Gabco Group
Privacy Policy — Gabco Mobile App
- App name:
- Gabco (Gabco Mobile App)
- Package / Bundle ID:
com.gabco.mobileapp- Effective date:
- 6 August 2026
- Last updated:
- 6 August 2026
This app collects location data — including precise location and location in the background. Section 2 sets out exactly what is collected, when, why, where it is sent, and how to turn it off. Location data is never sold and is never shared with advertisers, data brokers, or analytics providers.
1. Summary — what this app collects
The Gabco Mobile App is a workforce application for Gabco employees and authorized contractors. It is not a consumer app; you must sign in with an employee account issued by Gabco to use any feature.
| Data type | Collected? | Shared with third parties? | Purpose |
|---|---|---|---|
| Location — precise (GPS) | Yes | No (processed by our hosting providers only) | Proof of presence at customer sites, nearby-customer lists, delivery trip tracking |
| Location — approximate | Yes | No | Same as above; used when the operating system supplies a coarse fix |
| Location — in the background | Yes | No | Only while a delivery trip is active: live trip progress and ETA for dispatch, arrival/departure records |
| Email address / account credentials | Yes | No | Sign-in and authentication |
| Name, employee ID, job title, organization | Yes | No | Attribution of work records |
| Work activity (visits, inventory counts, notes, scans, trip and stop events) | Yes | No | Core business function |
| Camera images | No | No | The camera is used live for QR/barcode scanning; no image is captured, stored, or transmitted |
| Advertising / marketing identifiers | No | — | — |
| Analytics, crash-reporting or tracking SDKs | No | — | — |
| Contacts, calendar, photos, microphone, SMS, call logs, health data | No | — | — |
We do not sell your personal information, and we do not use it for advertising, marketing, or profiling.
2. Location data — full disclosure
This section describes, in detail, every way the app accesses, collects, uses, transmits, stores and retains location data. Location is central to how the app works and is disclosed here in full.
2.1 What location data we access
- Precise location (GPS) — latitude, longitude and horizontal accuracy in metres.
- Approximate (coarse/network) location — used when the operating system supplies a coarse fix instead of a precise one.
- Location in the background — collected while a delivery trip is active, including when the app is minimized, the screen is off, or the app is not in use.
- Timestamp of each location reading (UTC).
- A “mock location” indicator — a true/false signal from the operating system (Android) telling us whether the reading came from a fake/spoofed-GPS app. Used only to protect the integrity of proof-of-presence records.
We do not collect location history when you are not signed in, not on an active trip, and not performing a location-gated action.
2.2 When and how often location is collected
| Situation | What happens | Frequency |
|---|---|---|
| You open the nearby customers list (VMI) | A single location reading is taken on-device to sort and show customers near you | One reading per refresh |
| You start or submit a customer visit (VMI) | A single location reading is captured and sent to our servers as “location proof” | One reading per action |
| You scan a work order, start a trip, mark a stop reached / service started / finished / skipped, or finish a trip (Driver) | A single location reading is captured and sent as “location proof” for that event | One reading per action |
| A delivery trip is active (Driver) | Continuous background location tracking runs and uploads your position to our servers | Approximately every 10 seconds until you finish the trip |
| App is installed but you are signed out, idle, or no trip is active | No location is collected. Background tracking is stopped and does not run | Never |
Background tracking starts only after you explicitly start a delivery trip, and stops when you finish that trip, when you sign out, or when the tracking service is stopped.
2.3 Why we collect it (purposes)
- Proof of presence / work verification — to confirm that a customer visit or delivery stop event genuinely took place at the customer location. The app compares your position against the customer’s coordinates and normally requires you to be within 100 metres.
- Finding nearby customers — to sort and display the customer sites closest to you.
- Live trip progress and ETAs — so dispatch and operations staff can see where an active delivery trip is and inform customers of arrival times.
- Arrival and departure records — to timestamp and geo-stamp each stop for operational and dispute-resolution records.
- Integrity of records — to detect and reject spoofed/mock GPS readings.
Location data is not used for employee surveillance outside working trips, for advertising, for building marketing profiles, or for any purpose unrelated to the operational functions above.
2.4 Override of the location check
Some employee accounts are granted a “GPS override” permission by Gabco. If your account has it and you are further than 100 metres from the expected site, you may choose to proceed anyway. If you do, your actual current location is still captured and sent to our servers with that action, and the record is flagged accordingly.
