Privacy Policy: SmartSite
Effective date: <<FILL: DD Month YYYY>> Version: 1.1
1. Who is who
SmartSite ("the app", "the platform") is a construction site management platform for construction companies. It exists in two forms: a web app at https://smartsite.sgfinfra.com and a mobile app for iOS and Android ("SmartSite"). This policy covers both; the same server, database and rules apply to both.
Three parties appear in this policy:
- The Operator ("we", "us"): the entity that hosts and runs the SmartSite platform, publishes the mobile app and this policy:
- Legal name: SGF Infra Private Limited
- Registered address: <<FILL: full postal address, city, state, PIN>>
- Privacy contact / Grievance Officer: Karan Gupta, karang@sgfinfra.com, <<FILL: phone>>
- The Company ("your Company"): the construction company that employs or engages you and has a workspace on the platform. Each Company has its own isolated workspace; its administrators create the accounts, roles, projects and settings for its own staff, and they decide why and how your data is processed in the app.
- You ("the user"): an employee, engaged contractor or other person your Company has authorised to use the app.
Data protection roles. Under the Digital Personal Data Protection Act 2023 (India) and equivalent laws:
- Your Company is the Data Fiduciary (controller) for all personal data in its workspace. It determines the purposes and means of processing: which modules are used, who is enrolled for face verification, who is put in driver mode, for whom location tracking is switched on, who holds which role and permission, and how long business records are kept.
- The Operator is a Data Processor acting on your Company's instructions where the platform is hosted by a third party. The Operator hosts the servers, stores the data, applies the security measures in section 9, runs the automatic retention clean-ups in section 10 and processes your data only to provide the service to your Company; it does not use your data for its own purposes.
- Where your Company self-hosts SmartSite, the Operator and the Company are the same entity, which is then both fiduciary and processor. Everything in this policy applies unchanged; "the Operator" and "your Company" simply refer to the same organisation.
Your Company's own privacy notice or employment policy may add to this policy but cannot reduce the protections described here. Questions about why your Company processes your data go to your Company's administrator; questions about how the platform handles it, and grievance requests, go to the Operator's privacy contact in this section, who involves your Company where its decision is needed.
2. Scope: who uses the app
- The app is for employees and engaged contractors of a Company and for staff a Company authorises (for example an accountant or a vehicle driver). It is a business-to-business workplace tool.
- There is no public sign-up. A Company administrator creates every account in that Company's workspace and can deactivate it. A Company is onboarded on the platform by the Operator.
- Users must be 18 years or older. The app is not directed at children and we do not knowingly collect data from anyone under 18.
- The app also holds information about third parties that users enter in the course of work: vendors, suppliers, labour contractors, site workers and clients ("parties"). Section 4 covers this.
- Isolation between Companies. All data is scoped to the Company it belongs to. No user, administrator or record of one Company can see the data of another Company on the same platform.
3. Data collected
| Category | Examples | Where it comes from | Purpose | Legal basis (India DPDP Act 2023) |
|---|---|---|---|---|
| Account and identity | Name, mobile phone number (login identity), optional email, role, Company membership, project memberships | Company administrator; you (email) | Create and secure your account, apply your role permissions | Employment purposes (s.7(i)) for employees; consent at first login for contractors and other authorised users |
| Credentials | Password, stored only as an Argon2 hash; failed-login counter and temporary lock time | You | Authentication; brute-force protection | Same as above; security obligation of the fiduciary (s.8(5)) |
| Session data | Session token (stored as a SHA-256 hash), browser/app user-agent string, IP address, creation and expiry time | Your device | Keep you signed in (up to 30 days); detect misuse | Same as above |
| Face enrolment images | Up to 3 photographs of your face, plus a numeric face template ("embedding") computed from each and a detection-quality score | You, or an administrator enrolling you with your knowledge | Verify that the person punching attendance is you (see section 5) | Consent (s.6); employment/attendance purposes (s.7(i)) |
| Attendance punch records | Punch type (in/out), time, GPS latitude/longitude and accuracy, age of the GPS fix, distance from the project site, geofence result, one selfie per punch, face-match result and similarity score, device user-agent, platform (web/iOS/Android), device identifier, whether the OS reported a mock/fake location, and quality flags derived from these (for example low accuracy, unknown device). For members in driver mode (section 6.2) the punch is once a day, is not tied to a project site and has no geofence result. | You, at the moment you punch | Record and verify site attendance; detect spoofing; resolve disputes | Employment/attendance purposes (s.7(i)); consent for contractors |
