This application collects your device's precise GPS location in the background.
Background location collection occurs only while an active work session is running — that is, after you have authenticated and pressed "Start Day" in the application. A persistent notification titled "Italica Tracking Active" is displayed at all times while background location collection is active.
Background location is used exclusively for:
Background location is never sold, used for advertising, shared with third-party advertisers, or used outside the scope stated in this policy.
You can stop background location collection at any time by pressing
"End Day" in the application, or by revoking the
ACCESS_BACKGROUND_LOCATION permission in your device Settings.
This Privacy Policy applies to the Italica mobile application
("the App"), package identifier com.italica.app,
operated by Italica Group of Companies
("Italica", "we", "us", or "our").
The App is an enterprise field force management application. It is intended solely for authorised employees of Italica Group — including field sales representatives, coordinators, and management staff. It is not a consumer application and is not available to the general public.
All data collected through the App is used exclusively for authorised internal business operations of Italica Group. By using this App, you confirm that you have read and understood this Privacy Policy and agree to the collection and use of information as described herein.
When the App is open and active, we collect your device's precise GPS coordinates (latitude and longitude) for the following purposes:
This requires the ACCESS_FINE_LOCATION Android permission.
Precise location data is a sensitive data type under Google Play's
User Data Policy and is handled accordingly.
When you have started an active work session by pressing "Start Day", the App continues to collect your precise GPS location even when the App is not visible in the foreground. This background collection serves the following purposes:
Background location collection requires the ACCESS_BACKGROUND_LOCATION
Android permission, which you must explicitly grant. A persistent foreground service
notification is displayed at all times while background collection is active
(see Section 7).
The App requests the following Android permissions. All sensitive permissions are requested at runtime. You have the right to grant or deny each permission individually. See Section 12 for the effect of denying permissions.
| Permission | Reason Required |
|---|---|
ACCESS_FINE_LOCATION |
Precise GPS coordinates (latitude/longitude) for visit geo-stamping, start/end day location recording, and distance calculation during an active work session. |
ACCESS_COARSE_LOCATION |
Approximate location used as a fallback when precise GPS is temporarily unavailable. |
ACCESS_BACKGROUND_LOCATION |
Continuous GPS route collection while the App is not in the foreground, during an active work session. Required to record your route, verify visits, and calculate distance when you switch to other apps. A persistent notification is displayed whenever this permission is actively being used. This permission is only requested after an explicit in-app disclosure screen. |
FOREGROUND_SERVICE_LOCATION |
Declares that the App's location foreground service is of type "location" as required by Android API 34+. This is the technical mechanism that enables the persistent tracking notification and complies with Android's foreground service policy. |
FOREGROUND_SERVICE |
Runs the location foreground service with a visible persistent notification while work-day GPS tracking is active. |
CAMERA |
Capturing photos to attach to visit records, expense receipts, and product catalogue entries. |
READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE |
Selecting existing images from your device photo library to attach to visit or expense records. (Specific permission varies by Android version.) |
INTERNET |
Connecting to Italica's secure backend services (Supabase Auth, ERP proxy) for authentication, data synchronisation, and file uploads. |
Note: The exact set of permissions is declared in the App's
AndroidManifest.xml. Only permissions directly related to personal data
collection are listed above. All permissions are used solely for the purposes stated.
ACCESS_FINE_LOCATION; background collection additionally
requires ACCESS_BACKGROUND_LOCATION)All three conditions must be met simultaneously. The App does not collect location data passively, automatically on launch, or without a deliberate user action to start a work session.
Collected while the App is open and visible on screen. Used for visit geo-stamping, map display within the App, and recording start/end day GPS coordinates.
Collected while an active work session is running, even if you navigate away from the App or lock your device. A persistent notification (see Section 7) is displayed at all times during background collection. Background collection stops immediately when you press "End Day" or revoke background location permission.
Your name, email, and credentials authenticate you to the App and control access to data relevant to your assigned role, territory, and zone.
Your Start Day and End Day timestamps and GPS coordinates are recorded to document daily attendance. This data is used for payroll, HR records, workforce management, and compliance purposes.
GPS coordinates collected during your active work session are used to reconstruct your daily travel route. This route record is visible to authorised managers and administrators for field team oversight and territory management.
Total distance travelled during your work session is calculated from sequential GPS route data. This calculated distance is used to determine travel expense reimbursement amounts and pre-populate expense report fields.
When you log a customer or dealer visit in the App, your GPS coordinates at that moment are recorded and compared against the registered address of that customer or dealer. This geo-verification confirms that the visit was conducted at the correct location and attaches a location stamp to each visit record.
GPS-derived distance data pre-populates travel distance fields in expense reports. Receipt photos are stored and linked to expense records for audit purposes.
Customer visit records, lead visit records, and sales orders are associated with your employee account for CRM reporting, lead management, and sales performance tracking by authorised management.
Your zone assignment is used to display relevant products in the catalogue. No GPS or location data is used for product catalogue access.
Device model, OS version, and app version are used for debugging, compatibility testing, and providing technical support.
The App uses Android's standard runtime permission system. Permissions are requested only when needed and only for the purposes stated in this policy.
ACCESS_BACKGROUND_LOCATION, the App displays a dedicated
in-app disclosure screen that clearly states:
(a) the App accesses location in the background,
(b) this only occurs during an active work session,
(c) a persistent notification will always be shown, and
(d) the specific purposes for which background location is used.
You must explicitly acknowledge this disclosure before the Android system permission
dialog is presented. You may decline background location, which will disable route
tracking and background visit verification but will not prevent you from using
other App features.
Your authenticated use of the App, combined with granting the relevant permissions and actively initiating a work session, constitutes your ongoing consent to data collection as described in this policy.
