Summary
- CallerCRM is a business app. Organisations use it to assign sales leads to their calling agents, place calls and log the results.
- We collect only what the app needs to work: account details, the leads your organisation uploads, call outcomes and durations, WhatsApp conversations with leads, and basic device information for notifications and sign-in.
- We never record calls, never access your microphone, location, contacts, photos or SMS, and never sell data or show ads.
- Data is stored on servers in India. Lead, call and WhatsApp records are deleted automatically within 20 days. When an agent leaves their organisation, their account is deleted within 24–48 hours.
- You can ask us to access, correct or delete your data at any time by writing to privacy@codebyakshay.com.
Who we are
CallerCRM (Android package com.codebyakshay.callercrm) is developed and operated by CodeByAkshay, an enterprise registered in India under Udyam Registration No. UDYAM-MP-15-0022478, based in Madhya Pradesh, India ("CodeByAkshay", "we", "us").
This policy covers the CallerCRM mobile app, the servers it talks to, and this website.
Who controls your data
CallerCRM is used by organisations such as sales teams, call centres and businesses (each an "Organisation"). There are three kinds of people whose data we handle:
- Admins: people who manage an Organisation's account.
- Agents: calling staff whose accounts are created by an Admin.
- Leads: the prospective customers whose names and phone numbers an Organisation imports into CallerCRM so its agents can call them.
Under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the Organisation is the Data Fiduciary for the Agent and Lead data it puts into CallerCRM. It decides why that data is collected and is responsible for having a lawful basis to contact its Leads. CodeByAkshay acts as the Data Processor: we process that data only to provide the service to the Organisation. For the limited technical data described below (such as anonymous app usage statistics and security logs), we act as the Data Fiduciary.
If you are a Lead and want to know why an organisation contacted you, or want it to stop, please contact that organisation directly. You can also write to us and we will pass your request on and help it get resolved.
Data we collect
1. Account information
For Admins and Agents: name, username, password, phone number (optional), role (Admin or Agent), and which Admin an Agent belongs to. Passwords are stored only as a one-way cryptographic hash (bcrypt). Nobody can read your password, including us.
2. Lead information (provided by your Organisation)
Lead name and phone number, the link to the Google Sheet they were imported from, which Agent they are assigned to, the assignment date and the lead's current status.
3. Call activity
For each call an Agent places to a Lead through CallerCRM: the outcome the Agent selects (for example "Interested" or "Callback"), any note the Agent types, the call status, the call's duration and the date and time. Admins use this data for team reports, including daily attendance (calls made, total and average talk time, and newly interested leads).
How call duration is read: once a call placed from CallerCRM ends, the app looks through the most recent entries (up to 10) in your phone's call log for the outgoing call to that Lead's number, and reads only that call's duration. No other call-log entries are stored, uploaded or shared.
4. WhatsApp messages
If your Organisation uses the WhatsApp feature, we store the messages exchanged with Leads through the WhatsApp Business Platform (message text, sender, time, delivery and read status, and any delivery error). This includes the Lead's WhatsApp name and phone number.
5. Device and technical information
- Push notification token: lets us notify an Agent when new leads are assigned.
- App installation ID: a random identifier CallerCRM creates when first installed. It keeps you signed in on each device separately. It is not your IMEI, serial number or advertising ID.
- Platform and app version, for example "android" and "1.0.0".
- Server logs: IP address, time and the address of each request. We use these for security (for example, limiting repeated failed sign-ins) and troubleshooting.
6. App usage statistics
We use Expo Insights to count app launches and see which app and operating-system versions are in use. This data is anonymous and is not used to identify you or for advertising.
Data we don't collect
- We do not record calls or access your microphone.
- We do not access your location, contacts or address book, photos, files, camera or SMS.
- We do not collect your advertising ID and do not track you across other apps or websites.
- We do not ask for access to your Google account. Lead import reads only the specific Google Sheet link your Admin provides.
- We do not collect payment card or bank details in the app.
