Privacy policy
1. Controller
The controller is the operator identified in the imprint. Privacy enquiries can be sent to the email address stated there.
2. Data processed
- Account data: username, email address, password hash and email verification status
- Order data: destination number, package, category, language, interval or daily rate, and time
- Records of consent from the order process
- Payment references and status notifications from Stripe; CatCall does not store complete card details
- SMS content, delivery schedule, provider ID, delivery status and technical errors
- Blocklist entries used to enforce a requested delivery stop
- Technical security data such as session cookies and irreversibly hashed attributes used for access limits
- Server logs maintained by the hosting provider, including time, requested page, IP address and browser details
3. Purposes
Data is processed to manage accounts and contracts, allocate payments, schedule and deliver SMS messages, display delivery status, administer subscriptions, process support and deletion requests, and prevent misuse and technical attacks.
4. Recipients and service providers
- Stripe: payment processing, subscriptions, invoices, customer portal and fraud-prevention data. Stripe may process data internationally using contractual and statutory transfer mechanisms.
- Peoplefone AG, Switzerland: destination number, SMS content, and sending and delivery data required for SMS transmission.
- [Name des Hosters], Schweiz: hosting, database, backups, server and email operation.
Other disclosures are made only when necessary to provide the service, maintain security, enforce legal rights or comply with a legal obligation.
5. Recipient data
The destination number may be provided by the customer and is therefore not necessarily collected directly from the recipient. Customers may use only numbers they are authorised to use and whose owners have consented to receiving the messages. Recipients can block their number at any time through Block a number.
6. Cookies and account security
CatCall uses technically necessary session cookies. When “Stay signed in” is enabled, a random rotating login token is stored for up to 30 days. Only a hash of the server-side token is retained. No advertising or analytics cookies are used.
7. Retention
Data is retained only as long as necessary for contract performance, delivery records, security, handling objections or statutory retention duties. Short-lived security and reset tokens expire after minutes, hours or days. Persistent login tokens expire after no more than 30 days or are deleted following a password change or logout. Blocklist entries remain until the affected person or an administrator removes the block. Order and payment records may be retained to the extent required after account deletion and anonymised where possible.
8. Rights
Subject to applicable law, affected persons may request access, correction, release or transfer, deletion, restriction or objection to processing. Account holders can manage profile data, passwords, active logins and deletion requests under Account. Enquiries can also be sent using the contact details in the imprint.
9. Data security
Measures include HTTPS, access controls, hashed passwords and tokens, CSRF protection, request limits, signed Stripe webhooks, protected Peoplefone callbacks and prepared database statements. Absolute security cannot be guaranteed technically.
10. External information
Stripe Privacy Center · Peoplefone privacy information · FDPIC duty to provide information
11. Updates
This policy is updated when functions, service providers or legal requirements change.
Last updated: 22 July 2026