Italica — Innovating Trends

Privacy Policy

Application: Italica Effective Date: 29 July 2026 Operator: Italica Group of Companies
⚠ Background Location Disclosure

This application collects your device's precise GPS location in the background.

Background location collection occurs only while an active work session is running — that is, after you have authenticated and pressed "Start Day" in the application. A persistent notification titled "Italica Tracking Active" is displayed at all times while background location collection is active.

Background location is used exclusively for:

Background location is never sold, used for advertising, shared with third-party advertisers, or used outside the scope stated in this policy.

You can stop background location collection at any time by pressing "End Day" in the application, or by revoking the ACCESS_BACKGROUND_LOCATION permission in your device Settings.

This Privacy Policy applies to the Italica mobile application ("the App"), package identifier com.italica.app, operated by Italica Group of Companies ("Italica", "we", "us", or "our").

The App is an enterprise field force management application. It is intended solely for authorised employees of Italica Group — including field sales representatives, coordinators, and management staff. It is not a consumer application and is not available to the general public.

All data collected through the App is used exclusively for authorised internal business operations of Italica Group. By using this App, you confirm that you have read and understood this Privacy Policy and agree to the collection and use of information as described herein.


1. Personal Data We Collect

1.1 Account & Identity Data

1.2 Precise Location Data — Foreground

When the App is open and active, we collect your device's precise GPS coordinates (latitude and longitude) for the following purposes:

This requires the ACCESS_FINE_LOCATION Android permission. Precise location data is a sensitive data type under Google Play's User Data Policy and is handled accordingly.

1.3 Precise Location Data — Background (Sensitive)

When you have started an active work session by pressing "Start Day", the App continues to collect your precise GPS location even when the App is not visible in the foreground. This background collection serves the following purposes:

Background location collection requires the ACCESS_BACKGROUND_LOCATION Android permission, which you must explicitly grant. A persistent foreground service notification is displayed at all times while background collection is active (see Section 7).

1.4 Attendance & Work Session Data

1.5 Route & Distance Data

1.6 Customer & Dealer Visit Records

1.7 Expense & Business Data

1.8 Camera & Image Data

1.9 Device Information

1.10 What We Do NOT Collect


2. Android Permissions

The App requests the following Android permissions. All sensitive permissions are requested at runtime. You have the right to grant or deny each permission individually. See Section 12 for the effect of denying permissions.

Permission Reason Required
ACCESS_FINE_LOCATION Precise GPS coordinates (latitude/longitude) for visit geo-stamping, start/end day location recording, and distance calculation during an active work session.
ACCESS_COARSE_LOCATION Approximate location used as a fallback when precise GPS is temporarily unavailable.
ACCESS_BACKGROUND_LOCATION Continuous GPS route collection while the App is not in the foreground, during an active work session. Required to record your route, verify visits, and calculate distance when you switch to other apps. A persistent notification is displayed whenever this permission is actively being used. This permission is only requested after an explicit in-app disclosure screen.
FOREGROUND_SERVICE_LOCATION Declares that the App's location foreground service is of type "location" as required by Android API 34+. This is the technical mechanism that enables the persistent tracking notification and complies with Android's foreground service policy.
FOREGROUND_SERVICE Runs the location foreground service with a visible persistent notification while work-day GPS tracking is active.
CAMERA Capturing photos to attach to visit records, expense receipts, and product catalogue entries.
READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE Selecting existing images from your device photo library to attach to visit or expense records. (Specific permission varies by Android version.)
INTERNET Connecting to Italica's secure backend services (Supabase Auth, ERP proxy) for authentication, data synchronisation, and file uploads.

Note: The exact set of permissions is declared in the App's AndroidManifest.xml. Only permissions directly related to personal data collection are listed above. All permissions are used solely for the purposes stated.


3. When Location Is Collected

3.1 Location Collection Begins When ALL of the Following Are True:

  1. You are authenticated (logged in) to the App
  2. You have granted location permissions on your device (at minimum ACCESS_FINE_LOCATION; background collection additionally requires ACCESS_BACKGROUND_LOCATION)
  3. You have actively pressed "Start Day" within the App to begin your work session

All three conditions must be met simultaneously. The App does not collect location data passively, automatically on launch, or without a deliberate user action to start a work session.

