Mobile App Privacy Policy
How the Timemoz mobile app collects, uses, stores, and protects your data — and exactly why we ask for location, camera, and notification access.
Effective Date: August 18, 2026 · Last Updated: August 18, 2026
No selling of data
Your name and email stay inside the app and your company workspace. They are never shared or sold outside of it.
No background tracking
Location is read only at the moment you check in or check out — never silently in the background.
You stay in control
Every permission is optional, revocable in device settings, and you can request deletion of your data at any time.
1. Introduction
Timemoz ("we", "our", or "us") provides a mobile application used by field and sales teams to record attendance, check in at registered outlets, and submit proof of visit. This Privacy Policy explains what personal data the mobile app collects, why we collect it, how we use and protect it, and what choices you have.
This policy applies to the Timemoz mobile app distributed through the Google Play Store and the Apple App Store. Use of the Timemoz web platform is additionally covered by our general Privacy Policy.
The app is intended for employees and authorized personnel of companies that subscribe to Timemoz. By installing and using the app, you agree to the practices described here.
2. Permissions We Request and Why
We only request permissions that are required for a feature you actively use. Each one is asked for in context, with an explanation, and can be declined or revoked later.
Location (Precise)
Why we need it: To record your attendance and verify that your check-in or check-out happens at a registered outlet.
When it is used: Only while the app is open, and only at the moment you tap check-in, check-out, or open the outlet map.
If you decline: You can decline or revoke it. Attendance and outlet verification will not work, but the rest of the app still does.
Camera
Why we need it: To take a photo as proof that you arrived at the outlet you are visiting.
When it is used: Only when you open the camera screen and take the photo yourself.
If you decline: You can decline or revoke it. You will not be able to attach visit-proof photos.
Notifications (Push)
Why we need it: To send you schedules, visit assignments, attendance reminders, and important information from your company.
When it is used: Whenever your company or the system sends you a work-related message.
If you decline: You can decline it, or turn notifications off in your device settings at any time.
Photo Library / Storage (optional)
Why we need it: To let you attach an existing photo or save a report you generated in the app.
When it is used: Only when you pick a file yourself. We never scan or browse your gallery.
If you decline: Fully optional. Declining it does not block attendance.
No background location. The app does not collect location while it is closed or running in the background, and it does not follow your movements between check-ins. We capture a single coordinate at the moment you perform an attendance action, purely to confirm you are within the allowed radius of a registered outlet. You can revoke any permission at any time from your device settings, and the app keeps working with the affected feature disabled.
3. Data We Collect
The categories of data the Timemoz mobile app collects — and what it deliberately does not.
Account Information
- Full name
- Work email address
- Employee ID and role (if provided by your company)
- Company or team you belong to
- Profile photo (optional, uploaded by you)
Attendance and Location Data
- GPS coordinates captured at the moment of check-in or check-out
- Distance between you and the registered outlet
- Outlet name and visit timestamp
- Attendance status (present, late, on visit, finished)
Visit Proof Photos
- Photos you take as proof of arrival at an outlet
- The time and outlet the photo is attached to
- Photos are stored against your visit record only
Push Notification Data
- Device push token (an anonymous identifier issued by Apple or Google)
- Delivery status of the notifications we send you
Device and Technical Data
- Device model, operating system, and app version
- Crash reports and error logs
- Login timestamps and session activity
What We Do NOT Collect
- Contacts, call logs, or SMS messages
- Continuous background location tracking
- Microphone or audio recordings
- Files or photos in your gallery that you did not select
- Health, financial, or biometric data
4. How We Use Your Data
We use the data collected by the app only to:
- Create and secure your account, and identify you to your own company
- Record attendance and verify that a check-in happened at a registered outlet
- Attach visit-proof photos to the correct outlet and visit record
- Deliver work-related push notifications such as schedules and assignments
- Generate attendance and visit reports for your employer
- Keep the app secure, detect fraudulent check-ins, and prevent abuse
- Fix crashes and improve reliability using aggregated, anonymized data
- Respond to your support requests
Your Name and Email Address
We store your name and email address for one reason only: to create your account, sign you in, and identify you to your own company inside the app — so that an attendance record or a visit report is attributed to the right person.
We never sell your personal data to anyone.
We never share your name or email address with advertisers, data brokers, or any party outside the app.
We never use your data for advertising, ad targeting, or cross-app tracking.
