Who this applies to
Commstate is business software. You use it with an account issued by an organisation — your employer or the workspace administrator who invited you. That organisation controls your account and the business data you see in the app.
What the app collects
Account information. Your email address and password are sent to your organisation’s Commstate server when you sign in, so the app can authenticate you. Your name and profile details are shown in the app and can be edited there.
Business data. Orders, products, inventory, customer records, calls and messages belong to your organisation, not to the app. The app displays and edits them; it does not collect them for its own purposes.
Photographs, only when you take one. The app uses the camera to scan barcodes and to attach images to records. Images are captured only when you open the scanner or choose to attach a photo, and are sent only to your organisation’s server.
Audio, only while you are speaking to the assistant. The app uses the microphone for the in-app voice assistant. Recording happens only while that feature is active. Audio is sent to your organisation’s server for processing and is not retained on the device.
A push notification token. So the server can send you notifications about orders, calls and messages. The token identifies the installation, not you personally.
What the app does not collect
The app contains no analytics or crash-reporting software. There is no Google Analytics, Firebase Analytics, Sentry, Bugsnag, Amplitude, Mixpanel or Segment in the application. It does not build an advertising profile, does not track you across other apps or websites, and contains no advertising SDK.
It does not collect your contacts, calendar, precise location, SMS messages, call logs, or files outside those you explicitly choose to attach.
Who your data is shared with
Nobody outside your organisation’s own infrastructure. The app talks to the Commstate server your organisation operates, and to Google’s Firebase Cloud Messaging solely to deliver push notifications. There are no third-party advertising, analytics or data-broker recipients.
Where data is stored on your device
Authentication tokens are kept in the platform’s secure storage — Keychain on iOS, the Android Keystore-backed EncryptedSharedPreferences on Android. Preferences and cached content are kept in ordinary app storage. All of it is removed when you sign out or uninstall the app.
Security
Traffic between the app and the server uses HTTPS, and real-time connections use WSS. Access inside the product is governed by roles and permissions set by your organisation’s administrator.
Permissions and why they exist
| Permission | Why | When |
|---|---|---|
| Camera | Barcode scanning, attaching photos | Only while the scanner or picker is open |
| Microphone | The in-app voice assistant | Only while the assistant is listening |
| Photos / media | Attaching an existing image | Only when you pick a file |
| Notifications | Order, call and message alerts | Ongoing, if you allow it |
Each is requested at the moment it is first needed, and the app remains usable if you decline — you lose only the feature that needs it.
Your choices
You can revoke any permission in your device settings at any time. You can sign out, which clears stored credentials and cached data from the device.
Because your account is issued and controlled by your organisation, requests to access, correct, export or delete your account data go to your organisation’s administrator. They are the data controller; Commstate is the software they use.
Children
Commstate is business software and is not directed at children. It is not intended for use by anyone under 16.
Changes
Material changes to this policy will be reflected here with a new “last updated” date.
Contact
Questions about this policy
privacy@commstate.app