3.2 Location Collection Ends When Any of the Following Occur:

3.3 Foreground Location

Collected while the App is open and visible on screen. Used for visit geo-stamping, map display within the App, and recording start/end day GPS coordinates.

3.4 Background Location

Collected while an active work session is running, even if you navigate away from the App or lock your device. A persistent notification (see Section 7) is displayed at all times during background collection. Background collection stops immediately when you press "End Day" or revoke background location permission.


4. How We Use Your Data

4.1 Authentication & Access Control

Your name, email, and credentials authenticate you to the App and control access to data relevant to your assigned role, territory, and zone.

4.2 Attendance Tracking

Your Start Day and End Day timestamps and GPS coordinates are recorded to document daily attendance. This data is used for payroll, HR records, workforce management, and compliance purposes.

4.3 GPS Route Tracking

GPS coordinates collected during your active work session are used to reconstruct your daily travel route. This route record is visible to authorised managers and administrators for field team oversight and territory management.

4.4 Distance Calculation

Total distance travelled during your work session is calculated from sequential GPS route data. This calculated distance is used to determine travel expense reimbursement amounts and pre-populate expense report fields.

4.5 Customer & Dealer Visit Verification

When you log a customer or dealer visit in the App, your GPS coordinates at that moment are recorded and compared against the registered address of that customer or dealer. This geo-verification confirms that the visit was conducted at the correct location and attaches a location stamp to each visit record.

4.6 Expense Management

GPS-derived distance data pre-populates travel distance fields in expense reports. Receipt photos are stored and linked to expense records for audit purposes.

4.7 CRM & Sales Activity Tracking

Customer visit records, lead visit records, and sales orders are associated with your employee account for CRM reporting, lead management, and sales performance tracking by authorised management.

4.8 Product Catalogue

Your zone assignment is used to display relevant products in the catalogue. No GPS or location data is used for product catalogue access.

4.9 App Maintenance & Technical Support

Device model, OS version, and app version are used for debugging, compatibility testing, and providing technical support.

4.10 What We Do NOT Do With Your Data


5. User Consent & Permissions Flow

The App uses Android's standard runtime permission system. Permissions are requested only when needed and only for the purposes stated in this policy.

Your authenticated use of the App, combined with granting the relevant permissions and actively initiating a work session, constitutes your ongoing consent to data collection as described in this policy.


6. Enterprise Monitoring Disclosure

🏢 Employer-Managed Monitoring — Mandatory Disclosure

This is an employer-managed enterprise application. Italica Group of Companies, as your employer, operates this App to manage field force activities. The following monitoring activities are conducted as part of normal workforce management and are authorised under your employment agreement:

This monitoring is not covert. Every employee using this App:

This application complies with Google Play's Device and Network Abuse Policy requirements for monitoring applications. It is not spyware, consumer surveillance software, parental monitoring software, or a hidden tracking application.


7. Foreground Service & Persistent Notification

The App uses an Android Foreground Service to maintain reliable GPS tracking during an active work session. This is Android's approved mechanism for applications that legitimately require continuous background location access. The foreground service ensures that you are always aware that location tracking is occurring.

7.1 Persistent Notification

Whenever the foreground location service is running, a persistent notification is displayed. This notification:

7.2 How to Stop the Foreground Service

7.3 Foreground Service Type

The App declares FOREGROUND_SERVICE_LOCATION as required by Android API level 34 and above. This permission confirms to the Android system that the foreground service accesses location, ensuring proper system behaviour, power management disclosure, and user transparency.


8. Who Can Access Your Data

Role Data They Can Access
You (Employee) Your own attendance records, visit logs, GPS routes, expense entries, orders, and CRM activity.
Manager / Coordinator Attendance, visit records, GPS routes, and expense entries for employees in their assigned zone or state team.
HR / Admin All employee records for HR, payroll, compliance, and management reporting purposes.
IT / System Administrator System-level access for maintenance and security operations, governed by Italica's internal access control policies.
Third Parties None. Infrastructure service providers (Supabase, AWS) process data strictly per our instructions as data processors and do not access it for their own purposes. See Section 11.

