ESP (“the App”) is a workforce-management application operated by ESP Construction (“ESP Construction”, “we”, “us”) for our own employees, contractors, coordinators, and managers. It is not offered to the general public. Accounts are created and managed by ESP Construction. This policy describes what the App actually collects, why, who can see it, how long it is kept, and how to ask for deletion.
A shorter product overview, including views of the crew screens, is on the ESP App page.
1. Who this applies to
This policy covers everyone who uses the ESP mobile apps (iOS and Android), the crew web app, or the manager desktop/web application. The App is a workplace tool. It is not directed at children and we do not knowingly create accounts for anyone under 16.
2. Information we collect
Account and employment information
Provided by you or entered by ESP Construction when your account is set up:
- Name, email address, phone number, and a login password (stored only as a one-way hash)
- Employment details: company, role, start date, status, assigned projects, skills, home airport/city/country, and whether you are a foreman
- A profile photo, if one is uploaded — this is a directory avatar visible to managers and coordinators who can see the crew list, not HR identity data
Address and timezone
You can edit your own street address and IANA timezone in Profile. Managers can also see and update those fields as part of the employee record.
Travel documents and identity (PII)
When the travel-documents feature is enabled, you or an administrator may store:
- Date of birth
- Driver’s licence number, expiry date, and a photo of the licence
- Passport number, country of issue, expiry date, and a photo of the passport
These live in a private employee record, not in the regular crew directory. You may update your own travel-document fields. Blanking a field from the app does not erase it — an administrator has to clear it. Photos are uploaded over an authenticated connection and are never written to the device photo library by the App.
Banking and payroll beneficiary data
Administrators may store bank name, account and routing numbers, payee / beneficiary name, and the beneficiary’s and bank’s address fields used to pay you. Hourly cost rates and pay currency are employment records used to build pay runs; they are not shown on the crew Profile screens.
Location
The App uses location in two distinct ways. They are not the same data.
Clock-in and clock-out coordinates. When you clock in or out, the App may send the device’s GPS at that moment. Those coordinates are stored on the time-entry record so a manager can see whether the event happened inside the project’s geofence. If GPS is missing, delayed, or outside the fence, the clock event is still recorded and flagged for review. If the event is out of fence you are asked for a short note; the event itself is never discarded because GPS can be wrong.
Optional workday pings. If the location-tracking feature is switched on and you have allowed location permission on the device, the App may send a location ping about every five minutes while you are clocked in, so a manager can see who is currently on a shift. Pings are rejected if you are clocked out. They are not collected after you clock out. They are deleted automatically after 30 days by a server sweep.
The App may also record a permission-status event (for example that location permission was granted or denied). That event is not a GPS point.
Time and work records
Clock-in and clock-out times, project, shift type (day / night / travel), travel direction when the shift is travel, manager and employee notes, and the weekly timesheet built from those entries.
Receipt images and expenses
If you submit an expense, we store the amount, merchant, category, project, and — when you take one — a photo of the receipt. You can always enter the details by hand instead of using a photo or optional AI pre-fill.
Messages
Text you send in company or project conversations is stored so the thread is available on another device. Push notifications for new messages carry a name and a coarse label, not the message body.
Device tokens and on-device reminders
If you allow notifications, the App registers an Apple or Firebase device token so we can deliver a message alert. Logging out unregisters that token. Local clock-in / clock-out reminders are scheduled on your device from your assignments; they do not send location to us in order to fire.
Job applications (public apply form, when enabled)
If ESP opens the public application form, a candidate may submit contact details, work history, and a CV. That form is not an account. Rejected or withdrawn applications and their CVs are deleted after a retention window (180 days by default).
Optional in-app feedback
A small number of frequent users may be invited to send a bug report or suggestion, which can include a screenshot and text they choose to submit.
3. How we use this information
- Operate the workplace tool: sign-in, scheduling, time tracking, expenses, messaging, invoicing, and payroll
- Verify clock events against assigned job sites (geofencing) and flag unusual ones for review
- Show managers who is currently clocked in when location tracking is on and the worker has allowed location permission on the device
- Process expense reports, including optional AI-assisted receipt reading
- Remind you of an assigned shift using on-device notifications
- Respond to feedback and keep the App working
We do not use this information for advertising. The App contains no ads and no ad tracking.
