Effective date: September 12, 2026
Location disclosure. The Rental AutoPilot Staff app collects precise location data to enable attendance and staff operational coordination even when the app is minimized or not in use. It also uses foreground location for nearby PLN meter matching. If the client enables routine staff location and you grant background or "Always" location permission, the app may collect location approximately every ten minutes, but only during an active attendance shift or the working window configured for you. The server rejects routine location samples received outside that permitted window.
Who this notice is for: people who sign in to the Rental AutoPilot Staff app on iOS or Android, and staff using the same mobile portal in a browser. It supplements the Platform & CMS Privacy Notice.
Legal entity: PT Rental AutoPilot
Address: Jalan Sriwijaya 32, Legian, Kuta, Bali 80361
Privacy contact: admin@rentalautopilot.com
Who determines how staff data is used
Your employer, property manager, or other Rental AutoPilot client configures the staff modules, permissions, properties, teams, attendance rules, guest-contact access, and permitted working windows available to you. That client generally determines why staff and operational data is collected and which authorized people within its account may view it. Rental AutoPilot processes the data to provide and secure the configured app service. Questions about your employer's use of staff location or attendance should be directed to the client as well as to Rental AutoPilot.
Information the app processes
- Account and session: account identity, client, roles, permissions, property or pool access, sign-in cookies, locale, preferences, and security events.
- Device and push: an app-installation identifier, APNs or FCM push token, platform, app version, device label, user agent, notification and location permission or service status, last-active time, and notification-delivery results.
- Precise location: latitude, longitude, accuracy, source or provider, capture and receipt time, delayed-sample or mock-location indicators, and the related user, device, shift, attendance action, scan, property, or operational context.
- Camera and media: attendance proof photos, camera frames analyzed for liveness, PLN meter photos, attachments you select or capture, and associated OCR, quality, verification, or review results.
- Contacts: guest name, phone number, email, booking reference, channel, villa, and stay dates sent to your app when you are authorized and guest-contact saving is enabled.
- App activity: attendance, tasks, messages, calls, electricity scans, workflow actions, errors, diagnostics, and the content or metadata required by modules you use.
Precise and background location
Location is requested only for a feature that needs it and after you grant device permission. The app may request a fresh location when you start or end attendance, scan a PLN meter, or deliberately use another location-dependent feature. Routine sharing is used only when the client has enabled it for your account. On iOS, continuing routine updates while the app is minimized requires background or "Always" location access; on Android, the applicable background-location permission and service requirements apply.
Routine samples support authorized operational users in viewing a recent staff position and the nearest managed property. Attendance location supports clock-in and clock-out evidence. A PLN scan location helps prioritize registered meters near the scan and reduce incorrect property matches. The client may use these features for attendance, dispatch, safety, and operational coordination. Location is not used for advertising or cross-app tracking.
Depending on the client's permission setup and property or team scope, relevant location may be visible to client administrators, staff-profile managers, pool managers, and attendance reviewers. When an authorized user opens a staff-and-property map, Google Maps receives the coordinates needed to display that map.
Camera, attendance proof, and liveness checks
Attendance may ask you to use the camera and perform simple movements, such as blinking or turning your head. A MediaPipe face-landmark model analyzes the camera frames on your device to determine whether the requested movement occurred. It is not used to identify you or create a reusable facial-recognition template. Camera frames are evaluated locally, but one proof image, the liveness result, and the related attendance and location context are sent to Rental AutoPilot and stored as private, permission-controlled evidence.
Camera permission can also be used when you deliberately capture a meter photo or supported message or task attachment. You should avoid including unrelated people, documents, or personal information in operational images.
PLN meter photos and OCR
When you use the PLN workflow, the app can capture a meter image and attempt on-device text recognition. The image and scan context may also be sent to Rental AutoPilot's server and configured OCR or AI provider, including OpenAI where enabled, to assess image suitability, read the meter number and LCD value, identify a likely nearby property, and support staff or administrator review. Originals and generated evidence are stored privately in Google Cloud Storage and are delivered only through authenticated, permission-checked access.
