Timax Mobile Privacy Policy
iOS & Android · uk.timax.mobile
UK GDPR compliant · Last updated: 25 August 2026
This policy applies only to the Timax mobile app. If you use Timax in a web browser, read the separate Website Privacy Policy.
- 1. Introduction
- 2. Who Is Responsible for Your Data
- 3. Who This App Is For
- 4. Information We Collect
- 5. Device Permissions
- 6. How We Use Your Information
- 7. Legal Bases for Processing
- 8. How We Share Information
- 9. International Transfers
- 10. Data Retention
- 11. Security
- 12. Your Choices and Controls
- 13. Account and Data Deletion
- 14. Your Rights
- 15. App Store and Google Play Disclosures
- 16. Related Policies
- 17. Changes and Contact
This Privacy Policy explains how Timax ("Timax", "we", "us", "our") collects, uses, stores, and protects personal information when you use the Timax mobile application ("the App") for iOS and Android (uk.timax.mobile).
The App is a workforce tool for security and field staff. It lets you view shifts, book on and off site, complete welfare check-ins, respond to pre-shift confirmations, capture duty evidence, receive operational alerts, and manage your account on the move.
This policy applies only to the Timax mobile app. If you use Timax in a web browser (timax.uk or your organisation subdomain), see our separate Website Privacy Policy at https://timax.uk/privacy.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Timax is a business-to-business platform. In most cases:
- Your employer or contracting organisation (the organisation that invited you to Timax) is the data controller for employment and operational data about you, such as shift records, welfare check-ins, and evidence you submit while working.
- Timax acts as a data processor, providing the technology that stores and processes that information on the organisation's instructions.
- Timax is the data controller for limited platform data needed to operate the App itself, such as your login account, device registrations, and support communications with us.
If you have questions about how your employer uses your shift or welfare data, contact your employer first. For App, account, or platform questions, contact us using the details in section 17.
The App is for staff members whose employer uses Timax. Access is by invitation or account creation through your organisation. The App is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal data from children.
Information you provide or generate in the App:
- Account details: name, email address, organisation membership, and role information returned from your Timax account
- Authentication data: email and password when you sign in (your password is transmitted securely and stored by us only as a secure hash; we never store your plain-text password on the device)
- Shift and roster data: assigned shifts, open shifts, jobs, instructions, duties, notifications, and responses such as accept, decline, or apply
- Welfare and attendance records: book-on, check-in, and book-off submissions, including timestamps, notes, and answers to configured evidence questions
- Precise location: GPS latitude, longitude, and accuracy reading when you perform book-on, check-in, book-off, panic alert, or certain pre-shift responses, or when your employer's geofence rules require location verification
- Photos: images you capture with the camera or attach from your photo library as duty or welfare evidence
- Signatures: images you draw in the App for duty or evidence completion
- Pre-shift responses: attendance confirmations submitted through secure links opened in the App
Information collected automatically:
- Device and app data: device identifier generated by the App, device platform, operating system, app version, and optional device name when you register for notifications
- Push notification token: Expo push token used to deliver alerts to your device
- Session and security data: OAuth access and refresh tokens stored in your device's secure storage; organisation slug and cached profile or roster data stored locally to support offline viewing
- Technical connection data: IP address, request timestamps, and client headers sent to our servers when the App communicates with Timax (standard for secure API access)
- Realtime connection metadata: short-lived tokens and event subscriptions when the App connects to Timax realtime services to refresh shift status
Information we do not collect through the App:
- Biometric templates such as Face ID or fingerprint data — these remain on your device only and are never transmitted to Timax
- Continuous or background location tracking — the App requests location only while in use and only when you perform a relevant action
- Contacts, calendars, SMS, call logs, browsing history, or advertising identifiers
- Health, financial, or payment card data
The App may request the following device permissions. You can decline non-essential permissions, although some features will not work without them:
- Location (while using the App): to verify that you are at or near your assigned site when booking on, checking in, booking off, triggering a panic alert, or responding to certain pre-shift requests. Location is not collected in the background.
- Camera: to capture photo evidence for shift duties and welfare checks
- Photos / photo library: to attach existing images as evidence
- Notifications: to send operational alerts such as check-in reminders, book-on prompts, pre-shift confirmations, and open-shift availability (optional; you can turn these off in Profile or your device settings)
- Face ID / Touch ID / device biometrics (optional): to unlock an existing session on this device without re-entering your password; biometric data never leaves your device
On first use of a sensitive feature, the App or your operating system will show a permission prompt explaining why the permission is needed. You can change permissions at any time in your device settings.
