Skip to content

Privacy Policy

Last updated: 5 September 2026

What CallKin is

CallKin is a wristband with a unique tag that links to a page showing a wearer's emergency contact information. The wristband itself stores nothing except a web address: no names, phone numbers, or medical details are ever written to the physical band.

What we collect

We collect only what the product needs to function:

  • Guardian account: your name, phone number, and email address, collected when you sign up.
  • Dependent profiles: a first name and a decorative avatar color you choose. We do not collect last names, photos, or medical information.
  • Lost-mode status: whether a dependent's lost mode is currently on, and when it was turned on.
  • Band tokens: the unique identifier printed on each physical band and which dependent (if any) it's linked to.

Why we collect it

Your name and phone number are shown to anyone who scans a band linked to your dependent. That's the entire point of the product: letting a stranger who finds a lost child (or other dependent) reach a guardian immediately. Your email is used only for authentication and account-related messages (confirmation, password reset, security notices), never for marketing.

Legal basis: we process guardian and dependent data because it's necessary to provide the service you signed up for (contract necessity). Site-usage analytics (see "Who else sees it" below) are processed under our legitimate interest in understanding how CallKin is used, weighed against your privacy since no individual tracking occurs. We also rely on legitimate interest to run a bot-detection check (Cloudflare Turnstile) on our sign-in, sign-up, and password-reset forms, to prevent automated abuse of the service. The same legitimate interest covers the technical error reports we record when something goes wrong, which we need in order to keep the service working correctly.

Who else sees it

We use a small number of infrastructure providers to run CallKin, and don't sell or share your data beyond them:

  • Supabase: hosts our database and handles authentication.
  • Google: lets you sign in with your Google account instead of a password, if you choose to. If you use it, Google verifies your identity and shares your name, email address, and profile picture with us; we never see or store your Google password. Google's privacy policy
  • Resend: delivers account emails (confirmation, password reset).
  • Vercel: hosts the application and provides first-party, cookieless traffic analytics (pageviews, referrers, top pages, device and country breakdown) so we can see how the site is used, without tracking you individually or across other sites.
  • Shopify: handles the purchase of the physical band itself. Shopify order data (your shipping address, payment details) is entirely separate from your CallKin account. We never see it, and Shopify never sees your CallKin account data.
  • Cloudflare: runs a bot-detection check (Cloudflare Turnstile) on our sign-in, sign-up, and forgot-password forms, confirming you're a real visitor rather than an automated script. It processes your IP address, browser type, and similar technical signals for that purpose only, and doesn't build an advertising profile of you. It also stores an encrypted backup copy of our database (Cloudflare R2), used only to recover from a system failure. The backup is encrypted before it ever reaches Cloudflare's servers, so Cloudflare cannot read its contents, and backups are deleted after 30 days. Details: Cloudflare's privacy policy
  • Sentry: records technical error reports when something goes wrong on our servers, so we can find and fix it. Reports contain the error and the code path that caused it, never your IP address, cookies, or the contents of your requests, and band and invite links are stripped out before anything is sent. Error data is stored in Sentry's EU region, in Germany. Sentry's privacy policy

Outside of the infrastructure providers listed above, we don't use any third-party analytics, ad-tech, or advertising trackers on this site, and we never sell or share your data with advertisers.

Resend, Vercel, Cloudflare, and Google are based in the United States; all four are certified under the EU-U.S. Data Privacy Framework, the mechanism approved under GDPR for transferring personal data from the EU/EEA to the US. Supabase's database and authentication servers are located in Frankfurt, Germany, within the EU, as is our error-monitoring data at Sentry. Sentry's parent company is US-based and is also certified under the EU-U.S. Data Privacy Framework.

How long we keep it

We keep your data for as long as your account is active. If you sign up but never confirm your email address, that incomplete signup is automatically deleted after 7 days. If you delete your account, your guardian profile and any dependents only you guard are removed immediately from our live systems. An encrypted backup copy of our database may persist for up to 30 days afterward, as part of our routine backup rotation, before being permanently deleted; it's used only to recover from a system failure, never to look up or restore an individual account. See "Your rights" below.

Cookies

We only use cookies that are strictly necessary for the site to work, never for advertising or tracking. Because they're strictly necessary, they don't require consent under GDPR/ePrivacy rules, but we're listing them here for transparency:

  • Sign-in session: keeps you signed in to your dashboard, set by Supabase (our authentication provider).
  • Language preference: remembers whether you last viewed the site in English or Norwegian.

Cloudflare Turnstile (used only on the sign-in, sign-up, and forgot-password forms) doesn't set a tracking cookie on this site. Any storage it briefly uses is strictly necessary for that security check, the same as the cookies above.

Your rights

From your dashboard, you can at any time:

  • Edit your profile and your dependents' information.
  • Export a full copy of everything we store about you and your dependents.
  • Delete your account, which permanently removes your data (see the delete-account page for exactly what this affects).

If you're in the EU/EEA or UK, these correspond to your GDPR rights of access, portability, and erasure, as well as the right to restrict or object to how we process your data. Contact us (below) for any request our dashboard doesn't cover directly. You also have the right to lodge a complaint with your national data protection authority — in Norway, Datatilsynet (datatilsynet.no).

Contact

CallKin is operated by Martin Gigstad, a sole proprietor (enkeltpersonforetak) registered in Norway. Organization number: 938 201 935. John Strandruds vei 1, 1366 Lysaker, Norway.

Questions about this policy or your data: support@callkin.co

Changes to this policy

If this policy changes materially, we'll update the date at the top of this page and, for active accounts, note it in the dashboard.