← Home

Privacy Policy

phone.link — a product of Vir Reality Labs, Inc.

Effective date: April 17, 2026


At Vir Reality Labs, Inc. (“Vir Reality,” “we,” “us,” or “our”), the company behind the phone.link product, protecting your personal information is a priority. This Privacy Policy explains how we collect, use, share, and protect personal information in connection with our website, our SMS and phone verification services, and our related products (collectively, the “Services”).

This Privacy Policy is designed to help us comply with applicable privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), and, where applicable, the EU General Data Protection Regulation (the “GDPR”) and the UK GDPR.

This Privacy Policy does not describe how we use cookies and similar tracking technologies. For that information, please refer to our Cookies Policy.

Who We Are

The entity responsible for your personal information is Vir Reality Labs, Inc., a Delaware corporation with its principal place of business at 253 N. La Peer Dr., Beverly Hills, CA 90211. phone.link is a product of Vir Reality Labs, Inc. When you browse our website or when we process your data for our own purposes (for example, to fight fraud or improve our Services), we act as the “business” or “controller,” as applicable under the relevant law.

When we provide Services to our customers, we process personal information about their end users on their behalf and pursuant to their instructions. In those cases, our customers act as the “business” or “controller,” and we act as the “service provider” or “processor.”

What Personal Information We Collect

“Personal information” means information that identifies, relates to, or could reasonably be linked with an identifiable individual. Depending on how you interact with us, we may collect the following categories of personal information:

  • Identification data — such as full name, email and postal address, and phone number.
  • Professional data — such as company name, job title, resume or CV, and LinkedIn profile URL.
  • Account and login data — such as account IDs, log records, and IP address.
  • Location data — general geographic information inferred from IP address or provided by you.
  • Communications data — records of calls, chats, and emails with our customer support team, including dates and content.
  • Device and browsing data — IP address, pages viewed, date and time of connection, browser and device type, operating system, user ID, mobile advertising identifier, and general interaction data.
  • Content you provide to us — any information you choose to send us, such as in a contact form or support request.

When you provide information directly to us, we will indicate whether particular fields are required.

How We Collect Your Personal Information

We collect personal information in two main ways:

  • Directly from you — for example, when you fill out a form on our website, subscribe to our Services, contact customer support, or apply for a job.
  • Indirectly — from our customers (who provide information about their end users so we can deliver the Services), from our service providers, or from publicly available sources.

How We Use Your Personal Information

The table below summarizes the purposes for which we process personal information, the legal basis we rely on where applicable (primarily relevant under GDPR and similar laws), and how long we retain the information.

PurposeLegal Basis / Lawful GroundRetention Period
To perform contracts and manage the customer relationshipPerformance of a contract to which you or your company is partyFor the duration of the contractual relationship; transaction records are retained for 5 years for evidentiary purposes.
To analyze use of the Services, understand customer needs, and improve functionalityOur legitimate interest in improving our products and servicesUsage analytics are retained for up to 2 years; anonymized data may be retained indefinitely.
To manage customer feedback and reviewsOur legitimate interest in collecting feedback2 years from publication of the review.
To build and manage a prospect databaseOur legitimate interest in developing and promoting our business3 years from the last contact with you.
To send newsletters, product updates, and direct marketing communicationsOur legitimate interest in marketing to customers and prospects; your consent where required by law3 years from the end of the contractual relationship or last contact.
To respond to your information requests and inquiriesSteps taken at your request prior to entering a contractFor the duration of the contract if you become a client; otherwise 3 years from the last contact.
To retain administrative and financial recordsCompliance with our legal and regulatory obligationsInvoices and tax records for 7 years; transaction records for 5 years for evidentiary purposes.
To process job applications and manage recruitmentSteps taken at your request prior to entering a contractFor the duration of the recruitment process; up to 3 months after rejection; up to 5 years from a hiring decision for evidentiary purposes.
To maintain a CV databaseYour consent2 years from the last contact with you.
To prevent and detect fraudOur legitimate interest in preventing fraud and complying with lawFor the time necessary to qualify and respond to a fraud alert; relevant fraud records may be retained for 6 years from case closure.
To handle requests to exercise your privacy rightsCompliance with our legal obligationsIdentity verification documents are deleted once verification is complete; opt-out records are retained for 3 years; other records are retained for 3 years from the request.

