goGig
Privacy policy

gOGig Executor for iPhone

Applies to the iOS app in.gogig.executor.ios (“gOGig Executor”, “the app”) on iPhone. The Android app has its own policy.
Effective: 5 October 2026 · Last updated: 5 October 2026

gOGig Executor is a work app for field executors. You pick up a branding campaign, go to the site, capture photo or video proof that you were there, and submit it. Everything the app collects exists to make that proof verifiable and to pay you for it. There is no advertising in this app, no advertising identifier, no analytics SDK, and no tracking — the app never asks for App Tracking Transparency permission because it does nothing that would need it.

1. What we collect

DataWhyWhen
Phone numberIt is your login. Sign-in is a one-time password (OTP) sent to it.At sign-in
Name, role, executor IDIdentifies whose work a submission is, and who gets paid for it. If your account has no name yet, the app asks for your first and last name once, at sign-in.At sign-in, and returned by our server afterwards
Precise location (GPS)Checks you are inside the task’s geofence, and is written into each capture as proof of place.Only while the app is open and a capture or task screen is showing
Photos and videos you captureThey are the deliverable — the proof of the completed task.When you take them in the app
Attendance selfieProves the executor on site is the one signed in. The camera checks on the phone that a real face blinked before the photo is taken — see “Your face, specifically” below.When you mark attendance
AudioOnly as the sound track of a video you record. The app never records audio on its own.While recording a video
Capture metadataTime, GPS coordinates and accuracy, the device model, iOS version, time zone and the app build — written into each photo (as EXIF) and sent with the task, so a disputed capture can answer questions on its own. The task also carries the capture time as told by the last GPS fix, which changing the phone’s date or time does not move.At capture and at upload
Task answersThe form fields of the task you complete. What these are is set by the campaign — for example a shop name, a vehicle’s registration number, a measurement, or a survey the client asked for.On submission
Profile (optional)Your name, a profile photo and your date of birth, if you choose to add them — see “Your profile, specifically” below.When you edit your profile
Push tokenA Firebase Cloud Messaging token for this installation, stored against your account so we can send you notices about your work and uploads.After sign-in, and whenever iOS issues a new one
App and device diagnosticsApp version, device model, iOS version, screen size, locale, network type, free disk space, battery level and Low Power Mode, how many uploads are queued, and recent app logs. Your name and account ID are attached, so support can tell whose phone a report came from without having to ask.When you send a problem report, and automatically after an upload that could not be sent — see section 5
Upload queue statusHow many tasks on the phone are waiting to upload, uploading, failed, or uploaded today, split by campaign, with how long the oldest has waited and its recent upload errors. With it: the app version and build, device model, iOS version, time zone and network type, whether the app is open on screen or in the background, when it last came to and left the screen, and the time and campaign of the newest task captured on the phone. It is sent under your account, so the people running a campaign can see whose work is stuck on a phone and why. Only the latest status is kept; each one replaces the one before.Automatically while you are signed in, after tasks are saved, uploaded, or fail, and when the app is opened or leaves the screen
Location, specifically

The app asks for location “While Using the App” only. It does not ask for “Always” location and cannot read your location when it is closed or in the background. You can also turn off Precise Location in iOS Settings; tasks that check a geofence will then tell you they need a precise fix.

When you mark attendance, the app asks Apple’s own geocoding service to turn your coordinate into an area name shown on screen. That request goes to Apple under Apple’s privacy policy; it carries the coordinate and nothing about you.

Your face, specifically

The attendance camera uses Apple’s on-device Vision framework to find a face in the frame and to see that its eyes blink, so a printed photo cannot mark attendance. That analysis happens entirely on the phone, frame by frame, and is thrown away as it goes. No face geometry, template, or biometric identifier is stored or sent anywhere. What is uploaded is the selfie photograph itself and a yes/no for whether a blink was seen. The app does not use Face ID and does not have access to Face ID data.

Your profile, specifically

Signing in needs only your mobile number and the code sent to it (and, for a new account, your name). Everything else on your profile — a profile photo and your date of birth — is optional, added by you from the Profile screen, and stored with your account so the people who assign and review your work can see who did it. The photo is one you pick through the iOS photo picker, which hands the app that one image and nothing else; the app has no access to the rest of your photo library and does not ask for it. The picked photo is cropped to a small square on the phone before it is uploaded.

Camera and media, specifically

The app opens the camera to capture task proof. Captures are kept inside the app’s own storage; they are not saved to your Photos library, and the app does not read your library. Only files you capture for a task are uploaded.

Some campaigns ask the app to read a number off the photo for you — a vehicle registration plate, or a serial code on a board — instead of making you type it. When that happens the photo, with the coordinate and the job type, is sent to our detection service at detection.ec2.gogig.in, which returns the text it read. It is an assist and it can be overruled: if the read is wrong or the service cannot be reached, you type the value in and the task submits exactly as it would have.

Your phone number and messages, specifically

iOS does not let apps read the phone number of your SIM, and this app does not try: you type the number you sign in with. When the OTP arrives by SMS, iOS may offer the code above the keyboard; the app only receives it if you tap that suggestion. The app cannot read your messages, contacts, or call history.

Notifications, specifically

If you allow notifications, the app registers with Apple Push Notification service through Google’s Firebase Cloud Messaging. Firebase issues a token and an installation ID — random numbers for this installation of the app, reset if you reinstall — which we store against your account to address messages to this phone. Notices about your work (for example an urgent message from the operations team) are sent this way; an urgent notice is kept on the phone until you dismiss it. You can turn notifications off at any time in iOS Settings; the app keeps working without them. Firebase Cloud Messaging is the only Firebase product in the app — there is no Firebase Analytics or Crashlytics on iOS.

