CheckThatPhone
  • Features
  • Use cases
  • Docs
  • Pricing
  • Sign in
  • Get API Access
  • Dashboard

Privacy Policy

Last updated: September 3, 2026

1. Who We Are

CheckThatPhone ("CheckThatPhone," "we," "us," "our") operates the website at checkthatphone.com and the phone-validation API at api.checkthatphone.com/v1/lookup. Questions about this policy or your data: hello@checkthatphone.com.

2. Information We Collect

Account information

  • Email address (required to create an account)
  • Password hash if you sign up with email/password (we never store the plaintext password)
  • Google profile data (name, email, profile image) if you sign in with Google
  • IP address and user agent at sign-up and on each session (security and abuse detection)

Billing information

  • Name and billing address you provide to Stripe at checkout
  • Subscription plan, billing cycle, and renewal dates
  • We do not store payment card numbers. Stripe processes payments and stores card data under PCI DSS Level 1.

Service usage data

  • API key hashes (we display the plaintext key once and never store it again)
  • API request timestamps, response codes, credits used, and the source IP of the request
  • Aggregated daily usage records used for billing reconciliation

Phone numbers submitted via the API

Phone numbers and optional IP addresses you submit to our API are passed through to our upstream carrier-data provider in the United States for the duration of the lookup, then discarded. We do not store the phone numbers you query. Our internal usage analytics record only request metadata — your user ID, plan, the credits charged, upstream latency, and the prefix of the API key used — never the phone number itself. We do not sell, share for marketing, or otherwise repurpose phone numbers you submit.

When the optional do-not-call scrub is enabled on a lookup, the number is additionally checked against state do-not-call registry data and complaint-history records held by our upstream provider in the United States. The check happens during the lookup only; it does not add the number to any registry or list, and the same no-storage rule above applies.

Analytics

We use Google Analytics 4, provided by Google LLC, across the site — both our public pages (homepage, blog, pricing, docs, about, legal) and the authenticated /dashboard — to understand traffic patterns and product usage. It records the pages you visit, the referring site, your browser and device type, an approximate location derived from your IP address, and a random cookie identifier that lets Google count you as one visitor across pages (the _ga cookies, retained for up to two years). We send one custom event when an account is created. We never send the phone numbers you submit, your lookup results, your name, or your email address to analytics, and we do not use Google's advertising features (Google Signals, ads personalization) on this property. Google processes this data under its own privacy policy.

We also use PostHog, provided by PostHog Inc. (US cloud), for the same purpose: page views, referring site, browser and device type, approximate location from your IP address, and a random visitor identifier kept in your browser's local storage (not a cookie). When you are signed in, PostHog receives your account id so we can see how accounts move from sign-up to first API key to a paid plan; it never receives your email, name, phone numbers, or lookup results. PostHog processes this data under its own privacy policy.

You can turn both analytics services off at any time; see Your privacy choices below. We also honor the Global Privacy Control browser signal: when your browser sends it, neither analytics script is loaded at all.

Bot and abuse prevention

To protect our free demo lookup on the home page and our sign-up form from automated abuse, we use Cloudflare Turnstile, a privacy-preserving alternative to traditional CAPTCHAs. Turnstile runs a lightweight check in your browser to tell humans from bots and may process limited technical information (such as your IP address and browser characteristics) for that purpose. It does not ask you to solve puzzles and is not used to track you across sites. For details on how Cloudflare handles this data, see the Cloudflare Turnstile Privacy Addendum.

3. How We Use Information

  • Provide the API service and operate your account
  • Bill you for usage and process payments via Stripe
  • Send transactional and quota-related email (account confirmation, password reset, billing receipts, usage warnings)
  • Detect, prevent, and respond to abuse, fraud, and security incidents
  • Improve our service through aggregated, non-identifying analytics
  • Comply with legal obligations and respond to lawful requests

4. Subprocessors

We rely on a small set of service providers (subprocessors) to operate the platform. Each is bound by its own privacy and security commitments and processes data only as needed to deliver its function:

  • Payment processor (Stripe) — billing and card processing; we never store card numbers
  • Email delivery provider — transactional and account email
  • Cloud infrastructure provider — API delivery, edge compute, content delivery, and DDoS protection
  • Bot-mitigation service (Cloudflare Turnstile) — verifies that the free demo lookup and sign-up are used by humans, not bots; see the Turnstile Privacy Addendum
  • Application hosting provider — the marketing site and dashboard
  • Managed database & authentication provider — account records and sign-in sessions
  • Authentication provider for optional social sign-in (Google) — used only if you choose "Continue with Google"
  • Web-analytics providers (Google Analytics 4, PostHog) — aggregate traffic and product-usage measurement; see the Analytics section above for what they collect and how to opt out
  • Upstream carrier-data provider — performs the underlying carrier lookups in the United States, including, when requested, checks against state do-not-call registry and complaint-history data

We can provide the current named list of subprocessors on request — email hello@checkthatphone.com.

