Privacy Policy | GatePass BD
GatePass BD

Privacy Policy

This Privacy Policy explains what information the GatePass BD mobile application collects, how we use and protect that information, and the choices available to you.

Effective Date: 23 August 2026

Project 2morrow Software Limited ("we", "us", or "our") operates the GatePass BD mobile application (the "Application") for iOS and Android. This page explains what data the Application collects, how it is used, and the choices you have.

01

SaaS Service Model

GatePass BD is a Software as a Service (SaaS) platform provided to organizations and their employees to manage attendance, access control and field visit tasks.

  • Service provider role. We host and maintain the platform on behalf of your employer. Your employer determines which features are enabled and which data is recorded for your account.
  • Enterprise access only. The Application cannot be used without credentials issued by an organization that subscribes to our service.
  • Permission-based collection. Camera, location and photo library data are collected only after you grant permission through your device's system prompt. You may withdraw any permission at any time in your device settings.
02

Information We Collect

2.1 Information you or your employer provides

  • Full name
  • Official email address
  • Employee ID / code
  • Department and designation
  • Phone number
  • Profile photograph

2.2 Information collected while you use the Application

  • Attendance records — check-in and check-out times, working duration, break periods and attendance status.
  • Location data — your device's precise location at the moment you record attendance or check in to a visit task.
  • Leave and visit-task records — leave requests and reasons you write, and visit-task completion data.
  • Free-text entries — any text you type into fields such as a leave reason or note.

2.3 Information collected automatically by third-party components

The Application includes the Google Maps SDK to display maps and geo-fence boundaries. Google collects the following from the Application:

  • Device identifier
  • Crash data and performance data
  • Product interaction data

This collection is governed by Google's Privacy Policy . We do not use this data ourselves and it is not used for advertising.

03

Device Permissions

Permission Why it is used
Camera To capture your profile photograph and to verify your identity by face match when you record attendance or check in to a visit task.
Location (while using the app) To confirm that an attendance punch or visit-task check-in is taking place inside a geographical boundary configured by your employer.
Photo library To let you choose an existing photograph as your profile picture when the camera is not available.

Location is collected only while the Application is open and in use. We do not track your location in the background, and we never use location data for marketing or advertising.

04

How Face Verification Works

This section describes an important privacy protection built into the Application.

When you use face verification, the Application converts the captured image into a mathematical representation (an "embedding") and compares it against your stored profile photograph. This comparison happens entirely on your device.

Face verification is processed on the user's device. Face images and biometric templates produced during verification are not uploaded to our servers.

  • Only a similarity score is transmitted to our servers, together with whether the match succeeded.
  • No face image and no biometric template produced during verification is ever uploaded or stored on our servers.
  • Your profile photograph is stored on our servers as an ordinary profile picture so that it can be displayed in the Application and used for on-device comparison.

We do not use face data for any purpose other than verifying your identity for attendance, and we never share it with advertisers or data brokers.

05

How We Use Your Information

We use the information described above only to:

  • Authenticate you and keep you signed in.
  • Record and display attendance, breaks, leave and visit tasks.
  • Verify that attendance is recorded from an authorized location and by the correct person.
  • Generate attendance, leave and salary reports for you and your employer.
  • Provide customer support and keep the service secure and reliable.

We do not:

  • Sell your personal data.
  • Share your data with data brokers.
  • Use your data for advertising, or to track you across other companies' apps and websites.
  • Use your data to build advertising profiles.
06

Data Sharing

Your data is accessible to:

  • Your employer, through the administrator accounts they control. Your attendance, leave and visit-task records are visible to authorized administrators within your organization.
  • Our hosting and infrastructure providers, strictly to operate the service.
  • Google, limited to the SDK data described in section 2.3.
  • Legal authorities, where we are required by law to disclose information.

We do not otherwise disclose your personal data to third parties.

07

Data Security

We take reasonable measures to protect your information:

  • All communication between the Application and our servers uses encrypted HTTPS connections.
  • Access to organizational data is restricted by role-based permissions.
  • Face matching is performed on your device, so biometric templates are not transmitted.
  • Session credentials are stored within the Application's own private storage area, which the operating system isolates from other applications.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

08

Data Retention

We retain your personal data for as long as your account remains active with your employer, and for as long as necessary to fulfil the purposes described in this policy or to comply with legal obligations.

Because we act as a service provider to your employer, retention and deletion of employee records are primarily governed by your employer's internal policies.

09

Your Rights and Choices

  • Permissions — you can revoke camera, location or photo library access at any time in your device settings. Some features will stop working when you do.
  • Access and correction — to see or correct the personal data held about you, contact your organization's administrator in the first instance.
  • Deletion — to request deletion of your personal data, contact your employer's administrator or write to us using the contact information in section 11. Where we act on your employer's behalf, we will refer the request to them.

Depending on where you live, you may have additional rights under local data protection law.

10

Children's Privacy

The Application is an enterprise workplace tool intended for employees. It is not directed at children, and we do not knowingly collect personal data from anyone under 13.

If you believe a child has provided us with personal data, please contact us and we will delete it.

11

Contact Us

If you have questions about this Privacy Policy or our privacy practices, you can contact:

Project 2morrow Software Limited

Address
House 7, Road 1/C, Extension 2/2,
Block L, Banani, Dhaka 1213,
Bangladesh
12

Changes to This Policy

We may update this Privacy Policy from time to time. Changes take effect when we post the revised policy and update the Effective Date above.

Where changes are significant, we will make reasonable efforts to notify you or your employer.