| Location at punch and photo upload | Precise GPS position at the moment of a punch and, optionally, when you upload a site photo | Your device, in the foreground, when you tap the action | Geofence check against the project location; geo-tag of site photos | Same as above |
| Location tracking (background; only if enabled for you) | Precise GPS position (latitude/longitude), reported accuracy, speed, heading, time of the fix, your phone's battery level (percentage), whether the OS reported a mock/fake location, your device identifier, and the Company vehicle assigned to you at that time. A point is sent roughly every 2 hours (your Company sets the interval; default 120 minutes), plus one fix when you open the app and when you mark attendance, in the foreground and in the background, for as long as the app is installed, background location permission is granted and a Company administrator has switched "Track location" on for you. See section 6.3. | Your device, automatically | Show your Company's administrators the last reported position of drivers and Company vehicles (map), reconstruct the day's points and route (distance, stops) per vehicle, resolve disputes about vehicle use, safety of staff and vehicles | Employment purposes (s.7(i)); in addition, the app shows you a notice and asks for your agreement before tracking is enabled on your device |
| Vehicle assignment | Which Company vehicle or machine you are the driver of, from and to dates, notes | Company administrator | Link your location trail to the vehicle you drive; equipment records | Employment purposes; the Company's business records |
| Photos and files | Site progress photos, invoice/receipt photos on expenses, drawings, fuel and material photos, with file name, size, type, optional GPS and time taken | You | Site diary, expense records, drawing management | Employment purposes; performance of the Company's business |
| Device and push data (mobile app) | Installation/device identifier, device model, OS version, app version, push notification token, last-seen time | Your device when you sign in on the mobile app | Deliver notifications (approvals, to-dos); let you sign out lost devices | Employment purposes; consent for notifications (you can turn them off in device settings) |
| Business records you create | Expense entries and amounts, payment requests, material requests and receipts, task progress and quantities, to-dos, equipment fuel entries, approvals, comments and pins on drawings | You | Running the Company's projects; accounting | Employment purposes; the Company's legal and accounting obligations |
| Audit log | Action name, entity, time, your user ID and IP address for security-relevant actions (login, punch, approvals, deletions, exports, settings changes) | Server | Security, accountability, investigation of disputes | Security and accountability obligations of the fiduciary |
| Party data (third parties) | Name, phone number, type (supplier, contractor, worker, client), ledger balances, ratings | Entered by users | Manage vendors, labour and clients | The Company's business purposes; the user entering the data is responsible for having a lawful basis |
The platform does not collect: contacts, calendar, microphone audio, browsing history, health or motion/fitness data, financial account numbers of users, advertising identifiers, or any data for advertising or analytics. Location tracking (section 6.3) is off for every account unless a Company administrator switches it on for that member. The Operator does not use any of the above for its own purposes, does not build profiles across Companies and does not sell data.
3.1 If you are outside India
The platform is hosted in India and Companies using it operate in India. If a user is temporarily located in a jurisdiction with GDPR-style law, equivalent rights are honoured: access, rectification, erasure, restriction, portability of data you provided, objection to processing based on legitimate interests, and the right to complain to a supervisory authority. The lawful bases above map to "performance of the employment contract", "legitimate interests of the employer" and "explicit consent" (for facial images) respectively. Background location tracking (section 6.3) rests on your Company's legitimate interest in managing its vehicles and the safety of its staff, limited by the safeguards in that section (transparency in the app, a visible indicator, 90-day retention, admin-only access, no use for advertising); you may object, in which case your Company will consider whether tracking must stay on for your role. Contact the privacy contact in section 1 to exercise these rights; requests that need your Company's decision are passed to its administrator.
4. Third-party data entered by users
Users record information about vendors, labour contractors, workers and clients. For that data your Company is the fiduciary and the user entering it acts on the Company's behalf. Users must enter only what is needed for the work (name, phone, type, amounts) and must not upload identity documents of third parties unless their Company has instructed it for a lawful purpose. Third parties may contact the privacy contact in section 1 to ask what is held about them; the request is routed to the Company whose workspace holds the record.
5. Face data: how attendance verification works
This section is deliberately specific because facial images are sensitive.
- What is collected. During enrolment you (or an administrator, with you present) take up to three photographs of your face. The server computes a numeric template (a vector of numbers) from each image using a face-recognition model and stores both the image and the template. Each attendance punch also captures one selfie.