2. What we do not collect

  • No advertising identifier (IDFA), no ads, and no App Tracking Transparency prompt — the app does not track you.
  • No analytics, attribution, or cross-app tracking SDKs.
  • No contacts, messages, call history, calendars, health data, or Bluetooth.
  • No background or “Always” location.
  • No access to your photo library beyond the single photo you pick for your profile.
  • No face or biometric data — the blink check runs on the phone and keeps nothing.
  • No list of other apps installed on your phone.
  • No software downloaded or installed by the app. Updates come only from the App Store.

3. How your data is used

  • To sign you in and keep your session valid.
  • To show you the campaigns and tasks assigned to you.
  • To verify that a submitted task was captured at the right place and time, by you.
  • To process payment for verified work.
  • To notify you about your uploads and your work.
  • To investigate a problem you report, to fix faults, and to detect fraudulent or duplicated submissions.
We do not use your data for advertising or marketing profiling, and we do not sell it.

4. Who we share it with

We do not sell, rent, or trade your personal information. We disclose it only in these cases:

  • Service providers who host and operate the platform on our behalf (hosting, storage, SMS delivery for the OTP, push delivery through Firebase Cloud Messaging), bound to use it only for that purpose.
  • The client whose campaign you worked on, where the task proof itself — the capture, its location and time — is the deliverable they commissioned. This is the work product, not your account details.
  • When the law requires it, or to establish, exercise, or defend a legal claim, including investigating fraud.
Two third parties are contacted by the app itself, each described in section 1: Apple’s geocoding service, for the area name on the attendance screen, and Firebase Cloud Messaging with Apple Push Notification service, for notifications. Neither is sent your captures.

5. Diagnostics and problem reports

When you send a problem report from Settings, it carries the app’s recent log lines together with the device and queue facts listed in section 1, so that support can act on it without a phone call. Anything that looks like a login token or an inline image is stripped out of those logs before they are sent. Your name, account ID and role are attached, because a report nobody can trace back to an executor cannot be answered.

One thing is reported without being asked for. If a completed task cannot be uploaded — no signal, a full phone, a server that refuses it — the app files a report about that failure on its own, so that work stuck on a phone is something we find out about rather than something you have to tell us. Repeats are counted and sent as one report. It names the task and the error, never what is in your captures.

6. How your data is protected

  • Every request the app makes is HTTPS, enforced by iOS App Transport Security; the app makes no exceptions to it.
  • Your session tokens are kept in the iOS Keychain. Captures waiting in the offline queue are kept in the app’s private container, which other apps cannot read, under iOS Data Protection — encrypted by iOS and unreadable until the phone has been unlocked once after starting.
  • The app’s container is included in your own encrypted iPhone backups, the same as any app; nothing is backed up to us.
  • Access to submitted data on our side is limited to staff who need it to run campaigns and payments.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your data, we will notify you and the relevant authority as the law requires.

7. How long it is kept

  • On your phone: a capture stays on the device until it has been uploaded and the server has confirmed it, and then for as long as it is among the most recent tasks of its campaign; past that the app releases the file to free up storage. Nothing that has not reached the server is ever deleted automatically — an unsent capture is the only copy there is.
  • On our servers: task submissions and their proof are kept for as long as the campaign and its payment and audit records require, and afterwards for as long as the law obliges us to keep financial records.
  • Problem reports: kept while the issue is open and for a reasonable period afterwards for support history.
  • Upload queue status: only the latest one is kept; each status replaces the one before.
  • Push token: kept while you are signed in on this phone, and replaced when iOS issues a new one.
Deleting the app removes everything it stored on the iPhone, including anything still queued and unsent. Logging out cancels pending uploads and removes your session from the phone.

8. Your rights and choices

You can withdraw the camera, microphone, location or notification permission at any time in iOS Settings → gOGig. The app keeps working, but tasks that need a verified place or a capture cannot be completed without them — that verification is what the task is.

You can also ask us to:

  • tell you what personal data of yours we hold;
  • correct anything inaccurate;
  • delete your account and its data (see below);
  • have a grievance about your data addressed.
Write to support@gogig.in from — or naming — the phone number you registered with. We respond within 30 days. Indian users have these rights under the Digital Personal Data Protection Act, 2023.

9. Account and data deletion

Delete it yourself: in the app, open Settings → About gOGig → Delete my account, or go straight to dashboard.gogig.in/delete-account. Sign in with the phone number on your account, confirm, and the request is filed without anybody having to read an email.

Or write to us: email support@gogig.in with the subject “Delete my account”, naming your registered phone number. We verify the request against that number.

Either way, what is deleted is the same: your account, your profile details, your push token, and your submitted captures. We keep only what we are legally required to keep — payment and tax records for completed work, and any data under an active legal or fraud investigation. Those are retained for the statutory period and used for nothing else.

10. Children

gOGig Executor is a work app for adults engaged as field executors. It is not directed at children and we do not knowingly collect data from anyone under 18. If we learn that we have, we delete it.

11. Changes to this policy

If this policy changes, the updated version is posted at this address with a new “last updated” date. Material changes to what we collect or why will be communicated in the app before they take effect.

12. Contact

Questions, requests, or grievances about your data:

Email: support@gogig.in
Website: www.gogig.in

gOGig Executor for iPhone · in.gogig.executor.ios · Privacy policy, last updated 5 October 2026.