Legal · StaffTrakr
Privacy Policy
Important disclosure
Enterprise workforce monitoring disclosure
StaffTrakr is an enterprise workforce attendance platform. When your organisation enables it, the app may record GPS during work hours for attendance verification — not for advertising or personal surveillance. Your organisation is usually the data controller; we process workforce data on their behalf. Details: Section 1(b) (what we collect) and Section 2 (how monitoring works).
1. Information We Collect
a. Personal Information (Login / Account)
When your organisation registers you, you sign in to the employee app, or an administrator uses the admin console, we collect:
- Name, employee ID, username, designation, and shift details
- Work email and phone number
- Login credentials (password and MPIN, stored securely)
- Profile photo when uploaded by your organisation (the app displays it only)
- Organisation administrators: name, email, login credentials, and session or access logs when using the admin console
b. Location Information & GPS Monitoring
When your organisation enables location monitoring and you use the employee app for attendance, we collect precise location data, including:
- GPS coordinates at punch-in and punch-out
- Continuous location updates while you are punched in (on duty), including route and walking-path tracking
- GPS accuracy, speed, and direction (when available from the device)
- Timestamps linked to each location point for attendance verification
- Location points stored on StaffTrakr servers for attendance records and admin route maps
- When enabled by your organisation, live position and daily path history may also sync via Google Firebase (see Section 1(f))
- On native Android, background location is used while punched in; a persistent on-duty notification is always shown during active tracking
- In a browser or PWA, continuous background tracking may be limited compared with the native Android app
- Location monitoring stops when you punch out or log out
c. Attendance & Work Requests
To manage your work activity, we collect:
- Punch-in/out times, attendance status, and work hours
- Leave and work-from-home requests
d. Device & Usage Information
We may automatically collect:
- Device model, operating system, app version, and device identifier
- Device registration details (device name and identifier) for login security and trusted-device flows
- IP address, session tokens, and device info linked to attendance actions
- Push notification token (Firebase) for alerts
e. Biometric Unlock (Optional)
- If enabled, Face ID or fingerprint is used only to unlock the app on your device
- Biometric data stays on your device and is not sent to our servers
f. Firebase (Google)
We use Google Firebase for push notifications and, when enabled by your organisation, to sync live position and daily walking-path data for admin maps. Location data is also stored on StaffTrakr servers as described in Section 1(b). Firebase may process data on Google infrastructure, which may be located outside India, under Google's policies.
g. Organisation Subscriptions
When an organisation subscribes through our website, we collect:
- Organisation and billing contact details
- Payments are processed by Razorpay — we do not store card or banking details
h. Data Categories and Purpose Mapping
- Name, contact, and login details: account management and authentication (employees and admins)
- Location data: stored on StaffTrakr servers; when enabled, also synced via Firebase for live maps and daily trails
- Attendance and requests: work hours, leave, and WFH workflows
- Device and tokens: security, trusted devices, and notifications
- Firebase data: push delivery and live location trails (when enabled)
- Subscription and payment details: organisation billing and support
Our website and admin console use cookies and local storage for essential session and security features — see our Cookie Policy.
2. Workforce Location Monitoring
When your organisation requires location monitoring, it works as follows:
- Your employer (organisation administrator) can view punch locations, attendance history, and route maps in the admin console
- Your organisation must inform you and obtain any legally required consent before requiring the app or location access
- You may withdraw location permission in device settings; your organisation may restrict attendance if location is required by their policy
We do not sell location data and do not use it for advertising or unrelated profiling.
3. How We Use Your Information
We use your information to:
- Create and manage employee accounts
- Provide attendance, GPS location monitoring, leave, and work-from-home features
- Send operational notifications and support workforce workflows
- Show attendance history and route maps to employees and authorised administrators
- Process organisation subscriptions and payments
- Respond to support requests
- Maintain security and prevent misuse of the service
We do not sell personal data or use location for advertising.
4. Sharing of Information
We do not sell your personal data. We may share limited data with:
- Your organisation’s administrators and authorised managers (including location, attendance, and route data for workforce oversight)
- Service providers who help us operate the service (including cloud hosting, Google Firebase, and Razorpay, as described in Section 1)
- Legal authorities when required by law or to protect our rights
5. Third-Party Services
Our website and apps may use third-party services such as:
- Payment gateways (Razorpay) for organisation subscriptions
- Google Firebase (mobile app and admin): push notifications and live location sync — see Section 1(f) and Firebase Privacy & Security
- Google Play Services for Android app distribution
These services may collect or process data according to their own privacy policies and our agreements with them. Where they act as our processor, we instruct them only as needed to provide the service. Some subprocessors (including Google Firebase) may process data on servers located outside India; we use contractual and technical safeguards appropriate to the service.
6. Data Security
We implement appropriate technical and organisational measures to protect your data, including encryption in transit (HTTPS/TLS) and secure authentication mechanisms.
7. Data Retention and Account Deletion
We retain your data only as long as necessary to provide services and comply with legal obligations.
Account Deletion
- Employee accounts are created and managed by your organisation’s administrator
- There is no self-service delete in the mobile app — see our Delete Account page
- When an administrator deactivates or deletes your record, you can no longer log in or punch attendance
Data Retention
- Server-side retention is set by your organisation’s policies
- Local app data is cleared when you log out
- Certain information may be retained if required for legal or regulatory compliance
8. Your Rights
You have the right to:
- View your profile and attendance history in the app
- Change your password and MPIN
- Contact your organisation’s administrator to update records, ask how your location is used, or request account removal
- Withdraw permissions (such as location or notifications) through device settings
- Ask your employer whether location monitoring is required for your role and what consent applies in your region
- Request access, correction, or erasure of your personal data through your organisation where they are the data controller, or contact us for platform-related requests
Grievance and complaints (India)
Under applicable Indian law, including the Digital Personal Data Protection Act, 2023, you may raise a privacy grievance as follows:
- Work-related data (attendance, location, employee records): contact your organisation's administrator first — they are usually the data controller
- Platform, billing, or StaffTrakr support: email info@vnvlogixpace.com
- We will acknowledge grievances within the timelines required by applicable law and coordinate with your organisation where they control the relevant data
Permissions disclosure
- Location permission is required for punch-in/out and continuous route monitoring while on duty
- Background location on Android is used only while punched in, with a visible on-duty notification
- Notification permission is used for operational alerts and the on-duty tracking notification on Android
- Biometric unlock is optional and processed only on your device
- The app does not use the camera to capture or upload profile photos
9. Children's Privacy
StaffTrakr is a workforce app for employed adults. It is not intended for individuals under the age of 18. We do not knowingly collect personal data from children.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Updates will be posted on our website with a revised "Last updated" date.
11. Contact Us
If you have any questions or concerns, contact us at: