Gabco Group

Privacy Policy — Gabco Mobile App

App name:
Gabco (Gabco Mobile App)
Package / Bundle ID:
com.gabco.mobileapp
Effective date:
6 August 2026
Last updated:
6 August 2026

This app collects location data — including precise location and location in the background. Section 2 sets out exactly what is collected, when, why, where it is sent, and how to turn it off. Location data is never sold and is never shared with advertisers, data brokers, or analytics providers.

1. Summary — what this app collects

The Gabco Mobile App is a workforce application for Gabco employees and authorized contractors. It is not a consumer app; you must sign in with an employee account issued by Gabco to use any feature.

Data typeCollected?Shared with third parties?Purpose
Location — precise (GPS)YesNo (processed by our hosting providers only)Proof of presence at customer sites, nearby-customer lists, delivery trip tracking
Location — approximateYesNoSame as above; used when the operating system supplies a coarse fix
Location — in the backgroundYesNoOnly while a delivery trip is active: live trip progress and ETA for dispatch, arrival/departure records
Email address / account credentialsYesNoSign-in and authentication
Name, employee ID, job title, organizationYesNoAttribution of work records
Work activity (visits, inventory counts, notes, scans, trip and stop events)YesNoCore business function
Camera imagesNoNoThe camera is used live for QR/barcode scanning; no image is captured, stored, or transmitted
Advertising / marketing identifiersNo
Analytics, crash-reporting or tracking SDKsNo
Contacts, calendar, photos, microphone, SMS, call logs, health dataNo

We do not sell your personal information, and we do not use it for advertising, marketing, or profiling.

2. Location data — full disclosure

This section describes, in detail, every way the app accesses, collects, uses, transmits, stores and retains location data. Location is central to how the app works and is disclosed here in full.

2.1 What location data we access

  • Precise location (GPS) — latitude, longitude and horizontal accuracy in metres.
  • Approximate (coarse/network) location — used when the operating system supplies a coarse fix instead of a precise one.
  • Location in the background — collected while a delivery trip is active, including when the app is minimized, the screen is off, or the app is not in use.
  • Timestamp of each location reading (UTC).
  • A “mock location” indicator — a true/false signal from the operating system (Android) telling us whether the reading came from a fake/spoofed-GPS app. Used only to protect the integrity of proof-of-presence records.

We do not collect location history when you are not signed in, not on an active trip, and not performing a location-gated action.

2.2 When and how often location is collected

SituationWhat happensFrequency
You open the nearby customers list (VMI)A single location reading is taken on-device to sort and show customers near youOne reading per refresh
You start or submit a customer visit (VMI)A single location reading is captured and sent to our servers as “location proof”One reading per action
You scan a work order, start a trip, mark a stop reached / service started / finished / skipped, or finish a trip (Driver)A single location reading is captured and sent as “location proof” for that eventOne reading per action
A delivery trip is active (Driver)Continuous background location tracking runs and uploads your position to our serversApproximately every 10 seconds until you finish the trip
App is installed but you are signed out, idle, or no trip is activeNo location is collected. Background tracking is stopped and does not runNever

Background tracking starts only after you explicitly start a delivery trip, and stops when you finish that trip, when you sign out, or when the tracking service is stopped.

2.3 Why we collect it (purposes)

  1. Proof of presence / work verification — to confirm that a customer visit or delivery stop event genuinely took place at the customer location. The app compares your position against the customer’s coordinates and normally requires you to be within 100 metres.
  2. Finding nearby customers — to sort and display the customer sites closest to you.
  3. Live trip progress and ETAs — so dispatch and operations staff can see where an active delivery trip is and inform customers of arrival times.
  4. Arrival and departure records — to timestamp and geo-stamp each stop for operational and dispute-resolution records.
  5. Integrity of records — to detect and reject spoofed/mock GPS readings.

Location data is not used for employee surveillance outside working trips, for advertising, for building marketing profiles, or for any purpose unrelated to the operational functions above.

2.4 Override of the location check

Some employee accounts are granted a “GPS override” permission by Gabco. If your account has it and you are further than 100 metres from the expected site, you may choose to proceed anyway. If you do, your actual current location is still captured and sent to our servers with that action, and the record is flagged accordingly.

2.5 Where location data goes

Location readings are transmitted over an encrypted HTTPS/TLS connection to Gabco’s own backend systems at gabcobusinesssolutions.com (production) and gabcoerp.tecfy.co (test), which are operated for Gabco by our hosting providers. Location data:

  • is stored in Gabco’s business systems as part of your visit and trip records;
  • is visible to authorized Gabco staff (dispatch, operations, supervisors, administrators);
  • is not sold, rented, or shared with advertisers, data brokers, or analytics companies.