- What it is used for. Solely to check that the person punching attendance is the enrolled user. At each punch the server compares the selfie template with your enrolled templates and records a match result and a similarity score. The punch is accepted only if the face matches and the phone is within the project's attendance radius. Rejected attempts are also recorded, with the reason, so that your Company can audit attendance.
- Where it is processed. Entirely on the platform's own infrastructure: a self-hosted open-source face-recognition service (InsightFace) running on the Operator's server in India (AWS Mumbai, ap-south-1, or an equivalent Mumbai-region provider, see section 8). Images are stored in a private object-storage bucket in the same region. No image, template or selfie is sent to any third-party face-recognition or cloud AI service. Photos are not public and are never shared by link. Face templates are compared only against the enrolled templates of the same user in the same Company; they are never matched across Companies.
- What it is not used for. No identification of people other than the enrolled user, no searching of external databases, no emotion or demographic inference, no use for advertising, no sharing with anyone outside your Company (except the Operator and its hosting provider as processors, section 8).
- Who can see it. You can see your own enrolment photos and punch selfies. Your Company's administrators and users whose role includes attendance management can view punch records and selfies for the projects they manage. Nobody in any other Company can.
- Control. You can delete any enrolled photo yourself in the app (Me > Face). Deleting all photos disables face punch for you; an administrator can re-enrol you. On account deletion (section 10) all enrolment photos, templates and punch selfies are deleted.
- Device biometrics are different. If you turn on the optional app lock (Face ID / Touch ID / Android biometrics), that uses your phone's own biometric system. The app receives only a yes/no result and never receives or stores your device biometric data.
6. Location
The app uses location in three different ways. Sections 6.1 and 6.2 apply to everyone; section 6.3 applies only to members for whom a Company administrator has switched on tracking.
6.1 Attendance punch and photo geo-tag (foreground only)
- Location is read at the moment you tap Punch In / Punch Out, and optionally when you upload a site photo so that it can be geo-tagged.
- The punch record stores the GPS coordinates, reported accuracy, and the computed distance from the project site. Your Company's administrators can see this for the projects they manage.
- You can refuse the location permission; in that case attendance punch will not work and you must ask your supervisor to mark your attendance manually.
6.2 Driver mode attendance (selfie from anywhere)
- A Company administrator can put a member in driver mode. In driver mode you mark attendance once a day with a selfie, from wherever you are; the punch is not tied to a project site and there is no geofence check. Face verification (section 5) still applies.
- Driver mode is used for vehicle drivers and other staff whose work is not at one site. Your administrator tells you if your account is in driver mode; the punch screen also shows it.
- If location tracking (6.3) is on for you, your position is recorded separately by that feature, not by the punch.
6.3 Background location tracking ("Track location")
This section is deliberately specific because background tracking is intrusive and you should know exactly what happens.
- Who is tracked. Only members for whom an administrator of their own Company has switched the "Track location" setting on (Settings > Members). It is off by default. It is intended for drivers of Company vehicles and for staff whose role the Company decides needs it. The decision to track, and the policy on tracking hours, are your Company's; the Operator never switches tracking on.
- What is collected. Your precise position (latitude, longitude), reported accuracy, speed, heading, the time of the fix, your phone's battery level, whether the operating system reported a mock/fake location, your device identifier, and the Company vehicle assigned to you at that moment.
- When and how often. The mobile app sends a point roughly every 2 hours (your Company can change this interval; the default is 120 minutes), plus one fix each time you open the app and each time you mark attendance, using the phone's balanced (battery-saving) accuracy mode. It is not minute-by-minute tracking: between points your Company sees only your last reported position. It runs in the background as well as in the foreground: while the app is installed, background location permission ("Allow all the time" on Android, "Always" on iPhone) is granted and tracking is on for you, points keep being sent on that schedule, including outside working hours, unless your Company switches tracking off for you or tells you that tracking is limited to working hours. Your Company's written notice to you (see "Notice" below) states which applies.
- How you can tell. While tracking is running, your phone shows a persistent notification ("SmartSite: Sharing your location with your company") on Android, and the system background-location indicator on iPhone. The app's Me screen shows whether tracking is on for your account and whether the phone is currently reporting. Tracking is never hidden.
- Who sees it. Your Company's administrators and users of your Company whose role includes the location/vehicle tracking permission. They see a map with the last reported position of tracked members and Company vehicles, and day trails: the points recorded that day joined into a route, with distance travelled and stops, linked to the vehicle assigned to you that day. Only your Company sees this; it is never visible to other Companies on the platform, never shared outside your Company, never sold and never used for advertising. The Operator does not view location data except as needed to operate and support the platform on your Company's instruction.
