Staff mobile app & web workspace

Privacy Policy

Effective date: 15 August 2026

This Privacy Policy explains how Staff processes information when businesses and employees use the Staff mobile application and connected web workspace.

1. Scope and roles

Staff is a workforce and HR management service. A Business account manages its own employee workspace. For employee HR information, the Business using Staff generally determines why the information is processed; the site operator provides and administers the Staff service. This policy covers the Staff Android application and the connected Staff web portal.

2. Information we process

3. Device permissions and sensitive features

4. Why we use information

5. Sharing and service providers

Staff does not sell personal information and does not use employee information for third-party advertising.

6. Location-data safeguards

Live location is an attendance-related feature, not continuous background tracking. The current architecture updates location only while the app is open/active enough to provide the update and the Employee is Present at work. Staff does not intentionally collect location while the Employee is on break or not checked in. Only the latest location value is retained by the live-location module and is replaced by a newer update.

7. Data retention

HR and employment records are retained for as long as the relevant Business account needs them for workforce administration and any applicable legal or record-keeping requirements. FCM device tokens are removed when revoked, replaced, logged out where supported, or otherwise cleaned up. The live-location module retains only the latest coordinate rather than a location history. Uploaded images and equipment-history evidence may be retained with the related employment/equipment record until deleted under the Business retention process. Server backups or logs may persist for a limited additional period according to the hosting provider’s backup/security schedule.

8. Security

Staff uses role-based access, tenant separation, WordPress authentication/nonces, permission checks, encrypted storage for configured Firebase service credentials, and other application/server safeguards. No internet or storage system can be guaranteed 100% secure, so users should protect their credentials and promptly report suspected unauthorized access.

9. Your choices and rights

Depending on applicable law and the relationship with the employing Business, users may have rights to access, correct, delete, restrict or object to processing of personal information, or request a copy of certain data. Employees should normally contact their Business/employer for HR-record requests. Users may also contact the site operator using the details below for account or service-level privacy requests. Android permissions can be changed in device settings.

10. Account and data deletion

A user who wants an account or associated personal data deleted should contact the Business administrator or the site operator using the contact information below. Requests are verified before deletion. Some information may need to be retained where required for legal, payroll, accounting, employment, security or dispute-resolution purposes.

11. International processing

Service providers such as hosting providers or Firebase may process information in countries other than the user’s country. Where applicable, the Business and service operator should use appropriate contractual or legal safeguards for such transfers.

12. Children

Staff is a workplace/HR application and is not designed as a consumer service for children. Business administrators are responsible for ensuring that accounts and employee records are created and used lawfully for their workforce.

13. Changes to this policy

This policy may be updated when Staff features, service providers or legal requirements change. The effective date at the top of this page will be updated when material changes are published.

Contact and privacy requests

For privacy questions, access/correction requests, or account/data deletion requests, contact the site operator:

Burhan Selmani
hi@burhanselmani.com
https://burhanselmani.com/

← Back to Staff

Staff · Privacy Policy