SiteHub OS
Privacy PolicyTerms of ServiceSupport

Delete your account and personal data

This page explains how to ask for your SiteHub OS account and the personal data linked to it to be deleted, what is deleted, what is retained and why.

Your account belongs to the workspace of the company that employs or engages you ("your Company"), which is the data fiduciary for it; the platform is hosted by the Operator (SGF Infra Private Limited), which processes the data on your Company's behalf and runs the deletions below. Where your Company self-hosts SiteHub OS, the two are the same entity. See the Privacy Policy (/privacy, section 1) for the roles.

How to request deletion

In the app (web or mobile): sign in and open this page (in the SiteHub OS mobile app: Settings → Request account deletion), then confirm. If you are signed in, the request form is shown below this text. The request is recorded immediately and sent to your Company's administrator.

If you cannot sign in: email the Operator at karang@sgfinfra.com with the subject "SiteHub OS account deletion" and include your full name, the name of your Company and the mobile number registered on the account. The Operator will call or message that number to confirm it is you before proceeding, and will pass the request to your Company's administrator. You can also write to the Grievance Officer listed in the Privacy Policy (/privacy).

You do not need to give a reason. A request can be withdrawn by contacting your Company's administrator before it is processed.

What happens next

  1. Your request is logged with the date and time.
  2. Your Company's administrator reviews it (this is a workplace app, so the administrator also handles the end of your access and any handover).
  3. Within 30 days of the request the administrator processes it and the platform applies the deletions below. You receive a confirmation on the registered phone number or email if you provided one.
  4. Nightly database backups are kept for 30 days on a rolling basis, so a deleted copy may persist in a backup for up to 30 further days and is then overwritten. Backups are encrypted and are only used for disaster recovery.

If you leave your Company without submitting a request, your account is deactivated by the administrator. Deactivated accounts cannot sign in; the personal data below is still deleted only when you or your Company request it, or under your Company's retention schedule. If your Company stops using the platform altogether, its whole workspace, including your data, is deleted or handed over to it as described in the Privacy Policy, section 10.

What is deleted

DataAction
Face enrolment photos and face templates (embeddings)Deleted from storage and database
Attendance punch selfiesDeleted from storage; the punch row keeps only time, GPS result and match result
Login: password hash, sessions, failed-login countersDeleted; the account can no longer sign in
Registered devices and push notification tokensDeleted
Location tracking points (position, speed, heading, accuracy, battery level, mock flag, device id, assigned vehicle) and the day trails, distances and stops computed from themDeleted from the database immediately. Points that are not deleted with an account are in any case pruned automatically 90 days after they were recorded.
Your profile: name, phone number, emailReplaced by "Deleted user" and an internal placeholder; your phone number is removed
Pending deletion request recordKept only as an entry in the audit log showing that the request was processed

What is retained, and why

DataWhy it is kept
Attendance rows (date, project, present/absent, shift, punch time, geofence result) without selfies; for drivers, the once-a-day selfie punch row without the selfie and without a project or geofence resultPayroll, wage and statutory records; your Company is required to keep attendance and payment records under Indian labour and tax law
Vehicle assignment records (which vehicle or machine, from/to dates, notes)Part of the vehicle's history in the equipment register; the driver is shown as "Deleted user"
Expense entries, payment requests, material requests, purchase orders, receipts, fuel entries and their invoice/document photosAccounting and tax records (required for up to 8 years); these are records of your Company's transactions, not of you personally, and will show "Deleted user" as the creator
Task progress, site photos, to-dos, drawings, approvals, commentsProject records owned by your Company; they show "Deleted user" as the author
Audit log entries (action, time, IP address)Security and accountability; retained up to 24 months, then deleted
Party records you created about vendors, contractors, workers or clientsThese describe third parties, not you

Retained records no longer contain your name, phone number, face, selfies or location points. They cannot be used to identify you by anyone without access to the audit log, which is restricted to your Company's administrators and the Operator's technical staff and is itself purged on the schedule above.

Reinstating access

Deletion is permanent. If you later work with your Company (or another company that uses SiteHub OS) again, its administrator will create a new account and you will need to enrol your face again.

Questions

Operator's privacy contact / Grievance Officer: Karan Gupta, karang@sgfinfra.com, <<FILL: phone>>. For the status of a request, ask your Company's administrator. Privacy Policy: /privacy · Terms: /terms · Support: /support.