Mobile App Privacy

Mobile App Privacy Policy

How the Timemoz mobile app collects, uses, stores, and protects your data — and exactly why we ask for location, camera, and notification access.

Effective Date: August 18, 2026 · Last Updated: August 18, 2026

No selling of data

Your name and email stay inside the app and your company workspace. They are never shared or sold outside of it.

No background tracking

Location is read only at the moment you check in or check out — never silently in the background.

You stay in control

Every permission is optional, revocable in device settings, and you can request deletion of your data at any time.

1. Introduction

Timemoz ("we", "our", or "us") provides a mobile application used by field and sales teams to record attendance, check in at registered outlets, and submit proof of visit. This Privacy Policy explains what personal data the mobile app collects, why we collect it, how we use and protect it, and what choices you have.

This policy applies to the Timemoz mobile app distributed through the Google Play Store and the Apple App Store. Use of the Timemoz web platform is additionally covered by our general Privacy Policy.

The app is intended for employees and authorized personnel of companies that subscribe to Timemoz. By installing and using the app, you agree to the practices described here.

2. Permissions We Request and Why

We only request permissions that are required for a feature you actively use. Each one is asked for in context, with an explanation, and can be declined or revoked later.

Location (Precise)

Why we need it: To record your attendance and verify that your check-in or check-out happens at a registered outlet.

When it is used: Only while the app is open, and only at the moment you tap check-in, check-out, or open the outlet map.

If you decline: You can decline or revoke it. Attendance and outlet verification will not work, but the rest of the app still does.

Camera

Why we need it: To take a photo as proof that you arrived at the outlet you are visiting.

When it is used: Only when you open the camera screen and take the photo yourself.

If you decline: You can decline or revoke it. You will not be able to attach visit-proof photos.

Notifications (Push)

Why we need it: To send you schedules, visit assignments, attendance reminders, and important information from your company.

When it is used: Whenever your company or the system sends you a work-related message.

If you decline: You can decline it, or turn notifications off in your device settings at any time.

Photo Library / Storage (optional)

Why we need it: To let you attach an existing photo or save a report you generated in the app.

When it is used: Only when you pick a file yourself. We never scan or browse your gallery.

If you decline: Fully optional. Declining it does not block attendance.

No background location. The app does not collect location while it is closed or running in the background, and it does not follow your movements between check-ins. We capture a single coordinate at the moment you perform an attendance action, purely to confirm you are within the allowed radius of a registered outlet. You can revoke any permission at any time from your device settings, and the app keeps working with the affected feature disabled.

3. Data We Collect

The categories of data the Timemoz mobile app collects — and what it deliberately does not.

Account Information

  • Full name
  • Work email address
  • Employee ID and role (if provided by your company)
  • Company or team you belong to
  • Profile photo (optional, uploaded by you)

Attendance and Location Data

  • GPS coordinates captured at the moment of check-in or check-out
  • Distance between you and the registered outlet
  • Outlet name and visit timestamp
  • Attendance status (present, late, on visit, finished)

Visit Proof Photos

  • Photos you take as proof of arrival at an outlet
  • The time and outlet the photo is attached to
  • Photos are stored against your visit record only

Push Notification Data

  • Device push token (an anonymous identifier issued by Apple or Google)
  • Delivery status of the notifications we send you

Device and Technical Data

  • Device model, operating system, and app version
  • Crash reports and error logs
  • Login timestamps and session activity

What We Do NOT Collect

  • Contacts, call logs, or SMS messages
  • Continuous background location tracking
  • Microphone or audio recordings
  • Files or photos in your gallery that you did not select
  • Health, financial, or biometric data

4. How We Use Your Data

We use the data collected by the app only to:

  • Create and secure your account, and identify you to your own company
  • Record attendance and verify that a check-in happened at a registered outlet
  • Attach visit-proof photos to the correct outlet and visit record
  • Deliver work-related push notifications such as schedules and assignments
  • Generate attendance and visit reports for your employer
  • Keep the app secure, detect fraudulent check-ins, and prevent abuse
  • Fix crashes and improve reliability using aggregated, anonymized data
  • Respond to your support requests
Section 5

Your Name and Email Address

We store your name and email address for one reason only: to create your account, sign you in, and identify you to your own company inside the app — so that an attendance record or a visit report is attributed to the right person.

We never sell your personal data to anyone.

We never share your name or email address with advertisers, data brokers, or any party outside the app.