Phone permissions
CallerCRM asks for the following Android permissions. Each one is used only for the purpose shown.
| Permission | Why we need it | If you deny it |
|---|---|---|
Make and manage phone callsCALL_PHONE | To call a Lead directly from the app when you tap the call button. | You can't place calls from CallerCRM. |
Read phone statusREAD_PHONE_STATE | To detect when the call you started connects and ends, so the app can ask for the outcome at the right moment. | The app can't tell when a call ends. |
Read call logREAD_CALL_LOG | To read the duration of the call you just placed to a Lead (see "How call duration is read" above). | Call duration is not recorded. |
NotificationsPOST_NOTIFICATIONS | To alert you when new leads are assigned or team settings change. | You won't get lead alerts. |
| Internet, vibration | To sync with our servers and to vibrate for notifications. | — |
You can change these permissions at any time in your phone's Settings.
How we use data
- To provide CallerCRM: sign-in, lead lists, calling, outcome logging, the WhatsApp inbox and reports.
- To distribute leads imported from Google Sheets to Agents, and to notify Agents about new leads.
- To show Admins their team's calls, outcomes and attendance.
- To keep the service secure: authenticating users, managing sessions per device, limiting repeated failed sign-in attempts and investigating misuse.
- To fix bugs, keep the service running and understand which app versions are in use.
- To respond to your requests and support questions.
We do not sell personal data, use it for advertising or profiling, or make automated decisions that have legal or similarly significant effects on you.
Storage, retention & deletion
Our servers and database are hosted in India.
- Leads, call activity and WhatsApp messages are kept for no more than 20 days from when they are created, then permanently deleted.
- Agent accounts are kept while the Agent works for the Organisation. When an Agent leaves, the Admin deletes the account within 24–48 hours. Deleting an account also deletes its sign-in sessions, push tokens, lead assignments and call activity.
- Admin and Organisation accounts are kept until the Organisation asks us to close them. We then delete them and all associated data.
- Sign-in sessions expire automatically, and all of them are ended when a password is changed.
- Server logs are kept only as long as needed for security and troubleshooting.
On your phone: your sign-in tokens are kept in encrypted storage backed by the Android Keystore and are removed when you sign out. Uninstalling the app deletes all CallerCRM data from the phone.
To delete your account or data, see how to delete your account.
Security
- All traffic between the app and our servers is encrypted with HTTPS (TLS).
- Passwords are stored only as bcrypt hashes. Changing your own password requires your current one, and a change signs out every device.
- Access is role-based: Agents see only their own leads, and Admins see only their own team.
- Repeated failed sign-in attempts are rate-limited.
- We check the cryptographic signature on incoming WhatsApp webhook messages, so only genuine messages from Meta are accepted.
- The release app does not write personal data such as phone numbers to device logs.
No system is perfectly secure. If a personal data breach affects you, we will tell the affected Organisation and, where the law requires, the Data Protection Board of India and affected people, without undue delay.
Your rights
Under the DPDP Act you have the right to:
- Access: get a summary of the personal data we process about you and how we process it.
- Correction and completion: have inaccurate or incomplete data fixed.
- Erasure: have your data deleted when it is no longer needed.
- Withdraw consent, where processing is based on consent.
- Grievance redressal: raise a complaint with us and get a response.
- Nominate someone to exercise these rights for you in case of death or incapacity.
Because your Organisation controls Agent and Lead data, you can usually get the fastest result by asking your Admin. You can also write to us at privacy@codebyakshay.com. We will verify the request, coordinating with your Organisation where needed, and act on verified deletion requests within 48 hours. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Children
CallerCRM is a workplace tool meant for people aged 18 and over. We do not knowingly collect data from children. If you believe a child's data has been added, contact us and we will delete it.
Changes to this policy
We may update this policy when the app or the law changes. We will change the "Effective" date at the top. If a change is significant, we will notify Admins in the app or by email before it takes effect.
Contact & grievances
For privacy questions, data requests or complaints, contact our Grievance Officer:
Akshay Kumar Sinha, Grievance Officer
CodeByAkshay (UDYAM-MP-15-0022478), Madhya Pradesh, India
Email: privacy@codebyakshay.com
We aim to acknowledge every message within 48 hours.