CODEFY MOBILE APPLICATION PRIVACY NOTICE
Version: 1.0Effective Date: 1st August 2025Last Updated: 12th August 2026
This Mobile Application Privacy Notice explains how Codefy Hub For IT Solutions, trading as Codefy Hub, processes personal data and uses device permissions in connection with Codefy mobile applications.
This Notice supplements the Codefy Hub Privacy Policy and should be read together with the Codefy Hub Terms of Service, Codefy ERP Service Terms, Data Processing Addendum, and Subprocessors and Technology Providers List.
Different Codefy applications serve different purposes and therefore do not request or process the same categories of information.
1. Applications Covered
This Notice currently applies to:
Codefy Driver App
Used by Drivers in connection with transportation operations, trips, routing, telematics, tracking, status updates and other Driver functionality.
Codefy Supervisor App
Used by supervisors and operational personnel for transportation supervision, attendance, location based operations, QR scanning and related field functionality.
Codefy Rider App
Used by employees, students, parents, guardians and other authorized Riders to access transportation information, schedules, trip status, pickup and drop off information, notifications and other Rider functionality.
Additional applications may be added to this Notice as the Codefy product family develops.
2. Codefy's Privacy Role
The organization providing access to a Codefy mobile application may be an employer, school, Transport Provider, enterprise or another Codefy Customer.
Where that organization determines why and how personal data is processed through the application, it will generally act as controller and Codefy will generally act as processor.
Codefy may separately act as controller for limited processing relating to its own security, application administration, legal compliance, support and other purposes described in the Codefy Hub Privacy Policy.
3. Information May Come From Your Organization
A mobile user may not have supplied all information associated with their account directly to Codefy.
An employer may provide employee information.
A Transport Provider may provide Driver information.
A school may provide student transportation information.
A school or other authorized Customer may associate a parent or guardian with a student.
Questions concerning information supplied by one of these organizations should generally be directed to that organization where it acts as controller.
4. Device Permissions
Codefy applications may request access to device functionality where necessary for enabled features.
Depending on the application, this may include:
location;
precise location;
background location;
motion or activity information;
camera;
photos or images;
notifications;
biometric authentication;
network access;
and other technical capabilities.
Not every Codefy application requests every permission.
Codefy should request permissions in a manner proportionate to the functionality being provided and should explain material sensitive permissions before or when they are requested.
Google Play currently requires applications seeking background location access to provide a prominent in app disclosure, a privacy policy and additional permissions review materials.
5. Permission Choices
Where the mobile operating system allows a permission to be optional, users may generally grant, deny or later revoke that permission through their device settings.
Disabling a permission may prevent the relevant feature from functioning.
For example:
disabling Driver background location may prevent continuous trip detection or tracking;
disabling camera access may prevent QR scanning;
disabling notification permission may prevent operational notifications;
and declining optional Rider location access may prevent location based Rider functionality.
6. Driver App
The Driver App supports Drivers performing transportation activities managed through Codefy ERP.
Depending on enabled functionality, the Driver App may provide:
trip assignments;
trip schedules;
route information;
navigation related functionality;
trip status controls;
attendance functionality;
vehicle or project information;
notifications;
live tracking;
and telematics functionality.
7. Driver Identity and Account Information
The Driver App may process information such as:
Driver name;
Driver identifier;
telephone number;
account information;
transport organization;
assigned vehicle;
assigned trips;
route information;
application permissions;
device registration information;
and related operational information.
The exact information depends on Customer configuration.
8. Driver Location
Where tracking functionality is enabled, the Driver App may access precise device location to provide transportation tracking.
This may include GPS coordinates and related location measurements.
The current Android Driver implementation requests both fine and coarse location access.
Location may be associated within Codefy systems with relevant operational information such as the Driver, vehicle, trip or route.
9. Driver Background Location
The Driver App may request permission to access location while the application is operating in the background.
The current Android implementation explicitly declares background location and foreground location service permissions.
Where enabled, background location may be necessary for:
continuous active trip tracking;
trip detection;
recording trip movement;
maintaining live fleet visibility;
determining trip progress;
and related transportation operations.
This means tracking may continue while the Driver App is not actively visible on the screen.
10. Driver Motion and Activity Information
The Driver App may process motion related or activity information where telematics functionality requires it.
The current Driver application declares Android Activity Recognition permission.
Where Damoov technology is enabled, telematics processing may include GPS, accelerometer and gyroscope information, together with information associated with trip detection and driving behavior. Damoov describes these categories in its current technical privacy documentation.
11. Driver Telematics
Depending on the enabled tracking provider and configuration, telematics data may include:
GPS coordinates;
timestamp;
speed;
heading;
location accuracy;
motion sensor information;
trip start and stop information;
driving events;
device identifiers;
and other technical information necessary for transportation tracking.
Codefy's current fleet tracking gateway normalizes location coordinates, speed, heading, accuracy and timestamps received from the tracking provider and may associate that information with authorized trip, Driver and vehicle information.
12. Damoov Tracking Technology
Certain Driver App and fleet tracking functionality currently uses technology provided by Damoov Pte. Ltd.
Codefy supports tenant specific Damoov integrations and device tokens for transportation tracking.
Damoov describes its telematics technology as processing GPS coordinates, accelerometer and gyroscope data, timestamps, motion signals, trip information and driving behavior information, primarily using pseudonymized device identifiers.
Damoov's public documentation also describes additional device state and permission information that may be processed by its telematics technology, including charging state, WiFi status and relevant smartphone permission state.
13. Damoov's Role
For institutional deployments, Damoov currently describes the institution using its telematics technology as controller and Damoov as processor.
In a Codefy deployment, the precise legal relationship depends on the applicable Customer arrangement and processing chain.
Where Codefy appoints Damoov to process personal data on Codefy's behalf in providing Codefy services, Damoov will be identified through Codefy's Subprocessors and Technology Providers framework.
Codefy's own access to Damoov services is governed by Damoov's applicable service agreement.
14. Driver Tracking Disclosure
Before enabling persistent Driver tracking, Codefy should provide the Driver with a prominent disclosure explaining:
that precise location may be collected;
that collection may continue in the background;
that motion or telematics data may be processed;
the operational purposes of the tracking;
whether a third party tracking provider is involved;
and how disabling permissions affects functionality.
This disclosure should appear in the application before or in connection with the relevant operating system permission request.
15. Tracking Is Not an Emergency Service
Driver tracking is designed to support transportation operations.
It should not be relied upon as an emergency location service or as the sole mechanism for protecting Driver or Rider safety.
Location data may be delayed, incomplete or inaccurate due to:
GPS availability;
mobile connectivity;
device settings;
battery restrictions;
operating system behavior;
permissions;
hardware;
environmental conditions;
or third party provider availability.
16. Driver Notifications
The Driver App may request notification permission.
Notifications may include information relating to:
trip assignments;
schedule updates;
operational changes;
transportation status;
alerts;
and other application events.
Delivery depends on device settings, operating system functionality, connectivity and applicable notification infrastructure.
17. Driver Biometric Authentication
The Driver App may support biometric authentication provided by the user's device.
The current Android application declares biometric permission.
Where authentication is performed locally by Android or iOS, Codefy may receive confirmation that authentication was successful without obtaining the underlying fingerprint or facial biometric template.
If Codefy introduces a feature that directly stores or processes biometric templates, this Notice must be updated before that functionality is used.
18. Supervisor App
The Supervisor App supports transportation and field supervision functions.
Depending on Customer configuration, it may provide:
trip oversight;
attendance;
Driver or Rider status information;
location functionality;
QR scanning;
image upload;
tasks and subtasks; approval and petty cash workflows; vacation information; and manager reports;
and other operational tools.
The Supervisor App may process the supervisor's name, account and contact information and the operational records the user is authorized to view or update. This may include attendance records, assigned work, approval records, expense or petty cash workflow information, staff availability information, incident follow ups and licence expiry information, depending on the user's role and Customer configuration.
The Supervisor App uses device biometrics for user initiated authentication where the user enables biometric login or an attendance workflow requires local biometric verification. Android or iOS performs the biometric comparison locally. Codefy receives the authentication result and does not receive or store the underlying fingerprint or facial biometric template.
When a user attempts or submits attendance, the Supervisor App may collect attendance diagnostic information to validate the attendance decision, detect misuse and troubleshoot failed attempts. This may include location measurements, mocked location status, device and operating system details, application version, permission state, connectivity status and battery level or state. Diagnostic information may be provided to the relevant Customer and accessed by authorized Codefy personnel when needed for support, security or investigation.
19. Supervisor Location
The current Android Supervisor application requests fine and coarse location permissions only. It does not request background location or foreground service location permissions.
Location is accessed while the application is visible and the user initiates a relevant feature, such as attendance location verification or another enabled location based field workflow.
The application explains the relevant purpose before requesting location permission. A user may deny or revoke the permission, but the corresponding location based feature may then be unavailable.
20. Supervisor Camera
The Supervisor App may request camera permission.
The current Android configuration uses camera access for user initiated QR scanning. A user may also choose to open the device camera when attaching incident evidence or another enabled operational image.
