Privacy Policy

Last updated: January 22, 2026

1. Introduction

Effective Date: January 22, 2026

Welcome to CallPastNow. We understand that you are entrusting us with something deeply personal—the voices and memories of those you love. This trust is not something we take lightly.

This Privacy Policy explains how CallPastNow ("we," "us," or "our") collects, uses, shares, and protects your personal information when you visit our website at callpastnow.com ("Site") or use our services. We are committed to protecting your privacy and handling your data with transparency, respect, and care.

Our Commitment: We collect only what we need, we never sell your data, and we give you control over your information. We are real people, and we are here to help.

2. Information We Collect

We collect information to provide you with a meaningful experience and to improve our services. Here's what we collect and why:

CategoryData CollectedPurpose
Contact InformationEmail addressSend updates and launch notifications
PreferencesPurpose of interest (optional)Personalize communications
Consent RecordsMarketing consent status, timestampLegal compliance (GDPR/CCPA)
Device/Usage DataBrowser type, pages visited, session durationImprove website experience (with consent)
Technical IdentifiersIP address (anonymized), device fingerprintSecurity and fraud prevention

Information We Do NOT Collect: We do not collect sensitive personal information such as racial or ethnic origin, political opinions, religious beliefs, genetic data, biometric data, or health information through this website.

3. How We Use Your Information

We use your information only for specific, legitimate purposes. Under GDPR, we must have a "lawful basis" for processing your data. Here's how we use it:

PurposeData UsedLawful Basis (GDPR)
Send launch notificationsEmail addressConsent
Send marketing emailsEmail, preferencesConsent
Analyze website usageDevice/usage dataConsent
Prevent fraud and spamTechnical identifiersLegitimate Interest
Respond to inquiriesEmail, message contentConsent / Contract
Comply with legal obligationsAll relevant dataLegal Obligation

5. Third-Party Services

We use trusted third-party services to help operate our website and communicate with you. Here's who they are and what they do:

Mailchimp (Email Marketing)

  • Provider: The Rocket Science Group, LLC
  • Data Shared: Email address, consent status, preferences
  • Location: United States
  • Safeguards: EU-US Data Privacy Framework certified
  • Privacy Policy: mailchimp.com/legal/privacy

PostHog (Analytics)

  • Provider: PostHog, Inc.
  • Data Shared: Page views, session data, anonymized device info
  • Location: EU (hosted on EU servers)
  • Safeguards: Privacy-first analytics, consent-based tracking only
  • Privacy Policy: posthog.com/privacy

Google reCAPTCHA v3 (Bot Protection)

  • Provider: Google LLC
  • Data Shared: Hardware/software info, risk analysis score
  • Location: United States
  • Safeguards: Standard Contractual Clauses
  • Note: reCAPTCHA analyzes browser behavior to detect bots. We only receive a risk score, not the underlying data.
  • Privacy Policy: policies.google.com/privacy

6. Cookies and Tracking

Cookies are small text files stored on your device that help us provide and improve our services. Here are the cookies we use:

Strictly Necessary Cookies

These cookies are essential for the website to function. You cannot opt out of these.

Cookie NamePurposeDuration
cookie_consentRemembers your cookie preferences1 year
_grecaptchareCAPTCHA bot protectionSession

Analytics Cookies (Require Consent)

These cookies help us understand how visitors use our website.

Cookie NamePurposeDuration
ph_*PostHog analytics identifier1 year

Note: We do not currently use marketing or advertising cookies.

7. Your Privacy Rights (Global)

Regardless of where you live, we believe everyone deserves control over their personal data. Here are your rights:

  • Right to Access: Request a copy of all personal data we hold about you
  • Right to Correction: Request correction of inaccurate or incomplete data
  • Right to Deletion: Request deletion of your personal data ("right to be forgotten")
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Restrict Processing: Limit how we use your data
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time
  • Right to Lodge a Complaint: Complain to a supervisory authority

To exercise any of these rights: Email us at privacy@callpastnow.com

We will respond to all legitimate requests within 30 days (or within the timeframe required by applicable law).

8. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).

Important: We do NOT sell your personal information. We do NOT share your personal information for cross-context behavioral advertising.

Your California Rights

  • Right to Know: What personal information we collect and how it's used
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Request correction of inaccurate information
  • Right to Opt-Out: Opt out of sale/sharing (not applicable—we don't sell)
  • Right to Non-Discrimination: We will not treat you differently for exercising your rights

Categories of Personal Information Collected

CCPA CategoryExamplesCollected?
IdentifiersEmail address, IP addressYes
Internet ActivityBrowsing history, interactionsYes (with consent)
InferencesPreferences, interestsLimited
Sensitive Personal InfoAccount credentials, etc.No

To submit a request: Email privacy@callpastnow.com with "California Privacy Request" in the subject line.

