Who we are
Waqti is the workforce attendance, payroll and operations system operated by USF Group ("we", "us", "our"). The system is built, maintained and administered in-house by Reejan Gopan, Developer & Administrator of the Waqti Attendance System. It is provided exclusively to our employees, supervisors, engineers and authorized site personnel and is not a public product.
What the system does
Waqti is a full attendance and HR operations platform. It includes:
- Daily attendance — GPS-verified check-in / check-out with live selfie capture (camera only, gallery uploads blocked).
- Shift management — Day, night and crossing-midnight shifts, per-site overrides, weekly-off days.
- Geofencing — On-Site vs Outside-Site classification based on site coordinates and radius.
- Correction & OT — Admin review workflows for late, correction and overtime requests.
- Checkout review — Early and missed checkout approval before timesheet finalization.
- Leave management — Annual leave, paid off-days, sick and unpaid leave with balance tracking.
- Work-from-home — Requests and tracking for remote work days.
- Site transfers — Full transfer history for every employee.
- Supervisor roles — Crew dashboards and bulk attendance marking.
- Payroll — Salary settings, automated slips, allowances, deductions and monthly runs.
- Reports & archives — CSV / Excel export and monthly archive snapshots.
- AI-assisted modules — HR reports, fraud signals, payroll risk, site insights and admin AI chat.
- Push notifications — Web push and FCM for reminders, alerts and broadcasts.
- Audit logs — Immutable logs for sensitive admin actions and login events.
Information we collect
- Account information
Full name, employee code, designation, phone number, assigned site, role and one-way bcrypt-hashed password. Plain-text passwords are never stored.
- Location (GPS)
Latitude, longitude and accuracy captured only at check-in and check-out, with reverse-geocoded address.
- Selfie photos
One live selfie at each check-in and check-out, compressed in the browser before upload.
- Attendance records
Work date, timestamps, late status, on-site classification, working hours, and name/designation/site snapshots.
- Requests & reviews
Correction, late-review, overtime, checkout review, leave, and work-from-home requests with admin decisions.
- Payroll data
Basic salary, allowances, deductions, salary slips and payment status (visible to employee and authorized HR / admin only).
- Device & push tokens
Web-push endpoints and FCM device tokens used only for attendance notifications.
- Operational logs
Login audit records, admin action audit logs, reminder delivery logs and support ticket messages.
How we use your information
- Verify that check-ins and check-outs occur at assigned work sites.
- Calculate working hours, late minutes, overtime and salary.
- Generate monthly attendance reports, archives and salary slips.
- Resolve disputes via the correction, late-review and checkout-review flows.
- Send shift reminders and missed-checkout alerts (see Section 7 for schedule).
- Operate AI-assisted insight modules limited to internal HR use.
We do not sell your data, share it with advertisers, or use it for any purpose unrelated to your employment with USF Group.
Selfie storage & retention
Selfies are stored in a private, encrypted storage bucket (attendance-selfies). The database only stores the file path — never the image bytes themselves.
- Access granted exclusively through short-lived signed URLs minted by the server after authentication; raw URLs do not work.
- Employees can mint signed URLs only for their own selfies.
- Selfies are automatically deleted after 60 days by a daily 02:00 Asia/Dubai cleanup job.
- The attendance record is retained, with selfie fields nulled and deletion timestamp recorded.
Location data
Location is accessed only at the moment of check-in or check-out — never in the background and never while the app is closed. Coordinates are used to classify the check-in against the assigned site's geofence and are stored alongside the attendance record for audit purposes.
Notifications
Push notifications via web push (VAPID) on browsers and Firebase Cloud Messaging (FCM) on Android. Sent only for employment-related events:
You can disable notifications at any time from your device settings or the in-app notification toggle.
Data storage & security
- Data is hosted on Lovable Cloud infrastructure inside a managed Postgres database.
- All traffic is encrypted in transit over HTTPS.
- Row-level security and server-side authorization gate every sensitive read and write. The public anonymous key cannot read or modify any business table.
- All application logic runs through signed-session-token server functions; admin operations require an authenticated admin session.
- Passwords are stored as one-way bcrypt hashes.
- Sensitive admin actions and logins are written to immutable audit logs.
Data retention
- Selfies
Deleted after 60 days (see Section 5).
- Attendance, payroll & audit logs
Retained for the duration of employment and for the period required by UAE labour and tax regulations.
- Notifications & push tokens
Invalidated tokens are pruned automatically; notification history is kept for operational review.
Your rights
You may at any time:
- Request a copy of your attendance and payroll records.
- Request correction of inaccurate data via the in-app correction request flow.
- Request deletion of your account when your employment ends.
To exercise these rights, contact the system administrator listed in Section 13.
Children
This app is not intended for, and not made available to, anyone under 18.
Changes to this policy
We may update this policy occasionally. The "Last updated" date at the top of this page reflects the most recent revision.
Contact
For any privacy, data or system-related questions, contact:
This Privacy Policy is maintained by USF Group to answer common questions about data handling in Waqti.
© 2026 USF Group. All rights reserved.