Privacy policy (GDPR)
In short: CallerPeek has no cloud. Store customer data is processed exclusively on the store owner's server and phone. We — the software provider — have no access to it whatsoever.
1. Who is the data controller
The controller of store customer data is the store owner who installs the CallerPeek module. The software is a tool running entirely on their infrastructure — the CallerPeek provider is neither the controller nor a processor of that data.
2. How data flows
- On an incoming call the app sends the caller's number directly to the owner's store (encrypted over HTTPS) and displays the answer.
- There is no intermediary server. We do not collect numbers, build profiles or run analytics inside the product.
- Outside the store, the app connects only to callerpeek.com — once a day, to check for updates (only the app version is sent, no personal data).
3. This website
callerpeek.com uses Google Analytics 4 (ID G-75JVRXFL4Y) to measure traffic and content performance, based on our legitimate interest (Art. 6(1)(f) GDPR). Google Analytics stores cookies and processes, among others, a truncated IP address, device and browser type and the pages visited; this relates solely to the use of this website. You can object by blocking cookies in your browser or installing the Google Analytics opt-out add-on.
The server may keep standard access logs (IP address, request time) for security purposes, retained for up to 90 days. Fonts are loaded from Google Fonts (a standard HTTP request is sent).
Important: analytics applies to this website only. The CallerPeek app and the store module contain no analytics at all — we neither collect nor process your customers' data.
4. E-mail contact
If you write to info@callerpeek.com, you provide us with your e-mail address and the content of your message — we use them solely to reply and handle your request.
5. Notes for the store owner (controller)
- Showing customer data to the employee answering the phone falls within the controller's legitimate interest (Art. 6(1)(f) GDPR) — customer service.
- Each device has its own token; when an employee leaves, revoking the token is a single click.
- The module enforces HTTPS, limits the number of requests and keeps a local access log in your own admin panel.