The application does not use the camera continuously or for unrelated monitoring.
21. Supervisor Images and Media
The Supervisor App allows a user to select an image through the system photo picker or capture an image for incident evidence or another enabled operational upload.
The current Android application does not request broad media library or legacy external storage permissions. It receives only the image the user intentionally selects or captures for the relevant workflow.
Codefy does not access a user's image library for unrelated purposes.
22. Rider App
The Rider App is designed for multiple transportation user contexts.
It may be used by:
employees;
students;
parents;
guardians;
and other authorized Riders.
The functionality available to each user depends on the Customer configuration and the user's assigned role.
23. Rider Information
The Rider App may process information such as:
name;
email address;
telephone number;
home address;
profile image;
account identifier;
employee or student identifier;
organization or school;
authorized guardian relationship;
assigned transportation;
route;
pickup point;
drop off point;
trip information;
attendance;
transportation status;
notifications;
on demand transportation booking requests;
complaint category and description;
incident or complaint images;
Driver and vehicle ratings and related review information;
and related Customer configured information.
24. Employee Riders
An employee may use the Rider App to access transportation information connected with transportation provided or organized by their employer or another Customer.
This may include:
schedules;
routes;
pickup information;
trip status;
vehicle information;
notifications;
and optional location based features.
The employer or other organization may act as controller for this processing.
25. Student Riders
Students may use the Rider App in connection with school transportation where enabled by the applicable School or other Customer.
The application may display authorized information including:
transportation schedule;
route;
pickup and drop off information;
trip or vehicle status;
notifications;
and attendance related information.
Student information should be limited to what is reasonably necessary for the transportation purpose.
26. Parents and Guardians
Authorized parents or guardians may use the same Rider App to view transportation information relating to an associated student.
Depending on configuration, this may include:
trip status;
pickup and drop off information;
vehicle or route information;
notifications;
and other authorized school transportation information.
The Customer is responsible for correctly associating a parent or guardian with the relevant student where the Customer acts as controller.
27. Optional Rider Location
The Rider App may offer optional features that use the location of the user's own device.
This feature may be available to employees, students, parents or guardians.
A user may choose to enable location for purposes such as:
determining their current position;
locating a pickup point;
finding nearby transportation information;
displaying their position relative to a trip or route;
or using another location based feature.
28. Rider Location Is Not Continuous Driver Tracking
Optional Rider location is different from Driver telematics.
Unless separately disclosed and enabled, Codefy does not intend to continuously track an employee, student, parent or guardian merely because the Rider App is installed.
Where Rider location is optional, it should be accessed only in connection with the disclosed user initiated functionality and relevant permission.
The user may deny or revoke the permission.
The corresponding feature may then become unavailable.
29. Student Device Location
Where a student chooses to use an optional location based feature, the student's device location may be processed for the disclosed purpose.
Because student information may constitute children's personal data, the applicable School or Customer must ensure that use of such functionality has an appropriate lawful basis and required guardian authorization or consent.
Codefy should minimize retention and use of the student's own device location beyond the purpose for which it was requested.
30. Parent Device Location
Where a parent or guardian uses an optional location feature, Codefy may process the location of that parent's own device.
The parent's own location should be treated separately from the student's transportation data.
Using the Rider App to view a student's trip does not itself authorize continuous tracking of the parent's device.
31. Separation of Student Identity From Vehicle Telematics
Codefy seeks to minimize unnecessary transmission of identifiable student information to telematics providers.
Where technically practicable, tracking providers should process identifiers associated with a Driver device, vehicle, or trip rather than a student's identity.
Codefy may associate the tracked trip with student transportation information within the Codefy platform where necessary for the Service.
Damoov's current privacy architecture similarly describes telematics processing based primarily on pseudonymized DeviceTokens and separation of identity data from the telematics pipeline.
32. Children's Privacy
Student transportation functionality may involve children's personal data.
Where an employer, School or other Customer determines the purposes of processing, that Customer is responsible for establishing the appropriate lawful basis and satisfying applicable requirements concerning minors and guardian authorization.
Codefy will process Customer controlled student information according to Customer instructions where Codefy acts as processor.
Additional children's privacy provisions are contained in the Codefy Hub Privacy Policy and Data Processing Addendum.
33. Camera Access in Rider App
The current Android Rider or Employee application declares camera access.
Camera access may be used for enabled user initiated features such as image capture or QR related functionality where applicable.
The application should explain the actual purpose before requesting camera access.
34. Rider Images
The current Android Rider or Employee application declares access to media images, together with legacy image storage access for supported Android versions.
