Privacy Policy
Privacy Policy
Effective Date: 2026-09-02
Granite Logic, LLC ("Crafted Call", "we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use craftedcall.com (the "Service").
Information We Collect
Account information: Email address, name, and password (hashed by AWS Cognito — we never see your plaintext password).
Profile information: Location, biography, artist statement, portfolio images, and social links you choose to provide.
Submission content: Artwork files, artist statements, and related materials submitted to calls for artists.
Payment information: Payment is processed by Stripe. We store transaction records but never see raw card numbers.
Usage data: Pages visited, features used, and error logs for service improvement.
Device data: IP address, browser type, and device identifiers for security and analytics.
How We Use Your Information
- To provide, operate, and improve the Service
- To process transactions and send related notices
- To send administrative emails (submission confirmations, jury decisions, billing receipts)
- To detect and prevent fraud and abuse
- To comply with legal obligations
Text Messages (SMS)
If you enable SMS notifications in Settings → Notifications, we collect your mobile number, the date, time, and IP address of your consent, your verification and opt-out status, and delivery logs for the messages we send.
We use your mobile number only to send a one-time passcode that verifies the number and the transactional account notifications you turned on, such as an artwork being accepted, sold, or ready for pickup. We do not send marketing or promotional text messages.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are never sold or shared with any third party. Messages are delivered through Amazon Web Services acting only as our service provider.
Message frequency varies with your account activity. Message and data rates may apply. Reply STOP to any message to opt out, or turn SMS off in Settings → Notifications. Reply HELP or email support@craftedcall.com for help. The program terms are in our Terms of Service.
Cookies
We use strictly necessary cookies for authentication and security. We use functional cookies to remember your preferences. See our Cookie Policy for details.
Your Rights Under GDPR
If you are in the European Economic Area, you have the following rights:
- Right to access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate data.
- Right to erasure: Request deletion of your personal data, subject to legal retention requirements.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to restriction: Request that we limit how we use your data.
- Right to object: Object to processing based on legitimate interests.
To exercise these rights, visit Settings → Privacy or email privacy@craftedcall.com.
Legal basis for processing: We process your data on the basis of (a) contract performance (providing the Service), (b) legitimate interests (security, fraud prevention, service improvement), (c) legal obligation (financial record keeping), and (d) consent (marketing emails).
International transfers: Your data is stored in AWS us-east-1 (N. Virginia) with backup copies in AWS us-west-2 (Oregon) and a 30-day offsite backup copy held on encrypted equipment controlled by Granite Logic, LLC in the United States. Data transfers to the US from the EEA rely on Standard Contractual Clauses (SCCs).
Data Protection Officer: We do not have a designated DPO. Contact privacy@craftedcall.com for all privacy inquiries.
Your Rights Under CCPA
If you are a California resident, you have the following rights:
- Right to know: Request disclosure of personal information we collect, use, disclose, or sell about you.
- Right to delete: Request deletion of personal information, subject to exceptions.
- Right to opt-out of sale: We do not sell personal information. You may still submit a "Do Not Sell or Share" request from your account settings.
- Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise CCPA rights, visit Settings → Privacy or email privacy@craftedcall.com.
Retention
- Account data: Retained until you delete your account, then anonymized within 30 days.
- Audit logs: 90 days (aligned with our operational audit log retention policy).
- Submission artwork: Retained while the organization's account is active, then until the organization or artist deletes it.
- Financial records: 7 years, or longer where a tax law or an open assessment requires it.
- Email logs: 90 days for transactional delivery logs.
Breach Notification
If we experience a personal data breach we will assess it promptly and notify affected customers and any regulator we are required to notify as soon as practicable, in accordance with the law that applies to you. Contractual notification timeframes for organisation customers are set out in the Data Processing Addendum.
Children's Privacy
We do not knowingly collect personal information from children under 18. If we discover we have collected such data, we will delete it within 30 days.
Changes to This Policy
We will post material changes to this page with an updated effective date. For significant changes, we will notify you by email.
Contact
For privacy questions or requests: privacy@craftedcall.com
Granite Logic, LLC
66 Hanover Street, Suite 201
Manchester, New Hampshire 03101, United States
Privacy inquiries: privacy@craftedcall.com
Australia
This section applies to individuals in Australia and to personal information we handle in Australia. It applies in addition to the rest of this Privacy Policy. Where this section conflicts with another part of this Policy, this section prevails for individuals in Australia.
Who we are
Crafted Call is operated by Granite Logic, LLC, 66 Hanover Street, Suite 201, Manchester, New Hampshire 03101, United States. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
The personal information we collect and hold
- Account and identity: name, email address, password credentials held by our authentication provider, and the record of which versions of our legal terms you accepted and when.
- Profile and professional information: location, biography, artist statement, curriculum vitae, portfolio images, website and social links.
- Submission and program content: artwork files, statements, dimensions, pricing, jury scores and feedback, exhibition and inventory records.
- Commerce information: billing name and email, delivery and billing addresses, order and ticket records, membership and donation records, refunds, and payout details where you receive money through the platform. We do not hold full card numbers; card details are handled by Stripe.
- Communications: messages you send through the platform, support requests, email delivery and engagement events, and marketing preferences with the evidence of any consent you gave.
- Technical information: IP address, browser and device identifiers, pages visited, and error and security logs.
How we collect it
We collect most personal information directly from you when you create an account, complete a profile, submit to a call, buy a ticket or artwork, join as a member, make a donation, or contact us. We also collect personal information from the organisation you deal with - for example when a gallery adds you as a member, staff member, juror or volunteer, or imports a contact list. Where we collect your information from an organisation rather than from you, we take reasonable steps to ensure you are made aware of the matters in this section.
Why we use and disclose it
We use personal information to provide and operate the platform, to process payments and issue receipts and invoices, to deliver the programs the organisation you deal with is running, to send service messages, to prevent fraud and abuse, to improve and secure the service, and to meet our legal obligations.
We disclose personal information to: the organisation whose call, event, shop, membership or exhibition you are participating in; our service providers (below); and to a regulator, court or law enforcement body where we are required or authorised to do so.
We do not sell personal information and we do not disclose it to third parties for their own marketing.
Overseas recipients
Crafted Call is operated from the United States and your personal information is stored and processed overseas. We are likely to disclose personal information to recipients located in the United States.
Our service providers and the countries in which they hold or process personal information are listed at craftedcall.com/legal/subprocessors. We keep that list current and give notice before we add or change a provider that handles customer personal information.
Because these recipients are outside Australia, they are generally not subject to the Australian Privacy Principles and you may not be able to seek redress under the Privacy Act against them directly. Under Australian Privacy Principle 8 we take steps that are reasonable in the circumstances to ensure they do not breach the Australian Privacy Principles, including by binding them contractually to handle your information consistently with those principles, to keep it secure, to notify us of any breach, and to return or delete it when our arrangement ends. We remain accountable to you under Australian law for how those recipients handle your information.
How we keep it secure
We protect personal information with technical and organisational measures including encryption in transit and at rest, access controls and least-privilege administration, audit logging, network controls, and regular patching. No system is completely secure, and we cannot guarantee absolute security.
How long we keep it
We keep personal information only as long as we need it, then destroy or de-identify it, unless an Australian law requires us to keep it. In particular, Australian tax law requires us to keep records of transactions for at least five years, and longer where an assessment remains open. When you delete your account we de-identify your personal information and retain only the transaction records we are required to keep, with your identity reduced to what the law requires.
Backup copies are held on a rolling schedule and are not accessible for ordinary use. Where a backup is restored, we re-apply any deletion or de-identification that had already been made.
Accessing and correcting your information
You can access and correct most of your information directly at Settings, then Privacy. You can also ask us at privacy@craftedcall.com. We will respond within a reasonable period, which we aim to keep to 30 days, and we will tell you if we need longer and why. We do not charge you for making a request or for correcting information. If we refuse access or correction we will tell you why in writing and how to complain.
Some information is held by the organisation you deal with rather than by us. If your request concerns that information we will tell you and help you direct it to the right organisation.
Marketing
We only send you marketing email if you have asked us to, or asked the organisation you deal with to. Every marketing message identifies who authorised it and includes an unsubscribe link. Unsubscribing takes effect within five business days at the latest, and usually immediately. You can also change your preferences in your account at any time. Unsubscribing from marketing does not stop service messages such as receipts, submission confirmations and security notices.
If something goes wrong
If we experience a data breach that is likely to result in serious harm, we will assess it promptly and, where the Notifiable Data Breaches scheme applies, notify the Office of the Australian Information Commissioner and the individuals at risk as soon as practicable, and tell you what has happened, what information was involved, and what you should do.
Complaints
If you think we have mishandled your personal information, contact privacy@craftedcall.com with the details. We will acknowledge your complaint within 5 business days and give you a written response within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, GPO Box 5288, Sydney NSW 2001.
If your complaint concerns information we hold for a Western Australian public body, you may also contact the Office of the Information Commissioner Western Australia: oic.wa.gov.au.
Contact
Privacy enquiries: privacy@craftedcall.com
Granite Logic, LLC, 66 Hanover Street, Suite 201, Manchester, NH 03101, USA
This is version 1.2 of the Privacy Policy, effective September 2, 2026. View version history.
Questions? Contact legal@craftedcall.com.