We never build marketing profiles from your location or your photos.
We never publish your location or your photos publicly.
We may send you transactional email — account verification, password resets, or security alerts. Marketing email is only sent if you explicitly opt in, and you can unsubscribe at any time.
6. Data Sharing
We share data only in the limited circumstances below, and only to the extent needed to operate the app:
| Recipient | Purpose | Notes |
|---|---|---|
| Your employer / company workspace | Attendance verification and visit reporting | Only authorized supervisors within your own company |
| Cloud hosting and database providers | Storing and serving app data | Bound by data processing agreements; no independent use |
| Push providers (Apple APNs, Google FCM) | Delivering notifications to your device | Receives the push token and message payload only |
| Map and geocoding provider | Displaying outlet locations on a map | Receives only the coordinates needed to render the map |
| Legal authorities | Legal compliance | Only when required by valid, applicable law |
We do not share your data with advertisers or data brokers, and we do not transfer it to any third party for their own purposes.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information (name, email) | For the lifetime of your account |
| Attendance and location records | As long as your employer requires, up to 24 months |
| Visit proof photos | Up to 12 months, then permanently deleted |
| Push notification token | Until you log out or uninstall the app |
| Crash and error logs | Up to 90 days |
| Session and login logs | Up to 12 months |
When your account is deleted, your personal data is permanently removed within 30 days, except where a longer period is required by law or by your employer's legitimate record-keeping obligations.
8. Account and Data Deletion
You can request deletion of your account and the personal data associated with it at any time:
- In the app, open Settings → Account → Delete Account and confirm.
- Or email [email protected] from your registered address with the subject "Delete my account".
Deletion removes your profile, name, email, push token, visit proof photos, and location records. Attendance records your employer is legally required to keep as employment records may be retained by your company in anonymized or aggregated form. We confirm every deletion request in writing and complete it within 30 days.
9. Data Security
We protect your data using:
- HTTPS/TLS encryption for all data transmitted between the app and our servers
- Encryption at rest for stored photos and attendance records
- Role-based access control enforced server-side, so staff only see their own company's data
- Access to production data limited to authorized personnel and audited
- Session tokens stored in the device's secure storage (Keychain / Keystore)
- Regular security reviews and dependency updates
No system is completely secure. If a data breach affects your personal data, we will notify you and the relevant authorities without undue delay, as required by applicable law.
10. Legal Basis for Processing
Where data protection law such as the GDPR applies, we process your data on the following bases:
- Contract: to provide the app to you and your employer under our service agreement.
- Consent: for location, camera, and push notification access, which you grant per permission and can withdraw at any time.
- Legitimate interest: to keep the service secure, prevent fraudulent check-ins, and improve reliability.
- Legal obligation: where we must retain or disclose data under applicable law.
Your employer acts as the data controller for attendance and visit records; Timemoz acts as the data processor on their behalf.
11. Your Rights
Depending on your location, you may have the right to:
Access
Request a copy of the personal data we hold about you.
Correction
Ask us to correct inaccurate or incomplete data.
Deletion
Request permanent deletion of your account and personal data.
Export
Receive your data in a portable, machine-readable format.
Withdraw Consent
Revoke location, camera, or notification permissions at any time in your device settings.
Object / Restrict
Object to or restrict certain types of data processing.
To exercise any of these rights, contact us at the address below. We respond within 30 days.
12. International Data Transfers
Your data may be stored and processed on servers located outside your country of residence. When we transfer personal data across borders, we rely on appropriate safeguards such as standard contractual clauses and data processing agreements with our infrastructure providers.
13. Local Storage on Your Device
The app stores a small amount of data on your device to:
- Keep you signed in between sessions
- Remember your preferences and settings
- Queue attendance records taken offline until a connection is available
We do not use advertising identifiers, advertising cookies, or any cross-app tracking technology. Uninstalling the app removes this local data from your device.
14. Children's Privacy
The Timemoz mobile app is a workplace tool intended for employees and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
15. Changes to This Policy
We may update this Privacy Policy as the app evolves. When we do, we will update the "Last Updated" date at the top of this page. Continued use of the app after changes take effect constitutes acceptance of the updated policy.
If a change materially affects how we handle your data — for example a new permission or a new category of collected data — we will notify you in the app or by email before it takes effect, and where required we will ask for your consent again.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or the data the app collects, please contact us: