1. Introduction
Effective Date: January 22, 2026
Welcome to CallPastNow. We understand that you are entrusting us with something deeply personal—the voices and memories of those you love. This trust is not something we take lightly.
This Privacy Policy explains how CallPastNow ("we," "us," or "our") collects, uses, shares, and protects your personal information when you visit our website at callpastnow.com ("Site") or use our services. We are committed to protecting your privacy and handling your data with transparency, respect, and care.
Our Commitment: We collect only what we need, we never sell your data, and we give you control over your information. We are real people, and we are here to help.
2. Information We Collect
We collect information to provide you with a meaningful experience and to improve our services. Here's what we collect and why:
| Category | Data Collected | Purpose |
|---|---|---|
| Contact Information | Email address | Send updates and launch notifications |
| Preferences | Purpose of interest (optional) | Personalize communications |
| Consent Records | Marketing consent status, timestamp | Legal compliance (GDPR/CCPA) |
| Device/Usage Data | Browser type, pages visited, session duration | Improve website experience (with consent) |
| Technical Identifiers | IP address (anonymized), device fingerprint | Security and fraud prevention |
Information We Do NOT Collect: We do not collect sensitive personal information such as racial or ethnic origin, political opinions, religious beliefs, genetic data, biometric data, or health information through this website.
3. How We Use Your Information
We use your information only for specific, legitimate purposes. Under GDPR, we must have a "lawful basis" for processing your data. Here's how we use it:
| Purpose | Data Used | Lawful Basis (GDPR) |
|---|---|---|
| Send launch notifications | Email address | Consent |
| Send marketing emails | Email, preferences | Consent |
| Analyze website usage | Device/usage data | Consent |
| Prevent fraud and spam | Technical identifiers | Legitimate Interest |
| Respond to inquiries | Email, message content | Consent / Contract |
| Comply with legal obligations | All relevant data | Legal Obligation |
4. Consent Management
How You Give Consent
- Mailing List: By checking the opt-in checkbox and submitting the signup form
- Analytics Cookies: By clicking "Accept" on our cookie consent banner
- reCAPTCHA: Automatically activated for form protection (covered under our legitimate interest in preventing spam)
How to Withdraw Consent
You can withdraw consent at any time through these methods:
- Email Marketing: Click the "Unsubscribe" link in any email
- Analytics Cookies: Use the cookie settings link in our footer or clear your browser cookies
- All Data: Email us at privacy@callpastnow.com to request deletion
Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
5. Third-Party Services
We use trusted third-party services to help operate our website and communicate with you. Here's who they are and what they do:
Mailchimp (Email Marketing)
- Provider: The Rocket Science Group, LLC
- Data Shared: Email address, consent status, preferences
- Location: United States
- Safeguards: EU-US Data Privacy Framework certified
- Privacy Policy: mailchimp.com/legal/privacy
PostHog (Analytics)
- Provider: PostHog, Inc.
- Data Shared: Page views, session data, anonymized device info
- Location: EU (hosted on EU servers)
- Safeguards: Privacy-first analytics, consent-based tracking only
- Privacy Policy: posthog.com/privacy
Google reCAPTCHA v3 (Bot Protection)
- Provider: Google LLC
- Data Shared: Hardware/software info, risk analysis score
- Location: United States
- Safeguards: Standard Contractual Clauses
- Note: reCAPTCHA analyzes browser behavior to detect bots. We only receive a risk score, not the underlying data.
- Privacy Policy: policies.google.com/privacy
7. Your Privacy Rights (Global)
Regardless of where you live, we believe everyone deserves control over their personal data. Here are your rights:
- Right to Access: Request a copy of all personal data we hold about you
- Right to Correction: Request correction of inaccurate or incomplete data
- Right to Deletion: Request deletion of your personal data ("right to be forgotten")
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Restrict Processing: Limit how we use your data
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Lodge a Complaint: Complain to a supervisory authority
To exercise any of these rights: Email us at privacy@callpastnow.com
We will respond to all legitimate requests within 30 days (or within the timeframe required by applicable law).
8. California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
Important: We do NOT sell your personal information. We do NOT share your personal information for cross-context behavioral advertising.
Your California Rights
- Right to Know: What personal information we collect and how it's used
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out: Opt out of sale/sharing (not applicable—we don't sell)
- Right to Non-Discrimination: We will not treat you differently for exercising your rights
Categories of Personal Information Collected
| CCPA Category | Examples | Collected? |
|---|---|---|
| Identifiers | Email address, IP address | Yes |
| Internet Activity | Browsing history, interactions | Yes (with consent) |
| Inferences | Preferences, interests | Limited |
| Sensitive Personal Info | Account credentials, etc. | No |
To submit a request: Email privacy@callpastnow.com with "California Privacy Request" in the subject line.
