Privacy Policy
Effective date: March 19, 2026
Delete Risk ("we," "us," or "our") operates the Delete Risk mobile application for iOS and Android (the "App") and the Delete Risk web platform (the "Platform"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to both the App and the Platform.
1. Information We Collect
Account & Profile
When your organization provisions an account for you, we store your name, username, email address, phone number (if provided for SMS recovery), and role within your organization. This data is used to authenticate you, display your identity within the App, and enforce role-based access to features.
Time & Attendance
The App records clock-in and clock-out events, break start and end times, and any notes you add to time entries. This data is submitted to your organization for payroll processing and labor compliance.
Location Data
When you clock in, clock out, or start/end a break, the App captures a single GPS reading to verify you are at the assigned job site. During an active shift the App may also collect location data in the background at periodic intervals for safety and compliance purposes. Location data includes latitude, longitude, accuracy, altitude, heading, speed, and a timestamp. You can review location tracking settings within the App.
Background location use (iOS & Android): Background location tracking is active only while you are clocked in to an active shift. The App uses this data solely to verify job-site presence for safety and regulatory compliance. Background tracking stops automatically when you clock out.
Expense & Receipt Data
When you submit an expense, we collect the vendor name, amount, date, category, and any associated project. If you attach a receipt photo, the image is uploaded and stored securely. We may use automated processing to extract text from receipt images (vendor, amount, date, and category) to pre-fill expense fields for your convenience.
Device & Technical Data
We collect your device's push notification token so we can deliver notifications about checklists, expenses, and time-tracking activity. We also store your preferred language and theme settings locally on your device.
Biometric Data
If you enable Face ID or Touch ID login, authentication is handled entirely by your device's secure enclave. We never receive, transmit, or store your biometric templates. We only store a flag indicating that biometric login is enabled for your account.
2. Device Permissions
| Permission | Platform | Why We Need It |
|---|---|---|
| Camera | iOS & Android | To photograph receipts for expense reports and justification photos for time-entry flags. The camera is only activated when you choose to take a photo. |
| Photo Library | iOS & Android | To select an existing photo from your device as a receipt or justification attachment. |
| Location (When In Use) | iOS & Android | To verify you are at the assigned job site when clocking in, clocking out, or starting/ending a break. |
| Location (Always / Background) | iOS & Android | To track your position during an active shift for safety and regulatory compliance. Background tracking stops when you clock out. On iOS this appears as "Always Allow"; on Android as "Allow all the time." |
| Face ID / Touch ID / Biometrics | iOS & Android | Optional. Lets you log in quickly using biometric authentication instead of typing your password. |
| Push Notifications | iOS & Android | To notify you about checklist assignments, expense approvals, time-tracking reminders, and other activity. |
You can revoke any of the above permissions at any time through your device's Settings app. Revoking a permission may limit the functionality of certain App features.
3. How We Use Your Information
- Authenticate you and maintain your session.
- Record and display time-tracking, break, and attendance data for payroll and compliance.
- Verify job-site presence via GPS at clock-in/out and during active shifts.
- Process and store expense reports and receipt images.
- Deliver push notifications for relevant activity.
- Pre-fill expense fields using automated receipt text extraction.
- Support offline functionality by caching draft expenses and pending clock-in events on your device.
- Remember your language and theme preferences.
- Provide account recovery via SMS when enabled by your organization.
4. Data Storage & Security
Your data is transmitted over encrypted connections (HTTPS/TLS) and stored on secured servers. Receipt and justification images are stored in Amazon Web Services (AWS) S3 with access restricted to authorized personnel and signed, time-limited URLs. Biometric credentials (when enabled) are stored in your device's secure enclave and are never transmitted to our servers.
Certain data — such as draft expenses, pending clock-in events, and GPS points collected while offline — is stored locally on your device and synchronized with our servers once connectivity is restored.
Authentication tokens are stored securely on your device (AsyncStorage on mobile, HTTP-only cookies on web) and are invalidated upon logout.
5. Third-Party Services
The App relies on the following third-party services to function. We do not sell or share your personal data with third parties for advertising or marketing purposes.
