Privacy Policy
This Privacy Policy describes how Klaassen Group ("we," "us," or "our") collects, uses, and shares personal information through the Klaassen Group mobile app (the "App"). The App is provided to current employees of Klaassen Group and its operating companies for workforce-management purposes including timecards, vacation requests, push notifications, training, policy attestation, parts requisitions, and tool tracking.
This policy is intended to satisfy our obligations under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Apple's App Store privacy disclosure requirements. It covers the App only — separate notices govern data we hold about you in our internal HR and administrative systems, which are not accessible through the App.
1. Information the App collects
Below is every category of personal information the App collects from your device or transmits on your behalf, mapped to Apple's App Privacy framework. Unless otherwise stated, all information is linked to your identity as an employee, and none of it is used to track you across other companies' apps or websites.
Contact information
- Full name — displayed in the App and used in notifications.
- Work email address — used to sign you in.
- Phone number — used for SMS one-time-password sign-in.
- Physical address — you may add or update your address in the profile screen so HR has a current record on file.
Identifiers
- Internal user ID — used to associate every record you create or interact with.
- Push notification token — issued to the App by your device's operating system and registered with our servers so we can send push notifications.
- Authentication token — a long-lived bearer token kept on your device so you stay signed in between sessions.
Precise location
- GPS coordinates (latitude and longitude) sampled only at the moment you clock in or clock out on a timecard, and only if you have granted the App location permission. The App does not track your location at any other time. The reading is associated with the punch event so we can verify the worksite for payroll purposes.
User content
- Profile photo, if you upload one. Stored privately on our server and accessible only through authenticated App requests — never published to the public web.
- Free-text content you enter inside the App: timecard comments, vacation request reasons, tool-incident descriptions (lost or broken tools), parts requisition notes, and performance review responses.
Financial information (employment-related)
- Job and cost-code allocation you select when submitting a timecard. This identifies which project your hours belong to. The App does not collect or display salary, hourly rate, banking, or payment-card information.
Usage data
- Authentication events (sign-in, sign-out, OTP requests) recorded with the IP address and user-agent string of the request, for audit and abuse-prevention.
- Notification delivery preferences you set (whether you've opted in to SMS, push, or in-app notifications).
Diagnostics
- Server-side error logs, which may include user IDs to assist with troubleshooting.
- Aggregated, anonymized request metrics retained for seven days.
The App does not collect health or fitness data, your phone's contacts, browsing or search history, or any data used to track you across other apps or websites.
2. How we use what the App collects
- To provide the App — sign you in, display your timecards, deliver notifications, render the directory of your coworkers.
- To process workforce-management activities — payroll preparation, vacation tracking, tool accountability, and similar internal functions on the back end.
- To verify worksite attendance — clock-in/clock-out GPS coordinates are used to associate punches with a worksite. Location is not sampled at any other time.
- To secure the App — authentication logs and IP-based rate limits help us detect abuse.
- To meet legal obligations — for example, retaining payroll records for the period required by federal and provincial labour law.
3. Who the App shares information with
The App relies on the following third-party providers solely to operate. Each receives only the data needed to perform its function and is bound by its own privacy and security commitments.
| Provider | What they receive | Purpose |
|---|---|---|
| Twilio | Your phone number, the OTP code we issue, and the body of any operational SMS we send (which may include your name and event details such as a timecard date or a tool ID) | SMS delivery for one-time-password sign-in and operational notifications |
| Firebase Cloud Messaging (Google) | Your device's push token and the push payload (titles and bodies that may include your name and the subject of the notification) | Push notification delivery to your mobile device |
The App does not send your information to advertisers, analytics providers, attribution networks, or AI/ML services. We do not sell your personal information.
4. How we protect what the App collects
- Data is encrypted in transit (HTTPS/TLS) between your device and our servers.
- Authentication is enforced by long-lived bearer tokens stored on your device and revoked on sign-out. SMS one-time passwords expire after ten minutes.
- Profile photos are stored on a private server volume and are accessible only through authenticated App requests.
- Access to the data behind the App is restricted to authorized employees and contractors who need it to perform their work.
5. Your rights under PIPEDA
You may at any time:
- Access — request a copy of the personal information we hold about you.
- Correct — request correction of inaccurate or incomplete information.
- Withdraw consent — withdraw consent for specific uses where consent is the lawful basis. Some processing is necessary for your employment relationship and cannot be withdrawn while you remain employed.
- Complain — direct a privacy complaint to us, and if unresolved, to the Office of the Privacy Commissioner of Canada.
To exercise these rights, contact us using the details in Section 8.
6. How long we keep what the App collects
- Active employment records are retained for the duration of your employment.
- Records required by law (such as payroll) are retained for the period required by applicable federal and provincial law after your employment ends.
- Authentication tokens are deleted when you sign out of the App.
- One-time-password records expire ten minutes after issuance and are removed by an automated cleanup job that runs daily.
- Diagnostic logs are retained for a maximum of ninety days; aggregated request metrics for seven days.
7. Children's privacy
The App is intended exclusively for use by adult employees of Klaassen Group and its operating companies. We do not knowingly collect information from children under the age of majority.
8. Contact us
For privacy questions, requests, or complaints, contact our Privacy Office at:
Klaassen GroupPrivacy Office
privacy@klaassengroup.com
9. Changes to this policy
We may update this policy from time to time. The "Effective" date at the top of this page indicates when the latest version took effect. If we make material changes that affect data the App collects, we will notify you through the App.