Legal

Privacy Policy

How Waqti collects, uses, and protects employee data for USF Group.

Last updated: 19 June 2026
01

Who we are

Waqti is the workforce attendance, payroll and operations system operated by USF Group ("we", "us", "our"). The system is built, maintained and administered in-house by Reejan Gopan, Developer & Administrator of the Waqti Attendance System. It is provided exclusively to our employees, supervisors, engineers and authorized site personnel and is not a public product.

02

What the system does

Waqti is a full attendance and HR operations platform. It includes:

  • Daily attendanceGPS-verified check-in / check-out with live selfie capture (camera only, gallery uploads blocked).
  • Shift managementDay, night and crossing-midnight shifts, per-site overrides, weekly-off days.
  • GeofencingOn-Site vs Outside-Site classification based on site coordinates and radius.
  • Correction & OTAdmin review workflows for late, correction and overtime requests.
  • Checkout reviewEarly and missed checkout approval before timesheet finalization.
  • Leave managementAnnual leave, paid off-days, sick and unpaid leave with balance tracking.
  • Work-from-homeRequests and tracking for remote work days.
  • Site transfersFull transfer history for every employee.
  • Supervisor rolesCrew dashboards and bulk attendance marking.
  • PayrollSalary settings, automated slips, allowances, deductions and monthly runs.
  • Reports & archivesCSV / Excel export and monthly archive snapshots.
  • AI-assisted modulesHR reports, fraud signals, payroll risk, site insights and admin AI chat.
  • Push notificationsWeb push and FCM for reminders, alerts and broadcasts.
  • Audit logsImmutable logs for sensitive admin actions and login events.
03

Information we collect

  • Account information

    Full name, employee code, designation, phone number, assigned site, role and one-way bcrypt-hashed password. Plain-text passwords are never stored.

  • Location (GPS)

    Latitude, longitude and accuracy captured only at check-in and check-out, with reverse-geocoded address.

  • Selfie photos

    One live selfie at each check-in and check-out, compressed in the browser before upload.

  • Attendance records

    Work date, timestamps, late status, on-site classification, working hours, and name/designation/site snapshots.

  • Requests & reviews

    Correction, late-review, overtime, checkout review, leave, and work-from-home requests with admin decisions.

  • Payroll data

    Basic salary, allowances, deductions, salary slips and payment status (visible to employee and authorized HR / admin only).

  • Device & push tokens

    Web-push endpoints and FCM device tokens used only for attendance notifications.

  • Operational logs

    Login audit records, admin action audit logs, reminder delivery logs and support ticket messages.

04

How we use your information

  • Verify that check-ins and check-outs occur at assigned work sites.
  • Calculate working hours, late minutes, overtime and salary.
  • Generate monthly attendance reports, archives and salary slips.
  • Resolve disputes via the correction, late-review and checkout-review flows.
  • Send shift reminders and missed-checkout alerts (see Section 7 for schedule).
  • Operate AI-assisted insight modules limited to internal HR use.

We do not sell your data, share it with advertisers, or use it for any purpose unrelated to your employment with USF Group.

05

Selfie storage & retention

Selfies are stored in a private, encrypted storage bucket (attendance-selfies). The database only stores the file path — never the image bytes themselves.

  • Access granted exclusively through short-lived signed URLs minted by the server after authentication; raw URLs do not work.
  • Employees can mint signed URLs only for their own selfies.
  • Selfies are automatically deleted after 60 days by a daily 02:00 Asia/Dubai cleanup job.
  • The attendance record is retained, with selfie fields nulled and deletion timestamp recorded.
06

Location data

Location is accessed only at the moment of check-in or check-out — never in the background and never while the app is closed. Coordinates are used to classify the check-in against the assigned site's geofence and are stored alongside the attendance record for audit purposes.

07

Notifications

Push notifications via web push (VAPID) on browsers and Firebase Cloud Messaging (FCM) on Android. Sent only for employment-related events:

Check-in reminder
−10 min · Before shift start
Final check-in reminder
−1 min · Before shift start
Missed check-in alert
+5 min · After shift start
Missed check-in alert
+10 min · After shift start
Check-out reminder
0 min · At shift end
Missed check-out alert
+5 min · After shift end
Missed check-out alert
+10 min · After shift end

You can disable notifications at any time from your device settings or the in-app notification toggle.

08

Data storage & security

  • Data is hosted on Lovable Cloud infrastructure inside a managed Postgres database.
  • All traffic is encrypted in transit over HTTPS.
  • Row-level security and server-side authorization gate every sensitive read and write. The public anonymous key cannot read or modify any business table.
  • All application logic runs through signed-session-token server functions; admin operations require an authenticated admin session.
  • Passwords are stored as one-way bcrypt hashes.
  • Sensitive admin actions and logins are written to immutable audit logs.
09

Data retention

  • Selfies

    Deleted after 60 days (see Section 5).

  • Attendance, payroll & audit logs

    Retained for the duration of employment and for the period required by UAE labour and tax regulations.

  • Notifications & push tokens

    Invalidated tokens are pruned automatically; notification history is kept for operational review.

10

Your rights

You may at any time:

  • Request a copy of your attendance and payroll records.
  • Request correction of inaccurate data via the in-app correction request flow.
  • Request deletion of your account when your employment ends.

To exercise these rights, contact the system administrator listed in Section 13.

11

Children

This app is not intended for, and not made available to, anyone under 18.

12

Changes to this policy

We may update this policy occasionally. The "Last updated" date at the top of this page reflects the most recent revision.

13

Contact

For any privacy, data or system-related questions, contact:

Reejan Gopan
Developer & Administrator — Waqti Attendance System
USF Group
[email protected]

This Privacy Policy is maintained by USF Group to answer common questions about data handling in Waqti.

© 2026 USF Group. All rights reserved.