Guest contacts
Guest-contact saving works only if you have permission to view guest contact details, enable guest-contact saving in your personal Rental AutoPilot settings, and grant the app Contacts permission. Rental AutoPilot sends only the guest fields needed to create the contact card in your selected name format. The app searches the device address book for the supplied phone number and then adds or updates that contact locally. Rental AutoPilot does not upload your complete address book.
Turning off guest-contact saving or revoking Contacts permission stops future saves. Contacts already added to your device remain there until you edit or delete them. The operating system controls whether you grant full or limited contact access and may show its own permission choices.
Notifications and app badge
If you allow notifications, the app registers its installation and Apple Push Notification service or Firebase Cloud Messaging token. Notifications may concern guest or team messages, reservations, calls, attendance, PLN operations, Xero or other accounting operations, the CMS Notification Center, app updates, and other workflows you are authorized to access. The app badge is calculated from relevant unread messages, pending accounting operations, and Notification Center items available to your account.
A guest-contact synchronization notification may contain the guest fields needed to add or update the local contact. Notification text can appear on the lock screen according to your device settings. Signing out disables that installation and token for future Rental AutoPilot notifications.
Microphone and photo library
The app requests microphone or photo-library access only when you invoke a supported feature that needs it, such as participating in a call, recording or sending audio, choosing an attachment, or saving permitted media. Information you select or record is handled as part of the related call, message, evidence, or operational workflow.
How information is used and shared
We use Staff App data to authenticate you, show permitted modules, record attendance, coordinate operations, process meter scans, display and synchronize messages or tasks, save enabled guest contacts, deliver notifications, calculate the app badge, secure the account, troubleshoot errors, and maintain appropriate audit evidence.
We do not sell this information or use it for advertising. Information is available to authorized users within the client's account according to their permissions. It may be processed by the providers needed for the selected feature, including Apple or Google for push delivery, Google Cloud Storage for private media, Google Maps for maps, and configured messaging, OCR, translation, communications, or AI services. We require third parties handling app data for us to provide equivalent protection consistent with this notice and applicable platform requirements. We may also disclose information where required by law or necessary to protect rights, safety, or system integrity.
Retention
- Routine staff-location samples and attendance-location samples are scheduled for deletion after 30 days.
- Attendance proof images are scheduled for deletion after 90 days.
- Completed, failed, or expired push-delivery history is retained for 7 days.
- The installation identifier and push token are kept while the installation remains registered; signing out disables the installation for future notifications.
- PLN images, messages, tasks, attendance records, contacts sent for synchronization, and other operational records are retained according to the client's configured workflow and as needed for operations, audit, security, dispute handling, contractual duties, and applicable law.
Automated deletion may not immediately remove information from ordinary protected backups or from a connected provider that has its own retention obligations.
Your controls and deletion choices
You can deny or later revoke notification, Contacts, camera, microphone, photo, or location access in iOS or Android settings. Related attendance, scan, contact, media, call, or notification features may then be unavailable. You can turn guest-contact saving off in Rental AutoPilot personal settings. The client administrator can change staff-module, attendance, routine-location, and working-window configuration.
You can request correction or deletion through the client responsible for your staff account or by emailing Rental AutoPilot. A logged-in user can request account deletion from the Account area in Settings; confirmed deletion is scheduled after a 14-day grace period, subject to records that must be retained by law, legitimate security or dispute records, and ordinary backup cycles. We may need to verify your identity and the client's authority before acting.
Security, international processing, and children
We use technical and organizational measures designed to protect Staff App data and apply tenant, user, permission, and property checks before protected media or operational records are displayed. No system is completely secure, so protect your device and credentials and sign out of devices you no longer control. Providers may process information outside Indonesia; where required, we take reasonable steps to protect information processed internationally. The Staff App is a workplace and operations tool and is not intended for children.
Changes and contact
We may update this notice as app permissions or workflows change. Material changes may also be communicated in the app, through the CMS, or directly where appropriate. For privacy questions or requests, email admin@rentalautopilot.com.