Back to home

Legal

Privacy Policy

This policy describes how Forcefield handles personal information in the Android mobile app and the web dashboard. It is published to meet transparency requirements for workforce apps, including Google Play's Privacy, Deception and Device Abuse policies.

Last updated: May 26, 2026

1. Introduction

Forcefield ("we", "us", or "our") provides a workforce and field-operations platform made up of the Forcefield mobile application (Android) and the Forcefield web application (dashboard and APIs).

This Privacy Policy explains what personal information we process, why we process it, how it is shared, and what choices you have. It applies to field employees who use the mobile app and to managers and administrators who use the web dashboard.

Forcefield is typically deployed by your employer. In most cases your employer is the data controller for employment-related data, and Forcefield processes that data on your employer's instructions to deliver attendance, location, task, and approval features.

2. Information we collect

Depending on your role and how your organization configures Forcefield, we may collect:

  • Account and profile data: name, work email, employee identifier, role (for example field employee, manager, or administrator), and organization membership.
  • Authentication data: credentials and session tokens managed through our authentication provider (Supabase Auth).
  • Attendance and shift data: check-in and check-out times, site assignments, attendance state, swipe events, checkout reasons, travel requests, and related approval records.
  • Precise location data: GPS coordinates, accuracy, speed, and timestamps while you are checked in or otherwise in an active tracked work session. Location may be collected in the background on mobile devices (including when the app is not in the foreground) so that geofencing, live map visibility, and time-on-site records remain accurate.
  • Device and connectivity data: device identifiers used for device binding, app version, sync history, connectivity or offline events, and diagnostic signals used to support reliable field operations.
  • Task and workflow data: assigned tasks, task sessions, site or travel context, and notes submitted through the product.
  • Usage and technical data: server logs, API request metadata, and product analytics from our hosting providers (for example Vercel Analytics and Speed Insights on the website) to maintain security and performance.

3. How we use information

We use personal information to:

  • Provide check-in, check-out, geofence validation, and attendance records.
  • Display live and historical location to authorized managers within your organization.
  • Run approval workflows (for example early checkout, travel, or checkout purposes).
  • Operate background location capture and batch upload according to your organization's tracking settings.
  • Bind mobile devices to employee accounts where device binding is enabled.
  • Send in-app or push-related notifications for operational events your organization enables.
  • Maintain audit trails, security, fraud prevention, and troubleshooting.
  • Comply with law and respond to lawful requests.

4. Background location (important)

The Forcefield mobile app requests access to precise location, including background location on Android, because field attendance and live workforce visibility depend on GPS while you are on an active work session.

Location collection is intended to be active only while you are checked in or in another tracked work state defined by your organization. When you check out, tracking is designed to stop. Your organization may also configure capture intervals, batch uploads, geofence auto-checkout, and related policies.

Managers authorized by your organization may view your live position and location history on the dashboard live map and related attendance views.

You can control OS-level location permission in device settings. Denying location permission may prevent check-in, accurate attendance, or other features required by your employer's policies.

5. Legal basis

Where applicable privacy law requires a legal basis, we rely on one or more of the following: performance of an employment or service contract, legitimate interests of your employer in managing field operations (balanced against your rights), compliance with legal obligations, and your consent where required (for example acknowledging location monitoring before permissions are requested on mobile).

6. How information is shared

We do not sell your personal information. We share information only as needed to operate the service:

  • Within your organization: managers, administrators, and other roles your employer authorizes can access attendance, location, tasks, devices, and approvals according to role-based access controls.
  • Service providers: hosting, database, authentication, maps/geocoding, email, and analytics providers that help us run Forcefield (for example Supabase, Vercel, and Google Maps when configured). These providers process data under contractual safeguards.
  • Legal and safety: when required by law, to protect rights and safety, or to enforce our terms.
  • Business transfers: in connection with a merger, acquisition, or asset sale, subject to appropriate notice where required by law.

7. Data retention

We retain personal information for as long as your employer's account is active and as needed to provide the service, meet employment-record obligations, resolve disputes, and comply with law.

Retention periods for location history, attendance logs, and audit data are determined by your organization's policies and applicable law. Contact your employer for organization-specific retention schedules.

8. Security

We use technical and organizational measures designed to protect personal information, including encrypted transport (HTTPS), authenticated access, row-level security in the database, and role-based authorization in the application.

No method of transmission or storage is completely secure. If you believe your account has been compromised, contact your employer's administrator immediately.

9. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port personal information, or to object to certain processing.

Because your employer usually controls workforce data, many requests should be directed to your employer's HR or administrator. We will assist your employer in responding where we act as their processor.

You may also contact us using the details in Section 14 for product-related privacy questions.

10. Device permissions

The mobile app may request the following permissions:

  • Location (precise, foreground and background): attendance, geofencing, and live map features.
  • Notifications: operational alerts such as approvals or auto-checkout prompts where enabled.
  • Internet and network access: sync with your organization's Forcefield backend.
  • Foreground service (Android): continue lawful background location capture while checked in, with a visible ongoing notification where required by the OS.

11. Children's privacy

Forcefield is intended for workforce use and is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children.

12. International transfers

Your information may be processed in countries other than where you work, including where our service providers host infrastructure. Where required, we use appropriate safeguards for cross-border transfers.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Material changes may also be communicated through the app or your employer where appropriate.

14. Contact us

For workforce data requests (access, correction, deletion): contact your employer's administrator or HR team first.

For privacy questions about the Forcefield product: email Appdesk@bbtechsol.com.

Public policy URL: https://geoforcefield.vercel.app/privacy