep you signed in and protect forms, and a language-preference cookie to remember your interface language. We do not use advertising or cross-site tracking cookies in this version.

8. Retention and sharing with providers

We retain data while your account or identity is active and afterwards only for as long as reasonably necessary for security, billing records, moderation, disputes, legal obligations, backups, or restoration. A deleted or released alias may be held for the configured hold period where applicable.

We may use hosting, database, backup, SMTP, SMS, payment, and telephone-verification providers acting on our instructions or as independent controllers where their own legal obligations require it. If data is transferred internationally, the operator must apply an appropriate GDPR transfer safeguard.

9. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where consent applies. Some billing, security, and legal records may need to be retained for required periods even if an account or identity is deleted. You may also complain to your data-protection authority. Contact hi.there@wordfone.com to make a request.

10. Security and changes

We use measures such as password hashing, encrypted authenticator secrets, passkey public-key validation, prepared database queries, CSRF protection, secure session settings, rate limiting, access controls, audit records, payment webhooks, and least-necessary provider credentials. No online service can guarantee absolute security, so keep your password, recovery codes, payment account, and verification codes confidential. We may update this notice when the service or law changes and will publish the current date on this page.