Onsite Privacy Policy
This policy covers Onsite, the Workliance worker app — what we collect, why we collect it, and how long we keep it. We wrote it to match exactly what the app does, nothing more.
What we collect
Here is every piece of personal data the app collects, why it's collected, and exactly where it goes.
Phone number
Why
Used as your login identity. Today you sign in with a PIN; OTP-based login is planned.
Where it goes
Stored on our backend, in the workers collection.
Login PIN
Why
Authenticates you when you log in.
Where it goes
Sent to our backend as a hashed comparison — never stored on your device or transmitted in plaintext. Only your session token is stored locally, using secure encrypted storage.
Precise GPS location (lat/lng, accuracy, mock-detection flag)
Why
Confirms you're at the correct site when you check in/out or scan a patrol checkpoint. Accuracy and mock-location data are also checked to prevent spoofed locations.
Where it goes
Sent to our backend for each check-in, check-out, or patrol scan, and stored with that attendance/patrol record.
Camera — selfie photo
Why
Confirms it's really you checking in or scanning a checkpoint (anti-proxy verification) — not someone using your phone on your behalf.
Where it goes
Uploaded to secure cloud storage and automatically deleted after 15 days. Not shown to anyone else.
Biometric (fingerprint / face)
Why
Locally unlocks the app before a patrol scan, as an extra security gate on your device.
Where it goes
Never leaves your device. Your phone's biometric system only tells the app yes or no — we never see or store the biometric data itself.
Support report text
Why
Lets you report a problem through the app so our support team can help.
Where it goes
Sent to our backend, emailed to our support team, and saved to our database so we can help you.
Device push token (planned — not live yet)
Why
Will let us send you notifications, such as shift or attendance reminders.
Where it goes
Will be stored on our backend once push notifications are enabled.
Crash & error reports (Firebase Crashlytics)
Why
Helps us detect, diagnose, and fix crashes and errors — especially issues that only show up in the field, where we can't just plug in a device to check.
Where it goes
Sent automatically to Firebase (Google) when the app crashes or hits an error. Includes device model, OS version, app version, and a stack trace, along with your worker/guard ID, site ID, and the screen you were on, so we can find and fix the right issue.
App usage analytics (Firebase Analytics)
Why
Helps us understand which features are used and how the app performs, so we can improve it.
Where it goes
Aggregated usage events (such as screens viewed and app opens) sent to Firebase (Google). Used only to improve the app — never for advertising or shared with third parties.
How each feature uses your data
A quick summary of what's collected during each action in the app.
Attendance check-in / check-out
Uses your phone number (identity), GPS location, and a selfie photo to confirm you're at the right site and that it's really you.
Guard patrol checkpoint scan
Uses GPS location and a selfie photo for each scan, gated behind an on-device biometric unlock that never leaves your phone.
Report a problem
Sends the text you write to our support team by email and saves it to our database so we can follow up.
How long we keep it
Selfie photos are automatically and permanently deleted 15 days after they're taken — this is enforced by an active deletion rule on our storage, not a manual process.
Your login PIN is never stored in plaintext anywhere, so there's nothing to retain.
Phone numbers, attendance records, and patrol records are kept for as long as your account stays active with your employer, or as long as applicable Indian labour law requires us to retain employment and payroll-related records.
Support report text is kept as long as needed to resolve your report and for our support records.
Who we share it with
The vendor or site-admin company you work for can see your attendance, patrol, and profile data — managing that is the whole point of the app.
We never sell your data to anyone.
We never share your data with advertisers. Workliance doesn't run ads or use ad SDKs. We use Firebase (Google) for push notifications, crash reporting, and basic usage analytics — this data is used only to run and improve the app, never for advertising.
We may disclose data if required by law, such as a valid court order or government request.
Other workers never see your phone number, PIN, selfies, or location — that data is only visible to your employer's authorized admins and our backend systems.
Your rights
You can request a copy of your data, or ask us to delete it, at any time by emailing support@workliance.com.
The app doesn't yet have a self-serve "delete my account" option — we handle these requests manually today, and plan to add self-serve deletion in a future release.
Selfie photos already auto-expire within 15 days regardless of any request. Other records are removed from active systems on request, except where we're legally required to retain them (for example, payroll or statutory compliance records).
Security
We use industry-standard practices to protect your data, including secure transmission to our servers and restricted access to our backend systems.
Biometric data never leaves your device — it's checked locally by your phone's operating system and never reaches our servers.
Children's privacy
Workliance is a workforce app built for employed adults and is not directed at children. We do not knowingly collect data from anyone under 18.
Changes to this policy
We may update this policy as the app evolves — for example, when OTP login or push notifications go live. We'll update the "last updated" date below, and for material changes, we'll notify you in the app.
No ads, no ad tracking
The app contains no ad SDKs. We use Firebase for push notifications, crash reporting, and basic usage analytics — never for advertising or tracking across other apps.
Your data is never sold
We don't sell your personal data to anyone, for any reason.
Questions about this policy?