Privacy Policy
1. About this policy
This Privacy Policy explains how OnSite (“we”, “us”, “our”) collects, uses, stores and shares information when you use the OnSite mobile application and related services (together, the “Service”), and when you visit this website at onsitehq.co.uk.
OnSite is a business workforce and project operations application for construction, trade and similar field-based businesses. It is intended for use by employers and their authorised workers — not for general consumer or children's use.
If you use OnSite because your employer invited you, your employer controls much of the work-related information processed in the Service. This policy explains how the OnSite platform works. Your employer may also have workplace policies that apply to your employment data.
Privacy contact: privacy@onsitehq.co.uk
2. Who uses OnSite
OnSite supports company owners, administrators, managers, employees and subcontractors (where enabled), working within invite-based company accounts.
3. Information we collect
3.1 Account and identity
- Name and preferred name
- Email address
- Account identifiers (such as a Firebase user ID)
- Company membership and role
- Authentication credentials (handled by our authentication provider; we do not store your password in plain text)
- App version, build and push notification token where needed to deliver the Service
3.2 Workforce and employment records
- Clock-in / clock-out and work sessions
- Timesheets and attendance events
- Holiday and availability requests and approvals
- Tasks, checklists, communications and related audit history
- Job titles, employment type and company workforce records
3.3 Location information
OnSite uses location for work-related purposes only.
- Geofence arrival and departure — where configured, to detect approach to or departure from a worksite
- While clocked in — background location may be used to support occupational attendance verification for the duration of an active work session
- Work observations — while clocked in, OnSite records occupational observations at a company-configurable interval of every 10 minutes (Standard) or 5 minutes (Precise)
- When collection stops — continuous occupational location monitoring stops when you clock out
Ordinary work observations typically record whether you were inside or outside your assigned worksite and your distance from that site, together with accuracy information. They do not store a continuous route or journey map in the standard attendance ledger.
Authorised company users may see attendance-related information derived from work sessions and observations for legitimate workforce administration — not live tracking of personal movement outside work.
3.4 Location Investigation Evidence (optional)
Some companies may enable Location Investigation Evidence, an optional owner-controlled feature. If enabled, OnSite may also retain precise GPS coordinates from the same occupational observations while clocked in. This feature:
- does not increase observation frequency
- does not provide live tracking
- does not reconstruct routes or journeys
- is intended for exceptional business investigations with restricted owner/admin access and audit controls
Retention is configurable (for example 30 days, 6, 12 or 24 months). If disabled, retained precise evidence becomes inaccessible and is deleted according to the Service configuration.
3.5 Photos, video, audio and documents
Depending on use, we may process photos, videos, audio/voice notes, documents, transcripts and project uploads submitted through the Service.
3.6 Purchases and financial records
We process company purchase receipts, expense records and, for authorised users, bank statement/transaction information used for reconciliation. OnSite is not a bank or payment processor.
3.7 Communications and notifications
We process in-app communications and use push notifications (Firebase Cloud Messaging) and transactional email where applicable (for example invitations).
3.8 Feedback and diagnostics
If you submit feedback through the Service, we process the content you provide plus relevant technical context (such as app version) to investigate and respond.
3.9 AI-assisted processing
To provide certain features, content you or your company submit may be processed by third-party AI services:
| Provider | Typical purpose in OnSite |
|---|---|
| OpenAI | Transcription of voice notes and related audio |
| Google Gemini | Image/video/document understanding, project descriptions, walkthrough planning |
| ElevenLabs | Professional narration synthesis for walkthroughs |
| CleanVoice | Speech enhancement for walkthrough narration |
AI processing is used to provide app functionality — not for cross-app advertising.
4. How we use information
We use information to provide and operate OnSite, authenticate users, enforce permissions, deliver notifications, support receipts and reconciliation, maintain security, and comply with legal obligations.
5. How we share information
- Within your company — with users authorised by role
- Service providers — including Google Firebase/Google Cloud, email delivery providers, and the AI providers listed above
- Legal and safety — where required by law or to protect rights and integrity
We do not sell your personal information.
6. Security
We use measures appropriate to a cloud-hosted business application, including authenticated access, role-based permissions, encrypted transport (HTTPS/TLS), Firebase App Check, and additional server-side encryption for optional Location Investigation Evidence.
7. Data retention
- Personal account data — retained while your account is active; removed or anonymised when you delete your account
- Company business records — may be retained after account deletion where required for payroll, tax, financial, employment, safety or audit purposes
- Location Investigation Evidence — retained only if enabled, for the selected period
8. Account deletion
You can delete your OnSite sign-in account in the app: Settings → Account → Delete Account.
You must type “Delete my account” and re-enter your password to confirm.
When deletion completes:
- your Firebase Authentication account is permanently deleted
- your personal account/profile data and company access are removed
- linked employee records are unlinked and anonymised (business display identity may be retained on the employee record)
- historical employer/company business records may remain as described above
- deletion cannot be undone
If you are the only Owner of a company, you must transfer ownership or otherwise resolve company ownership before deleting your account.
Creating a new account later with the same email address does not automatically restore previous company access.
9. International processing
Data may be processed in the United Kingdom, European Economic Area, United States and other countries where our providers operate, using appropriate safeguards where required.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to certain processing, and to complain to a supervisory authority. Contact privacy@onsitehq.co.uk. Employment records held by your employer may also require contacting your employer directly.
11. Children's privacy
OnSite is a business workforce application and is not directed at children. We do not knowingly provide the Service to children under 16.
12. Changes
We may update this policy from time to time by posting a new version at this URL and updating the effective date.
13. Contact
Email: privacy@onsitehq.co.uk
Support: onsitehq.co.uk/support