We never use your data for advertising, ad targeting, or cross-app tracking.

We never build marketing profiles from your location or your photos.

We never publish your location or your photos publicly.

We may send you transactional email — account verification, password resets, or security alerts. Marketing email is only sent if you explicitly opt in, and you can unsubscribe at any time.

6. Data Sharing

We share data only in the limited circumstances below, and only to the extent needed to operate the app:

RecipientPurposeNotes
Your employer / company workspaceAttendance verification and visit reportingOnly authorized supervisors within your own company
Cloud hosting and database providersStoring and serving app dataBound by data processing agreements; no independent use
Push providers (Apple APNs, Google FCM)Delivering notifications to your deviceReceives the push token and message payload only
Map and geocoding providerDisplaying outlet locations on a mapReceives only the coordinates needed to render the map
Legal authoritiesLegal complianceOnly when required by valid, applicable law

We do not share your data with advertisers or data brokers, and we do not transfer it to any third party for their own purposes.

7. Data Retention

Data TypeRetention Period
Account information (name, email)For the lifetime of your account
Attendance and location recordsAs long as your employer requires, up to 24 months
Visit proof photosUp to 12 months, then permanently deleted
Push notification tokenUntil you log out or uninstall the app
Crash and error logsUp to 90 days
Session and login logsUp to 12 months

When your account is deleted, your personal data is permanently removed within 30 days, except where a longer period is required by law or by your employer's legitimate record-keeping obligations.

8. Account and Data Deletion

You can request deletion of your account and the personal data associated with it at any time:

  • In the app, open Settings → Account → Delete Account and confirm.
  • Or email [email protected] from your registered address with the subject "Delete my account".

Deletion removes your profile, name, email, push token, visit proof photos, and location records. Attendance records your employer is legally required to keep as employment records may be retained by your company in anonymized or aggregated form. We confirm every deletion request in writing and complete it within 30 days.

9. Data Security

We protect your data using:

  • HTTPS/TLS encryption for all data transmitted between the app and our servers
  • Encryption at rest for stored photos and attendance records
  • Role-based access control enforced server-side, so staff only see their own company's data
  • Access to production data limited to authorized personnel and audited
  • Session tokens stored in the device's secure storage (Keychain / Keystore)
  • Regular security reviews and dependency updates

No system is completely secure. If a data breach affects your personal data, we will notify you and the relevant authorities without undue delay, as required by applicable law.

10. Legal Basis for Processing

Where data protection law such as the GDPR applies, we process your data on the following bases:

  • Contract: to provide the app to you and your employer under our service agreement.
  • Consent: for location, camera, and push notification access, which you grant per permission and can withdraw at any time.
  • Legitimate interest: to keep the service secure, prevent fraudulent check-ins, and improve reliability.
  • Legal obligation: where we must retain or disclose data under applicable law.

Your employer acts as the data controller for attendance and visit records; Timemoz acts as the data processor on their behalf.

11. Your Rights

Depending on your location, you may have the right to:

Access

Request a copy of the personal data we hold about you.

Correction

Ask us to correct inaccurate or incomplete data.

Deletion

Request permanent deletion of your account and personal data.

Export

Receive your data in a portable, machine-readable format.

Withdraw Consent

Revoke location, camera, or notification permissions at any time in your device settings.

Object / Restrict

Object to or restrict certain types of data processing.

To exercise any of these rights, contact us at the address below. We respond within 30 days.

12. International Data Transfers

Your data may be stored and processed on servers located outside your country of residence. When we transfer personal data across borders, we rely on appropriate safeguards such as standard contractual clauses and data processing agreements with our infrastructure providers.

13. Local Storage on Your Device

The app stores a small amount of data on your device to:

  • Keep you signed in between sessions
  • Remember your preferences and settings
  • Queue attendance records taken offline until a connection is available

We do not use advertising identifiers, advertising cookies, or any cross-app tracking technology. Uninstalling the app removes this local data from your device.

14. Children's Privacy

The Timemoz mobile app is a workplace tool intended for employees and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

15. Changes to This Policy

We may update this Privacy Policy as the app evolves. When we do, we will update the "Last Updated" date at the top of this page. Continued use of the app after changes take effect constitutes acceptance of the updated policy.

If a change materially affects how we handle your data — for example a new permission or a new category of collected data — we will notify you in the app or by email before it takes effect, and where required we will ask for your consent again.

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or the data the app collects, please contact us: