Privacy Policy
Updated at 19 August 2026
CalliSign is a trading name of MB Skaitmenos grupė, a company registered in Lithuania. In this policy “we”, “us” and “our” mean that company, which is responsible for the personal information described here. Our postal address and company registration number are available on request at hello@callisign.com.
This policy covers callisign.com and its subdomains. It says what we collect, who we send it to, how long we keep it and what you can ask us to do about it. It is written to describe the system we actually run, so where it names a table, a retention period or a supplier, that is the real one.
What we collect
When you buy a signature we collect the following, and nothing else:
Your name and email address, which you type at checkout.
Your billing country and postal code, which our payment provider collects inside its own form. On a wallet payment (Apple Pay, Google Pay, Link or PayPal) the wallet also passes us a city and region.
A phone number, but only if you pay with a wallet (Apple Pay, Google Pay, Link or PayPal) and it passes one to our payment provider. We never ask you for one, and you cannot type one into our checkout.
Your card details go directly to our payment provider and never reach our servers. We keep only the last four digits and which method you used, so that your receipt and any dispute can be matched to the payment.
Your answers to the order brief: the exact spelling of the name you want signed, style choices, whether you write left or right handed, and anything else you tell the calligrapher.
Any file you upload with the brief, which is normally a photograph of your current signature and, if you bought the headshot product, a photograph of you.
If you are buying a gift, the recipient's name and email address, the delivery date and timezone you choose, and the message you write to them.
Your IP address and browser user agent, and the timestamp at which you accepted our terms. We keep these as evidence if the payment is later disputed, which is what allows us to answer a chargeback on your behalf.
Advertising click identifiers and campaign tags that arrive in the address of the page you land on, plus that landing address itself, so we can tell which advertising works.
Which steps of the site you viewed, against a random session identifier that is not linked to your name unless you go on to buy.
We do not ask for your age or your job title, and we do not run accounts, so there is no password to lose.
Who we share it with
We do not sell personal information, and we have never done so. We share it with the suppliers we need to run the shop, each of them acting on our instructions:
Stripe, for payments, wallets, PayPal and disputes. They receive your card details directly, along with your name, email and billing address.
Supabase, which hosts our database and the private storage your uploaded files sit in.
Vercel, which hosts and serves the site.
Resend, which sends the emails your order produces: receipts, brief confirmations, reminders, gift certificates.
Klaviyo, which sends our marketing email. They receive your email address, your first name, and the fact and value of an order.
Our own fulfilment system at crm.callisign.com, which is where your calligrapher reads your brief. It receives your name, email, order reference and every answer you gave.
Meta, Google and TikTok, for advertising measurement. What they receive is described under advertising below.
Our image editing provider, but only if you bought the headshot product, and only the photograph you uploaded for it. See the section on photo editing.
Sentry, which records software errors so we can fix them. Email addresses, postal addresses, payment fragments and the private links in this site's addresses are removed before an error leaves our systems.
We will also disclose information where the law requires it, and to a buyer of the business if it is ever sold, in which case this policy travels with it.
Advertising, and what the ad platforms receive
We measure our advertising from our own database rather than trusting the platforms' own reports, but the platforms are told when a sale happens so that they can stop showing you an advert for something you have already bought.
What Meta, Google and TikTok receive for a purchase is: the value and currency, the products, and a set of matching signals. Your email address, name, city, region, postal code, country and, where a wallet gave us one, your phone number are converted to a one-way hash before they are sent, so the platform can recognise a customer it already knows without us handing over the address itself. Two identifiers are sent as they are, because a hash of them is meaningless: the click identifier from the advert you arrived on, and a customer reference generated by our payment provider. Your IP address and browser user agent are sent as part of the same measurement.
We do not currently send anything to TikTok, because that integration is not switched on.
There is no cookie consent banner on this site. We sell into the United States and Canada, where advertising measurement of this kind does not require prior opt-in. If you are in the EEA or the UK, please see the section on your rights below, and write to us: we will honour an objection.
Cookies and similar technologies
We set the following ourselves. None of them can be read by another site, none of them identifies you by name, and all of them expire after a year:
cs_fbclid, cs_gclid, cs_gbraid, cs_wbraid, cs_ttclid and cs_msclkid, which remember which advert you arrived from.
cs_utm_source, cs_utm_medium, cs_utm_campaign, cs_utm_term and cs_utm_content, which remember which campaign it belonged to.
cs_landing, the first page of your visit. Any private link in it is stripped before it is stored.
