Last updated: 6 October 2026
Privacy Policy
1. The short version
- Your audit content never reaches us. Photos, videos, observations, recommendations, GPS tracks of your drives and the reports you generate are stored only on the device you use (the browser's local database, plus any folder copy or ZIP you export). We do not receive, store or have access to them.
- We keep your account, licence and payment records so we can provide and bill the service.
- We record activity metadata — for example when you sign in, which screens you open, and how many captures or reports you make — but never their content. This is used to run the licence, keep accounts secure, support you and improve the product.
- We do not sell personal data and we do not use advertising or third-party analytics trackers.
2. Personal data we collect
| Category | What |
|---|---|
| Access requests | Name, organisation, e-mail, phone and your message when you request a demo or access; the IP address it was sent from. |
| Account | Name, e-mail, organisation, phone, role and account status. Your password is stored only as a one-way (bcrypt) hash. If you use “Continue with Google”, we receive your Google e-mail address and name. |
| Licence and payments | Plan, licence dates, agreed price, device limit, and payment records (date, amount, GST, invoice/reference number, method, notes). |
| Devices and sessions | For each signed-in browser: a random device identifier (cookie), IP address, browser, operating system, device type, sign-in method, when it was signed in, last seen and signed out. |
| Activity tracking (metadata only) | Sign-ins and failed sign-ins, sign-outs, password changes, licence checks, devices added or removed; screens viewed and time spent; a heartbeat every 60 seconds while the app is open (to show “online now”, last seen and active minutes per day); in the field tool: tool opened, route file loaded (file size, number of chainage labels, route length), video or GPS file loaded (format, size, duration), live mode started, capture saved or deleted (the main issue category only), ZIP export/import (counts), report generated (numbers of observations, issues and annexures, and the chainage range in km), and error messages from the app. |
| Support | The questions and replies you send through Help & support. |
| Admin actions | A record of changes our administrators make to your account or licence (who, what, when). |
We do not collect: captured photos or video frames, observation or recommendation text, the location of individual captures, project or client names you type into the report, or the generated Word documents.
3. Why we use it (purposes)
- To create and manage your account and provide the service you have licensed (contract and your consent).
- To enforce the licence: checking that your account is active and your licence valid, and applying the device limit.
- To keep accounts and the service secure: detecting misuse, rate-limiting sign-in attempts and investigating incidents.
- To answer support requests and send in-app renewal reminders.
- To record payments and meet accounting and tax obligations.
- To understand, in aggregate, how the product is used so we can fix problems and improve it.
We process personal data on the basis of your consent given when you request access or sign in, and for the legitimate uses permitted by Section 7 of the DPDP Act (including where you have voluntarily provided data for a specified purpose and to meet legal obligations).
4. How long we keep it
- Account, licence and support data: while your account exists, and up to 2 years after it is closed, unless you ask us to erase it earlier (see section 7).
- Payment and invoice records: 8 years, as required for accounting records under Indian law.
- Detailed activity events: 12 months (our administrators can set a different period). After that only daily totals per account are kept (for example active minutes and number of reports per day).
- Access requests that do not become an account: 12 months.
- Database backups: 14 days.
5. Who we share it with
Only with service providers who help us run the service, under appropriate confidentiality and security obligations:
- Our hosting and database providers, which store the account, licence and activity data described above. Data may be processed on servers outside India where permitted under the DPDP Act.
- Google, only if you choose “Continue with Google” (for signing in).
- The field tool loads its map and software libraries from public content networks (OpenStreetMap map tiles, cdnjs and jsDelivr). Like any website, those services receive your IP address and, for map tiles, the map area being viewed. No audit content is sent to them.
We may also disclose data where required by law, a court order or a competent authority.
6. Cookies and local storage
We use only cookies that are necessary for the service: a sign-in session cookie, a security (CSRF) cookie and a random device identifier used for the device limit. The browser's local storage holds your theme choice, the field tool's settings and any usage events waiting to be sent while you are offline; the field tool's local database holds your audit content on your device. We do not use advertising or analytics cookies.
7. Your rights
Under the DPDP Act you may:
- ask for a summary of the personal data we process about you and how we process it;
- ask us to correct, complete or update it;
- ask us to erase it (we may keep what the law requires us to keep, such as invoices);
- withdraw your consent (this will end your use of the service, since the licence cannot run without the account data);
- nominate another person to exercise these rights on your behalf in case of death or incapacity;
- raise a grievance with our Grievance Officer and, if unresolved, complain to the Data Protection Board of India.
To exercise any right, write to the Grievance Officer below from your registered e-mail address. Because your audit content is only on your device, you can delete it at any time yourself by clearing the field tool's data in your browser.
8. Security
Data is transmitted over HTTPS. Passwords and admin keys are stored as bcrypt hashes; sign-in attempts are rate-limited; administrator access needs a second 32-character key; every administrator action is logged. No system is perfectly secure; if we become aware of a personal data breach affecting you we will inform you and the Data Protection Board as the DPDP Act requires.
9. Children
The service is for professionals and is not intended for anyone under 18. We do not knowingly collect children's data.
10. Changes
We may update this policy. The date at the top shows the latest version; significant changes will be announced in the app.
11. Contact and Grievance Officer
Geo Designs & Research Pvt. Ltd.
Registered office: B-10, Krishna Industrial Estate, Opp B.I.D.C., Gorwa Estate, Vadodara - 390 016, Gujarat, India
Corporate office: FP Number 55, Behind Makarpura Railway Station, Maneja, Vadodara 390013
Phone (+91) 265-229-0222 / 228-3081
info@geogroup.in · geogroup.in
Grievance Officer
Aditya Pancholi
For privacy requests, corrections, erasure and complaints. We aim to respond within 30 days.