What it readsA week on Crowd
CROWD
Built for youAll your sitesRegister
CROWD
What it readsA week on CrowdBuilt for youAll your sitesRegister
Legal — 01

Privacy Policy

What the Crowd employee app collects, why it needs it, who can see it, and how to ask us about it. Written for the app on Google Play, not as a template.

Effective
8 September 2026
Applies to
com.crowdautomation.app
Operated by
Crowd Automation, Ethiopia
Contact
emranhi001@gmail.com
§ 01

Who this is for, and who decides

Crowd is not a consumer app and you cannot sign up for it. Your employer runs a Crowd workspace, creates your account inside it, and gives you the address to sign in at. Everything the app knows about you arrives that way.

That matters for this document, because it means your employer decides what is recorded about you and for how long it is kept. We hold and process it on their instructions. Where the law separates the two roles, your employer is the data controller and Crowd Automation is the processor acting for them.

If you want your records changed or removed, the fastest route is your own company’s Crowd administrator. § 07 covers what to do when that is not enough.

§ 02

What the app collects

Five things, and nothing beyond them. Each one exists because a screen in the app cannot work without it.

  • Precise location — latitude, longitude, the accuracy in metres the handset reports, and, on Android, whether the operating system flags the reading as mocked. Used to check that you are inside your work site’s boundary when you record attendance. § 04 describes exactly when it is read.
  • Who you are at work — your work email address, your name, and the record your employer keeps: employee number, job title, hire date, the team or department you sit in, and who you report to. Created by your employer. You can edit your own display name.
  • Attendance events — the time of each check-in and check-out, the position above, and the verdict the server reached (recorded, or refused for being outside the boundary).
  • Notifications — what has been sent to you, and whether you have opened it. This includes notices that a report is due or has been reviewed; the report itself is filed on the web, not in this app, so no report content passes through it.
  • This handset, so it can be reached — the model name (“Pixel 8”), the platform, the app version, and a push token issued by the operating system. The first three label this session in the list of devices signed in to your account; the token is the address a notification is delivered to.

What the app does not touch. No contacts, no calendar, no camera or microphone, no photo library, no files on the device, no SMS or call logs, no browsing history, and no advertising identifier. There is no advertising in Crowd. There is no analytics SDK and no crash-reporting SDK — the app does not report on itself, which is a deliberate decision and the reason § 08 asks you to tell us when something goes wrong.

§ 03

The same thing, as Google Play states it

This is the declaration filed in the Play Console’s Data safety section, reproduced so the two can be compared. Nothing is collected for advertising or marketing, nothing is sold, and nothing is shared with a third party for that party’s own purposes.

Data typeWhat it is herePurposeShared
Location — preciseCoordinates and accuracy at the moment of a check-in or check-outApp functionalityNo
Personal info — nameYour display nameApp functionalityNo
Personal info — email addressThe work address you sign in withApp functionality, Account managementNo
Personal info — otherEmployee number, job title, hire date, team, reporting lineApp functionalityNo
App activity — other actionsAttendance events and notifications readApp functionalityNo
Device or other IDsPush token, device model, platform, app versionApp functionalityNo
  • All of it is encrypted in transit. The released app carries no exemption allowing plain HTTP.
  • None of it is optional in the sense Play means, because none of it is collected for a purpose you could decline and keep using the feature. Location is the one you control directly, by permission — see § 04.
  • You can request deletion of the data we hold about you. § 07 says how, and what the limits are.
§ 04

Location, in detail

This is the permission worth being precise about, so here is the whole of it.

  • Crowd requests foreground location only. It does not request background location and cannot read your position while it is closed.
  • A reading is taken in three situations and no others: when the attendance screen is open, when you bring the app back to the front, and at the instant you record a check-in or check-out.
  • Readings inside the same minute are reused rather than retaken, so the app does not hold the GPS radio open.
  • The position is stored against the attendance event it belongs to, because that record is the evidence your employer relies on for it. It is not used to build a movement history, and there is no screen anywhere in the product that shows where somebody has been between checks.
  • If the permission is off, the app does not send the check at all rather than sending one with no position. A check with no position is recorded as a refusal, and a refusal is a permanent mark on your attendance record — so a phone problem is not allowed to become one.
§ 05

Who can see it

Inside your company: you, and the people whose role in your workspace gives them access — typically your manager, HR, and the company’s administrators. Each company’s data is isolated at the database level, so one company’s workspace cannot read another’s.

Outside it: nobody, except a small number of providers who process data on our behalf and for no purpose of their own.

  • Expo — relays push notifications and serves app updates. Receives the push token and the build’s version information.
  • Google (Firebase Cloud Messaging) — the Android transport that delivers a notification to the handset. Receives the push token and the notification itself.
  • Our hosting provider — runs the servers the app talks to.

We do not sell personal data, we do not share it for advertising, and there is no tracking or attribution SDK in the app. We disclose data to anyone else only where the law obliges us to.

§ 06

How long it is kept

Your employer decides. Attendance events and filed reports are employment records: they belong to the company’s workspace and remain there for as long as that company keeps them, which is usually set by the record-keeping rules the company is subject to.

Two things expire on their own. Sign-in sessions are short-lived and are refreshed while you use the app. Signing out removes this handset’s push registration immediately, so notifications stop reaching it — which is what you want if the phone is shared or is about to be.

§ 07

Your choices, and deletion

  • Location — revoke it at any time in Android Settings → Apps → Crowd → Permissions. The rest of the app keeps working; you will not be able to record attendance from this phone while it is off, and your employer can enter the record for you.
  • Notifications — revoke the permission in Android Settings, or sign out, which removes this handset from the devices your notifications go to.
  • Your account — Crowd does not let you create an account and does not let you delete one, because the account and the records inside it belong to your employer. Ending your membership is your employer’s administrator’s to do, and it removes your access.
  • Asking us directly — to see, correct, or request deletion of the data we hold about you, write to emranhi001@gmail.com from your work address. We reply within 30 days. Where what you are asking about is your employer’s employment record, we pass the request to them and act on their instruction — and we tell you that we have done so, rather than leaving you without an answer.
§ 08

How it is protected

  • Sign-in credentials are held in the Android Keystore through the operating system’s own secure storage, never in ordinary app storage a backup could carry off the device.
  • Every request travels over HTTPS. The exception that allows plain HTTP to a development machine is added only to development builds and cannot reach a released one.
  • A session is bound to one company’s workspace and is not valid against any other.
  • Because the app carries no crash reporting, we learn about a failure only when somebody tells us. If the app shows you an error screen with a reference code on it, sending us that code is what lets us find the exact request in our logs.
§ 09

Children

Crowd is a workplace tool, used by employed adults whose accounts are created by an employer. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child’s data has reached us, write to emranhi001@gmail.com and we will remove it.

§ 10

Changes, and contact

If this policy changes we update the effective date at the top of the page. For a change that affects what is collected or who can see it, we say so in the app or by email to your work address rather than relying on you to re-read this.

Crowd Automation — Ethiopia. Questions about this policy, or a request under § 07: emranhi001@gmail.com. For help with the app itself, see Support.

© 2026 Crowd Automation
PrivacySupport
Crowd for Android · com.crowdautomation.app