9. Data Storage & Security

All personal data is protected by the following technical measures:

While Italica implements strong security measures to protect your data, no digital system is completely immune to security risks. In the event of a data breach that affects your personal data, we will notify affected individuals as required by applicable law.


10. Data Retention

Data Type Retention Period Reason
Account data (name, email, credentials) Duration of employment. Permanently deleted within 30 days of account deactivation. Authentication, account management
GPS route data & location records 12 months from date of collection, then permanently deleted. Route verification, expense calculation, compliance
Attendance records (Start Day / End Day) Duration of employment, plus up to 3 years after account closure for HR and payroll compliance. HR records, payroll, legal compliance
Customer & dealer visit records 3 years from the date of visit. CRM history, business compliance
Expense records & receipt images 7 years from the date of expense. Financial audit and tax compliance requirements
Device information Deleted within 30 days of account deactivation. App support and compatibility

Upon account deletion, personal identity data (name, email address) is permanently removed within 30 days. Business records may be retained in anonymised or aggregated form as required by applicable Indian law.


11. Data Sharing & Third-Party Services

We share data only with the following service providers who are technically necessary to operate the App. Each provider acts as a data processor under our instruction and is contractually prohibited from using your data for their own purposes.

Provider Purpose Data Processed Privacy Policy
Supabase Authentication, user data storage, and file storage Account data, GPS/location records, visit records, expense data, images supabase.com/privacy
Amazon Web Services (AWS) Cloud server infrastructure — Mumbai, India (ap-south-1) All app data resides on AWS infrastructure (Supabase is hosted on AWS ap-south-1). Data does not leave India. aws.amazon.com/privacy
Google Play Store App distribution and update delivery only No personal data from the App is shared with Google Play. policies.google.com/privacy

We do not:


12. Your Rights & Control

12.1 Data Rights

You have the following rights regarding your personal data. To exercise these rights, contact us at the details provided in Section 16.

We will respond to all data rights requests within 30 days.

12.2 Revoking Permissions

You can revoke any App permission at any time via: Settings → Apps → Italica → Permissions

If You Revoke Effect on the App
Foreground Location
(ACCESS_FINE_LOCATION)
Visit geo-stamping, map display, start/end location recording, and all background tracking are disabled. GPS route tracking stops immediately. The foreground service will be stopped.
Background Location
(ACCESS_BACKGROUND_LOCATION)
GPS route recording while the App is not in the foreground is disabled. Foreground location features (visit check-in geo-stamp while the App is open) continue to work if foreground permission is still granted.
Camera Photo capture is disabled. You can still select images from your gallery. Previously uploaded photos are not affected.

12.3 If Location Permissions Are Denied

You may deny location permissions at any time. If location access is denied:


13. Google Play Data Safety Consistency

The following table summarises the data types declared in the Google Play Console Data Safety form for this application. This Privacy Policy is consistent with those declarations.

Data Type Collected Encrypted in Transit Shared Externally User Can Request Deletion
Precise location Yes Yes (TLS 1.2+) No Yes
Coarse location Yes (fallback) Yes No Yes
Name Yes Yes No Yes
Email address Yes Yes No Yes
Photos / images Yes Yes No Yes
Financial info (expense records) Yes Yes No Yes
App interactions / usage data Yes Yes No Yes
Device identifiers (model, OS) Yes Yes No Yes
Advertising identifiers No

Data collected is used solely for App functionality. It is not collected for advertising, not shared with ad networks, not used for marketing profiling, and not processed by AI or machine learning systems.


14. Children's Privacy

This App is intended solely for authorised employees of Italica Group and is restricted to individuals 18 years of age or older. The App is not intended for, marketed to, or knowingly used by anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has gained access to this App, please contact us immediately at the details in Section 16.


15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the App's features, applicable law, or our data practices. When we make material changes, we will:

Continued use of the App after any changes to this policy constitutes your acceptance of the updated terms. We encourage you to review this policy periodically.


16. Contact Us

For privacy-related questions, data access requests, account deletion requests, or to report a security concern, please contact us:

Italica Group of Companies

📧 Email: info@italicatiles.com

🌐 Website: italicatiles.com

We aim to respond to all privacy-related requests within 30 days of receipt.


17. Regulatory Compliance

This Privacy Policy has been prepared in compliance with: