Privacy Policy
1. Controller
The controller of personal data processed in connection with the callerpeek.com website and the sale of the CallerPeek software is:
CONSALTEX Marcin Mazurekul. Tadeusza Manteuffla 8/47
03-988 Warsaw, Poland
VAT ID (NIP): PL 8671431725 · REGON: 140233336
E-mail: info@callerpeek.com
This policy explains what data we process, why, and what rights you have under the EU General Data Protection Regulation (GDPR).
2. The short version
- The CallerPeek software is self-hosted: the Android application communicates directly with the module installed on your own server. We have no access to that traffic and no database of your customers, phone numbers, or calls.
- The callerpeek.com website counts visits with our own Matomo instance, hosted on our server — without cookies and with IP anonymisation, which is why there is no cookie banner and no data goes to anyone else. We use no advertising or marketing trackers.
- Beyond that, we process personal data only when you contact us or purchase the software.
3. What we process and why
3.1 Website visits — server logs
Our web server records standard technical logs (IP address, date and time, requested URL, browser identification) for the purpose of security, abuse prevention, and error diagnostics. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR). Logs are deleted automatically after no more than 90 days. We do not use these logs to profile visitors.
3.2 Website visits — analytics
We measure traffic on callerpeek.com with Matomo, analytics software installed on our own server (stats.consaltex.pl). We do not use Google Analytics or any other third-party analytics service: the data never reaches another company and never leaves the European Economic Area.
We collect only aggregate data about how the site is used: which pages are viewed, the address a visit came from, approximate country-level location, device and browser type, chosen language, and clicks on the purchase buttons. It serves one purpose — knowing which content is useful and whether the site works properly.
The measurement is configured so that it cannot identify an individual:
- no cookies — Matomo stores nothing in your browser, so we do not recognise you on a later visit and we do not need your consent for this kind of measurement,
- your IP address is anonymised (truncated) before it is stored,
- no cross-site tracking — we do not combine this data with any other service or with your purchase details.
Legal basis: our legitimate interest in keeping statistics for our own website (Art. 6(1)(f) GDPR). Because the measurement neither stores nor reads anything on your device, it does not require consent — which is why you will not see a cookie banner here.
Right to object. You can switch this measurement off for yourself at any time on the Matomo opt-out page. We also honour the Do Not Track setting in your browser.
3.3 Contact by e-mail
If you write to info@callerpeek.com, we process your e-mail address, name (if provided), and the content of your message in order to reply and handle your request. Legal basis: our legitimate interest in responding to inquiries (Art. 6(1)(f) GDPR) or, where the inquiry concerns a purchase, steps prior to entering into a contract (Art. 6(1)(b) GDPR). Correspondence is retained for as long as necessary to handle the matter and for the limitation periods of potential claims.
3.4 Purchases
Orders on callerpeek.com are processed by Paddle, acting as the merchant of record. Paddle collects the data required to process your payment (name, e-mail address, billing country, payment details) and acts as an independent controller of that data under its own privacy policy, available at paddle.com. From Paddle we receive your name, e-mail address, and order details, which we process to deliver the software, issue your license key, and provide updates and support during the license period. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and, after the contract ends, our legitimate interest in defending against potential claims (Art. 6(1)(f) GDPR).
Orders placed earlier at consaltex.pl, before we moved sales to Paddle, are covered by the privacy policy published on that site.
3.5 Support
When you request technical support, we process the information you choose to share (e.g., configuration details, log excerpts). Please do not send us your customers' personal data in support requests; where log excerpts are needed, anonymize phone numbers and names first.
4. Data processed by the CallerPeek software itself
The CallerPeek module/plugin and the Android application process personal data of your customers (names, phone numbers, order history) exclusively within your own infrastructure: on your server and on your staff's devices. This data never reaches us. For that processing, you (the shop operator) are the data controller, and your staff members' devices act on your behalf. The software is designed to support your GDPR compliance: direct HTTPS-only communication, per-employee access tokens with instant revocation, query rate limits, and configurable log retention.
5. The CallerPeek Android application
This section covers the CallerPeek application distributed through Google Play. It is separate because the application asks for access to the call log, and the answer to "what happens to that data" belongs in one place.
5.1 Where the data goes
The application sends no caller data to us — ever. It talks to exactly one address: the CallerPeek module or plugin installed in the shop operator's own infrastructure, chosen by the operator when the device is paired. We run no server capable of receiving a caller's number, a customer's name or an order, so there is nothing on our side to store, sell or hand over. After the software is bought, no communication concerning your customers passes through us at any point.
Installed from Google Play, the application contacts us at no point whatsoever. Its only network destination is the shop it was paired with. Updates are handled by Google Play, so the application's own update check is switched off — decided by the installation source, not by a setting you could get wrong.
The application is also distributed as a file from our website, for phones without Google services. That copy — and only that copy — asks once a day for a static file, callerpeek.com/app/version.json, because there it is the only way to learn that a newer version exists. The request is a plain download: it carries no number, no customer, no shop identifier and no device identifier. All that reaches us is a line in a web server log, exactly like any visit to our website.
5.2 Permissions and why each is required
| Permission | Why the application needs it |
|---|---|
| READ_CALL_LOG READ_PHONE_STATE READ_PHONE_NUMBERS | To obtain the number of the call currently ringing — the single input the product works from. From Android 9 onward the system will not disclose that number to an application without READ_CALL_LOG. The application never reads your call history. It queries no call log records and holds no code capable of doing so; it uses only the number the system supplies with the incoming call. On dual-SIM phones READ_PHONE_STATE also lets you restrict the application to one SIM. |
| CAMERA | Scanning the pairing QR code shown in the module's panel. Used at that moment and no other. No photograph or video is taken, stored or transmitted. |
| SYSTEM_ALERT_WINDOW USE_FULL_SCREEN_INTENT POST_NOTIFICATIONS | Displaying the customer card over the system's call screen and on the lock screen, and notifying you about missed calls. |
| FOREGROUND_SERVICE WAKE_LOCK RECEIVE_BOOT_COMPLETED REQUEST_IGNORE_BATTERY_OPTIMIZATIONS | Keeping the application ready to react to a call, surviving a reboot, and preventing the system's power saving from silencing it. |
| INTERNET | Reaching the shop's own module and the update file described in Section 5.1. |
The application does not ask for contacts, SMS, location, microphone or file access.
5.3 What is stored on the phone
The application keeps the ten most recent lookups on the device, so that a missed call can be returned. Each entry holds the time, the caller's number and the card the shop returned. Nothing older is kept: the eleventh entry displaces the first. This history lives only in the application's private storage on that phone, is never transmitted anywhere, and is not backed up to any cloud service of ours.
You can erase it at any time by clearing the history in the application, by clearing the application's data in Android settings, or by uninstalling the application. Removing the device from the module's panel cuts its access instantly, from the shop's side.
5.4 What we do not do
We do not sell data obtained through the application, do not share it with third parties, do not use it for advertising or profiling, and do not transfer it to any other application. The application contains no advertising, no analytics and no tracking code, and requires no account with us. Data read from the call log is used solely for the user-facing feature described above and is never transferred off the device except to the shop the user paired it with.
6. Recipients of data
We share data only with service providers necessary to operate our business: our hosting provider (servers located in the European Economic Area), Paddle as merchant of record for international sales, and our accounting service (for tax records). Visit statistics go to no one — Matomo runs on our own server (Section 3.2). We do not sell personal data and do not share it for advertising purposes.
7. Transfers outside the EEA
Our own processing takes place in the EEA — this includes visit statistics, because Matomo runs on our own server and we transfer no analytics data outside the EEA. Paddle may transfer payment data outside the EEA under appropriate safeguards (such as EU Standard Contractual Clauses); details are provided in Paddle's privacy policy.
8. Your rights
Under the GDPR you have the right to: access your data, rectify it, erase it, restrict its processing, receive it in a portable format, object to processing based on legitimate interest, and withdraw consent at any time (without affecting the lawfulness of processing before withdrawal). To exercise these rights, e-mail info@callerpeek.com. You also have the right to lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (Prezes UODO, uodo.gov.pl), or the authority in your country of residence.
9. Cookies
We do no cookie-based tracking and set no analytics or advertising cookies. That is why there is no cookie consent banner here. Our visit statistics work without cookies (Section 3.2). The only file the site itself stores is strictly necessary for it to work and does not require consent:
| Cookie | Purpose | Duration |
|---|---|---|
| PHPSESSID | Remembers the language version you chose, for the duration of your visit | until you close the browser |
On the purchase pages we load the checkout script of Paddle, our merchant of record. Paddle may set its own cookies and identifiers needed to process payments and prevent fraud — it then acts as an independent controller, under its own privacy and cookie policy available at paddle.com. If you would rather those scripts did not load, do not open the purchase pages.
To switch our statistics off for yourself, use the Matomo opt-out page (Section 3.2).
10. Changes
We may update this policy to reflect changes in our services or the law. The current version is always available at callerpeek.com, with the date of the last update shown at the top.