Security and data
Who can see what, stated exactly.
Field data is sensitive twice over: it is your crew's whereabouts and your client's property. Both are handled on a need-to-know basis.
Company isolation
Every record carries its company
Punches, sites, units, photos, receipts and settings are stamped with the company that owns them, and every read is filtered by that company on the server.
Enforced server-side, not in the app
The phone never decides what it is allowed to see. A token from one company cannot reach another company's data even if the request is crafted by hand.
What a tech can see
Their own hours only
A tech sees their punches, their jobs and their receipts. Crew members cannot see each other's hours or pay.
Admins see the company
Whoever holds the admin role sees all hours, approves timesheets and expenses, and edits punches. Every edit is written to an audit trail with who changed what.
Location data
Only while the clock runs
Location is read at the punch and sampled on a ten-minute cadence during a shift. Off the clock, nothing is collected.
Stored as distance and grade
What the record keeps is the fix, its accuracy and the distance to the job site — used to verify presence, not to trace a route around town.
Client-facing records
Read-only and revocable
Shared records are read-only links you can kill at any time. They expose one property and one week.
Scoped by construction
Pay rates, other properties, other clients and other techs' timesheets are not part of the shared record.
Retention and export
Your history stays yours
Records and photos are kept for the life of the account so last year's turn is still provable this year.
Export on demand
Any property's week prints to a clean sheet, and account data can be exported on request.
Deletion on request
Ask and an account and its data are removed. Records already shared with a client are revoked at the same time.