Privacy policy
Plain words on what Callboard collects, where it lives and who can see it. Written for the Australian Privacy Act and for the staff whose phones are enrolled, not only for the businesses that pay for it.
Callboard · Last updated 1 October 2026
01 Who we are and what this covers
Callboard is made and operated by ThinkVeridian Pty Ltd, an Australian company. This policy explains what personal information we collect, why, where it is kept, who can see it and how you can reach us about it. It is written to meet the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
It covers three groups of people: visitors to callboardmdm.com, the people who run a Callboard workspace (owners, admins and managers), and the staff whose company phones are enrolled in a workspace. If you are one of those staff, the business that gave you the phone is the one that decided to monitor it. This policy tells you what we do with the data; your employer's notice tells you why they collect it.
02 Information we collect from workspace users
When a business creates a workspace we collect the name, work email address and password of the person who signs up, the business name, and the country and state the business operates in. Passwords are stored as salted hashes and are never readable by us.
When owners add staff to the workspace we hold each person's name, work email and role. We keep a log of sign-ins and of changes made in the workspace (who added a phone, who changed a setting) so owners can audit their own account.
For billing we hold the plan, the number of enrolled phones and invoice history. Card details are entered directly with Stripe and never touch our servers. Customers who pay by invoice give us a billing contact and, where they choose, a purchase order number.
03 Information collected from enrolled phones
The app installed on a company phone reads the phone's own call history and reports it to the workspace that enrolled it. For each call it sends:
- the direction (incoming, outgoing, missed or declined), the start time and the duration
- the other party's phone number, stored the way the workspace has chosen (see the next section)
- which SIM slot the call used, when the phone has more than one
- the phone's current state (idle, ringing, on a call) and a check-in every few minutes so the board knows the phone is reachable
- the phone model, Android version and app version, for support
The app does not record calls, does not read contacts, messages, email, photos or files, does not use the microphone or camera, and does not collect location. It only runs on phones a business enrols through its own device management, and the phone shows a persistent notification while the app is reporting.
04 How phone numbers are stored
By default a workspace stores each phone number as a one-way keyed hash plus the last three digits. That is enough to match a returned call to a missed one and to show a rep which caller is waiting, without keeping the full number in the database. The key used for hashing is unique to the workspace and is itself stored encrypted.
A workspace owner can switch on full-number storage. When they do, full numbers are held in that workspace's own database only, and the owner is responsible for making sure their staff notice covers it. Numbers a workspace marks as excluded (for example staff or family numbers) are dropped before anything is stored.
05 Why we use the information
We use workspace data to run the service the business has asked for: the live board, the follow-up list, reports, leads, daily report emails and any CRM connector or webhook the owner has switched on. We use account data to sign you in, bill you, answer support requests and tell you about changes to the service or these terms.
We do not sell personal information, we do not use call data for advertising, and we do not train models on customer data. We look at aggregate usage (how many workspaces, how many phones, which features are used) to run and improve the product.
06 Where data is kept
Each workspace has its own database. It is not a row in a shared table, and it can be exported or deleted on its own. Databases, backups and the application run on dedicated infrastructure in multiple regions around the world. A workspace lives in the region that matches its country, so Australian customers stay in Australia, and we do not move it without telling you.
The providers we rely on, what each one sees and where it operates are listed on our security page. We tell customers before adding a provider that would handle personal information.
07 Who can access it
Inside a workspace, access follows the roles its owner sets. Owners see everything in their workspace, managers see the board and reports, and a rep sees nothing on the phone at all: the app has no screen for browsing calls.
Our own staff can open a workspace only through a support session that the workspace owner grants, that expires, and that is written to the workspace's audit log. Outside of that, our platform console shows workspace names, plans, phone counts and billing state, not call data.
We disclose personal information only to the providers named on the security page, to a workspace's own connectors when its owner has turned them on, or when the law requires it. If we receive a lawful request for a customer's data we tell the customer unless we are legally prevented from doing so.
08 Security
Every connection uses TLS. Data at rest is on encrypted storage. Credentials for connectors and webhooks are encrypted with a key that is never stored beside the data. Sessions are held on the server and can be revoked, and a removed phone stops being able to report immediately. We keep an audit log of administrative changes, run a responsible disclosure programme, and describe our controls in more detail on the security page.
If we become aware of a data breach that is likely to cause serious harm we will notify the affected customers and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
09 Retention and deletion
Call data is kept for as long as the workspace is open, so reports over any date range keep working. An owner can delete individual numbers, exclude numbers going forward, or ask us to purge a range.
When a workspace is closed, the owner can export everything first. Its database is dropped thirty days after closing, and backups that contain it expire within a further thirty days. Account records needed for tax and accounting are kept for the period Australian law requires, then deleted.
10 Cookies and the website
callboardmdm.com sets a session cookie when you sign in and a short-lived cookie to protect forms. We do not run advertising trackers. The contact form stores what you send us so we can reply, and the sign-up form stores your details so we can create the workspace once you verify your email.
11 Your rights
You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Workspace owners can do most of this themselves from the workspace. Staff whose phone is enrolled should ask their employer first, since the employer controls that workspace; we will help either party with the request.
Write to legal@callboardmdm.com. We answer within thirty days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
12 Changes
When we change this policy we update the date at the top and, for changes that affect how we use personal information, email workspace owners before the change takes effect. Earlier versions are available on request.
- QuestionsPrivacy questions and access requests go to legal@callboardmdm.com. Anything about your workspace or the app goes to help@callboardmdm.com.