_fbc, which is the same click identifier in the format Meta requires.
cs_currency, which remembers which currency to show you prices in.
cs_express_h, which remembers how many payment buttons your browser offers, so that the checkout does not move under your finger while it loads.
Meta, Google and Klaviyo set their own cookies when their scripts load. Your browser will let you block all of this, and the site works without it.
We also keep a few things in your browser's own storage rather than in a cookie: a random session identifier for measuring the site, the advertising tags above, whether you have dismissed the discount popup, and the countdown on an offer page. They never leave your device except as described above.
Photo editing and AI processing
If you buy our professional headshot product, we ask you to upload one photograph of yourself after checkout, as part of your order brief. This section explains exactly what happens to it. It applies only to that product: your signature is drawn by hand by a calligrapher and no photograph of you is involved in producing it.
What we do with the photo. We send it to a third-party AI image editing service, which returns edited versions of the same photograph. Depending on the style you choose, the edit changes the background, the lighting, the framing and the clothing the person appears to be wearing; one of the styles keeps your own clothing and changes only the surroundings. In every case the service is instructed to leave your face unchanged. We store both your original photo and the edited versions in private storage that is not reachable from the public internet, and we serve them to you through links that expire after one hour.
How long we keep it. We delete the photograph you uploaded 30 days after your headshots are delivered. That period matches our money-back guarantee, so that we can still help you if you ask for a change. The edited versions remain available on your order page, because they are what you bought.
What we do not do with it. We do not use your photograph to train any model, we do not sell it or share it for advertising, and we do not use it for identification, verification or matching of any kind. We do not knowingly collect or store a faceprint, a facial template or any other biometric identifier derived from it, and we do not ask any provider to produce one.
Who processes it. Our current providers are Google (Gemini) and fal.ai, acting as processors on our instructions. Providers may change; the commitments in this section apply to whichever one we use.
Your choices. Uploading the photograph is entirely optional and only ever requested if you bought the headshot product. If you would rather we did not process a photograph of you, do not upload one and email hello@callisign.com, and we will refund that item. You can ask us to delete your photograph at any time before the 30 days are up by emailing the same address.
Illinois, Texas and Washington residents. If any image you send us is treated as a biometric identifier under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act or Washington law, your upload is your consent to the processing described above, for the purpose described above, under the retention schedule described above. We will not disclose it to anyone other than the processor named above without your separate consent, except where the law requires it.
How long we keep it
The photograph you upload for a headshot is deleted 30 days after your headshots are delivered, automatically. The headshots themselves stay, because they are what you bought.
A gift code is valid for 12 months from the day it is bought.
Your order, your receipt, your brief and any reference image you sent with it are kept for ten years, which is how long a trader is required to keep records of a sale. We would rather keep them for a shorter time and are reviewing it.
Records of the emails we sent you, and of the pages viewed on the site, are kept as operating records.
You can ask us to delete what we hold at any time, and we will, except where we are required to keep a record of the sale itself.
Your rights
Wherever you live, you may ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to us using it for advertising measurement. Write to hello@callisign.com from the address you ordered with and we will answer within one month. We will not charge you for it and we will not treat you differently for asking.
If you are in California, the CCPA gives you the rights to know, to delete, to correct and to opt out of the sale or sharing of personal information. We do not sell personal information. Sharing it with an advertising platform for measurement may count as “sharing” under that law, and you may opt out by writing to us at the address above.
If you are in the EEA or the UK, the GDPR applies to you. We rely on the contract with you to take payment and deliver your order, on your consent for the photograph you choose to upload, and on our legitimate interest in measuring our own advertising and preventing fraud. You have the rights above plus the rights to restrict processing, to receive your data in a portable form and to complain to your local supervisory authority.
Security
Your card details never reach us. Everything else sits in a database that is closed to the public internet by default, and the files you upload are in private storage that can only be reached through links we generate, which expire after an hour. Access to our own systems requires a second factor. No system is perfectly secure, and if we ever have a breach that affects you we will tell you.
Children
This is a product for adults and we do not knowingly collect anything from anyone under 13. If you believe a child has given us information, write to us and we will delete it.
Changes to this policy
We will change this policy when the system changes, and the date at the top is the date it last did. If a change matters to you, we will say so by email rather than expecting you to reread it.
Contact us
Questions, requests and complaints all go to the same place, and a person answers.
Via Email: hello@callisign.com
Questions? Email hello@callisign.com.