Who We Share Your Personal Information With

We may share personal information with the following categories of recipients:

  • Our employees and personnel who need access to perform their jobs.
  • Our service providers and processors, such as hosting providers, CRM tools, email service providers, analytics tools, payment processors, billing tools, cookie management platforms, fraud prevention tools, monitoring and dashboard tools, and OTP delivery carriers.
  • Our business partners acting as independent data controllers. We are not responsible for their processing of your personal information; please review their own privacy policies.
  • Legal, judicial, regulatory, or law enforcement authorities when required by law or to respond to valid legal process, or to protect our rights, property, or safety, or those of our users or the public.
  • A successor entity in connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy.

Sale or sharing of personal information. We do not sell your personal information in exchange for money. We do not knowingly sell or share the personal information of consumers under 16 years of age. We may “share” personal information as defined under the CCPA (e.g., for cross-context behavioral advertising) through the use of cookies and similar technologies; please see our Cookies Policy for details and how to opt out.

International Data Transfers

Vir Reality is headquartered in the United States, and your personal information is primarily stored in the United States. If you are located outside the United States, your personal information may be transferred to, stored in, and processed in the United States or other countries where we or our service providers operate.

Where required by applicable law (for example, for transfers out of the European Economic Area or the United Kingdom), we use appropriate safeguards to protect your personal information, such as: (i) transfers to countries that have received an adequacy decision from the relevant authority; (ii) Standard Contractual Clauses approved by the European Commission or the UK Information Commissioner’s Office; or (iii) other safeguards permitted by applicable law.

How We Protect Your Personal Information

We maintain administrative, technical, and physical safeguards designed to protect your personal information against unauthorized access, use, alteration, or disclosure. These include encryption in transit, access controls, and regular review of our security practices. No method of transmission over the internet or method of electronic storage is entirely secure, however, and we cannot guarantee absolute security.

Your Rights

Subject to applicable law and certain exceptions, you may have the following rights regarding your personal information:

  • Right to know / right of access — request confirmation that we process your personal information, and a copy of that information.
  • Right to correct / rectify — request correction of inaccurate, incomplete, or outdated personal information.
  • Right to delete / right to be forgotten — request deletion of your personal information.
  • Right to restrict processing — in certain circumstances, request that we limit how we process your personal information.
  • Right to object — object to processing based on our legitimate interests, including direct marketing.
  • Right to data portability — receive a copy of the personal information you provided to us in a portable, machine-readable format, and request that we transmit it to another entity.
  • Right to opt out of sale or sharing — opt out of any sale or sharing of your personal information as defined under applicable law.
  • Right to non-discrimination — we will not discriminate against you for exercising any of your privacy rights.
  • Right to withdraw consent — for processing based on consent, withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint — file a complaint with a competent data protection authority, such as the California Privacy Protection Agency (CPPA) or, where applicable, your local EU data protection authority.

You may exercise these rights by emailing us at team@phone.link. We may ask you to provide information to verify your identity before responding to your request. You may also designate an authorized agent to make a request on your behalf, subject to verification as permitted by law.

Children’s Privacy

Our Services are not directed to, and we do not knowingly collect personal information from, children under the age of 13 (or a higher age threshold where required by applicable law). If we learn that we have collected personal information from a child without appropriate consent, we will take steps to delete it.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect changes in applicable law, our services, or our business practices. Changes will take effect on the date indicated at the top of this policy. We encourage you to review this page periodically. Where required by law, we will provide additional notice of material changes.

Contact Us

If you have any questions about this Privacy Policy or our privacy practices, you can contact us at:

Vir Reality Labs, Inc.
253 N. La Peer Dr., Beverly Hills, CA 90211
Email: team@phone.link