Privacy Policy

Last Updated: 2026-01-12

Our Commitment

CallBoard is built by a stagehand, for stagehands. Your privacy matters to us. We will never sell your data, spam you with nonsense, or do anything sketchy. This policy explains exactly what data we collect and why.

1. Information We Collect

Account Information

  • Email address (required for account creation and notifications)
  • Phone number (required for SMS-based two-factor authentication)
  • Name and username (for profile display)
  • Password (encrypted, never stored in plain text)

Content You Create

  • Call records (dates, times, venues, earnings)
  • Expense records and uploaded receipts
  • Skills and certifications
  • Public profile information (bio, location, etc.)
  • Availability settings

Usage Data

  • Browser type and version
  • Device type (mobile, desktop, tablet)
  • IP address and approximate location
  • Pages visited and features used
  • Login history and session data

2. How We Use Your Information

  • Provide the service: Store and display your calls, expenses, skills, etc.
  • Authentication: Verify your identity and keep your account secure
  • Notifications: Send email/SMS notifications (you control preferences)
  • Analytics: Understand how people use CallBoard to improve features
  • Support: Help troubleshoot issues and respond to questions
  • Legal compliance: Respond to legal requests if required

3. Information Sharing

We do not sell your data. Period. Here's who can see your information:

Public Profiles

Your public profile (/@username) is visible to anyone with the link. You control what information appears on your profile through privacy settings. Everything is opt-in—by default, profiles are private.

Service Providers

We use third-party services that may have access to limited data:

  • Hosting: Your data is stored on secure servers (Coolify, PostgreSQL)
  • Email: Mailgun sends transactional emails and notifications
  • Analytics: Umami (privacy-focused, no tracking cookies)

SMS & Text Messaging (Twilio)

We use Twilio to send SMS messages for:

  • Two-factor authentication codes
  • Security alerts (suspicious login attempts)
  • Work call offers and availability requests (if you enable SMS notifications)
  • Schedule confirmations and critical updates (if you enable SMS notifications)

Your SMS Consent:

  • You consent to receive text messages when you provide your phone number and check the SMS consent box
  • Standard message and data rates may apply
  • You can disable optional SMS notifications at any time in settings
  • Security codes (2FA) are required for account security and cannot be fully disabled if you use phone-based authentication
  • We do not use your phone number for marketing or promotional messages unrelated to CallBoard
  • Message frequency: As needed for security (typically 1-3 per login) and based on your notification preferences

Twilio Privacy: Twilio processes your phone number to deliver messages but does not use your data for other purposes. See Twilio's Privacy Policy.

To opt out of SMS notifications: Visit Settings → Notifications, or reply STOP, END, CANCEL, UNSUBSCRIBE, or QUIT to any message.

Legal Requirements

We may disclose your information if required by law, court order, or to protect the safety of our users.

4. How We Use Your Data

What We Never Do

  • Sell your data to data brokers or third parties
  • Share your earnings, work history, or contact info for marketing purposes
  • Track you across other websites
  • Show you random ads unrelated to theater work

What We May Do

To improve CallBoard and show you relevant opportunities, we may:

  • Show occasional offers from industry partners (e.g., equipment discounts, training opportunities) that match your skills
  • Collect aggregated, anonymized metadata (venue names, company names, job roles) to improve autocomplete suggestions
  • These offers are always clearly labeled as "Partner Offer" and are optional
  • You can disable partner offers entirely in privacy settings

How Partner Offers Work

Example: If you have "Rigging" in your skills, we might show you a discount from a rigging equipment supplier. We don't give them your email or data—we just show you the offer. It's like a bulletin board, not surveillance.

Aggregated Metadata

What "aggregated" means: We look at patterns across all users (e.g., "100 users worked at 'Lincoln Center'") without connecting data to individual people. Your specific earnings, dates worked, and work patterns remain private.

You're in control: You can opt out of metadata collection in privacy settings at any time.

5. Transparency Commitments

Data Sales Warrant Canary

Last Updated: 2026-01-12

As of this date, CallBoard:

  • ✅ Has NEVER sold user data to third parties
  • ✅ Has NEVER received a National Security Letter or FISA order
  • ✅ Has NEVER been compelled to provide user data to government agencies
  • ✅ Has NEVER provided user data to advertisers or data brokers

Our Update Schedule

We will update this section monthly. If any statement above changes, we will:

  • Update this page immediately (or as legally permitted)
  • Notify users via email and in-app notification
  • Provide transparency reports as legally allowed

Our Promise

If we ever consider selling user data, we will:

  • Notify all users at least 60 days in advance
  • Provide opt-out and account deletion options
  • Never apply changes retroactively to existing data

6. Data Security

  • Passwords are hashed using industry-standard bcrypt
  • All connections use HTTPS encryption
  • Two-factor authentication available (SMS, email, TOTP)
  • Sensitive operations require re-authentication
  • Database backups are encrypted at rest
  • Access logs monitored for suspicious activity

7. Your Rights & Choices

Access & Export

You can access all your data through CallBoard's interface. Data export features are coming in a future update.

Correction

You can update or correct your information at any time through account settings.

Deletion

You can delete your account at any time through account settings. Deletion is permanent and cannot be undone. Some data may be retained in backups for a limited time.

Notification Preferences

Control which emails and notifications you receive through notification settings. You can opt out of promotional emails but will still receive essential account-related messages.

8. Cookies & Tracking

CallBoard uses minimal cookies for essential functionality:

  • Session cookie: Keeps you logged in (required)
  • Analytics: Umami (privacy-focused, no personal data, no cross-site tracking)

We do not use advertising cookies or third-party tracking pixels. We do not participate in ad networks or retargeting campaigns.

9. Children's Privacy

CallBoard is not intended for users under 13. We do not knowingly collect information from children. If we discover that a child under 13 has created an account, we will delete it immediately.

10. International Users

CallBoard is hosted in the United States. By using the service, you consent to the transfer of your data to the US. We comply with applicable data protection laws, including GDPR for EU users.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes via email or in-app notification. Continued use of CallBoard after changes constitutes acceptance.

12. Contact Us

Questions about privacy? Want to exercise your data rights? Contact us:

Send feedback to help improve CallBoard