Sassy

Privacy Policy

Effective date: 15 July 2026  ·  Last updated: 15 July 2026

Sassy is a workforce management platform (web and mobile app) that helps organisations run attendance, leave, payroll, documents, and related HR operations. This Privacy Policy explains what information the Sassy app and services collect, how it is used, and the choices you have.

Who controls your data. Sassy is provided to you through your employer or organisation. In most cases your employer is the “data controller” and decides what data is collected and why; Sassy acts as a “data processor” that handles the data on their instructions. For questions specific to how your organisation uses Sassy, please also contact your HR/administrator. Sassy is the controller for account security, platform operation, and improving the service.
Contents
  1. Information we collect
  2. How we use information
  3. App permissions
  4. Location data
  5. Camera & biometric (face) data
  6. How we share information
  7. Data retention
  8. Security
  9. Your rights & choices
  10. Children
  11. Changes & contact

1. Information we collect

We collect only what is needed to run the workforce features your organisation has enabled:

Account & profile

Name, work email, phone number, employee code, profile photo, designation, department, location/branch, and login credentials (passwords are stored only as secure hashes).

Employment & HR records

Attendance and check-in/out records, leave and shift data, performance and onboarding information, and documents you or your employer upload.

Identity & statutory information

Where your employer requires it for payroll and legal compliance, we process identifiers such as PAN, Aadhaar, UAN, ESIC number, and bank account details.

Location information

When enabled by your employer and permitted by you, GPS location for attendance check-in, geo-fence validation, and — if your employer turns it on — work-hour route/field tracking. See section 4.

Camera & biometric information

For selfie check-in and optional Face ID attendance/login, we process facial images and a mathematical face template to verify your identity. See section 5.

Device & technical information

Device model, operating system, app version, battery level, network type, IP address, and integrity signals (such as rooted-device or mock-location detection) used to keep attendance trustworthy.

Usage information

Features used, actions taken, and system logs, to operate and improve the service.

2. How we use information

We do not sell your personal data, and we do not use it for third-party advertising.

3. App permissions (mobile)

Each permission is optional at the device level and can be changed in your device settings; some features will not work without the related permission.

4. Location data

Location is collected to record where an attendance action occurs, to confirm you are within an authorised office geo-fence, and, where your employer enables it, to map your route during working hours. Location is linked to your identity and is shared with your employer for these purposes. You can disable location access from your device settings; doing so may prevent GPS-based check-in. Route/field tracking, where used, applies during configured working periods.

5. Camera & biometric (face) data

If your organisation enables face-based attendance or login, the app captures a facial image and derives a face template used only to verify that it is you. Face data is not used to identify you to third parties or for any unrelated purpose, and it is not sold. Face templates are stored securely and are deleted when you leave the organisation or on a valid request, subject to any legal retention requirements. You can use password-based login instead where available.

6. How we share information

7. Data retention

We retain your information for as long as your account is active and as your employer instructs, plus any period required by law (for example, payroll and tax records). Location pings are retained for a limited, configurable window and then automatically pruned. Face templates are deleted on exit or valid request, subject to legal limits.

8. Security

We protect data with encryption in transit (HTTPS), access controls, hashed passwords, and per-organisation data isolation. No method of transmission or storage is 100% secure, but we work to protect your information and to promptly address any issues.

9. Your rights & choices

Depending on your location (including under India’s DPDP Act and, where applicable, the GDPR), you may have the right to access, correct, or delete your personal data, and to withdraw consent (for example, by turning off location or using password login instead of Face ID). Because your employer is usually the data controller, please direct such requests to your HR/administrator; Sassy will support them in responding. You may also contact us using the details below.

10. Children

Sassy is a workplace product and is not directed to, or intended for, anyone under 18 (or the local minimum working age). We do not knowingly collect data from children.

11. Changes & contact

We may update this Privacy Policy from time to time. Material changes will be posted on this page with a new effective date. If you continue to use Sassy after an update, the revised policy applies.

For privacy questions or requests, contact us at privacy@sassy.work.