- Map tiles. The map in the administrator's browser draws its background map from OpenStreetMap (section 8). The mobile app does not contact OpenStreetMap and your location points are not sent to it.
- Where it is stored. On the platform's server and database in India (section 8), in your Company's workspace, like all other app data.
- How long. Location points are kept for 90 days from the time they were recorded and are then deleted automatically; day trails, distances and stops are computed from the points and disappear with them. They are deleted earlier if your account is deleted (section 10). Vehicle assignment records (which vehicle, from, to) are equipment records and are kept with the vehicle's history.
- Notice and agreement. Before tracking starts on your device the app shows you a notice explaining the above and asks you to agree; only then does it ask the operating system for background location permission. Your Company also informs tracked members in writing (or in the app) when tracking is enabled for them and what its policy on tracking hours is.
- How to turn it off. Ask your administrator to switch "Track location" off for your account; tracking stops on the next check-in of the app. You can also withdraw the background location permission in your phone's settings or uninstall the app, which stops the phone from reporting; your Company will see that reporting has stopped. If your role requires tracking while on duty, turning it off during duty hours is a matter between you and your Company under the Terms of Use, not something the app enforces beyond recording the gap.
- What it is not used for. No advertising, no profiling for purposes unrelated to work, no sharing with third parties, no sale, no use to infer health, religion or any other sensitive category. Speed is recorded as reported by the phone's GPS; your Company may use it in relation to vehicle use and safety.
7. Photos, camera and files
- The camera is used for attendance selfies (front camera) and for site, invoice, drawing, material and fuel photos (back camera). Photos are uploaded to your Company's private storage on the platform; they are resized on the server and stored with the record they belong to.
- On the mobile app you may also pick an existing photo from your gallery for an invoice or site photo. The app uses the system photo picker and does not read your gallery in bulk.
- Every file download goes through the server and is checked against your Company membership and role. Files are never public and no public links are generated.
8. Sharing and processors
Personal data is not sold, rented or shared with third parties for their own purposes. The only recipients are:
| Recipient | Role | What they receive | Location |
|---|---|---|---|
| The Operator (section 1) | Data processor for your Company (or the same entity as your Company where it self-hosts): runs the platform, applies security, retention and support | All data in your Company's workspace, processed only to provide the service on your Company's instructions | India |
| Hosting provider of the Operator: Amazon Web Services (AWS) Mumbai (ap-south-1) or an equivalent Indian-region cloud provider (<<FILL: provider actually used, e.g. AWS ap-south-1 or Oracle Cloud ap-mumbai-1>>) | Sub-processor: virtual server, object storage, encrypted backups | All app data, at rest on the Operator's instance and bucket; the provider does not access it for its own purposes | Mumbai, India |
| Apple Push Notification service (APNs) | Push delivery for the iOS app | Push token and the notification text (short, non-sensitive, for example "1 approval pending") | Apple's infrastructure |
| Firebase Cloud Messaging (FCM) / Google Play services | Push delivery for the Android app | Push token and notification text as above | Google's infrastructure |
| Apple and Google | App distribution platforms | Standard platform data (app install, crash reports if you enabled them in your OS settings) governed by their policies | Their infrastructure |
| OpenStreetMap Foundation (third-party map tiles, administrators' browsers only) | Provides the background map images (tiles) for the vehicle map | When a Company administrator opens the vehicle map in the web app, their browser requests map tiles directly from tile.openstreetmap.org. OpenStreetMap receives the administrator's IP address, browser user-agent and the coordinates of the map tiles being viewed (which reveal the general area being looked at). No tracked person's identity or location points are sent; the points are drawn on top of the tiles from the platform's own server. The mobile app never contacts OpenStreetMap. Governed by the OpenStreetMap Foundation's privacy policy. | OpenStreetMap Foundation's infrastructure (outside India) |
There are no analytics SDKs, advertising SDKs, crash-reporting SDKs, social logins or other third-party components in the app. The OpenStreetMap tile request above is the only third-party service contacted by a browser while using the web app, and only on the administrators' map pages. Data may be disclosed to authorities where Indian law requires it; the Operator informs the affected Company unless the law prohibits it.
9. Security measures
- HTTPS (TLS) for every connection; HSTS enforced. The mobile app talks only to the platform's server over HTTPS.
- Passwords hashed with Argon2; session tokens stored hashed; sessions expire after 30 days; account locks after 10 failed logins; rate limits on login and punch.