This may support user initiated selection or uploading of a profile image or an incident or complaint image. Images selected or captured by the user may be uploaded to Codefy managed storage and made available to the relevant Customer personnel for the related profile or complaint workflow.
Codefy should not use image access for unrelated purposes.
35. Rider Biometric Authentication
The current Android Rider or Employee application declares biometric authentication capability.
Where biometric authentication occurs locally on the user's device, Codefy does not need to receive or store the underlying fingerprint or face template.
36. Notifications Across Mobile Applications
Codefy applications may use push notifications to communicate operational information.
Depending on the app, notifications may concern:
trip assignments;
trip changes;
pickup or drop off information;
attendance;
approvals;
transportation status;
system messages;
and security events.
Push delivery may require a device push token and may depend on Apple, Google or another mobile notification infrastructure.
37. Application and Device Information
Codefy may process technical data necessary to operate, secure and troubleshoot mobile applications.
This may include:
device type;
operating system;
app version;
device or application identifiers;
push notification token;
session information;
IP address;
error information;
authentication information;
and diagnostic events.
38. Account Security
Codefy may process security information to:
authenticate users;
prevent unauthorized access;
maintain sessions;
detect suspicious activity;
protect Customer Data;
and investigate security incidents.
Users should protect their mobile device and credentials.
Customers should promptly disable accounts for lost, stolen or reassigned devices where appropriate.
39. Data Shared With the Customer
Information collected or generated through a Codefy mobile application may be made available to the relevant Customer where necessary to provide the Service.
Depending on role and functionality, this can include:
Driver tracking information;
trip activity;
attendance events;
operational status;
Rider transportation information;
and other Customer controlled data.
Customer personnel can access information only according to applicable roles and permissions configured within Codefy ERP.
40. Who May View Transportation Information
Depending on authorized access and the applicable workflow, transportation information may be visible to:
Customer administrators;
transportation operations teams;
supervisors;
Transport Providers;
authorized enterprise personnel;
school personnel;
Drivers;
Riders;
parents or guardians;
and authorized recipients of limited tracking links.
Customers are responsible for assigning organizational access appropriately.
41. Third Party Technology Providers
Mobile application functionality may rely on third party technology providers.
These may include providers of:
telematics;
maps;
mobile notifications;
authentication;
cloud services;
analytics;
communications;
and other infrastructure.
Material providers processing Customer Personal Data on Codefy's behalf will be identified through the Codefy Subprocessors and Technology Providers List.
42. Third Party Maps and Navigation
Codefy applications may use third party maps, geocoding or navigation technology.
Use of map functionality may result in location related information being transmitted to an applicable map provider where necessary to deliver the feature.
The exact providers should be identified through Codefy's current technology provider inventory.
43. Artificial Intelligence in Mobile Applications
A Codefy mobile application may expose functionality supported by Codefy ERP AI features.
Where a user intentionally invokes an AI feature, information necessary to process the user's request may be transmitted to Codefy and an authorized AI provider where applicable.
Codefy will address such providers through its general Privacy Policy and Subprocessor framework.
Location or telematics information should not be transmitted to AI services merely because it exists in the mobile application unless such processing is necessary for an expressly enabled and lawful AI feature.
44. Information We Do Not Need
Codefy mobile applications should not request unnecessary access to information or device capabilities unrelated to enabled functionality.
Codefy does not intend to use mobile permissions for unrelated advertising surveillance.
If a future feature requires a materially different category of data or device access, this Notice and the relevant in app disclosure should be updated before or when that processing is introduced.
45. Advertising and Cross App Tracking
Codefy mobile applications are enterprise and operational applications.
Unless expressly disclosed in an updated notice, Codefy does not use Driver, Rider or student location information for third party behavioral advertising.
Codefy does not intend to sell Driver, Rider, student or guardian location data to data brokers or advertisers.
Damoov similarly states in its current privacy materials that it does not sell personal data or share it with advertisers or data brokers.
46. Retention
Mobile application information is retained according to the Codefy Hub Privacy Policy, the applicable Customer agreement, Customer instructions, operational requirements and applicable law.
Different categories may have different retention periods.
For example, account records, attendance records, application diagnostics and telematics data need not have identical retention schedules.
47. Tracking Retention
Driver and vehicle tracking data may be retained for a period determined by:
Customer requirements;
Codefy configuration;
legal requirements;
security requirements;
and the applicable tracking technology configuration.
Damoov currently publishes different retention detail depending on data category and service configuration, so Codefy should not promise one universal Damoov retention period unless it matches Codefy's actual arrangement.
48. Data Security
Codefy implements technical and organizational safeguards intended to protect personal data processed through its mobile applications.