9. International Data Transfers

CallPastNow is based in the United States. If you are accessing our website from outside the US, please be aware that your information may be transferred to, stored, and processed in the United States.

Safeguards for EU/EEA/UK Users

We protect international data transfers through:

  • EU-US Data Privacy Framework: Our email provider (Mailchimp) is certified under the EU-US DPF
  • Standard Contractual Clauses (SCCs): We use EU-approved SCCs with service providers
  • Supplementary Measures: Including encryption in transit and at rest

By using our website, you acknowledge that your data may be transferred internationally with these protections in place.

10. Data Security

We implement robust security measures to protect your personal data:

Technical Measures

  • TLS 1.3 encryption for all data in transit (HTTPS)
  • AES-256 encryption for data at rest
  • Access controls and authentication for systems
  • Regular security assessments and updates
  • DDoS protection and Web Application Firewall

Organizational Measures

  • Privacy by Design principles in all development
  • Vendor security assessments before engagement
  • Data minimization (we only collect what we need)
  • Staff training on data protection

Breach Notification

In the unlikely event of a data breach affecting your personal information, we will:

  • Notify affected users within 72 hours (as required by GDPR)
  • Report to relevant supervisory authorities where required
  • Provide information about the breach and steps to protect yourself

11. Data Retention

We retain your data only for as long as necessary to fulfill the purposes described in this policy:

Data TypeRetention PeriodReason
Email (subscribed)Until unsubscribe + 30 daysActive subscription
Consent records6 years after collectionLegal compliance proof
Analytics data26 monthsWebsite improvement
reCAPTCHA dataSession onlyImmediate security check
Support inquiries2 years after resolutionService improvement

After the retention period, data is securely deleted or anonymized.

12. Children's Privacy

CallPastNow is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@callpastnow.com.

If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information as quickly as possible.

For users between 13-16 years old (or the applicable age of consent in your jurisdiction), parental consent may be required for certain processing activities.

13. Do Not Track Signals

We respect your browser's privacy signals:

  • Do Not Track (DNT): We honor DNT browser signals. When DNT is enabled, we will not load analytics cookies without explicit consent.
  • Global Privacy Control (GPC): We recognize and honor GPC signals as a valid opt-out mechanism, treating them as a request to opt out of data sharing and targeted advertising (though we don't engage in these practices).

Note: Strictly necessary cookies (like cookie consent preferences) will still function regardless of these signals, as they are essential to website operation.

14. Automated Decision-Making

reCAPTCHA Risk Assessment

We use Google reCAPTCHA v3 to protect our forms from spam and abuse. This involves automated analysis of your browser behavior to generate a risk score.

  • What it analyzes: Mouse movements, typing patterns, browser characteristics
  • What we receive: A risk score (0.0 to 1.0) indicating likelihood of being a bot
  • Effect: Low scores may prevent form submission; you can retry or contact us directly
  • Appeal: If you're incorrectly blocked, email us at privacy@callpastnow.com

AI and Automated Decisions

We do not currently use AI or automated decision-making that significantly affects you (such as credit decisions or automated profiling for marketing). If this changes in the future, we will:

  • Update this policy with clear disclosures
  • Provide information about the logic involved
  • Offer a way to request human review of automated decisions

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons.

Minor Changes

For minor updates (typos, clarifications), we will update the "Last Updated" date at the top of this policy.

Material Changes

For significant changes that affect your rights or how we use your data, we will:

  • Provide at least 30 days' notice before the changes take effect
  • Notify you via email (if you're subscribed to our mailing list)
  • Display a prominent notice on our website
  • Request new consent where required by law

Policy Archive: Previous versions of this policy are available upon request. Email privacy@callpastnow.com to request historical versions.

16. Contact Us

We're here to help with any privacy questions or concerns:

Privacy Contact

Email: privacy@callpastnow.com

We aim to respond to all inquiries within 5 business days.

Supervisory Authorities

If you're not satisfied with our response, you have the right to lodge a complaint with a supervisory authority:

Key Points Summary

  • We only collect email, preferences, and consent data for mailing list signup
  • We do NOT sell your personal information
  • Analytics only run with your explicit consent
  • You can access, correct, or delete your data anytime
  • We honor Do Not Track and Global Privacy Control signals
  • Questions? Email privacy@callpastnow.com

Thank you for trusting CallPastNow with your memories.

We take that trust seriously.