Privacy Policy — AccessCore Mobile

Effective date: July 26, 2026
Applies to: the AccessCore Mobile application for iOS and Android ("the App").
Provided by: Cloud Access Key, a Utah company ("we", "our", "us").
Contact: legal@cloudaccesskey.com

1. Summary

AccessCore Mobile is a tool for managing and operating physical door-access hardware. You sign in to an account that an administrator has set up for you, and depending on your role you can unlock doors, manage users and schedules, or adopt and configure gateway devices.

In plain terms:

2. Information we collect

Account information

When an administrator creates your account and when you sign in, the App handles your name, email address, and a user identifier, plus your assigned role (end user, client administrator, or dealer administrator). This is required to sign you in and to show you the doors, users, and devices you're authorized for.

Location information (precise GPS) — optional, unlock only

If you use the door-unlock feature and grant permission, the App reads your device's precise location while the App is in the foreground to:

Your location is not collected in the background, not stored on your device after use, not retained by the App, and not used for advertising or tracking. If you decline the location permission, location-gated unlocking will not function, but the rest of the App still works.

On Android 11 and older, the operating system requires a location permission in order to scan for Bluetooth devices. In that case the permission is a technical prerequisite for Bluetooth setup — the App does not read or transmit your location for Bluetooth scanning.

Device information

At sign-in, the App sends a device name (for example, "iPhone 15 (iOS 18)") so you can recognize and manage your saved passkeys ("which devices can sign in to my account"). We do not collect advertising identifiers.

Like any online service, our servers also keep standard sign-in security records: your IP address and device/browser information are recorded when you sign in, so you and your administrator can review account access.

Authentication credentials (passkeys / WebAuthn)

The App uses passkeys for sign-in. Your passkey private key and your biometrics are created and stored by your device's operating system (Apple Keychain / Android Credential Manager) and never leave your device. When you sign in, your device produces a one-time cryptographic signature that we verify; we never receive your biometric data or your private key.

Camera (QR scanning) — setup only

During device adoption you may scan a QR code printed on the gateway hardware. The camera operates as a live scanner: it reads a short device serial from the code and discards the video frames. No photos or video are saved or transmitted — only the short serial string, which identifies the hardware (not you).

Bluetooth (device setup) — setup only

When adopting a gateway over Bluetooth, the App reads the gateway's hardware serial numbers to provision it. This is information about the access-control device, not about you or your phone.

Information we do NOT collect

We do not use analytics or telemetry, crash/diagnostics SDKs, advertising or attribution SDKs, or any third-party tracking. We do not collect your contacts, photos library, microphone, health data, or browsing activity.

3. How we use information

We use the information above only to:

We do not use your information for advertising, profiling, or automated decision-making beyond the access-control rules your administrator configures.

4. How information is shared

We do not sell your personal information and we do not share it with third parties for their own marketing or purposes.

Your data is transmitted only between the App and the AccessCore backend service. That service runs on cloud infrastructure (Amazon Web Services) acting as our hosting/processing provider under contract; they process data on our behalf and not for their own purposes. We may disclose information if required by law or to protect the security and integrity of the access-control system.

5. Data retention

6. Security

All communication between the App and our servers uses encrypted HTTPS/TLS. Your sign-in token is stored in the device's secure keystore (Apple Keychain / Android Keystore). Passkeys provide phishing-resistant authentication, and your private keys and biometrics remain on your device.

7. Your rights and choices

8. Children's privacy

The App is a workplace/property access-control tool and is not directed to children. We do not knowingly collect personal information from children.

9. Permissions reference

Permission When asked Why Leaves device?
Location (precise) When you use door unlock Show nearby doors; confirm proximity on unlock Only coordinates, only on an unlock/override attempt
Bluetooth When adopting a gateway Provision the gateway device Gateway serials only; no personal data
Camera When scanning a setup QR Read the device's short serial No — only the decoded serial string is sent
Face ID / biometrics Sign-in / unlock On-device authentication gate No — never leaves the device
Notifications (not used)

10. Changes to this policy

If we change how the App handles data, we will update this policy and revise the effective date. Material changes will be communicated through the App or the service.

11. Contact

Cloud Access Key
Email: legal@cloudaccesskey.com
Address: 1316 E Spring Water Way, Eagle Mountain, UT 84005

Get Started

Talk with a certified dealer to scope your project.