9. International Data Transfers
CallPastNow is based in the United States. If you are accessing our website from outside the US, please be aware that your information may be transferred to, stored, and processed in the United States.
Safeguards for EU/EEA/UK Users
We protect international data transfers through:
- EU-US Data Privacy Framework: Our email provider (Mailchimp) is certified under the EU-US DPF
- Standard Contractual Clauses (SCCs): We use EU-approved SCCs with service providers
- Supplementary Measures: Including encryption in transit and at rest
By using our website, you acknowledge that your data may be transferred internationally with these protections in place.
10. Data Security
We implement robust security measures to protect your personal data:
Technical Measures
- TLS 1.3 encryption for all data in transit (HTTPS)
- AES-256 encryption for data at rest
- Access controls and authentication for systems
- Regular security assessments and updates
- DDoS protection and Web Application Firewall
Organizational Measures
- Privacy by Design principles in all development
- Vendor security assessments before engagement
- Data minimization (we only collect what we need)
- Staff training on data protection
Breach Notification
In the unlikely event of a data breach affecting your personal information, we will:
- Notify affected users within 72 hours (as required by GDPR)
- Report to relevant supervisory authorities where required
- Provide information about the breach and steps to protect yourself
11. Data Retention
We retain your data only for as long as necessary to fulfill the purposes described in this policy:
| Data Type | Retention Period | Reason |
|---|---|---|
| Email (subscribed) | Until unsubscribe + 30 days | Active subscription |
| Consent records | 6 years after collection | Legal compliance proof |
| Analytics data | 26 months | Website improvement |
| reCAPTCHA data | Session only | Immediate security check |
| Support inquiries | 2 years after resolution | Service improvement |
After the retention period, data is securely deleted or anonymized.
12. Children's Privacy
CallPastNow is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@callpastnow.com.
If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information as quickly as possible.
For users between 13-16 years old (or the applicable age of consent in your jurisdiction), parental consent may be required for certain processing activities.
13. Do Not Track Signals
We respect your browser's privacy signals:
- Do Not Track (DNT): We honor DNT browser signals. When DNT is enabled, we will not load analytics cookies without explicit consent.
- Global Privacy Control (GPC): We recognize and honor GPC signals as a valid opt-out mechanism, treating them as a request to opt out of data sharing and targeted advertising (though we don't engage in these practices).
Note: Strictly necessary cookies (like cookie consent preferences) will still function regardless of these signals, as they are essential to website operation.
14. Automated Decision-Making
reCAPTCHA Risk Assessment
We use Google reCAPTCHA v3 to protect our forms from spam and abuse. This involves automated analysis of your browser behavior to generate a risk score.
- What it analyzes: Mouse movements, typing patterns, browser characteristics
- What we receive: A risk score (0.0 to 1.0) indicating likelihood of being a bot
- Effect: Low scores may prevent form submission; you can retry or contact us directly
- Appeal: If you're incorrectly blocked, email us at privacy@callpastnow.com
AI and Automated Decisions
We do not currently use AI or automated decision-making that significantly affects you (such as credit decisions or automated profiling for marketing). If this changes in the future, we will:
- Update this policy with clear disclosures
- Provide information about the logic involved
- Offer a way to request human review of automated decisions
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons.
Minor Changes
For minor updates (typos, clarifications), we will update the "Last Updated" date at the top of this policy.
Material Changes
For significant changes that affect your rights or how we use your data, we will:
- Provide at least 30 days' notice before the changes take effect
- Notify you via email (if you're subscribed to our mailing list)
- Display a prominent notice on our website
- Request new consent where required by law
Policy Archive: Previous versions of this policy are available upon request. Email privacy@callpastnow.com to request historical versions.
16. Contact Us
We're here to help with any privacy questions or concerns:
Privacy Contact
Email: privacy@callpastnow.com
We aim to respond to all inquiries within 5 business days.
Supervisory Authorities
If you're not satisfied with our response, you have the right to lodge a complaint with a supervisory authority:
- EU: Your local Data Protection Authority (find yours at EDPB Members)
- UK: Information Commissioner's Office (ico.org.uk)
- California: Office of the Attorney General (oag.ca.gov/privacy)
Key Points Summary
- We only collect email, preferences, and consent data for mailing list signup
- We do NOT sell your personal information
- Analytics only run with your explicit consent
- You can access, correct, or delete your data anytime
- We honor Do Not Track and Global Privacy Control signals
- Questions? Email privacy@callpastnow.com
Thank you for trusting CallPastNow with your memories.
We take that trust seriously.