- Expo / EAS — delivers over-the-air updates and push notifications via the Expo Push Notification service.
- Amazon Web Services (AWS) — stores receipt and justification images securely in S3.
- OpenStreetMap — provides map tiles for the GPS event map feature. Your IP address may be visible to OpenStreetMap tile servers when loading map imagery.
The App does not integrate any third-party analytics, advertising, crash-reporting, or user-tracking SDKs.
6. Tracking & Advertising
We do not track you. The App does not use advertising identifiers (IDFA on iOS or GAID on Android), does not participate in ad networks, and does not track you across other companies' apps or websites. We do not request App Tracking Transparency (ATT) permission on iOS because we have no tracking to disclose.
7. App Store & Google Play Data Disclosures
The tables below summarize the data we collect and how it maps to the disclosure categories required by Apple's App Privacy ("nutrition labels") and Google Play's Data Safety section.
Apple App Privacy (iOS)
| Data Type | Collected | Linked to Identity | Purpose |
|---|---|---|---|
| Name | Yes | Yes | App Functionality |
| Email Address | Yes | Yes | App Functionality |
| Phone Number | Yes | Yes | App Functionality (SMS recovery) |
| Precise Location | Yes | Yes | App Functionality (job-site verification) |
| Photos | Yes | Yes | App Functionality (receipts & justifications) |
| User ID | Yes | Yes | App Functionality |
| Device ID | Yes | Yes | App Functionality (push tokens) |
Data used to track you: None. We do not use any collected data for tracking purposes.
Google Play Data Safety (Android)
| Data Type | Collected | Shared | Purpose |
|---|---|---|---|
| Name | Yes | No | App functionality, Account management |
| Email address | Yes | No | App functionality, Account management |
| Phone number | Yes | No | App functionality (SMS recovery) |
| Precise location | Yes | No | App functionality (job-site verification) |
| Photos | Yes | No | App functionality (receipts & justifications) |
| Other user-generated content | Yes | No | App functionality (time entries, expense data) |
| Device identifiers | Yes | No | App functionality (push notifications) |
All collected data is encrypted in transit. Data is not shared with third parties. Users can request deletion (see Section 11).
8. Data Sharing
Your data is accessible to authorized members of your organization (e.g., managers approving time entries or expenses) and to Delete Risk platform administrators who support the service. We may also disclose data if required by law or to protect the rights and safety of our users.
We do not sell your personal data to anyone. We do not share your personal data with third parties for their own marketing or advertising purposes.
9. Data Retention
We retain your data for as long as your account is active or as needed to provide the service and comply with legal obligations. When your account is deactivated, your data is retained in accordance with your organization's data-retention policies and applicable regulations.
10. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data. You can revoke device permissions (camera, location, notifications) at any time through your device settings. To request access to or deletion of your data, contact your organization administrator or reach out to us at the address below.
11. Data Deletion
You may request deletion of your personal data at any time by contacting us at support@deleterisk.com. Upon receiving a verified deletion request, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., payroll records required by labor regulations). Your organization administrator can also deactivate your account, which disables access and begins the retention/deletion process per your organization's policies.
12. California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights regarding your personal information:
- Right to Know: You may request details about the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- No Sale of Personal Information: We do not sell personal information as defined by the CCPA.
To exercise any of these rights, contact us at support@deleterisk.com.
13. International Users
The App is primarily intended for use within the United States. If you access the App from outside the United States, please be aware that your data may be transferred to and processed in the United States, where data-protection laws may differ from those of your country.
14. Children's Privacy
The App is intended for use by employees and contractors of subscribing organizations. We do not knowingly collect personal information from children under 13 (or under 16 in the EEA). If you believe a child has provided us with personal information, please contact us so we can remove it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page and, for material changes, notify users through the App or via email. Continued use of the App after changes are posted constitutes acceptance of the updated policy.
16. Contact Us
If you have questions or concerns about this Privacy Policy or wish to exercise your data rights, please contact us at:
Delete Risk
Email: support@deleterisk.com