5. Data Retention

  • Account data — retained while your account is active. On deletion request, we erase or anonymize within 30 days.
  • Billing records — retained for up to 7 years to meet tax, accounting, and financial-reporting obligations.
  • Daily usage records — retained for up to 3 years for billing reconciliation and dispute resolution.
  • Audit and security events — retained for up to 1 year.
  • API key hashes — retained until you revoke the key or delete your account.
  • Phone numbers submitted to the API — not retained. Passed to the upstream carrier-data provider for the duration of the lookup and then discarded; not stored, not cached, not logged.

6. International Transfers

We operate from the United States, and your data is processed in the United States. If you access the service from the EU, UK, or Switzerland, we rely on the Standard Contractual Clauses (SCCs) and the UK Addendum, or other lawful transfer mechanisms such as the EU-US Data Privacy Framework where applicable, for cross-border transfers.

7. Your GDPR Rights (EU/EEA/UK)

If you are in the EEA or the UK, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten"), subject to legal retention obligations
  • Restrict or object to processing
  • Receive your data in a portable, machine-readable format
  • Withdraw consent at any time where consent is the legal basis
  • Lodge a complaint with your supervisory authority

To exercise these rights, email hello@checkthatphone.com. We do not engage in solely automated decision-making with legal or similarly significant effect.

8. Your Privacy Choices and CCPA Rights (California)

California residents have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of any "sale" or "sharing" of personal information. We do not sell personal information, and we do not share it for cross-context behavioral advertising. To submit a request, email hello@checkthatphone.com.

The only third-party tracking on this site is the analytics described above (Google Analytics and PostHog). You can opt out of both in either of two ways, and neither affects your account or the API:

  • Global Privacy Control. Turn on the GPC signal in your browser or a browser extension. We treat it as an opt-out request and never load either analytics script for that browser. Your current status: checking…
  • Turn it off here.
    Stored only in this browser (no cookie, nothing sent to us). Clearing site data resets it.

You can also install Google's own Analytics opt-out add-on or block googletagmanager.com with a tracker-blocking extension.

9. Cookies

We use a small number of cookies:

  • Session cookies set by our authentication system to keep you signed in to the dashboard. Required for the service to function.
  • First-touch attribution cookie (ctp_ft, first-party, 90 days) that remembers the page and referrer you first arrived from, so we know which channels bring customers. It is read once when an account is created and is never shared.
  • Google Analytics cookies (_ga and _ga_*, set by Google, up to two years) across the site, including the dashboard, to measure aggregate traffic and product usage. Not set when you opt out as described in section 8.
  • PostHog sets no cookies; its visitor identifier is kept in your browser's local storage and is cleared by the opt-out switch in section 8.

10. Children's Privacy

The service is not intended for individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected such information, contact us and we will delete it.

11. Security

We use TLS for data in transit, encryption at rest where supported by our infrastructure providers, access controls limiting who can see customer data, hashed credentials and hashed API keys, and routine security review of dependencies. No system is perfectly secure; we cannot guarantee absolute protection.

12. Account Deletion

You can delete your account yourself from the Account page in the dashboard, or by emailing hello@checkthatphone.com. On deletion we cancel your subscription, revoke your API keys, and erase your personal data subject to the retention windows above for legal and financial records.

13. Changes to This Policy

We may update this policy from time to time. Material changes will be announced by email to active account holders and noted with a new "Last updated" date at the top of this page. Continued use of the service after a change indicates acceptance of the updated policy.

14. Contact

Questions, requests, or complaints regarding this policy: hello@checkthatphone.com.

Related: Terms of Service

CheckThatPhone provides real-time phone validation for US & Canada numbers.

Product

  • Home
  • Features
  • Pricing

Resources

  • Docs
  • Use cases
  • Blog

Company

  • Contact us
  • Get API access

© 2026 CheckThatPhone. All rights reserved.  Terms · Privacy · Your privacy choices