1. Overview
This Privacy Policy explains how Intugine Technologies (“Intugine”,
“we”, “us” or “our”) collects, uses, shares and protects information
through the Hub Incharge App (the “App”).
The App is a business-to-business (B2B) field-operations tool and a part of the
IntuTrace platform. It is used by authorised field teams to record duty
activity — check-in and check-out, duty status, odometer readings and trip summaries
— for the facilities and vehicles they are assigned to.
No self-service sign-up. The App does not let you create your own account.
Access is provisioned by Intugine for your organisation. Your ability to use the App is
governed by the agreement between your organisation and Intugine.
This Policy is written to be consistent with India’s Digital Personal Data
Protection Act, 2023 (the “DPDP Act”) and the rules notified under it, and
with Google Play’s data-safety requirements. By using the App, you acknowledge this Policy.
2. Data at a glance
A summary of what the App collects, why, and who it is shared with. The sections below give the full detail.
| Information | Why we collect it | Shared with |
Sign-in details Facility username, password, mobile number, one-time password (OTP) |
Authenticate you and issue a secure session |
IntuTrace platform (our backend) |
Location Approximate & precise location at the time of an action |
Validate that check-in / duty / odometer events happen at the correct place |
IntuTrace platform (our backend) |
Odometer capture Photo of the vehicle odometer and the reading (manual or scanned) |
Record the start / end reading for a trip |
IntuTrace platform (our backend) |
Duty & trip records Check-in/out times, duty status, trip summary |
Maintain the duty log your organisation relies on |
IntuTrace platform (our backend) |
Device & technical Device identifiers, OS & app version, network state, integrity signals |
Deliver notifications, keep the session secure, detect tampering |
IntuTrace platform; Google (for push & OTP auto-fill) |
Notifications FCM topic subscription |
Send duty-related push notifications |
Google Firebase Cloud Messaging |
We do not sell or rent your data.
We do not use it for advertising or build ad profiles.
We do not target children.
3. Information we collect
We collect only the information needed to run the App for your organisation. The categories are:
3.1 Sign-in and account information
- Facility username and password you use to sign in.
- Mobile number to which the one-time password (OTP) is sent.
- One-time password (OTP) — a 4-digit code used once to verify sign-in. To make sign-in faster, the App may use Google’s SMS Retriever to auto-fill this code from the verification SMS. This retrieves only the one-time code and does not read your other messages.
- Session token issued after a successful sign-in, stored encrypted on your device.
3.2 Location
- Approximate and precise location, collected at the moment of an action (sign-in, check-in, check-out, odometer upload) — not as continuous background tracking.
- Used to confirm the action occurred at the correct facility or geofence. A freshness check discards stale coordinates so an outdated location is not recorded against your activity.
3.3 Odometer capture
- A photo of the vehicle odometer taken with your device camera, and the resulting reading (entered manually or read from the image).
- Reading from the image may be performed on your device or on our backend, depending on the configuration in force.
3.4 Duty and trip records
- Check-in and check-out times, duty status transitions, and the trip summary associated with your session.
3.5 Device and technical information
- Device identifiers and model information, operating-system and App version, and network state, used to operate the App and deliver notifications.
- Device-integrity signals (for example, indicators of a modified or rooted device) used to protect the integrity of the data you record.
3.6 Notifications
- We use Google Firebase Cloud Messaging (FCM) in a topic-based model. The App subscribes to the topics relevant to your role after sign-in and leaves them on sign-out.
- We do not store or use the FCM device token to identify or profile you.
4. How we use the information
- Authentication & session management — verify who you are and keep your session secure.
- Geofence validation — confirm that duty and odometer events occur at the correct location.
- Odometer & trip logging — record and summarise trips for your organisation.
- Duty-log management — maintain the check-in / on-duty / duty-ended workflow.
- Notifications — deliver duty-related messages to you.
- Security & integrity — detect tampering, protect the accuracy of recorded data, and prevent abuse.
- Service operation & support — operate, maintain, improve and provide support for the App, and meet legal obligations.
5. Legal basis & consent
Under the DPDP Act, we process your personal data on the basis of your consent and,
where applicable, legitimate uses such as performing the service your organisation
has contracted for, and compliance with legal obligations.
- Consent is specific, informed and unambiguous, and is given in plain language.
- Some data is necessary for the core function of the App (for example, location to validate a check-in, and the odometer reading to record a trip). Declining to provide it may mean the corresponding feature cannot be completed.
- You can withdraw consent at any time; see Section 9.
6. Sharing & third parties
We share information only with the parties needed to provide the service, and never to sell or rent it.
- IntuTrace platform (our backend) — the primary system that stores and processes the duty, odometer and trip data you record.
- Google — for push notifications (Firebase Cloud Messaging) and OTP auto-fill (SMS Retriever via Google Play services).
- Cloud / hosting providers — infrastructure that hosts the IntuTrace platform, acting as processors on our behalf.
- Your organisation — the duty and trip records you create are part of the service your organisation subscribes to and are visible to authorised personnel within it.
- Legal authorities — where we are required to disclose data by law, court order, or to protect rights and safety.
We do not sell, rent, or trade your personal data, and we do not use it for advertising or to build
advertising profiles.
7. Retention & deletion
- We keep your data for as long as needed to provide the service, fulfil the purposes in this Policy, and meet legal, tax or audit obligations.
- When the purpose is fulfilled or you withdraw consent (and no legal duty requires us to keep it), we delete or anonymise the data.
- You can request deletion of your personal data through the contact details in Section 13.
8. Security
We use reasonable safeguards to protect your data, including:
- Encryption in transit — all communication with our servers is over TLS.
- Encryption at rest — your session token is stored in encrypted device storage.
- Access controls — least-privilege access for our personnel and systems.
- Device-integrity checks — to detect tampering and protect the accuracy of recorded data.
- No cloud backup of app data — the App is configured to disallow automatic cloud backup of its data.
No method of transmission or storage is 100% secure. If a personal-data breach occurs, we will
notify the Data Protection Board of India and, where required, the affected
individuals, in line with the DPDP Act.
9. Your rights
Under the DPDP Act, you have the right to:
- Access a summary of your personal data and how it has been processed.
- Correct inaccurate or incomplete data.
- Erase your personal data, subject to any legal retention duty.
- Withdraw consent at any time, as easily as it was given.
- Grievance redressal — raise a concern and have it addressed.
- Complain to the Data Protection Board of India if you believe your rights have not been respected.
To exercise any of these rights, contact us using the details in Section 13.
We will verify your identity before acting on a request.
10. Children’s data
The App is a B2B professional tool and is not directed at children. We do not
knowingly collect personal data from children. If you believe a child has provided us data,
contact us and we will delete it.
11. International data transfers
Your data may be processed on servers located in India or in other countries where we or our
processors operate. Any cross-border transfer is made in accordance with the DPDP Act and the
restrictions notified by the Government of India, with appropriate safeguards in place.
12. Changes to this Policy
We may update this Policy from time to time. For material changes, we will notify you through the
App and/or by email, and update the “Last updated” date above. Continued use of the App
after changes take effect constitutes acceptance of the revised Policy.