1. About this policy
TraceOn is an employee attendance and location tracking service operated by Appseed Technologies Private Limited ("TraceOn", "we", "us"). It consists of a mobile app for employees, a web dashboard for administrators and managers, and the backend service that supports both.
This policy explains what personal information TraceOn handles, why, and what choices you have. It applies to the TraceOn mobile app, the TraceOn web dashboard, and api.traceon.in.
2. Our role, and your employer's role
TraceOn is provided to organisations, not to individuals. Your employer subscribes to TraceOn and creates an account for you.
This matters for your privacy rights:
- Your employer decides what data is collected about you, how often your location is recorded, how long it is kept, and who inside the organisation can see it. In data protection terms, your employer is the data controller.
- We process that data on your employer's instructions. We are the data processor. We do not decide how your attendance or location data is used, and we do not use it for our own purposes.
If you want your data corrected, exported, or deleted, start with your employer — see section 10.
3. Information we collect
3.1 Account and profile information
Created by your employer's administrator, not by you:
- Name
- Employee code
- Email address (optional)
- Phone number (optional)
- Job role, level, and branch
- Who you report to (your manager)
- Whether your account is active
3.2 Attendance records
- Check-in and check-out times for each work session
- An optional reason or note attached to a session
3.3 Location information
This is the most sensitive category, so we describe it precisely:
- GPS coordinates (latitude and longitude) and the time each reading was taken
- Whether the reading was recorded manually (at check-in or check-out) or automatically (at intervals during a session)
- Whether your device reported the location as mocked or simulated
Important limits on location collection:
- Location is only recorded while you are checked in. Every location reading is tied to an open attendance session. When you check out, recording stops.
- The interval is set by your employer, not by us. It defaults to one reading every 30 minutes and is configurable per organisation.
- We collect location in the background while a session is active, so tracking continues when the app is not on screen. Your device will show a persistent notification while this is happening.
- We do not collect location when you are checked out, on leave, or not using the app.
3.4 Information stored on your device
The app keeps some information locally on your phone, so that it works when you have no signal:
- Offline attendance data. If you check in, move, or check out while your device is offline, TraceOn stores that activity on your device — including the full list of location readings taken during the session — and uploads it once you are back online. Until then it stays on your phone.
- Your session tokens, so you do not have to sign in every time.
- A cached copy of your profile (name, employee code, role) so screens load without a network call.
- Your app preferences, such as whether biometric unlock is enabled.
This data is held in the app's private storage. Clearing the app's data or uninstalling the app removes it — and removes any attendance activity that has not yet been uploaded.
3.5 Device and technical information
- Device push notification token, platform (Android/iOS), device name
- App version and operating system version
- Network connection state
- Whether your device reports developer mode as enabled, and whether it appears to be an emulator. We check this only to detect attempts to falsify location.
- Server logs, including request metadata and timestamps
3.6 Authentication information
- A securely hashed version of your password (we never store your password in readable form)
- Session tokens issued when you sign in
If your employer uses single sign-on, your password is verified against your employer's own system, and we never receive or store it.
3.7 Biometric data
The app can use fingerprint or Face ID to unlock. This never leaves your device. Your biometric data is held by your device's operating system, is never transmitted to us, and we cannot access it.
4. How we use information
We use the information above only to:
- Authenticate you and keep your account secure
- Record and display attendance
- Show location and movement history to authorised people in your organisation
- Send you notifications relevant to your work (for example attendance reminders)
- Produce attendance and activity reports for your employer
- Operate, troubleshoot, secure, and improve the service
- Meet legal obligations
5. Who we share information with
Within your organisation. Your attendance and location data is visible to administrators, and to managers for the people who report to them. Your employer decides who holds those roles.
Service providers who help us operate TraceOn:
| Provider | Purpose | Data involved |
|---|---|---|
| Google Firebase (Cloud Messaging) | Delivering push notifications | Device push token, platform, app and OS version |
| Google Firebase (Analytics) | Bundled with the above. We do not send analytics events ourselves; the SDK may collect basic app usage automatically | App open and usage events, device model, coarse region |
| Our email delivery provider | Account, welcome, and password reset emails | Name, email address |
| Our cloud hosting provider | Running the service and storing data | All service data |
Your employer's own systems. If your organisation uses single sign-on, your credentials are sent to your employer's authentication system to be verified.
Legal requirements. We may disclose information where required by law, or to protect the rights, safety, or property of TraceOn, our customers, or the public.
6. What we do not do
- We do not sell your personal information.
- We do not share it with advertisers or use it for advertising or ad targeting.
- We do not use your attendance or location data to build profiles for our own commercial purposes.
- We do not track your location when you are checked out.
7. How we protect information
- Passwords are hashed with bcrypt and are never stored or transmitted in readable form.
- Traffic between the apps and our production servers is sent over encrypted HTTPS connections.
- Access is controlled by role: employees see only their own data; managers see only their reports; administrators see only their own organisation.
- Each organisation's data is isolated from every other organisation's.
- Sessions expire and require re-authentication.
No system is perfectly secure, but we work to protect your information using measures appropriate to its sensitivity.
8. How long we keep information
Retention is set by your employer under its agreement with us. In general:
- Attendance and location records are kept for as long as your employer requires them, and for as long as your employer's account is active.
- Account information is kept while your account exists.
- When your employer ends its subscription, its data is deleted or returned according to that agreement.
If you want to know your employer's specific retention period, ask your employer.
9. Children
TraceOn is a workplace tool and is not directed at children. We do not knowingly collect information from anyone under 16.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal information, and to object to processing.
Because your employer controls your data, please contact your employer's TraceOn administrator or HR team first. They can act on most requests directly.
If your employer cannot help, or you have a concern about how we handle data as a processor, contact us at the address in section 14. We will respond and, where appropriate, direct your request to your employer. You also have the right to complain to your local data protection authority.
11. Device permissions
The app requests only the permissions it needs. You can withdraw any of them in your device settings, though some features will stop working.
| Permission | Why | If you decline |
|---|---|---|
| Location (precise and approximate) | Record where you check in and out | You cannot record attendance |
| Background location | Continue recording during an active session | Tracking stops when the app is not on screen |
| Notifications | Attendance reminders and alerts | You will not receive reminders |
| Foreground service | Keep tracking running while checked in | Background tracking is unreliable |
| Ignore battery optimisation | Stop the system suspending tracking | Location readings may be missed |
| Run at startup | Resume an active session after a restart | You may need to check in again |
| Biometric / Face ID | Unlock the app | Sign in with your password instead |
| Network state, internet | Communicate with our servers | The app cannot function |
| Vibrate, wake lock | Deliver notifications reliably | Notifications may be less noticeable |
12. International transfers
Your information may be stored and processed in [COUNTRY / REGION]. Where data is transferred across borders, we use appropriate safeguards as required by applicable law.
13. Changes to this policy
We may update this policy. When we do, we will change the "Last updated" date above, and we will tell you about significant changes through the app or by email. Continuing to use TraceOn after a change means you accept the updated policy.
14. Contact us
Questions about this policy or how we handle your information:
Appseed Technologies Private Limited
Email: contact@appseed.in
Address: 3rd floor, MIG-115 Bhaskara Nilayam, Road No.1, KPHB, Kukatpally, Hyderabad, Telangana 500072
For requests about your own data, please contact your employer's TraceOn administrator first.