2.6 Background-location notice and controls

  • Before background tracking is enabled, the app shows an in-app disclosure explaining that Gabco collects location in the background during an active delivery trip, even when the app is closed or not in use, and asks you to accept.
  • You must separately grant the operating system’s location permission — on Android, “Allow all the time” for background tracking; on iOS, the “Always” permission.
  • On Android, a persistent notification (“Gabco trip tracking”) is displayed the entire time background tracking is running. On iOS, the system background-location indicator is shown.
  • You can revoke location permission at any time in device settings (Android: Settings → Apps → Gabco → Permissions → Location; iOS: Settings → Gabco → Location). If you revoke it, location-gated features — starting or submitting visits, scanning work orders, recording stop events, and trip tracking — will not function, because verified location is required for those records.

2.7 Retention of location data

  • On your device: location captured for a visit that has not yet been uploaded (for example, while you are offline) is kept in the app’s local database until the record is successfully submitted, after which the pending copy is removed. Uninstalling the app deletes all local app data.
  • On our servers: location proofs and trip location trails are retained as part of the associated business record (visit, trip, delivery) for as long as that record is needed for operational, accounting, contractual and legal purposes, and then deleted or anonymized in line with Gabco’s records-retention schedule.

3. Other data we collect

3.1 Account and identity data

  • Email address and password (the password is transmitted to our authentication endpoint to verify you; it is not stored on the device).
  • Employee ID, display name, first/last name, job title, organization ID.
  • Role and feature flags (for example whether VMI is enabled for you, whether GPS override is permitted).
  • An access token representing your signed-in session, stored on the device in the operating system’s secure credential store (Android Keystore-backed storage / iOS Keychain) and deleted when you sign out.

3.2 Work and business data

  • Vendor-Managed Inventory (VMI): customer and site selected, product identifiers, names and codes, counted quantities, how each entry was added (search, typed code, or QR scan), free-text notes you write, and start/end/submit timestamps.
  • Driver: scanned work-order barcode/QR token, trip and stop identifiers, stop event types (reached, service started, finished, skipped), the reason/excuse you select when skipping a stop, and event timestamps.
  • Cached copies of customer names, addresses, site coordinates, product catalogues and work orders, downloaded so the app keeps working offline.

3.3 Technical data

  • GPS accuracy and the mock-location indicator described in Section 2.1.
  • Network connectivity state (used only on-device to decide when to retry uploads).
  • Standard network information inherent to any internet request to our servers, such as your IP address and request timestamps, recorded in server logs.

The app contains no analytics SDK, no crash-reporting SDK, no advertising SDK, and no third-party trackers. Verbose diagnostic logging inside the app is compiled out of release builds.

4. Permissions the app requests, and why

Android

PermissionWhy it is needed
ACCESS_FINE_LOCATIONPrecise location for proof of presence, nearby customers, and trip tracking
ACCESS_COARSE_LOCATIONApproximate location fallback for the same purposes
ACCESS_BACKGROUND_LOCATIONContinue trip tracking while the app is in the background or closed, during an active delivery trip only
FOREGROUND_SERVICE, FOREGROUND_SERVICE_LOCATIONRun the trip-tracking service with a visible, ongoing notification
POST_NOTIFICATIONSDisplay the tracking notification and operational alerts
CAMERALive QR/barcode scanning of work orders and product codes; no photo is captured or stored
INTERNETCommunicate with Gabco servers
WAKE_LOCKKeep location uploads reliable during an active trip
RECEIVE_BOOT_COMPLETEDAllow the tracking service to be restored after a device restart

iOS

Permission stringWhy it is needed
NSLocationWhenInUseUsageDescriptionLocation while using the app, for nearby customer sites and trip/visit events
NSLocationAlwaysAndWhenInUseUsageDescription / NSLocationAlwaysUsageDescriptionBackground location while a delivery trip is active
UIBackgroundModes: locationContinue trip tracking in the background
NSCameraUsageDescriptionLive QR/barcode scanning

Denying a permission does not stop you from signing in, but features that depend on it will not be available.

6. Who we share data with

We share personal data only in these limited cases:

  • Within Gabco — with authorized supervisors, dispatch, operations and administrative staff who need it to run the business.
  • Hosting and infrastructure providers — the companies that operate the servers and databases on which the Gabco backend runs, acting on our instructions as processors.
  • Map tiles — the driver map screens load map imagery from the OpenStreetMap public tile service (tile.openstreetmap.org). This request reveals your device’s IP address and the map area being viewed to that service. Your identity, your GPS trail, and your work records are not sent to it.
  • External navigation apps — if you tap “navigate” for a stop, the app hands the destination address coordinates to Apple Maps or Google Maps on your device. That app then operates under its own privacy policy. Your Gabco account data is not passed to it.
  • Customers and business partners — limited operational information such as expected arrival time or confirmation that a delivery was made.
  • Legal and safety — where we are required to disclose by law, regulation, or legal process, or to protect the rights, property or safety of Gabco, our employees, or others.
  • Business transfers — in a merger, acquisition or asset sale, subject to this policy continuing to apply.

We do not sell personal information, and we do not disclose personal information for cross-context behavioural advertising.

7. International transfers

Gabco’s servers and hosting providers may be located outside your country of residence, including in Canada, the United States, and the European Union. Where personal data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms, and the data remains protected under this policy.

8. Security

  • All communication between the app and Gabco servers uses HTTPS/TLS encryption.
  • Session tokens are stored in the operating system’s secure credential store (Android Keystore-backed storage / iOS Keychain) and are erased on sign-out.
  • Your password is never written to device storage.
  • Application data on the device is protected by the operating system’s app sandbox and by your device passcode/biometric lock. Please keep a device lock enabled.
  • Verbose diagnostic logging is disabled in release builds so that location and customer data are not written to device logs.
  • Access to location and work records in our backend is restricted to authorized personnel.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

9. Data retention and deletion

DataRetention
Session token on deviceUntil sign-out, session expiry, or app uninstall
Pending (offline) visit records on deviceUntil successfully uploaded, then removed
Cached customers, products and work orders on deviceUntil refreshed, overwritten, or the app is uninstalled
Visit records, trip records, location proofs and trip location trails on our serversFor as long as required for operational, accounting, contractual and legal purposes, then deleted or anonymized
Server access logsFor a limited period for security and troubleshooting

Uninstalling the app removes all data the app stored on your device. It does not delete records already submitted to Gabco’s business systems.

10. Your rights

Subject to applicable law, you may request to:

  • access the personal data we hold about you, including your location records;
  • correct inaccurate data;
  • delete data, where we are not required to retain it for legal, contractual or legitimate business reasons;
  • restrict or object to certain processing;
  • withdraw consent where processing is based on consent;
  • receive a copy of data you provided, in a portable format;
  • complain to your local data protection authority — in Canada, the Office of the Privacy Commissioner of Canada or your provincial commissioner.

To exercise these rights, contact us using the details in Section 13. We will respond within the timeframe required by applicable law. Because this is a workplace application, some records (such as proof that work was performed) must be retained by Gabco even if you leave the organization.

11. Children

This app is intended solely for use by Gabco employees and authorized contractors who are adults. It is not directed at children, and we do not knowingly collect personal information from anyone under 16 years of age.

12. Changes to this policy

We may update this policy from time to time. When we do, we will change the “Last updated” date above and publish the revised policy at this same URL. If we make a material change to how location data is collected or used, we will provide additional notice — for example, an in-app notice — before that change takes effect.

13. Contact us

If you have questions about this policy, or wish to exercise your privacy rights, contact Gabco’s privacy contact:

Gabco Group

236 Lowson Crescent
Winnipeg, Manitoba R3P 2H8
Canada

Email: info@gabcogroup.com
Phone: (833) 542-4144
Web: gabcogroup.com

Appendix A — App store declarations

This appendix aligns this policy with the disclosures made in the app stores.

Google Play — Data safety

Location

  • Approximate locationCollected, not shared, required. Purpose: App functionality. Not used for advertising or analytics.
  • Precise locationCollected, not shared, required. Purpose: App functionality. Not used for advertising or analytics.
  • Collected in the background while a delivery trip is active.
  • Data is encrypted in transit. Users can request deletion (see Section 10).

Personal info — Name, Email address, User IDs: collected, not shared, required. Purpose: account management, app functionality.

App activity / Other — visit and trip records (in-app actions and free-text notes): collected, not shared, required. Purpose: app functionality.

Not collected: photos and videos, contacts, calendar, messages, health and fitness, financial info, browsing history, advertising ID, crash logs, diagnostics/analytics.

Background location justification (Play Console): background location is used only while a driver has explicitly started a delivery trip, to provide dispatch with live trip progress and ETAs and to record arrival/departure at each stop. It is disclosed in-app before it is enabled, requires the user’s acceptance, runs as a foreground service with a persistent notification, and is stopped when the trip finishes.

Apple — App Privacy (“Data Used to Track You”: None)

Data linked to the user, used for App Functionality only:

  • Location — Precise Location, Coarse Location (including background collection during active trips)
  • Contact Info — Name, Email Address
  • Identifiers — User ID
  • Usage Data / Other Data — work records created in the app

No data is used for tracking, advertising, or third-party analytics.