RETA One

Privacy Policy

Last updated July 29, 2026

RETA One is an offline-first attendance app used by field supervisors to record worker time and attendance by scanning QR badges. This policy explains what information the app collects, how it is used, and who to contact with questions.

Effective: July 30, 2026  ·  App ID: com.swifttechglobix.retaone

Contents

  1. Scope of this policy
  2. Information we collect
  3. Device permissions
  4. How information is used
  5. Offline storage & encryption
  6. Data sharing
  7. Data retention
  8. Access & deletion requests
  9. Security
  10. Children's privacy
  11. Changes to this policy
  12. Contact

1. Scope of this policy

RETA One is a business tool, not a consumer social app. It has two kinds of people in its data flow, and this policy covers both:

  • Supervisors — the person who signs in on the phone and uses it to run a shift. Supervisors are given the app by their employer.
  • Workers — the employees a supervisor scans in and out. Workers do not install or log into the app themselves; their attendance data is entered by the supervisor on their behalf, as part of their employer's normal time-and-attendance record-keeping.

Because RETA One is deployed by an employer to its own supervisors, the employer (the organization operating RETA One) is the data controller for worker records. This policy describes what the app itself collects and does with that data on the device and in transit to the backend.

2. Information we collect

Supervisor account data

  • Email address and password, used to sign in.
  • Supervisor name and employee number, returned by the backend after login.

Attendance data (captured per scan)

  • Worker identifier read from a QR badge, or entered manually as a fallback ID check.
  • Clock-in / clock-out direction and timestamp.
  • A short audit photo taken at the moment of the scan.
  • The GPS location and nearby Wi-Fi network name (SSID) at the time of the scan, used to automatically detect which job site the scan happened at.
  • Exception flags — for example, an unrecognized badge or a scan outside the expected site boundary — and any reason a supervisor selects to resolve one.

Device data

  • A device identifier generated on the device itself, used only to tag which phone a batch of attendance records came from during sync.

RETA One does not collect contacts, browsing history, or any data unrelated to running a shift, and it contains no advertising or analytics SDKs.

3. Device permissions

The Android app requests the following permissions. Each exists to support a specific, visible feature — none run in the background for unrelated purposes.

PermissionUsed for
CAMERAScanning QR badges and capturing the per-scan audit photo.
ACCESS_FINE_LOCATION
ACCESS_COARSE_LOCATION
Detecting which job site a scan session is happening at, and flagging scans outside the expected site boundary.
ACCESS_WIFI_STATE
NEARBY_WIFI_DEVICES
CHANGE_WIFI_STATE
Reading the connected Wi-Fi network name as a secondary signal for site detection.
INTERNET
ACCESS_NETWORK_STATE
Syncing queued attendance records and photos to the backend when a connection is available.

4. How information is used

Attendance data collected on the device is used solely to produce a workforce time and attendance record for the employer: who was on site, when, and where. Location and Wi-Fi data are used only to auto-select the correct job site for a scan session, not to track a supervisor's or worker's movement outside of that purpose.

5. Offline storage & encryption

RETA One is built to work with no signal for extended periods. Every scan is written immediately to an encrypted local database on the device (SQLCipher). Nothing is held in plaintext on disk. When the device regains connectivity, queued records — and, on a lower priority queue, photos — sync to the backend in the background, without interrupting scanning for the next worker.

6. Data sharing

Attendance data is transmitted only to RETA One's own backend (api.reta1ne.com) that the employer's supervisors sign into. It is not sold, not shared with advertisers, and not passed to any third-party analytics or marketing service — the app does not include any such SDKs.

7. Data retention

Attendance records remain on the device, encrypted, until they successfully sync to the backend, after which they continue to exist as part of the employer's attendance history. Retention of that synced record is governed by the employer's own record-keeping obligations and settings on the backend, not by the mobile app itself.

8. Access & deletion requests

A worker who wants to review, correct, or request deletion of their attendance records should start with their employer's supervisor or HR contact, since the employer holds the underlying record. Supervisors, or anyone with a question this policy doesn't answer, can reach us directly using the contact details below.

9. Security

Attendance data is encrypted at rest on the device and transmitted over an encrypted connection during sync. Supervisor sessions use token-based authentication rather than storing a reusable password on the device.

10. Children's privacy

RETA One is a workplace tool intended for use by adult supervisors managing an adult workforce. It is not directed at children, and we do not knowingly collect data from children through the app.

11. Changes to this policy

If how RETA One collects or uses data changes, this page will be updated and the effective date at the top will change to match. Continued use of the app after an update means you accept the revised policy.

12. Contact

Questions about this policy or how RETA One handles data can be sent to:

RETA One
rudolf@rudolfgoosen.co.za


This document is the privacy policy for the RETA One mobile application (com.swifttechglobix.retaone), published for use in app store and app gallery listings.