1. Scope and roles
Staff is a workforce and HR management service. A Business account manages its own employee workspace. For employee HR information, the Business using Staff generally determines why the information is processed; the site operator provides and administers the Staff service. This policy covers the Staff Android application and the connected Staff web portal.
2. Information we process
- Account and identity data: name, username, email address, phone number, employee number, profile image, role and account identifiers.
- Employment and HR data: department, position, manager, hire/employment details, attendance, leave, payroll information, projects, tasks, equipment assignments, notes and other records entered by the Business or Employee.
- Attendance data: check-in, check-out and break events, including QR-based attendance actions.
- Location data: the Employee device may provide current coordinates while the Employee is marked Present at work. Location updates are not requested while on break or while not checked in. Staff stores only the latest reported coordinate for the live-location feature; it does not maintain a route/location-history log.
- Photos and files: profile photos and photos voluntarily submitted to document equipment condition.
- Push-notification data: Firebase Cloud Messaging (FCM) device registration tokens used to deliver Staff notifications.
- Device/app interaction data: authentication/session information and technical information normally processed by the WordPress/web server, such as request time, IP address and browser/app user agent, where available in server logs.
3. Device permissions and sensitive features
- Location: used for the live employee-location feature while the Employee is Present at work.
- Camera: used when scanning attendance QR codes.
- Photos/media: used when the user deliberately chooses a profile or equipment-condition image.
- Notifications: used to deliver work-related alerts, such as leave, task, attendance or equipment updates.
- Staff does not use these permissions for advertising. Permission availability can be controlled through Android settings; disabling a permission can prevent the related feature from working.
4. Why we use information
- Authenticate users and keep accounts signed in securely.
- Provide employee, attendance, leave, payroll, project, task and equipment functions.
- Show live/last-known employee location to the authorized Business while the live-location feature is active.
- Send operational and HR notifications.
- Allow employees and managers to update work records and provide evidence such as equipment-condition photos.
- Maintain security, prevent abuse, diagnose errors and protect tenant separation between Businesses.
- Meet legal, employment, accounting or record-keeping obligations applicable to the Business or service operator.
5. Sharing and service providers
Staff does not sell personal information and does not use employee information for third-party advertising.
- Firebase Cloud Messaging / Google: receives the information necessary to route push notifications, including a device registration token and privacy-minimized notification payload.
- OpenStreetMap tile servers: map tiles may be requested when a map is displayed. The tile provider can receive ordinary web-request information such as IP address and user agent. Employee coordinates are handled by Staff; map rendering may necessarily request tiles for the viewed area.
- Hosting and infrastructure providers: the WordPress host, network and related infrastructure process data as necessary to operate the service.
- Authorized Business users/managers: information is shown according to Staff roles and permissions.
- Information may also be disclosed when required by law, to protect rights/security, or in connection with a lawful organizational transfer.
6. Location-data safeguards
Live location is an attendance-related feature, not continuous background tracking. The current architecture updates location only while the app is open/active enough to provide the update and the Employee is Present at work. Staff does not intentionally collect location while the Employee is on break or not checked in. Only the latest location value is retained by the live-location module and is replaced by a newer update.
7. Data retention
HR and employment records are retained for as long as the relevant Business account needs them for workforce administration and any applicable legal or record-keeping requirements. FCM device tokens are removed when revoked, replaced, logged out where supported, or otherwise cleaned up. The live-location module retains only the latest coordinate rather than a location history. Uploaded images and equipment-history evidence may be retained with the related employment/equipment record until deleted under the Business retention process. Server backups or logs may persist for a limited additional period according to the hosting provider’s backup/security schedule.
8. Security
Staff uses role-based access, tenant separation, WordPress authentication/nonces, permission checks, encrypted storage for configured Firebase service credentials, and other application/server safeguards. No internet or storage system can be guaranteed 100% secure, so users should protect their credentials and promptly report suspected unauthorized access.
9. Your choices and rights
Depending on applicable law and the relationship with the employing Business, users may have rights to access, correct, delete, restrict or object to processing of personal information, or request a copy of certain data. Employees should normally contact their Business/employer for HR-record requests. Users may also contact the site operator using the details below for account or service-level privacy requests. Android permissions can be changed in device settings.
10. Account and data deletion
A user who wants an account or associated personal data deleted should contact the Business administrator or the site operator using the contact information below. Requests are verified before deletion. Some information may need to be retained where required for legal, payroll, accounting, employment, security or dispute-resolution purposes.
11. International processing
Service providers such as hosting providers or Firebase may process information in countries other than the user’s country. Where applicable, the Business and service operator should use appropriate contractual or legal safeguards for such transfers.
12. Children
Staff is a workplace/HR application and is not designed as a consumer service for children. Business administrators are responsible for ensuring that accounts and employee records are created and used lawfully for their workforce.
13. Changes to this policy
This policy may be updated when Staff features, service providers or legal requirements change. The effective date at the top of this page will be updated when material changes are published.
Contact and privacy requests
For privacy questions, access/correction requests, or account/data deletion requests, contact the site operator:
Burhan Selmani
hi@burhanselmani.com
https://burhanselmani.com/