2.5 Where location data goes
Location readings are transmitted over an encrypted HTTPS/TLS connection to Gabco’s own backend systems at gabcobusinesssolutions.com (production) and gabcoerp.tecfy.co (test), which are operated for Gabco by our hosting providers. Location data:
- is stored in Gabco’s business systems as part of your visit and trip records;
- is visible to authorized Gabco staff (dispatch, operations, supervisors, administrators);
- is not sold, rented, or shared with advertisers, data brokers, or analytics companies.
2.6 Background-location notice and controls
- Before background tracking is enabled, the app shows an in-app disclosure explaining that Gabco collects location in the background during an active delivery trip, even when the app is closed or not in use, and asks you to accept.
- You must separately grant the operating system’s location permission — on Android, “Allow all the time” for background tracking; on iOS, the “Always” permission.
- On Android, a persistent notification (“Gabco trip tracking”) is displayed the entire time background tracking is running. On iOS, the system background-location indicator is shown.
- You can revoke location permission at any time in device settings (Android: Settings → Apps → Gabco → Permissions → Location; iOS: Settings → Gabco → Location). If you revoke it, location-gated features — starting or submitting visits, scanning work orders, recording stop events, and trip tracking — will not function, because verified location is required for those records.
2.7 Retention of location data
- On your device: location captured for a visit that has not yet been uploaded (for example, while you are offline) is kept in the app’s local database until the record is successfully submitted, after which the pending copy is removed. Uninstalling the app deletes all local app data.
- On our servers: location proofs and trip location trails are retained as part of the associated business record (visit, trip, delivery) for as long as that record is needed for operational, accounting, contractual and legal purposes, and then deleted or anonymized in line with Gabco’s records-retention schedule.
3. Other data we collect
3.1 Account and identity data
- Email address and password (the password is transmitted to our authentication endpoint to verify you; it is not stored on the device).
- Employee ID, display name, first/last name, job title, organization ID.
- Role and feature flags (for example whether VMI is enabled for you, whether GPS override is permitted).
- An access token representing your signed-in session, stored on the device in the operating system’s secure credential store (Android Keystore-backed storage / iOS Keychain) and deleted when you sign out.
3.2 Work and business data
- Vendor-Managed Inventory (VMI): customer and site selected, product identifiers, names and codes, counted quantities, how each entry was added (search, typed code, or QR scan), free-text notes you write, and start/end/submit timestamps.
- Driver: scanned work-order barcode/QR token, trip and stop identifiers, stop event types (reached, service started, finished, skipped), the reason/excuse you select when skipping a stop, and event timestamps.
- Cached copies of customer names, addresses, site coordinates, product catalogues and work orders, downloaded so the app keeps working offline.
3.3 Technical data
- GPS accuracy and the mock-location indicator described in Section 2.1.
- Network connectivity state (used only on-device to decide when to retry uploads).
- Standard network information inherent to any internet request to our servers, such as your IP address and request timestamps, recorded in server logs.
The app contains no analytics SDK, no crash-reporting SDK, no advertising SDK, and no third-party trackers. Verbose diagnostic logging inside the app is compiled out of release builds.
4. Permissions the app requests, and why
Android
| Permission | Why it is needed |
|---|---|
ACCESS_FINE_LOCATION | Precise location for proof of presence, nearby customers, and trip tracking |
ACCESS_COARSE_LOCATION | Approximate location fallback for the same purposes |
ACCESS_BACKGROUND_LOCATION | Continue trip tracking while the app is in the background or closed, during an active delivery trip only |
FOREGROUND_SERVICE, FOREGROUND_SERVICE_LOCATION | Run the trip-tracking service with a visible, ongoing notification |
POST_NOTIFICATIONS | Display the tracking notification and operational alerts |
CAMERA | Live QR/barcode scanning of work orders and product codes; no photo is captured or stored |
INTERNET | Communicate with Gabco servers |
WAKE_LOCK | Keep location uploads reliable during an active trip |
RECEIVE_BOOT_COMPLETED | Allow the tracking service to be restored after a device restart |
iOS
| Permission string | Why it is needed |
|---|---|
NSLocationWhenInUseUsageDescription | Location while using the app, for nearby customer sites and trip/visit events |
NSLocationAlwaysAndWhenInUseUsageDescription / NSLocationAlwaysUsageDescription | Background location while a delivery trip is active |
UIBackgroundModes: location | Continue trip tracking in the background |
NSCameraUsageDescription | Live QR/barcode scanning |
Denying a permission does not stop you from signing in, but features that depend on it will not be available.
5. Legal basis and the employment context
The app processes personal data in the context of your employment or contracting relationship with Gabco. Depending on where you are located, our legal basis is one or more of:
- performance and administration of your employment or service contract;
- our legitimate interests in verifying that field work was performed, coordinating deliveries, informing customers of arrival times, protecting company and customer assets, and resolving operational disputes;
- compliance with legal obligations (for example, records of work performed);
- consent, where required by law for background location collection — which you may withdraw at any time by revoking the permission (see Section 2.6), accepting that location-dependent features will then stop working.
In Canada, we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. Where the EU/UK GDPR applies, Gabco acts as the data controller for this processing.
7. International transfers
Gabco’s servers and hosting providers may be located outside your country of residence, including in Canada, the United States, and the European Union. Where personal data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms, and the data remains protected under this policy.
8. Security
- All communication between the app and Gabco servers uses HTTPS/TLS encryption.
- Session tokens are stored in the operating system’s secure credential store (Android Keystore-backed storage / iOS Keychain) and are erased on sign-out.
- Your password is never written to device storage.
- Application data on the device is protected by the operating system’s app sandbox and by your device passcode/biometric lock. Please keep a device lock enabled.
- Verbose diagnostic logging is disabled in release builds so that location and customer data are not written to device logs.
- Access to location and work records in our backend is restricted to authorized personnel.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Data retention and deletion
| Data | Retention |
|---|---|
| Session token on device | Until sign-out, session expiry, or app uninstall |
| Pending (offline) visit records on device | Until successfully uploaded, then removed |
| Cached customers, products and work orders on device | Until refreshed, overwritten, or the app is uninstalled |
| Visit records, trip records, location proofs and trip location trails on our servers | For as long as required for operational, accounting, contractual and legal purposes, then deleted or anonymized |
| Server access logs | For a limited period for security and troubleshooting |
Uninstalling the app removes all data the app stored on your device. It does not delete records already submitted to Gabco’s business systems.
10. Your rights
Subject to applicable law, you may request to:
- access the personal data we hold about you, including your location records;
- correct inaccurate data;
- delete data, where we are not required to retain it for legal, contractual or legitimate business reasons;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent;
- receive a copy of data you provided, in a portable format;
- complain to your local data protection authority — in Canada, the Office of the Privacy Commissioner of Canada or your provincial commissioner.
To exercise these rights, contact us using the details in Section 13. We will respond within the timeframe required by applicable law. Because this is a workplace application, some records (such as proof that work was performed) must be retained by Gabco even if you leave the organization.
11. Children
This app is intended solely for use by Gabco employees and authorized contractors who are adults. It is not directed at children, and we do not knowingly collect personal information from anyone under 16 years of age.
12. Changes to this policy
We may update this policy from time to time. When we do, we will change the “Last updated” date above and publish the revised policy at this same URL. If we make a material change to how location data is collected or used, we will provide additional notice — for example, an in-app notice — before that change takes effect.
13. Contact us
If you have questions about this policy, or wish to exercise your privacy rights, contact Gabco’s privacy contact:
Gabco Group
236 Lowson Crescent
Winnipeg, Manitoba R3P 2H8
Canada
Email: info@gabcogroup.com
Phone: (833) 542-4144
Web: gabcogroup.com
Appendix A — App store declarations
This appendix aligns this policy with the disclosures made in the app stores.
Google Play — Data safety
Location
- Approximate location — Collected, not shared, required. Purpose: App functionality. Not used for advertising or analytics.
- Precise location — Collected, not shared, required. Purpose: App functionality. Not used for advertising or analytics.
- Collected in the background while a delivery trip is active.
- Data is encrypted in transit. Users can request deletion (see Section 10).
Personal info — Name, Email address, User IDs: collected, not shared, required. Purpose: account management, app functionality.
App activity / Other — visit and trip records (in-app actions and free-text notes): collected, not shared, required. Purpose: app functionality.
Not collected: photos and videos, contacts, calendar, messages, health and fitness, financial info, browsing history, advertising ID, crash logs, diagnostics/analytics.
Background location justification (Play Console): background location is used only while a driver has explicitly started a delivery trip, to provide dispatch with live trip progress and ETAs and to record arrival/departure at each stop. It is disclosed in-app before it is enabled, requires the user’s acceptance, runs as a foreground service with a persistent notification, and is stopped when the trip finishes.
Apple — App Privacy (“Data Used to Track You”: None)
Data linked to the user, used for App Functionality only:
- Location — Precise Location, Coarse Location (including background collection during active trips)
- Contact Info — Name, Email Address
- Identifiers — User ID
- Usage Data / Other Data — work records created in the app
No data is used for tracking, advertising, or third-party analytics.