CallingCard

Privacy Policy

Last updated September 9, 2026

What we collect

If you're applying for jobs: your name and email address; anything you add to your profile (headline, phone number, location, bio, skills, industries, portfolio and LinkedIn links); your work history and any certifications you claim; résumés you upload, including the text we extract from them to suggest profile details and compute match scores; the applications you submit, including cover letters and answers to an employer's screening form; and, only if you opt in, the mobile carrier you select for text notifications (see below).

If you're hiring: your organization's name, website, description, logo, industry and size; the jobs you post; if you go through verification, your legal business name, tax ID, and a supporting document; and, if you upgrade to a paid plan or buy add-on job slots, your organization's billing relationship with Stripe (see below) — CallingCard never receives or stores your card number.

Automatically: a record of certain actions (sign-ins, résumé and document downloads, application submissions, job publishes, plan changes) with who did it and a short non-sensitive description. Job pages count views. We don't use advertising or cross-site tracking cookies; the only cookie we set is the one that keeps you signed in.

If you sign in with Google, LinkedIn, or Microsoft

We request the minimum each provider offers: your name, email address, and profile picture. From Microsoft we additionally read your job title once, to pre-fill your headline. We don't request or store anything beyond that — not your contacts, calendar, documents, organization directory, or any other data those accounts could expose.

As part of connecting your account, our authentication library (Auth.js) may store an access token and, if provided by the identity provider, a refresh token. These credentials are stored for authentication and session-management purposes. CallingCard does not use them to access your contacts, calendar, documents, organization directory, or other unrelated information.

Text message notifications

Text notifications are currently paused for new opt-ins — the option isn't shown in the product right now, so no one can turn it on today. If you opted in and verified a number before this was paused, that preference is unaffected and status-change texts still send to you; the rest of this section describes how that works.

When active, opting in lets us text you when an application's status changes, in addition to the email you already get. CallingCard doesn't operate a dedicated SMS network — for opted-in text notifications, we send a message to an email-to-SMS gateway associated with your mobile carrier, using our transactional-email provider.

Your carrier receives the phone number or gateway address and the message contents needed to deliver the text. Opt-in requires confirming a one-time code we text to that number first — we don't enable text notifications based solely on a carrier guess. You can turn this off for an individual application or for your account at any time from your profile.

How we use information

Depending on how you use CallingCard, we use this information to:

  • create and maintain your account, profile, and organization memberships;
  • authenticate you when you sign in;
  • publish jobs and show them to applicants;
  • send applications — and everything you included in them — to the employer you apply to;
  • suggest profile details from an uploaded résumé and compute match scores (see below);
  • send transactional email, and if you've opted in, text messages about application status, password resets, and similar account activity;
  • process plan and add-on-slot payments through Stripe;
  • enforce the response-time rules that determine whether a job stays visible (see terms);
  • prevent abuse and keep the platform secure; and
  • comply with the law and enforce our terms.

We don't use any of this to sell your information, show you targeted or cross-site advertising, market to you based on your applications, or run background checks or drug tests — CallingCard doesn't offer those (see below).

How résumé matching works

Match scores come from a rules-based comparison of profile and job information, including keyword and skill overlap, together with the relevance of your work history — not an AI or machine-learning model. No AI provider is used anywhere in CallingCard, so there is nothing to train on your résumé or applications, and nothing is sent to one.

The score is computed fresh each time it's shown, not stored. You can see it on your own dashboard for any job you've applied to; the employer reviewing that job can see it too, and can optionally sort applicants by it — off by default. The score is one optional sorting signal and does not itself determine whether an application is accepted, rejected, or advanced; a person on the hiring side always makes that call.

Who we share information with

We don't sell your personal information. We use the following vendors to provide infrastructure and other services for CallingCard; they receive the information needed to provide those services under their agreements with us:

  • Neon — our database host, where account and application data is stored.
  • Vercel — our application host and file storage (résumés and uploaded documents).
  • Resend — our transactional-email provider, which also helps deliver text notifications for opted-in applicants by relaying them to the applicable carrier email-to-SMS gateway (see above). Receives your email address (or your carrier's gateway address for texts) and the contents of those messages.
  • Stripe — processes plan upgrades and add-on job slot purchases. Stripe receives your payment details directly; CallingCard never receives or stores your card number. Stripe may separately collect billing information, such as a billing address, as part of processing a payment.
  • OpenStreetMap (Nominatim) — converts a typed location into map coordinates. Receives the location text from a job posting or your profile. It doesn't receive your name or any identifier.

