Heaston Innovations Free Optimization Scan

This page describes the privacy practices for mobile applications published by Heaston Innovations LLC (“Heaston Innovations,” “we,” “us,” or “our”). Each app we publish has its own section below covering exactly what that app collects, how it is used, and how you can remove it.

For the privacy practices that apply to the Heaston Innovations website and general business, see our main Privacy Policy. This page focuses on our apps.


HICRM (Android)

This section is the privacy policy for the HICRM Android app (package com.heastoninnovations.hicrm). It is the policy referenced from the app’s Google Play listing.

HICRM is a business tool. It is the mobile companion for the Heaston Innovations CRM platform at crm.heastoninnovations.com, and it is intended for people who already have a CRM account with us or with a business that uses our platform. It is not a consumer app.

The app has three jobs: it displays the CRM platform inside a native Android shell, it receives push notifications, and it places and receives business phone calls. Everything below follows from those three jobs.

What the app collects

Account and sign-in information. You sign in with the email address and password for your CRM account. Credentials are sent over HTTPS to our server, where the password is verified against a salted hash — we never see or store your password in readable form. After sign-in the app keeps a session token on the device so you do not have to sign in every time. That token is held in Android’s encrypted preference storage (AndroidX Security Crypto), backed by the device keystore. Signing out or uninstalling clears it.

Push notification token. The app registers a push token with Firebase Cloud Messaging (Google) so it can wake up for incoming calls and CRM alerts. To be precise about where that token goes: the app passes it directly to Twilio, our telephony provider, so Twilio can ring your device for an incoming call. Our CRM server does not store it. The token is an opaque delivery address for your device — it is not a name, a number, or a contact record.

Voice calls and microphone audio. HICRM places and receives business calls in the app. While a call is active the app uses your device microphone and streams that audio through Twilio to connect the call, the same way a carrier carries any phone call. Call metadata — the numbers involved, the direction, the time and the duration — is written to your business’s CRM record so the call appears in that contact’s history.

The app itself does not record calls and keeps no audio on your device. If the business that owns the CRM account has separately enabled call recording inside the CRM platform, that recording is made and stored on the platform side and is governed by that business’s own policies and your CRM platform terms — not by the app.

Business content shown inside the app. Most of what you see in HICRM is the CRM platform itself: contacts, leads, appointments, tasks, messages, and other records you or your colleagues entered. That business data belongs to the CRM account and is processed under the terms of that account. The app displays it; it does not independently collect or copy it.

Device and diagnostic information. The app writes basic technical information — Android version, app version, and error messages — to a local diagnostic log on the device, so a problem can be described accurately if you contact support. That log stays on your device unless you choose to send it to us.

What the app does not do

Permissions the app requests, and why

PermissionWhy the app needs it
INTERNETReach the CRM platform and the calling service. Required for the app to function at all.
RECORD_AUDIOCapture your voice during an in-app call. Used only while a call is connected.
POST_NOTIFICATIONSShow incoming-call alerts and CRM notifications. You can decline or revoke this at any time.
MANAGE_OWN_CALLSRegister the app’s calls with Android’s telecom system so an in-app call behaves like a normal phone call.
USE_FULL_SCREEN_INTENTShow a full-screen incoming-call screen when the phone is locked.
FOREGROUND_SERVICE, FOREGROUND_SERVICE_PHONE_CALL, FOREGROUND_SERVICE_MICROPHONEKeep a call running reliably while the app is in the background, with the ongoing-call notification Android requires.
MODIFY_AUDIO_SETTINGSRoute call audio correctly between earpiece, speaker, and headset.
WAKE_LOCKKeep the device awake for the duration of an active call.
REQUEST_IGNORE_BATTERY_OPTIMIZATIONSOptional. Asks Android not to suspend the app so incoming-call notifications arrive reliably. You can decline this and still use the app.

The app requests no permission beyond this list.

How the information is used

We do not use any of this for advertising, for profiling, or for any purpose unrelated to running the CRM service you signed in to.

Service providers

We use two third-party processors, and only for the functions described above:

We share your information with no one else, and we do not sell it.

Data retention

WhatHow long we keep it
Session token on your deviceUntil you sign out, uninstall, or the session expires (about 30 days of inactivity).
Push notification tokenWhile the app is installed and signed in. Invalidated when you sign out or uninstall, and it expires on its own once the app stops using it.
Microphone audioNot retained. Audio is streamed to connect the live call and is not stored by the app.
Call metadata (number, direction, time, duration)Kept in the CRM record for as long as the CRM account is active, because it is part of that contact’s business history.
CRM business recordsKept for as long as the CRM account is active. Deleted on request as described below.
Local diagnostic logStays on your device. Cleared when you clear app storage or uninstall.
Account record (name, email, role)Kept while the account exists; removed within 30 days of a verified deletion request, subject to the legal exception below.

Where we are required to keep something to meet a legal, tax, or accounting obligation, or to resolve a dispute, we keep only what that obligation requires and only for as long as it requires.

Deleting your data

To remove data from the device: sign out of the app, or uninstall it. Either clears the session token, the cached pages, and the local diagnostic log. Uninstalling also stops the push token from being usable.

To delete your account and the data associated with it: email team@heastoninnovations.com from the email address on the account, with “HICRM deletion request” in the subject line. We will confirm the request, delete the account and its associated personal data within 30 days, and confirm in writing when it is done. There is no charge for this.

One thing to be clear about: if you are a staff user on a CRM account that belongs to a business, the business records in that account (contacts, leads, appointment history) belong to that business, not to you individually. We will delete your own user account and personal data on your request, but a request to delete the business’s records has to come from the account owner.

Security

All traffic between the app and our servers uses HTTPS. Passwords are stored only as salted hashes. The session token is held in Android’s encrypted preference storage backed by the device keystore. No system is perfectly secure, but we do not keep anything on the device that does not need to be there.

Children

HICRM is a business tool intended for adults. It is not directed to children under 13, we do not market it to children, and we do not knowingly collect personal information from children through the app. If you believe a child has provided us information through the app, email us and we will delete it.


Contact and operator

Heaston Innovations LLC
Columbia, SC

Email: team@heastoninnovations.com

Questions, deletion requests, or concerns about how any of our apps handle your data can be sent to the email above.