Legal

Privacy Policy

Effective: June 30, 2026 Version 1.0 GDPR · CCPA · LGPD

1 Introduction

EMLOCA ("Employee Locator," "we," "us," "our") provides a real-time employee GPS location tracking platform accessible via mobile application and web dashboard. This Privacy Policy explains what personal information we collect, why we collect it, and how we handle it — including the personal information of employees whose location is tracked through our platform.

By creating an account or using EMLOCA's services, you agree to this Privacy Policy. If you do not agree, please discontinue use of the platform.

2 Who We Are

EMLOCA operates the domain emloca.com and its associated subdomains.

EMLOCA acts in two capacities:

Contact: privacy@emloca.com

3 Data We Collect

a) Account & Identity Data

When registering or managing an account, we collect: name, work email address, company name, job title, and account credentials. Passwords are stored exclusively as bcrypt hashes — never in plain text.

b) Employee Location Data

The core function of EMLOCA is collecting GPS coordinates from employees who have installed the EMLOCA Tracker mobile application and activated tracking. We collect:

This data is linked to the employee's profile within the employer's EMLOCA account. Tracking only occurs while the EMLOCA Tracker app is actively running — the app does not operate silently in the background without the employee's knowledge.

c) Device & Technical Data

We collect the mobile device's unique identifier, operating system version, and app version. This is used to authenticate GPS pings and diagnose technical issues.

d) Communications Data

When you contact our support team, we retain email correspondence to resolve your request and improve our service. Communications are not retained beyond 12 months after resolution.

e) Usage Analytics

We collect anonymized, aggregated data about how features are used (page visits, feature usage frequency, session duration). This data cannot be linked back to individual users and is used exclusively to improve EMLOCA.

What we do NOT collect: We do not collect sensitive personal data such as racial or ethnic origin, political opinions, religious or philosophical beliefs, health or medical data, biometric identifiers, genetic data, or financial account numbers.

4 How We Use Your Data

We use collected data solely for:

We do not use your data for: advertising networks, behavioral profiling for marketing purposes, sale or rental to third parties, or any purpose not listed above.

5 Data Sharing — We Never Sell

EMLOCA does not sell, rent, or trade personal data. We have no advertising partnerships or data broker relationships. We share data only with the following service providers, and only to the extent necessary:

RecipientPurposeData Shared
OpenStreetMap / Leaflet.jsMap tile rendering (open-source, no account)Map tile requests only — no personal data
Let's EncryptSSL/TLS certificate issuance and renewalDomain name only
Telegram Bot APIAlert notifications (only if enabled by Account Admin)Alert message text; no GPS coordinates or employee names
SMTP Email ProviderAlert and notification delivery (only if configured)Alert text and recipient email address
Payment ProcessorSubscription billingBilling contact information; no location data

All service providers are required to process data only as instructed and in accordance with applicable data protection law. We do not authorize any service provider to use your data for their own purposes.

We may disclose data if required by law, court order, or to protect the safety of users — always limited to the minimum necessary and after assessing the legal obligation.

6 Data Retention

Data TypeRetention Period
Account & identity dataDuration of active account + 90 days after account closure
GPS location events12 months from the date of collection
Trip history & waypoints24 months from trip date
Geofence event logs12 months
Alert event logs6 months
Support communications12 months after issue resolution
System audit logs12 months

After the applicable retention period, data is permanently deleted from production databases and backups. Account Administrators may delete employee data earlier through the dashboard settings.

7 Security

We implement technical and organizational measures to protect your data:

No system is entirely immune to security incidents. If you suspect unauthorized access to your account, contact security@emloca.com immediately.

8 Employer Responsibilities

Important: This section establishes obligations that Account Administrators (employers) must fulfill independently. EMLOCA provides the tracking technology but does not provide legal advice.

As the Account Administrator deploying EMLOCA to track your employees, you are the data controller for your employees' location data. You bear full responsibility for:

We strongly recommend consulting with employment law and data protection counsel in your jurisdiction before deploying employee location tracking.

9 Employee Rights

Employees whose location is tracked through EMLOCA have the following rights regarding their personal data. Requests may be directed to the employer (Account Administrator) or directly to us at privacy@emloca.com:

We respond to verified rights requests within 30 days. Complex requests may take up to 90 days, and we will notify you if an extension is needed.

10 International Data Transfers

EMLOCA servers are hosted in the United States. If you access EMLOCA from the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws governing international transfers, your data will be transferred to and processed in the United States.

We use appropriate safeguards for such transfers, including Standard Contractual Clauses (SCCs) approved by the European Commission where applicable. By using EMLOCA, EEA and UK users acknowledge that their data may be transferred internationally subject to these protections.

11 Children's Privacy

EMLOCA is a professional business platform intended exclusively for users aged 18 and older. We do not knowingly collect personal information from individuals under 18. If we learn that we have inadvertently collected data from a minor, we will delete it promptly. If you believe a minor's data has been submitted, please contact privacy@emloca.com.

12 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, product features, or legal requirements. When we make material changes, we will:

Your continued use of EMLOCA after the updated effective date constitutes your acceptance of the revised Policy. If you disagree with the changes, please discontinue use and contact us to close your account.

13 Contact

For privacy-related inquiries, data rights requests, or complaints regarding this Policy:

EMLOCA — Privacy Team
Email: privacy@emloca.com
Response time: 30 business days

General support: support@emloca.com

EEA residents who are not satisfied with our response may escalate to their national data protection supervisory authority. A list of EEA authorities is available at edpb.europa.eu.