Skip to main content
Mercvox icon
mercvox
Legal

Security

Last updated: September 2026

1. Our Approach

Mercvox is operated by Driftel Labs, based in Toronto, Ontario, Canada. This page describes, in plain language, how we protect your data and your callers' data.

Every claim on this page reflects what our systems actually do today — no fine print, no badges we haven't earned. As Mercvox grows, we'll keep raising the bar, including formal certifications and Canadian data residency, and we'll update this page as we do.

2. Payments

We never see or store your card details. All payments are handled by Stripe, a certified PCI DSS Level 1 payment provider — the highest level in the card industry. Your card number, expiry, and CVV go directly to Stripe and never touch our servers.

We store only what we need to manage your subscription: your plan, billing status, and a Stripe reference — never raw card data.

3. Encryption

  • In transit: all traffic between you, our servers, and our providers is encrypted using TLS.
  • Integration tokens at rest: OAuth and integration tokens (for example, Google Calendar) are encrypted at rest using AES-256 before they are stored.
  • Database at rest: our database is hosted on Supabase, which provides managed encryption at rest for stored data.
  • Passwords: account passwords are stored as a one-way hash (bcrypt) — we never store plain-text passwords.

4. Where Your Data Lives

Mercvox is a Canadian company, but our data is currently processed and stored on servers located in the United States (via providers including Supabase and Railway).

Under Canada's PIPEDA, cross-border transfers are permitted where reasonable safeguards are in place. We cover exactly what this means — including your rights and our intention to offer Canadian data residency — in the Data Storage Location section of our Privacy Policy.

5. Access Controls

  • Access to production systems is restricted to authorized team members only.
  • Within your dashboard, role-based access controls what each team member you invite can see and do.
  • We do not sell your data or your callers' data, and we do not use caller data for anything beyond operating the service for the specific business that received the call.

6. Monitoring

We use Sentry to monitor our systems for errors and to help us detect and respond to potential security incidents. This lets us catch and fix problems quickly, often before they affect you.

7. Call Recording & AI Disclosure

Mercvox answers calls with an AI assistant on behalf of your business. Callers are informed that their call may be recorded and handled by an AI assistant. This supports transparency and helps meet consent expectations, including two-party-consent US states and PIPEDA.

Call transcripts and recordings are processed to operate the service for your business — creating bookings, sending confirmations, and surfacing call summaries in your dashboard — and are never shared with other businesses or used for advertising.

8. Reporting a Concern

If you believe you've found a security vulnerability or have a concern about how your data is handled, please contact us at [email protected]. We take every report seriously and will respond promptly.

Breach notification: in the event of a data breach, we will notify affected users as required by applicable law — within 72 hours where required — and take immediate steps to contain and remediate the issue.