Also if its for business, anyone signing up agrees with a data-processing-agreement (which I dont known if thats the case here) but normally they promise not to use PII for other services then the one provided.
It would take analysis of that DPA if thats the case or not.
Dont know much about it, but would Droidian or Mobian be feasible? https://devices.droidian.org/#/devices