VisitsTracker

VisitsTracker › Privacy

Privacy policy

What VisitsTracker records about a worker, who can see it, how long it is kept, and how to get a copy of it or have it deleted.

Last updated 13 August 202612 sections

Effective 12 August 2026. This policy covers the VisitsTracker mobile app (com.fieldproxy.sensenxt), the VisitsTracker web console, and the API behind both.

If you are a field worker using this app: your employer decides that you are tracked, when, and who in their organisation can see it. We run the software on their behalf. Everything held about you is visible to you inside the app under “Your tracking” — exact counts, the retention period, and every person who can currently see your location, by name. You can export all of it yourself from that screen.

1. Who is responsible for your data

VisitsTracker is sold to businesses, which deploy it to their own staff.

  • Your employer is the data controller. They decide who is tracked, what the collection hours are, how long records are kept, and who inside their organisation can see them.
  • We are the data processor. We store and process the data on their instructions and do not use it for our own purposes.

Questions about why you are tracked, or requests to stop, go to your employer. Questions about how the software handles data, and requests we can act on directly, come to us.

Operated by Fieldproxy Pvt Ltd, Chennai, India (TODO: full registered address and CIN). Contact: privacy@visitstracker.com.

2. What we collect

Location, and what travels with it

The mobile app records your device’s precise location, including while the app is closed, the screen is off, and after the phone restarts. It is captured about once a minute while you are moving and every five minutes while you are stationary, and uploaded to your employer’s workspace.

Each recorded reading also carries:

  • Its accuracy, your speed, heading and altitude, and the distance travelled since recording began.
  • Your phone’s battery level and whether it is charging.
  • Physical activity — whether your phone detects that you are walking, cycling, in a vehicle, or still. This is what the app uses to decide how often to record, and it is stored alongside the reading.
  • Whether the reading came from a mock-location tool, and an identifier for the device that sent it.

The app asks for these permissions only after showing you an in-app screen explaining them, and it never records before you accept.

Account and identity

  • Your name, and the email address or phone number you sign in with.
  • Which workspace you belong to, your role, and whether your seat is tracked.
  • A notification token for your device, if push messages are enabled.

Work records you create

  • Attendance punches, including where you were when you punched.
  • Visits to customer sites, derived from your location trail.
  • Job paperwork: outcomes, parts, notes, custom fields, photographs, attached files and signatures you capture.
  • Leave requests, expense claims and mileage claims.
  • SOS alerts you raise.

Device information

Handset model, operating system version, battery and power-saving state, and whether location services or mock-location tools are active. This is used to explain gaps in a record — a phone that was switched off is a different fact from a phone that was hidden.

What we do not collect

  • Your contacts, messages, call history, browsing, or other apps.
  • Your microphone or camera except when you take a photo or a signature in the app.
  • Any advertising identifier. The app contains no advertising or analytics SDK.

3. When location is and is not collected

  • Only while tracking is on. A persistent notification stays in your status bar for the whole time recording is active, and it cannot be swiped away. If it is not there, nothing is being recorded.
  • Only if your seat is tracked. Untracked seats — office and admin staff — are not collected from at all.
  • Within your workspace’s collection hours, if it has set any. When an employer configures collection hours, fixes recorded outside them are refused by the server and never stored. Workspaces are not required to set hours, and by default they have none — in that case location is collected whenever tracking is on, including outside your working hours. The app’s “Your tracking” screen tells you which applies to you.
  • Not after you sign out. Signing out stops recording and erases what the phone still holds, including fixes that had not yet uploaded.
  • Not after your employer stops it. Deactivating your account, untracking your seat, or a lapsed subscription stops collection at the server on the next upload.

4. Why we process it

PurposeWhat it uses
Verifying attendance and hours workedLocation, punches, device state
Recording and proving visits to customer sitesLocation, site data
Measuring mileage for expense and payroll purposesLocation trail
Producing dispute evidence when a record is challengedAll of the above, plus the edit history
Dispatching and routing workLocation, job and site addresses
Running the service: sign-in, notifications, support, billingAccount data, device token

Where the UK or EU GDPR applies, the employer’s lawful basis is normally their legitimate interest in verifying work performed and in operating payroll, balanced against your rights — a balance they are responsible for and must be able to explain to you.

We do not sell personal data, and we do not use it for advertising or to train machine-learning models.

5. Who can see it

  • You. The full record, in the app, at any time.
  • Named people in your employer’s workspace — managers, administrators and auditors your employer has granted access to. The “Who can see your location” screen lists every one of them by name, with the reason and, for a temporary grant, the date it lapses.
  • People your employer shares a link with, where they create a share link for a specific record. Those links expire.
  • Us, only as needed to operate and support the service, and our sub-processors below.

6. Sub-processors

We use these third parties to run the service. They act on our instructions and may not use the data for their own purposes.

ProviderWhat it handles
Microsoft Azure MapsMap tiles, and turning addresses into coordinates and coordinates into addresses. Requests are made by our servers, not by your phone.
Google (Firebase Cloud Messaging)Delivery of push notifications to your device.
Resend or PostmarkTransactional email: invitations, password resets, alerts.
StripeYour employer’s subscription billing. No worker location data is sent to Stripe.
Our hosting providerServers and database storage for the region your workspace runs in.

7. Where it is stored

Each workspace runs in one regional cell and its data stays there. Cells currently operate in the United Kingdom, South Africa, Australia & New Zealand, and India. Your employer chose the cell when they signed up; the app shows you which one you sign in to.

All traffic between the app and our servers is encrypted with TLS. Released builds of the app cannot send data over an unencrypted connection at all — the platform blocks it.

8. How long it is kept

  • Location fixes and work records: for the retention period your employer sets, 24 months by default. Older raw location is deleted. Your “Your tracking” screen shows the figure that applies to you.
  • Legal hold: an employer can suspend deletion for the workspace or for one person — for example while a dispute is live. When that is on, the same screen says so.
  • On your phone: the app keeps at most five days of recorded fixes locally so tracking survives a dead network, and erases them when you sign out.
  • Trials that are not converted are deleted within three weeks of expiry.
  • When a workspace closes, its data is purged on the schedule in the employer’s agreement.

9. Your rights

Depending on where you live you may have rights to access, correct, delete, restrict or object to the processing of your personal data, and to complain to a regulator.

  • Access and portability, immediately: “Your tracking” → Everything held about me exports the complete record as a ZIP, and My last 7 days exports a PDF. Neither needs anyone’s approval.
  • Correction: raise it with your employer, who can amend records. Amendments are recorded in an append-only history rather than overwriting what was there.
  • Deletion: because your employer is the controller, deletion requests go to them first — they may have payroll or legal obligations to retain records. If you cannot resolve it with them, write to privacy@visitstracker.com and we will help, and will act on a controller instruction to delete.
  • Withdrawing device permission: you can turn off location permission for the app in your phone’s settings at any time. Recording stops. Your employer will be able to see that it stopped.

10. Children

VisitsTracker is a workplace tool provided to employees and contractors. It is not directed at children and we do not knowingly collect data from anyone under 16.

11. Changes to this policy

If we change how data is handled in a way that affects you, we will update this page and change the effective date at the top. Where the change is material, workers will be asked to read the in-app disclosure again before recording continues.

12. Contact

privacy@visitstracker.com