This is an employer-managed enterprise application. Italica Group of Companies, as your employer, operates this App to manage field force activities. The following monitoring activities are conducted as part of normal workforce management and are authorised under your employment agreement:
This monitoring is not covert. Every employee using this App:
This application complies with Google Play's Device and Network Abuse Policy requirements for monitoring applications. It is not spyware, consumer surveillance software, parental monitoring software, or a hidden tracking application.
The App uses an Android Foreground Service to maintain reliable GPS tracking during an active work session. This is Android's approved mechanism for applications that legitimately require continuous background location access. The foreground service ensures that you are always aware that location tracking is occurring.
Whenever the foreground location service is running, a persistent notification is displayed. This notification:
The App declares FOREGROUND_SERVICE_LOCATION as required by Android API
level 34 and above. This permission confirms to the Android system that the foreground
service accesses location, ensuring proper system behaviour, power management disclosure,
and user transparency.
| Role | Data They Can Access |
|---|---|
| You (Employee) | Your own attendance records, visit logs, GPS routes, expense entries, orders, and CRM activity. |
| Manager / Coordinator | Attendance, visit records, GPS routes, and expense entries for employees in their assigned zone or state team. |
| HR / Admin | All employee records for HR, payroll, compliance, and management reporting purposes. |
| IT / System Administrator | System-level access for maintenance and security operations, governed by Italica's internal access control policies. |
| Third Parties | None. Infrastructure service providers (Supabase, AWS) process data strictly per our instructions as data processors and do not access it for their own purposes. See Section 11. |
All personal data is protected by the following technical measures:
While Italica implements strong security measures to protect your data, no digital system is completely immune to security risks. In the event of a data breach that affects your personal data, we will notify affected individuals as required by applicable law.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data (name, email, credentials) | Duration of employment. Permanently deleted within 30 days of account deactivation. | Authentication, account management |
| GPS route data & location records | 12 months from date of collection, then permanently deleted. | Route verification, expense calculation, compliance |
| Attendance records (Start Day / End Day) | Duration of employment, plus up to 3 years after account closure for HR and payroll compliance. | HR records, payroll, legal compliance |
| Customer & dealer visit records | 3 years from the date of visit. | CRM history, business compliance |
| Expense records & receipt images | 7 years from the date of expense. | Financial audit and tax compliance requirements |
| Device information | Deleted within 30 days of account deactivation. | App support and compatibility |
Upon account deletion, personal identity data (name, email address) is permanently removed within 30 days. Business records may be retained in anonymised or aggregated form as required by applicable Indian law.
We share data only with the following service providers who are technically necessary to operate the App. Each provider acts as a data processor under our instruction and is contractually prohibited from using your data for their own purposes.
| Provider | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|
| Supabase | Authentication, user data storage, and file storage | Account data, GPS/location records, visit records, expense data, images | supabase.com/privacy |
| Amazon Web Services (AWS) | Cloud server infrastructure — Mumbai, India (ap-south-1) | All app data resides on AWS infrastructure (Supabase is hosted on AWS ap-south-1). Data does not leave India. | aws.amazon.com/privacy |
| Google Play Store | App distribution and update delivery only | No personal data from the App is shared with Google Play. | policies.google.com/privacy |
We do not:
You have the following rights regarding your personal data. To exercise these rights, contact us at the details provided in Section 16.
We will respond to all data rights requests within 30 days.
You can revoke any App permission at any time via: Settings → Apps → Italica → Permissions
| If You Revoke | Effect on the App |
|---|---|
| Foreground Location ( ACCESS_FINE_LOCATION) |
Visit geo-stamping, map display, start/end location recording, and all background tracking are disabled. GPS route tracking stops immediately. The foreground service will be stopped. |
| Background Location ( ACCESS_BACKGROUND_LOCATION) |
GPS route recording while the App is not in the foreground is disabled. Foreground location features (visit check-in geo-stamp while the App is open) continue to work if foreground permission is still granted. |
| Camera | Photo capture is disabled. You can still select images from your gallery. Previously uploaded photos are not affected. |
You may deny location permissions at any time. If location access is denied:
The following table summarises the data types declared in the Google Play Console Data Safety form for this application. This Privacy Policy is consistent with those declarations.
| Data Type | Collected | Encrypted in Transit | Shared Externally | User Can Request Deletion |
|---|---|---|---|---|
| Precise location | Yes | Yes (TLS 1.2+) | No | Yes |
| Coarse location | Yes (fallback) | Yes | No | Yes |
| Name | Yes | Yes | No | Yes |
| Email address | Yes | Yes | No | Yes |
| Photos / images | Yes | Yes | No | Yes |
| Financial info (expense records) | Yes | Yes | No | Yes |
| App interactions / usage data | Yes | Yes | No | Yes |
| Device identifiers (model, OS) | Yes | Yes | No | Yes |
| Advertising identifiers | No | — | — | — |
Data collected is used solely for App functionality. It is not collected for advertising, not shared with ad networks, not used for marketing profiling, and not processed by AI or machine learning systems.
This App is intended solely for authorised employees of Italica Group and is restricted to individuals 18 years of age or older. The App is not intended for, marketed to, or knowingly used by anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has gained access to this App, please contact us immediately at the details in Section 16.
We may update this Privacy Policy from time to time to reflect changes in the App's features, applicable law, or our data practices. When we make material changes, we will:
Continued use of the App after any changes to this policy constitutes your acceptance of the updated terms. We encourage you to review this policy periodically.
For privacy-related questions, data access requests, account deletion requests, or to report a security concern, please contact us:
We aim to respond to all privacy-related requests within 30 days of receipt.
This Privacy Policy has been prepared in compliance with: