Privacy
Callout — employment scheduling notifications. Operated by Noah Schwartz (sole proprietor); the business is Callout Solutions LLC, in formation.
In short
Callout is a workplace scheduling tool. It holds the employment information it needs to work out who can legally and practically cover an open shift, and a record of the messages it exchanged doing so. It is not advertising technology: there is no tracking of you across other sites, no profile sold to anyone, and no marketing use of your number.
What is stored
- Identity and contact — name, employee code, mobile phone number, home store, and whether the record is active. The phone number is how an inbound text is matched to a person.
- Employment attributes used by the compliance rules — position, wage rate, certifications and their expiry dates, weekly availability, maximum weekly hours, and whether the employee may work at another store. Wage rate is held because the manager is shown the projected cost of a change before approving it.
- Schedule and time — assigned shifts, and clock-in/clock-out records where available. These are what the overtime rules are computed against.
- Messages — the full text of messages sent and received, the staff member’s identifying number on the schedule, the number a message was actually delivered to, timestamps, delivery identifiers and any delivery error. Those last two are separate on purpose: the number a message is addressed to comes from the consent record for that person, so it can differ from the identifying number the schedule uses, and we record both rather than assuming they match. Messages recorded before this distinction was stored show no delivery number rather than a guessed one. Inbound messages also store the intent the system read from them and how confident it was.
- Consent records — which phone number consented to receive messages for which person, and an append-only history of every consent event: the invitation, the verbatim
YESthat granted it, and anySTOPthat withdrew it, each with its timestamp and delivery identifier. This record is what proves an opt-out was honored, so it cannot be edited — only added to. - Decisions and audit trail — every offer, acceptance, decline, approval and escalation, each candidate the rules considered with the reason they passed or were excluded, and a timestamped audit event for every state change. This exists so a schedule change can be explained after the fact.
- Reliability events — objective attendance facts only: no-show, late callout, late arrival. Declining an offer is never recorded against you; that is a deliberate commitment, not an oversight.
Why
To find someone who is actually allowed to work an open shift — certified, available, not already booked, and within federal, Nevada and company overtime limits — to ask them, to get a manager’s approval, and to be able to show afterwards how that decision was reached. The audit trail is the point of the system, not a by-product: a scheduling decision that cannot be explained is not one a manager should have to defend.
Who else processes it
No data is sold, rented, or shared for anyone’s marketing. It is handled by the service providers that make the product function, each only for that purpose:
- Twilio — delivers and receives the text messages. Twilio sees the phone number and the message content, as any messaging carrier must.
- Anthropic — classifies free-text inbound messages, so that “can’t make it tomorrow” is understood as a callout. The message text is sent for that classification. Exact keywords (
YES,NO,OUT) are matched locally and are never sent anywhere. - Supabase (database) and Amazon Web Services (application hosting) — store and run the system.
How long it is kept
The pilot runs on synthetic employee data, and pilot operational records are routinely destroyed when the demo environment is reset.
The real personal data we handle during the pilot — participating testers' phone numbers and the messages they send — is kept only while the pilot runs. It is then deleted from our systems, and we redact the message content held by our messaging provider.
One deliberate exception: the consent record itself — the invitation, the verbatim opt-in reply, and any opt-out, with their timestamps — is retained as compliance evidence, because proof that an opt-out was honored has to survive the opt-out.
Before any real employee data enters the system, retention terms will be agreed with the employer and this policy will be updated first.
Pilot status — the data in the system today
The system is in a pilot. The employee records, schedules, wages and punch data loaded into it are synthetic — generated fictional people with fictional 555 phone numbers that belong to nobody. Real mobile numbers exist only for the handful of team members taking part in a live demonstration, and only as consent enrollment records — each one entered by invitation and activated by that person’s own YES. They are never written into employee records. No real employee’s personal data has been loaded.
Two different limits apply, and they are enforced in different places. Separation between customer organizations is enforced by the database: the application connects with no standing permission to read across organizations, and each request is confined to the one the signed-in person belongs to. Which locations a manager can see, and whether they may approve changes or only look, is enforced by the application from permissions granted to that specific account — not by the database, and not as a property of being logged in.
One pilot limitation remains, and it is a real one: the manager sign-in is a shared credential rather than one login per person, so the system can record which organization is acting but not always which individual. That is why real employee data has not been loaded into it.
If you ask us for a demo
The form on the front page is the one place this site collects information from someone who is not an employee of a customer. It stores exactly what you type — your name, email address, company, and how many locations you run — and the time you sent it. Nothing else: no cookie is set for it, there is no analytics or tracking on the page, and your submission is not enriched from any other source.
It is used to reply to you and for nothing else. It is not a mailing list, it is not shared, and it is not sold. It is also not connected to any customer’s data: a demo request belongs to no organization in the system, and is stored where the scheduling application cannot read it at all — only an operator can. We keep it while we are in contact and delete it when a conversation has clearly ended, or sooner if you ask at support@callout.solutions.
Your requests
To ask what is held about you, to correct it, to have it deleted, or to have your number removed from messaging: support@callout.solutions. To stop messages immediately, reply STOP to any message — see the messaging terms. Because this is a workplace system operated for your employer, we may need to route a request through them; we will tell you if that happens rather than quietly forwarding it.
This page describes the system as currently built. It is updated when what the system stores or who processes it changes.