Depending on the processing, these may include:
authentication;
role based access;
secure communications;
access controls;
logging;
tenant isolation;
security monitoring;
and encryption.
The current Android Supervisor application disables Android cloud backup and excludes app-owned data from device-to-device transfer. This reduces the risk of device-bound authentication credentials and locally stored operational data being restored to another device. A user who reinstalls the application or changes devices may need to sign in again; records already held in Codefy or Customer systems are not deleted by this device-level protection.
Damoov's current privacy materials also describe measures including TLS, encryption at rest and role based access controls for its telematics platform.
No mobile or information system can guarantee absolute security.
49. Data Subject Rights
Users may have rights concerning their personal data under applicable law.
These may include rights relating to:
access;
correction;
deletion;
consent withdrawal;
objection;
restriction;
and information concerning processing.
Where information is controlled by an employer, School, Transport Provider or other Customer, that organization may be the appropriate first point of contact.
Codefy will support Customer requests according to its applicable Data Processing Addendum.
50. Deleting or Correcting Mobile Account Information
Current Codefy mobile applications use organizational accounts provisioned or authorized by the relevant Customer and do not offer public self service account creation.
Where a user wishes to correct or delete personal information connected with an organizational mobile account, the request may be submitted to the applicable employer, School, Transport Provider or other Customer, or to privacy@codefyhub.com. A request should include the name of the Codefy application, the organization that provided the account and sufficient account contact information for Codefy or the Customer to verify and locate the relevant account. Codefy may ask for additional verification before acting on a request and will route Customer controlled requests to the relevant Customer where appropriate.
Codefy may need to retain certain records where required for legal, security, audit or legitimate operational purposes.
Deleting an application from a device does not necessarily delete the organizational records associated with that user's account.
51. Revoking Permissions
A user can generally change mobile permissions through their device settings.
Revocation may stop future access through that permission but does not automatically erase information previously processed lawfully.
Users wishing to request deletion of previously processed personal data should use the applicable privacy request process.
52. Application Uninstallation
Uninstalling a Codefy application generally stops the application itself from operating on that device.
However, uninstalling does not automatically delete information already stored in Codefy ERP or Customer systems.
Customer controlled information remains subject to Customer instructions, applicable retention rules and the Codefy Hub Privacy Policy.
53. Security Incidents
Security incidents involving personal data processed through Codefy mobile applications are handled under the Codefy Hub Privacy Policy and applicable Data Processing Addendum.
Where Codefy acts as processor, Codefy will cooperate with the applicable Customer according to the parties' contractual and legal obligations.
54. International Processing
Mobile application data may be processed using technology providers located outside Egypt.
Where applicable, Codefy will address international processing and transfer requirements through its Privacy Policy, DPA and Subprocessor framework.
Damoov currently states that its telematics data may be stored or processed in Singapore, Germany or the United States, while its more recent technical documentation describes infrastructure hosted in Germany.
Because provider architectures may change, the Subprocessor List should remain the operational source for current provider processing information.
55. Changes to Mobile Functionality
Codefy may update mobile applications and their functionality.
An update may add, remove or change device permissions.
Where a change materially affects personal data processing, Codefy will update applicable privacy disclosures and obtain any permissions or consent required under applicable law.
56. App Store Privacy Information
Codefy should maintain Google Play Data Safety disclosures, Apple privacy disclosures and other app store privacy information so that they remain consistent with actual application behavior and this Notice.
For the Driver App in particular, background location disclosures should remain consistent with the application's manifest, actual functionality, in app disclosure and store listing. Google currently requires prominent disclosure and additional review for qualifying background location use.
57. Contact and Privacy Requests
Privacy questions concerning Codefy mobile applications may be directed to:
Codefy Hub For IT SolutionsTrading as Codefy Hub16 Omar Ibn Al Khattab, Sheraton, Cairo, EgyptRegistration# 773819371Legal: legal@codefyhub.comPrivacy: privacy@codefyhub.com
Where the application is provided through an employer, School, enterprise or Transport Provider, that organization may also be the appropriate contact for requests concerning Customer controlled information.
58. Relationship With Other Codefy Legal Documents
This Mobile Application Privacy Notice forms part of the broader Codefy privacy framework.
Users should also review, as applicable:
Codefy Hub Privacy Policy
Codefy Hub Terms of Service
Codefy ERP Service Terms
Codefy Data Processing Addendum
Codefy Subprocessors and Technology Providers List
Where there is a conflict concerning a specific mobile privacy practice, this Notice provides the more detailed description of mobile application processing, subject to applicable law and any controlling contractual agreement.