- Server-side authorisation on every request, scoped to your Company, project and role; no cross-Company access at any role level.
- Private object-storage bucket with public access blocked and server-side encryption; database backups nightly, encrypted at rest, retained 30 days.
- Security headers (CSP, frame-ancestors none), input validation, parameterised database queries, upload type and size validation.
- Audit log of security-relevant actions.
- Access to the production server limited to the Operator's technical administrators over SSH with key authentication.
No system is perfectly secure. If the Operator learns of a breach affecting your personal data it will notify your Company without undue delay, and the Operator and your Company will notify you and the Data Protection Board of India as required by the DPDP Act.
10. Retention
Retention periods are built into the platform and applied uniformly for every Company; the clean-ups run automatically.
| Data | Retained for | Then |
|---|---|---|
| Face enrolment photos and templates | While your account is active | Deleted when you remove them, when an administrator removes them, or on account deletion |
| Punch selfies | While your account is active | Deleted on account deletion (the punch row itself is kept without the selfie, see below) |
| Session records | 30 days from creation or until logout | Deleted |
| Device and push records | While the device is signed in | Deleted on sign-out, device removal or account deletion |
| Location tracking points (section 6.3), including derived day trails, distances and stops | 90 days from the time each point was recorded | Deleted automatically by a daily clean-up; deleted immediately on account deletion |
| Vehicle assignment records (which vehicle, from/to dates) | Life of the vehicle's record in the equipment register | Kept as an equipment record; your name is replaced by "Deleted user" on account deletion |
| Attendance rows, expense entries, material, fuel, task and approval records | Duration of the project plus the period required by Indian accounting and tax law (currently up to 8 years) | Kept as your Company's business records; your name is replaced by "Deleted user" on account deletion |
| Invoice and site photos | Same as the business record they belong to | Kept as business records; not linked to a deleted user |
| Audit log | Up to 24 months | Deleted or anonymised |
| Database backups | 30 days rolling | Overwritten; deletions propagate as backups age out |
If your Company stops using the platform, its workspace data is handed over to it or deleted on its instruction, as agreed between the Company and the Operator; deleted data ages out of backups within 30 days.
11. Your rights and how to exercise them
Under the DPDP Act 2023 (and equivalent laws where applicable) you have the right to:
- Access: obtain a summary of the personal data held about you and how it is processed.
- Correction and completion: fix inaccurate data (most profile data can be edited in the app under Me).
- Erasure: request deletion of your personal data. Use Me > Request account deletion in the app (web or mobile), or email karang@sgfinfra.com from any address with your registered phone number. See
/delete-accountfor what is deleted and what is retained. - Withdraw consent / object: for face verification, delete your enrolled photos in the app; for notifications, disable them in device settings; for location tracking, ask your administrator to switch "Track location" off for you, or withdraw the background location permission in your phone's settings (section 6.3). Withdrawal does not affect processing already done, and may mean that some functions (face punch, driver duties that require tracking) are no longer available to you.
- Grievance redressal: contact the Grievance Officer named in section 1. We acknowledge within 2 working days and respond within 30 days, involving your Company where the decision is its to make. If you are not satisfied you may approach the Data Protection Board of India.
- Nominate: under the DPDP Act you may nominate a person to exercise these rights in the event of death or incapacity; write to the privacy contact.
Requests are verified against the registered phone number before they are actioned. Requests that require a decision by your Company as fiduciary (for example whether tracking stays on for your role, or whether a business record is retained) are forwarded to your Company's administrator, and you are told the outcome.
12. Cookies and local storage
- The web app sets one strictly necessary cookie (httpOnly, secure) to keep you signed in. No tracking or advertising cookies.
- The web app's service worker caches app pages and static assets on your device for faster loading. The mobile app stores the session token in the device's secure keychain/keystore and a small local cache of recent data.
13. Changes to this policy
Any change is posted here with a new effective date and version. For material changes (new data category, new recipient, new purpose) users are notified in the app before the change takes effect, and Companies are notified so they can update their own staff notices. Version 1.1 restates the roles of the Operator and the Company for a platform used by several Companies; the data practices (background location tracking in section 6.3, driver mode in section 6.2, the OpenStreetMap map tiles in section 8, retention in section 10) are unchanged from version 1.0.
14. Contact
Operator: SGF Infra Private Limited, <<FILL: address>>
Privacy contact / Grievance Officer: Karan Gupta, karang@sgfinfra.com, <<FILL: phone>>
Your Company's administrator: ask your office or project manager.
Support: see /support.