This Privacy Policy applies to the MS Core Tech Face Attendance mobile application (developed by MS Core Tech, "we", "our", or "Us"). It governs how personal, location, and facial biometric information is collected, processed, cached, and secured across our Flutter mobile application, administrative cloud portals, and underlying backend services.
The application serves enterprise clients, employers, and educational institutions ("Organizations" or "Data Controllers") to manage employee/student attendance, prevent time spoofing, enforce workplace geofences, and automate shift management.
To deliver touchless biometric verification and site-bound attendance marking, the application requests specific runtime hardware permissions and processes the following data categories:
| Data Category & Permission | Specific Technical Elements | Operational Purpose |
|---|---|---|
Camera Permissionandroid.permission.CAMERA
|
Real-time camera video frame stream, facial landmark bounding boxes, facial capture images during registration/punching. | Detecting facial structures using Google ML Kit to execute touchless 1:N attendance identification. |
Location ServicesACCESS_FINE_LOCATIONACCESS_COARSE_LOCATION
|
GPS Latitude, Longitude, location accuracy metrics, geofence radius boundary check, reverse geocoded street address. | Validating whether employee is within designated workplace office/branch geofence coordinates during clock-in/out. |
Push NotificationsPOST_NOTIFICATIONS
|
Firebase Cloud Messaging (FCM) push token, notification channel IDs, device OS notification permissions. | Delivering instant shift status alerts, punch confirmation receipts, broadcast announcements, and reminders. |
| Profile & Roster Data | Full Name, Mobile Phone / Contact Number, Email Address, Designation, Employee/User ID, Branch ID. | User authentication, OTP session verification, roster binding, and payroll attendance report generation. |
| Local Storage & Device Data | Device model, OS version, SQLite local database (via sqflite), Shared Preferences state, network sync queue. |
Offline attendance queueing when internet is unavailable, local session persistence, and system diagnostics. |
We recognize the sensitive nature of facial biometric data. The MS Core Tech Face Attendance app implements strict privacy-by-design standards in accordance with global biometric standards and Google Play Console policies:
Facial recognition is powered by Google ML Kit Face Detection. Camera frames are processed to locate facial landmarks (eyes, nose, contours) and generate non-reconstructible mathematical vector embeddings. We never store raw video recordings, and feature vectors cannot be converted back into a photograph.
- Zero Passive Camera Recording: Camera access is active ONLY when the user or administrator explicitly opens the facial recognition/registration camera view.
- Purpose Limitation: Biometric facial templates are strictly restricted to identity verification for attendance tracking. They are never shared, sold, rented, or used for advertising, surveillance, or third-party profiling.
- Secure Transmission & Storage: Biometric feature vectors are encrypted using TLS 1.3 in transit and stored in protected, access-controlled cloud database partitions.
The MS Core Tech Face Attendance application utilizes precise location services (via geolocator, google_maps_flutter, and geocoding plugins) to enforce authorized work-site attendance:
Location coordinates (Latitude & Longitude) are requested only at the moment of clock-in, clock-out, or break logs to verify that the punch occurs within the organization's approved geofence perimeter. The app does not track your continuous location in the background when the app is closed.
- Anti-Spoofing & Fraud Prevention: Location metadata prevents proxy attendance, mock-location exploits, and remote clock-in fraud.
- Reverse Geocoding: Latitude and longitude coordinates are converted into readable site/office address labels for administrative attendance logs.
The app incorporates Firebase Cloud Messaging (firebase_messaging) and local notification handlers (flutter_local_notifications) under the POST_NOTIFICATIONS runtime permission:
- Notification Types: Attendance clock-in confirmation receipts, shift schedule updates, break reminders, and official broadcast alerts.
- FCM Token Handling: Unique Firebase Cloud Messaging tokens are registered with the server to target messages to your specific device. Tokens are refreshed periodically and automatically cleared upon logout.
- User Preference Control: Push notification permissions can be granted or revoked at any time through Android/iOS device settings.
We process collected information under the following legitimate operational grounds:
- Executing touchless, fast, and secure workplace clock-in/out attendance recording.
- Validating attendance authenticity against designated office/branch geofenced locations.
- Generating verified timecard reports, total hours worked, and overtime calculations for enterprise payroll processing.
- Sending shift notifications and attendance reminders via Firebase Cloud Messaging.
- Caching attendance punches locally in an encrypted SQLite database during network outages and syncing seamlessly once connected.
- Authenticating authorized user sessions using cryptographically signed JSON Web Tokens (JWT) and secure OTP validation.
MS Core Tech does NOT sell, rent, monetize, or trade user personal or biometric data under any circumstances. Data disclosures are strictly limited to necessary service operations:
- Your Employing Organization: Designated organization administrators, HR officers, and branch managers have access to employee roster details and time logs as dictated by employment contracts.
- Google Firebase Services: Firebase Core and Firebase Cloud Messaging for infrastructure notifications subject to Google Cloud Privacy terms.
- Google Maps Platform: Geocoding and location display components for verifying address and geofence coordinates.
- Legal Compliance: Where required by statutory labor regulations, law enforcement subpoenas, or court orders under applicable law.
Data retention timelines adhere strictly to organizational governance and employment record standards:
- Active Account Status: Facial reference templates and profile records remain active throughout an employee's period of service or enrollment.
- Account Termination & Biometric Deletion: Upon employee termination or account deactivation by an Organization Administrator, biometric facial vectors are immediately purged from active recognition indexes.
- Historical Attendance Logs: Timestamped punch logs and location-stamped check-in records are retained for statutory wage and labor compliance periods established by your employer.
We enforce multi-layered administrative, technical, and physical security measures to safeguard data against unauthorized access or disclosure:
All API communications are encrypted via TLS 1.3. Biometric templates and database entries are stored encrypted at rest.
User passwords and security credentials are hashed using salted bcrypt algorithms (10 rounds minimum).
Offline attendance logs in SQLite (sqflite) are stored within protected sandbox directories.
Role-Based Access Control ensures complete multi-tenant data isolation between different customer organizations.
Depending on applicable national and regional privacy statutes (including GDPR, CCPA, and statutory data protection laws), users maintain the following rights:
- Right to Access: View historical attendance timestamps, geofence logs, and profile records inside the app dashboard.
- Right to Rectification: Request correction of inaccurate employee profile details through organization administrators.
- Right to Biometric Erasure: Request permanent removal of facial feature templates upon resignation or departure.
- Permission Controls: Grant or revoke Camera, Location, and Push Notification runtime permissions via device Settings at any time.
If you have questions regarding this Privacy Policy, biometric processing, or wish to exercise data protection rights, please contact your Organization's HR / IT department or MS Core Tech Data Privacy Desk:
Company: MS Core Tech
Support Desk Email: sales@abucomputers.com
Compliance Desk: sales@abucomputers.com