in.gogig.executor.ios (“gOGig Executor”, “the app”) on iPhone. The Android app has its own policy.gOGig Executor is a work app for field executors. You pick up a branding campaign, go to the site, capture photo or video proof that you were there, and submit it. Everything the app collects exists to make that proof verifiable and to pay you for it. There is no advertising in this app, no advertising identifier, no analytics SDK, and no tracking — the app never asks for App Tracking Transparency permission because it does nothing that would need it.
| Data | Why | When |
|---|---|---|
| Phone number | It is your login. Sign-in is a one-time password (OTP) sent to it. | At sign-in |
| Name, role, executor ID | Identifies whose work a submission is, and who gets paid for it. If your account has no name yet, the app asks for your first and last name once, at sign-in. | At sign-in, and returned by our server afterwards |
| Precise location (GPS) | Checks you are inside the task’s geofence, and is written into each capture as proof of place. | Only while the app is open and a capture or task screen is showing |
| Photos and videos you capture | They are the deliverable — the proof of the completed task. | When you take them in the app |
| Attendance selfie | Proves the executor on site is the one signed in. The camera checks on the phone that a real face blinked before the photo is taken — see “Your face, specifically” below. | When you mark attendance |
| Audio | Only as the sound track of a video you record. The app never records audio on its own. | While recording a video |
| Capture metadata | Time, GPS coordinates and accuracy, the device model, iOS version, time zone and the app build — written into each photo (as EXIF) and sent with the task, so a disputed capture can answer questions on its own. The task also carries the capture time as told by the last GPS fix, which changing the phone’s date or time does not move. | At capture and at upload |
| Task answers | The form fields of the task you complete. What these are is set by the campaign — for example a shop name, a vehicle’s registration number, a measurement, or a survey the client asked for. | On submission |
| Profile (optional) | Your name, a profile photo and your date of birth, if you choose to add them — see “Your profile, specifically” below. | When you edit your profile |
| Push token | A Firebase Cloud Messaging token for this installation, stored against your account so we can send you notices about your work and uploads. | After sign-in, and whenever iOS issues a new one |
| App and device diagnostics | App version, device model, iOS version, screen size, locale, network type, free disk space, battery level and Low Power Mode, how many uploads are queued, and recent app logs. Your name and account ID are attached, so support can tell whose phone a report came from without having to ask. | When you send a problem report, and automatically after an upload that could not be sent — see section 5 |
| Upload queue status | How many tasks on the phone are waiting to upload, uploading, failed, or uploaded today, split by campaign, with how long the oldest has waited and its recent upload errors. With it: the app version and build, device model, iOS version, time zone and network type, whether the app is open on screen or in the background, when it last came to and left the screen, and the time and campaign of the newest task captured on the phone. It is sent under your account, so the people running a campaign can see whose work is stuck on a phone and why. Only the latest status is kept; each one replaces the one before. | Automatically while you are signed in, after tasks are saved, uploaded, or fail, and when the app is opened or leaves the screen |
The app asks for location “While Using the App” only. It does not ask for “Always” location and cannot read your location when it is closed or in the background. You can also turn off Precise Location in iOS Settings; tasks that check a geofence will then tell you they need a precise fix.
When you mark attendance, the app asks Apple’s own geocoding service to turn your coordinate into an area name shown on screen. That request goes to Apple under Apple’s privacy policy; it carries the coordinate and nothing about you.
The attendance camera uses Apple’s on-device Vision framework to find a face in the frame and to see that its eyes blink, so a printed photo cannot mark attendance. That analysis happens entirely on the phone, frame by frame, and is thrown away as it goes. No face geometry, template, or biometric identifier is stored or sent anywhere. What is uploaded is the selfie photograph itself and a yes/no for whether a blink was seen. The app does not use Face ID and does not have access to Face ID data.
Signing in needs only your mobile number and the code sent to it (and, for a new account, your name). Everything else on your profile — a profile photo and your date of birth — is optional, added by you from the Profile screen, and stored with your account so the people who assign and review your work can see who did it. The photo is one you pick through the iOS photo picker, which hands the app that one image and nothing else; the app has no access to the rest of your photo library and does not ask for it. The picked photo is cropped to a small square on the phone before it is uploaded.
The app opens the camera to capture task proof. Captures are kept inside the app’s own storage; they are not saved to your Photos library, and the app does not read your library. Only files you capture for a task are uploaded.
Some campaigns ask the app to read a number off the photo for you — a vehicle registration plate, or a serial code on a board — instead of making you type it. When that happens the photo, with the coordinate and the job type, is sent to our detection service at detection.ec2.gogig.in, which returns the text it read. It is an assist and it can be overruled: if the read is wrong or the service cannot be reached, you type the value in and the task submits exactly as it would have.
iOS does not let apps read the phone number of your SIM, and this app does not try: you type the number you sign in with. When the OTP arrives by SMS, iOS may offer the code above the keyboard; the app only receives it if you tap that suggestion. The app cannot read your messages, contacts, or call history.
If you allow notifications, the app registers with Apple Push Notification service through Google’s Firebase Cloud Messaging. Firebase issues a token and an installation ID — random numbers for this installation of the app, reset if you reinstall — which we store against your account to address messages to this phone. Notices about your work (for example an urgent message from the operations team) are sent this way; an urgent notice is kept on the phone until you dismiss it. You can turn notifications off at any time in iOS Settings; the app keeps working without them. Firebase Cloud Messaging is the only Firebase product in the app — there is no Firebase Analytics or Crashlytics on iOS.
We do not sell, rent, or trade your personal information. We disclose it only in these cases:
When you send a problem report from Settings, it carries the app’s recent log lines together with the device and queue facts listed in section 1, so that support can act on it without a phone call. Anything that looks like a login token or an inline image is stripped out of those logs before they are sent. Your name, account ID and role are attached, because a report nobody can trace back to an executor cannot be answered.
One thing is reported without being asked for. If a completed task cannot be uploaded — no signal, a full phone, a server that refuses it — the app files a report about that failure on its own, so that work stuck on a phone is something we find out about rather than something you have to tell us. Repeats are counted and sent as one report. It names the task and the error, never what is in your captures.
You can withdraw the camera, microphone, location or notification permission at any time in iOS Settings → gOGig. The app keeps working, but tasks that need a verified place or a capture cannot be completed without them — that verification is what the task is.
You can also ask us to:
Delete it yourself: in the app, open Settings → About gOGig → Delete my account, or go straight to dashboard.gogig.in/delete-account. Sign in with the phone number on your account, confirm, and the request is filed without anybody having to read an email.
Or write to us: email support@gogig.in with the subject “Delete my account”, naming your registered phone number. We verify the request against that number.
Either way, what is deleted is the same: your account, your profile details, your push token, and your submitted captures. We keep only what we are legally required to keep — payment and tax records for completed work, and any data under an active legal or fraud investigation. Those are retained for the statutory period and used for nothing else.
gOGig Executor is a work app for adults engaged as field executors. It is not directed at children and we do not knowingly collect data from anyone under 18. If we learn that we have, we delete it.
If this policy changes, the updated version is posted at this address with a new “last updated” date. Material changes to what we collect or why will be communicated in the app before they take effect.
Questions, requests, or grievances about your data:
Email: support@gogig.in
Website: www.gogig.in
in.gogig.executor.ios · Privacy policy, last updated 5 October 2026.