4. Who can access each category
| Category | Who can see it |
|---|---|
| Name, contact, assignments, profile photo, address, timezone | The worker; managers and coordinators who can see the crew directory |
| Clock events and timesheets (including clock-in/out coordinates) | The worker for their own entries; managers and admins reviewing time and payroll |
| Workday location pings (30-day window) | Managers and admins. Only written while the worker is clocked in and has allowed location permission on the device |
| Date of birth, passport, driver’s licence and their photos | The worker (self-service) and administrators. Not ordinary managers |
| Banking and payroll beneficiary fields | Administrators only. Never shown in the crew Profile screens. Reads and writes are audit-logged |
| Pay rates used to build a pay run | Managers and admins on the office side. Omitted from the crew app’s employee model |
| Receipt images and expense rows | The worker who submitted them; managers reviewing expenses and project cost |
| Message threads | Participants in that conversation, plus managers who can open company/project channels |
5. How long we keep it
- Workday location pings: automatically deleted after 30 days.
- Clock-in / clock-out coordinates: stored on the time-entry row and kept for as long as that time, payroll, and invoicing record is retained.
- Employment, timesheet, payroll, expense, invoice, and message records: kept as long as ESP Construction needs them for running the business and meeting employment, tax, and accounting recordkeeping duties. We do not invent a shorter “app only” clock for those records.
- Account access: disabled when employment or the engagement ends. Disabling a login is not the same as erasing historical time and pay records.
- Rejected or withdrawn job applications and their CVs: deleted after the applicant-retention window (180 days by default).
6. How to request access, correction, or deletion
Because accounts are provisioned by ESP Construction, there is no self-serve “delete my account” control in the App. To see, correct, or delete personal information:
- Correct address, timezone, and travel-document fields yourself in Profile where those screens are available
- Ask your manager, or
- Email info@espconstruction.ca with the subject “ESP App data request”
We will remove or restrict what we can. Some time, payroll, tax, and invoice records cannot be erased on request because they are part of statutory employment and accounting records. Location pings do not need a request — they already expire after 30 days.
Under Canadian privacy law applicable to this business (including PIPEDA and, where it applies, Ontario’s employment-related privacy rules), you may also contact us to withdraw consent for optional collection such as workday location pings, or turn off location permission for the App on the device. Clock-in/out coordinates remain part of verifying a time record when geofencing is in use.
7. Third-party services
Some optional features send limited data to processors who work for us:
| Feature | What is sent | Purpose |
|---|---|---|
| Optional AI receipt reading, skill suggestions, or project assistant | A receipt image or the relevant text, only when that feature is used | Extract or suggest information. Not used to train the provider’s foundation models |
| Push notifications | A device token and a short notification payload (name + coarse label, not message body or location) | Apple Push Notification service or Firebase Cloud Messaging, to deliver an alert |
| Optional in-app feedback | The text and screenshot you submit | Internal product-feedback tooling |
Hosting is on infrastructure we operate (application server and PostgreSQL). We do not sell personal information. We do not share it with advertisers.
8. Security
Passwords are hashed with argon2; they are never stored in plain text. Traffic between the App and our servers is encrypted in transit. Banking, government-ID, and date-of-birth fields sit behind administrator (or, for travel documents only, self-or-admin) endpoints and are audit-logged. Native apps keep session tokens in the platform keychain / encrypted preferences, marked not to leave the device, and do not write passport or receipt bytes into the shared photo library.
9. Children
The App is a workplace tool for adults employed or contracted by ESP Construction. We do not knowingly collect personal information from children.
10. Changes to this policy
If the App starts collecting a new category of personal information, or we change who can see a category listed here, we will update this page and the “Last updated” date. Material changes will also be noted in the App’s About / release notes when a store build ships.
11. Contact us
Questions about this policy or your data:
ESP Construction
16969 Mountainview Rd, Caledon East, ON L7C 2V8, Canada
Email: info@espconstruction.ca
Phone: (647) 205-6353
Store reviewers: this URL is https://espconstruction.ca/privacy.html and does not require authentication.