Data security
How the information you give us is actually held. This is a description of the system as built, not a list of certifications we do not have.
Last updated 23 September 2026.
What we collect from this website
Only what you type into the form: your name, business name, email address, phone number, the sector you picked, and your message. If you asked for a call back, we also store the exact sentence you agreed to, the moment you agreed to it, and the IP address it came from — that record exists so there is evidence of consent before anyone rings you, and for no other purpose.
There is no analytics on this site. No Google Analytics, no advertising pixels, no third-party tracking of any kind, no session recording. The only cookie this site sets is the one that keeps an operator signed in to our own internal admin page, and you will never receive it.
How it is protected
- In transit. The whole site is HTTPS only. Plain HTTP is redirected, and HSTS is set, so a browser that has seen this site once will refuse to connect insecurely afterwards.
- At rest. Form submissions land in a database file on our own server, readable only by the service account that runs the API and by root. It is not in any cloud storage bucket and not in any third-party CRM.
- Credentials. The admin password is stored only as an scrypt hash. Sessions are HMAC-signed cookies marked HttpOnly, Secure and SameSite, so no script on the page can read them. Writes require a CSRF token tied to the session.
- Secrets. API keys and the password hash live in a root-owned file with mode 600 on the server. None of them are in our source code repository, and the repository is checked before every deploy for anything that looks like a key.
- In the browser. A strict Content-Security-Policy with no inline scripts, plus X-Frame-Options, X-Content-Type-Options and a Referrer Policy, on every response including static files.
- Abuse. Submissions and voice generation are rate limited per IP address and in total, so neither can be used to run up a bill or flood the inbox.
Who can see it
The people who run Call Marlin, through a password-protected internal page. Nobody else. We do not sell your information, we do not rent it, and we do not hand it to advertisers or data brokers. We have no reason to and no arrangement that would let us.
Call recordings and transcripts
Call audio and transcripts belong to the customer whose phone line it is. We process them to run the service and to show you what was said. Retention is set per customer, and when a customer leaves, their call data is deleted rather than kept “for analytics”.
The recordings published on this website are a separate thing entirely: identifying details have been cut out of both the audio and the transcript before publication, and the businesses are not named.
If something goes wrong
If customer data is exposed, we will tell the affected customers directly, and within 72 hours of establishing what happened — what was taken, when, what we have done, and what you should do. We would rather send an uncomfortable email than a late one.
If you have found a security problem in this site or the service, please tell us before telling anyone else, through the contact form. We will not threaten you for reporting it.
What we are not claiming
We are not SOC 2 certified, not ISO 27001 certified, and not HIPAA compliant. If you handle protected health information and need a business associate agreement, we cannot sign one today — tell us and we will say so plainly rather than sell you something that puts you in breach.
