This Privacy Policy describes how Vector4 Tech ("we," "us," or "our") collects, uses, and protects information in connection with the T.R.A.C.E. Mobile Android application (the "App") and its associated web platform at trace.sanchez.ph.
T.R.A.C.E. Mobile is an enterprise-grade asset management tool designed for use by authorized employees and administrators within hospitality and resort properties. The App is not intended for use by the general public or minors.
1. Information We Collect
1.1 Account & Authentication Data
When you log in to the App, we collect:
- Your username and password hash (stored locally using encrypted secure storage for offline authentication fallback)
- Your session token (JWT), stored securely on-device
- Your assigned role and permissions as configured by your administrator
We do not store plain-text passwords on device or on our servers. Passwords are hashed server-side using bcrypt.
1.2 Device & App Data
The App may collect or process the following information on your device:
- Device model, OS version, and App version — used for compatibility and support purposes
- Network connectivity status — to determine whether to operate in online or offline mode
- Local SQLite database — stores a cached copy of asset records, spaces, custody data, and audit results on-device for offline operation. This data is synchronized with the server upon reconnection.
- Cached images— asset and item photos may be cached locally using the device's storage to reduce network load
1.3 Camera & Image Data
The App requests access to your device's camera for the following purposes:
- Scanning QR codes and barcodes for asset identification
- Capturing asset photographs during field audits or item commissioning
Images you capture are uploaded to the enterprise server and associated with the asset record. We do not use your camera feed for any other purpose, and no video is recorded or streamed.
1.4 RFID & Audit Data
The App communicates with external UHF RFID handheld readers via Bluetooth or USB. Data processed includes:
- GS1 SGTIN-96 EPC tag values read from physical RFID tags attached to assets
- Audit session records — timestamps, scanned tag lists, room/space associations, and discrepancy reports
This data is transmitted to and stored on your organization's T.R.A.C.E. server.
1.5 Push Notifications (Firebase)
The App uses Firebase Cloud Messaging (FCM) by Google to deliver push notifications. In connection with this:
- A Firebase registration token is generated by your device and sent to our server to enable targeted notifications
- Notifications may include alerts about pending approvals, custody handovers, maintenance assignments, and other workflow events
- Google's Firebase services may collect data per their own Privacy Policy
1.6 Usage & Activity Logs
Actions performed within the App (e.g., asset transfers, tag commissions, approval submissions) are recorded as audit log entries on the server. These logs are cryptographically sealed using SHA-256 hash chains and are attributable to your user account. This is a core compliance feature of the platform.
2. How We Use Your Information
We use the information collected for the following purposes:
- To authenticate users and enforce role-based access control
- To operate the asset management platform, including audits, custody tracking, maintenance workflows, and financial compliance reporting
- To enable offline functionality through local data caching and delta sync
- To deliver push notifications for workflow events and approvals
- To generate tamper-proof audit trails for regulatory compliance
- To provide technical support and troubleshoot issues
- To improve the App based on usage patterns (aggregated, non-personally-identifiable)
3. Data Sharing & Disclosure
We do not sell your personal data to third parties. Data may be shared in the following limited circumstances:
- Within your organization:Asset and audit data is shared with authorized administrators and managers of your employing organization as part of the platform's core function.
- Google Firebase:Firebase registration tokens and notification payloads are processed by Google's FCM infrastructure. See Google's Privacy Policy.
- Legal requirements: We may disclose data if required by law, regulation, court order, or other legal process.
- Business transfer: In the event of a merger, acquisition, or asset sale, data may be transferred subject to the same privacy protections.
4. Data Storage & Security
- Server-side: All asset records, audit logs, user accounts, and media are stored in a PostgreSQL database hosted on private infrastructure. The database enforces row-level security and cryptographic hash integrity on audit records.
- On-device: Credentials and tokens are stored using Flutter Secure Storage (backed by Android Keystore on Android), which encrypts data at rest. The local SQLite cache contains asset data but does not store raw passwords.
- In transit: All network communication between the App and the server uses HTTPS (TLS). Sensitive tokens are transmitted in encrypted request headers.
- Access control: Only authenticated and authorized users may access the platform. All API endpoints enforce JWT-based authentication and role validation.
5. Data Retention
- Audit logs and custody records are retained indefinitely for compliance and regulatory purposes, as required by enterprise asset management standards.
- User account datais retained for the duration of your employment or engagement with the organization, and may be archived or deleted upon account termination as directed by your organization's administrator.
- Local cached data on your device is cleared upon logout or when the App is uninstalled.
6. Permissions Requested
The App requests the following Android permissions and explains why:
| Permission | Purpose |
|---|---|
CAMERA | Scanning QR/barcodes and capturing asset photos during field audits |
INTERNET | Syncing asset data, authentication, and receiving push notifications |
ACCESS_NETWORK_STATE | Detecting online/offline status to activate the appropriate sync mode |
RECEIVE_BOOT_COMPLETED | Re-registering FCM push notification service after device restart |
POST_NOTIFICATIONS | Displaying workflow alerts (Android 13+) |
READ_EXTERNAL_STORAGE / READ_MEDIA_IMAGES | Selecting existing images from gallery for asset photos (Android versions that require it) |
VIBRATE | Haptic feedback for RFID scan events |
7. Children's Privacy
The App is an enterprise B2B tool intended solely for use by authorized adult employees and administrators. We do not knowingly collect any personal information from individuals under the age of 18. If you believe a minor has used the App, please contact us immediately.
8. Your Rights
Depending on your jurisdiction, you may have rights regarding your personal data, including:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated personal data (subject to compliance retention obligations)
- Portability: Request an export of your data in a machine-readable format
To exercise any of these rights, please contact your organization's T.R.A.C.E. administrator or reach us directly at support@trace.sanchez.ph.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the App, applicable laws, or our practices. We will update the "Last updated" date at the top of this page. For significant changes, we may notify users through the App or via email. Continued use of the App after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact:
Vector4 Tech
Developer of T.R.A.C.E. — Total Resource Asset & Compliance Engine
Email: support@trace.sanchez.ph
Website: trace.sanchez.ph