- Authenticating you and keeping your session secure
- Showing your shifts, jobs, notifications, and organisation context
- Recording attendance, welfare check-ins, panic alerts, and configured evidence
- Verifying geofence and site-presence rules set by your employer
- Delivering push notifications about operational events you or your employer have enabled
- Syncing shift status in near real time while you are using the App
- Caching recent data on your device so you can view key information when offline
- Operating, maintaining, securing, and improving the Timax platform
- Complying with legal obligations and responding to lawful requests
Where Timax or your employer processes your personal data, the legal bases may include:
- Performance of a contract — to provide the App and workforce services to you and your employer
- Legitimate interests — to operate, secure, and improve the platform, verify attendance, and protect lone workers, balanced against your rights
- Legal obligation — where UK employment, health and safety, or record-keeping laws require processing
- Consent — where required, for example push notifications or location where your employer or applicable law requires explicit consent (you may withdraw consent through device settings or in-app controls)
We do not sell your personal information. We share data only as needed to provide the service:
- Your employer organisation and its authorised administrators, who configure shifts, welfare rules, and reporting in Timax
- Infrastructure and communications providers that help us host the platform, deliver email or SMS where configured by your employer, and send push notifications
- Expo and Google Firebase Cloud Messaging (Android) / Apple Push Notification service (iOS) to deliver push notifications to your device
- Professional advisers or authorities when required by law, regulation, court order, or to protect rights, safety, and security
The App does not contain advertising SDKs and does not use your data for cross-app or cross-website advertising tracking.
Timax is operated from the United Kingdom. Your data is primarily processed in the UK or European Economic Area. Some service providers used for push delivery, cloud hosting, or operational tooling may process limited data in other countries. Where required, we use appropriate safeguards such as UK-approved contractual protections.
- Shift, welfare, and evidence records are retained according to your employer's Timax configuration and applicable legal requirements
- Account, device, and push registration data are kept while your account is active and for a limited period afterwards for security and audit purposes
- Cached data on your device remains until you sign out, clear app data, or uninstall the App
- Server logs and security records are kept for a limited period, then deleted or anonymised
We protect personal data using HTTPS/TLS encryption in transit, secure password hashing, access controls, tenant separation between organisations, and device secure storage for session tokens. Optional biometric unlock adds an extra device-level gate to your refresh token. Contact us immediately at support@timax.uk if you believe your account has been compromised.
- Push notifications: toggle off in Profile → Push notifications or in your device notification settings
- Location, camera, and photos: manage in your device settings; without these permissions, location-verified actions and photo evidence cannot be submitted
- Biometric sign-in: optional; disable in Profile → Security
- Sign out: clears in-app session state; cached local data may remain until removed by the system
Staff accounts are usually created and managed by your employer. To deactivate your App access or request deletion of employment-related records, contact your employer or Timax administrator first.
You may also contact Timax directly to request deletion of your user account and associated platform data:
- Email: support@timax.uk from your registered email address with the subject line "Timax mobile account deletion request"
- Include your name, employer organisation, and the email address linked to your account
We verify your identity before processing deletion requests and aim to complete verified requests within 30 days. Some information may be retained where required by law or where your employer must keep employment, welfare, or audit records. Deleting your account does not automatically delete records your employer must keep for legal or contractual reasons.
Under UK GDPR you may have the right to access, rectify, erase, restrict, or object to processing, and to data portability where applicable. Contact your employer for employment and shift records they control. Contact support@timax.uk for platform account matters. You may also complain to the UK Information Commissioner's Office at ico.org.uk.
To help you understand our practices, the App collects data linked to your identity, including:
- Contact info: name and email address
- Location: precise location, collected only when you perform relevant in-app actions and not in the background
- Photos: user-generated photos submitted as evidence
- User content: signatures, notes, and evidence answers
- Identifiers: device ID and push notification token
- App info: app interactions related to shifts, welfare actions, and notifications
This data is used for app functionality, account management, fraud prevention, security, and compliance. It is not used for third-party advertising or cross-app tracking. Our Apple App Privacy and Google Play Data safety declarations are intended to match this policy.
We may update this policy from time to time. The latest version is always available in the App under Profile → Privacy Policy and at https://timax.uk/mobile/privacy-policy. Material changes may be communicated by email or in-app notice where appropriate.
Questions about this policy or the Timax mobile App:
- Email: support@timax.uk
- Website: https://timax.uk
- In-app: Profile → Privacy Policy
Website users: Timax Website Privacy Policy · App Store / Play Console URL: https://timax.uk/mobile/privacy-policy