Privacy notice
Effective 14 August 2026
Who handles the information
CallGrow enquiries and setup work are handled by Jimi Cohen. Privacy questions and requests can be sent to jimi@wemakeimpact.org.
Public website visitors
The hosting service may process ordinary technical request information, such as IP address, browser information, requested page, time and security events, to deliver and protect the site. CallGrow does not add analytics, advertising cookies or cross-site tracking to this public page.
Enquiries
If you use an email link, your email address, message and anything you include are used to answer the enquiry, assess fit, prepare a requested scope and retain a reasonable business record. You do not need to include sensitive information. Your email provider and the receiving email provider also process the message under their own terms.
Authorised operator workspace
A successful sign-in creates a strictly necessary, secure session cookie named cg_session. It expires after 12 hours or when the service restarts. Passwords are handled as one-way password hashes; the service does not need to store the readable password.
When an authorised operator uses a deployed workspace, it may handle contact names and phone numbers, message content, call and message events, approximate provider costs, and configuration choices. Those records support the requested calling and messaging service. The operator is responsible for telling the people they contact how their information is used and for having any consent or other lawful basis required for calls, messages and recordings.
Inbound SMS that is only a standard opt-out or opt-in keyword is also stored on a suppression list, together with any numbers or email addresses the operator adds by hand. That list is used to block further texts or emails (and, when the operator records a do-not-call entry, further calls) to that contact. Removing an entry requires a recent sign-in.
Service providers and location
The public service is hosted by Fly.io, and telephone services are provided through Telnyx. Email providers process emailed enquiries. These providers may process information in countries other than your own. A customer’s final deployment and provider configuration are documented in its agreed setup scope.
Retention and security
Enquiries are kept only as long as reasonably needed to respond, manage an agreed service, resolve disputes and meet legal or accounting obligations. Workspace records remain in the isolated deployment until the operator deletes them or the agreed service ends, subject to backups and legal requirements. CallGrow uses password access, secure cookies, restrictive browser policies, spend controls and optional signed-webhook verification, but no online service can promise absolute security.
Your choices and requests
You may ask for access to or correction or deletion of information linked to you, object to further enquiry contact, or make a privacy complaint by emailing jimi@wemakeimpact.org. Enough information may be requested to verify the request and find the relevant record. Some records may need to be retained where the law permits or requires it.
Changes
Material changes will be posted here with a new effective date. If a proposed customer setup introduces materially different data handling, that handling should be described in the written scope before activation.