Employers you apply to can see your profile, résumé, cover letter, and screening-form answers for that application. Other applicants can't. Creating a CallingCard profile doesn't by itself make it publicly searchable or visible to other applicants — your profile information is made available to an employer specifically because you applied to a job of theirs; it isn't published in a general public directory.

After an employer receives your application, the employer may use and retain that information according to its own privacy practices and legal obligations. CallingCard doesn't control an employer's independent handling of information once they've received it.

If you're part of a hiring team

If you write interview notes, scorecards, or referrals as part of an organization's hiring activity, those records stay with the organization if you later delete your personal account — a colleague's hiring records shouldn't disappear because you left. What we remove is your direct identifiers (name, email) from those records; we don't rewrite or scan the note text itself, so anything you wrote that mentions you by name or context could still be identifying.

Background checks and drug testing

CallingCard doesn't currently offer background checks, drug testing, or DOT screening, and we don't collect or hold any data related to them. If we introduce this later, we'll update this policy before it goes live.

How we protect information

Where implemented as described here, sensitive data is encrypted with AES-256-GCM in our application before it's written to the database or file storage — not just at the disk level. That currently covers every uploaded file (résumés, screening-form uploads, verification and certification documents), along with your phone number, cover letters, extracted résumé text, screening-form answers, credential numbers, recruiter notes, interview scorecards, referral notes, and organization tax IDs.

Names and email addresses are stored unencrypted, because they're how accounts are looked up at sign-in. We never store your password in plaintext — we store a bcrypt-derived hash instead. Signing in requires a fresh session at least every 24 hours of inactivity, and resetting your password signs out every other device.

No security measure eliminates every risk. We can't guarantee that information will never be accessed, disclosed, or altered through a security incident outside our control.

How long we keep information

Account data is kept while your account exists. When you request deletion from your account page, your account enters a 30-day restoration period — you can restore it yourself at any point in that window. After that, we begin permanently deleting your profile, applications, résumés, and organization memberships from our active systems. Copies may remain temporarily in encrypted backups until those backups are rotated or overwritten in accordance with our backup-retention practices.

One exception applies to personal account deletion, covered in more detail above: interview notes, scorecards, and referrals you wrote as part of a hiring team stay with the organization, with your direct identifiers removed rather than the record itself deleted.

Organization deletion is a separate action from personal account deletion, and works differently. An organization's owner can request deletion of the whole organization through the same account controls, with the same 30-day restoration period. Deleting an organization deletes its jobs, the applications submitted to those jobs, and its internal hiring records — including notes, scorecards, and referrals — along with it. It does not delete the accounts of people who applied: an applicant loses that one application from their own history, the same as if the corresponding job posting had simply been taken down.

Your choices

You can view and edit your profile at any time. You can download a copy of the personal information available for export through your account page as a JSON file, and request deletion from the same place — both self-serve, no need to wait on us for either. Depending on where you live, you may have additional rights over your personal information under state privacy law — for example, California residents may have rights under the CCPA/CPRA to access, delete, or correct their information, or to opt out of its sale or sharing. To exercise any state-law right beyond the export and deletion tools above, contact privacy@callingcard.work.

Sale, sharing, and opt-outs

We don't sell personal information for money, and we don't use it for cross-site targeted advertising. Some state privacy laws define “sale,” “sharing,” and targeted advertising more broadly than the ordinary meaning of those words. If you believe a state-law opt-out right applies to how we work with a vendor, contact privacy@callingcard.work.

Children

CallingCard isn't intended for anyone under 16, and we don't knowingly collect information from them.

Where this policy applies

CallingCard is currently intended for use in the United States. We don't currently market CallingCard as a service for users outside the United States. If you access it from another country, your information may be processed in the United States by CallingCard and by the service providers described in this policy.

Changes

If we change this policy materially, we'll update the date at the top and, where the change affects how we use data you've already given us, tell you directly.

Contact

Questions about this policy or your data go to privacy@callingcard.work (also reachable from contact). Export and deletion are both self-serve from your account page, so you don't need to wait on us for either.

Legal entity: callingcard.work.