Privacy Policy — AccessCore Mobile
Effective date: July 26, 2026
Applies to: the AccessCore Mobile application for iOS and Android ("the App").
Provided by: Cloud Access Key, a Utah company ("we", "our", "us").
Contact: legal@cloudaccesskey.com
1. Summary
AccessCore Mobile is a tool for managing and operating physical door-access hardware. You sign in to an account that an administrator has set up for you, and depending on your role you can unlock doors, manage users and schedules, or adopt and configure gateway devices.
In plain terms:
- We collect only what the App needs to authenticate you and operate door access — your account identity, and (optionally) your device's location at the moment you ask to unlock a door.
- We do not use analytics, advertising, tracking, or crash-reporting SDKs. The App does not track you across other apps or websites.
- We do not sell or share your personal information with third parties for their own purposes.
- Your biometrics (Face ID / fingerprint) and passkeys are handled by your device's operating system and never leave your device — we only receive the cryptographic sign-in proof, never your biometric data or private keys.
- The camera is used only to scan a QR code on a device during setup; images are never saved or transmitted.
2. Information we collect
Account information
When an administrator creates your account and when you sign in, the App handles your name, email address, and a user identifier, plus your assigned role (end user, client administrator, or dealer administrator). This is required to sign you in and to show you the doors, users, and devices you're authorized for.
Location information (precise GPS) — optional, unlock only
If you use the door-unlock feature and grant permission, the App reads your device's precise location while the App is in the foreground to:
- show you which nearby doors are within range, and
- include your coordinates only when you actually attempt to unlock or override a door, so our server can confirm you are physically near it.
Your location is not collected in the background, not stored on your device after use, not retained by the App, and not used for advertising or tracking. If you decline the location permission, location-gated unlocking will not function, but the rest of the App still works.
On Android 11 and older, the operating system requires a location permission in order to scan for Bluetooth devices. In that case the permission is a technical prerequisite for Bluetooth setup — the App does not read or transmit your location for Bluetooth scanning.
Device information
At sign-in, the App sends a device name (for example, "iPhone 15 (iOS 18)") so you can recognize and manage your saved passkeys ("which devices can sign in to my account"). We do not collect advertising identifiers.
Like any online service, our servers also keep standard sign-in security records: your IP address and device/browser information are recorded when you sign in, so you and your administrator can review account access.
Authentication credentials (passkeys / WebAuthn)
The App uses passkeys for sign-in. Your passkey private key and your biometrics are created and stored by your device's operating system (Apple Keychain / Android Credential Manager) and never leave your device. When you sign in, your device produces a one-time cryptographic signature that we verify; we never receive your biometric data or your private key.
Camera (QR scanning) — setup only
During device adoption you may scan a QR code printed on the gateway hardware. The camera operates as a live scanner: it reads a short device serial from the code and discards the video frames. No photos or video are saved or transmitted — only the short serial string, which identifies the hardware (not you).
Bluetooth (device setup) — setup only
When adopting a gateway over Bluetooth, the App reads the gateway's hardware serial numbers to provision it. This is information about the access-control device, not about you or your phone.
Information we do NOT collect
We do not use analytics or telemetry, crash/diagnostics SDKs, advertising or attribution SDKs, or any third-party tracking. We do not collect your contacts, photos library, microphone, health data, or browsing activity.
3. How we use information
We use the information above only to:
- authenticate you and keep your session secure;
- show and operate the doors, users, schedules, and devices your role permits;
- verify door-proximity when you request an unlock;
- let you view and manage your own access history and passkeys.
We do not use your information for advertising, profiling, or automated decision-making beyond the access-control rules your administrator configures.
4. How information is shared
We do not sell your personal information and we do not share it with third parties for their own marketing or purposes.
Your data is transmitted only between the App and the AccessCore backend service. That service runs on cloud infrastructure (Amazon Web Services) acting as our hosting/processing provider under contract; they process data on our behalf and not for their own purposes. We may disclose information if required by law or to protect the security and integrity of the access-control system.
5. Data retention
- Sign-in token: stored securely on your device and removed when you log out; the server session is revoked at logout.
- Location: never persisted by the App; used in-memory at the moment of an unlock and then discarded.
- Account selection / cached settings: stored on your device and cleared when you log out.
- Door and card access events held by the backend (door identifiers, card numbers, and access grant/deny results) are automatically deleted after six months. Related diagnostic event data is deleted after one month, and device health telemetry after fourteen days.
- Account records and security logs (your account profile, administrative audit records, and the sign-in records described in §2) are retained for as long as your organization's service relationship with us remains active — they are needed to operate and secure the access-control service.
6. Security
All communication between the App and our servers uses encrypted HTTPS/TLS. Your sign-in token is stored in the device's secure keystore (Apple Keychain / Android Keystore). Passkeys provide phishing-resistant authentication, and your private keys and biometrics remain on your device.
7. Your rights and choices
- Permissions: you can grant or revoke Location, Camera, and Bluetooth access at any time in your device settings. Some features depend on them.
- Access: within the App you can view your profile, your passkeys, and your own access history.
- Account deletion: accounts are provisioned and managed by your organization's administrator. To request deletion of your account and associated personal data, use Settings → Request account deletion in the App (which starts an email to legal@cloudaccesskey.com), or contact your organization's administrator directly — administrators can remove user accounts in the web portal or the App, which immediately revokes door access. Logging out of the App removes locally stored data from your device.
- Depending on where you live, you may have additional rights (access, correction, deletion, portability) under laws such as the GDPR or CCPA. To exercise them, contact us at legal@cloudaccesskey.com.
8. Children's privacy
The App is a workplace/property access-control tool and is not directed to children. We do not knowingly collect personal information from children.
9. Permissions reference
| Permission | When asked | Why | Leaves device? |
|---|---|---|---|
| Location (precise) | When you use door unlock | Show nearby doors; confirm proximity on unlock | Only coordinates, only on an unlock/override attempt |
| Bluetooth | When adopting a gateway | Provision the gateway device | Gateway serials only; no personal data |
| Camera | When scanning a setup QR | Read the device's short serial | No — only the decoded serial string is sent |
| Face ID / biometrics | Sign-in / unlock | On-device authentication gate | No — never leaves the device |
| Notifications | (not used) | — | — |
10. Changes to this policy
If we change how the App handles data, we will update this policy and revise the effective date. Material changes will be communicated through the App or the service.
11. Contact
Cloud Access Key
Email: legal@cloudaccesskey.com
Address: 1316 E Spring Water Way, Eagle Mountain, UT 84005