Back to Access Management Retail Execution

Access Management Retail Execution

Privacy Notice

Last updated: September 3, 2026

This notice explains how the web service and its fourteen Android apps handle workforce, retail execution and shop data. It applies both to users whose organization has provided them an account and to shop owners who sign up for Khata themselves.

Which apps this notice covers

This notice covers the Access Management web service and all fourteen of its Android apps. The apps share one backend and one database, but they do not all collect the same things, so the table below is the quickest honest answer to "what does this app take?"

AppHow you sign inLocationCamera
Khata (खाता)You sign yourself up with your phone number and an SMS codeNeverNever
Access Management Retail ExecutionCompany-issued phone number and passwordPrecise, including in the background while a shift is openYes
AuditCompany-issued phone number and passwordPrecise, at check-in and stamped on every evidence photoYes
DispatchCompany-issued phone number and passwordPrecise, when a delivery is completedYes
PromoterCompany-issued phone number and passwordPrecise, at store check-inYes (photos carry no location)
ShelfCompany-issued phone number and passwordPrecise, at store check-in and on photosYes
StoreCompany-issued phone number and passwordPrecise, at store check-in and on photosYes
VanCompany-issued phone number and passwordPrecise, at store check-inSignature capture only
BeatCompany-issued phone number and passwordPrecise, at check-in and clock-in/clock-outNever
CollectCompany-issued phone number and passwordPrecise, at store check-inNever
ManagerCompany-issued phone number and passwordCollects none; displaysthe team's last known positionsNever
LearnCompany-issued phone number and passwordNeverNever
DistributorCompany-issued phone number and passwordNeverNever
RetailerAn outlet access code issued by the supplying companyNeverNever

Khata is the only app in which you create your own account. In every other app the account is created for you by the business that employs or supplies you, and that business decides who holds it. This difference decides what deletion means for you, so it is explained again under Deleting your data.

Information the service handles

Account and identity

For the thirteen work apps: your name, phone number, role, organization, and assigned region, plus a password stored only as a bcrypt hash that the application itself is not permitted to read back. The Retailer app instead uses an outlet access code, which is stored as a SHA-256 digest and shown in full exactly once, when it is issued. For Khata: your phone number, your shop name, and your language, script and calendar preferences. Nothing else — Khata asks for no name, no email and no address.

Location

Eight apps collect precise location, and only for specific events: starting or ending a shift, checking in at a store, or completing a delivery. Each fix records latitude, longitude, accuracy, and how far you were from the store, so that a visit can be verified as genuine.

One app — Access Management Retail Execution — also collects location in the background, roughly every 25 seconds or 40 metres, but only after you clock in and grant the permission. Android shows a persistent notification for the whole time this is running. Clocking out or signing out stops it. These background points are the one category of data with a short, automatic lifetime: they are deleted after 48 hours by a job that runs every hour.

Photos, signatures and work evidence

Six apps take photos: shelf and display pictures, proof of delivery, and audit evidence. Depending on the app, a photo is stored with the coordinates and time it was taken, its dimensions and file size, and a cryptographic hash used to detect reuse of an old picture. Audit evidence photos always carry coordinates; Promoter photos never do.

Three apps capture a handwritten signature from a store manager confirming that a visit happened, together with that manager's name and phone number. Alongside this sit your task answers, checklists, stock counts, price observations, issue reports, and the times at which each was recorded.

Information about other people

Some apps record details of people who never installed anything themselves. You should assume anything you type about another person is stored:

  • Khata— the names, phone numbers and outstanding credit balances of your shop's customers, and every sale recorded against them.
  • Promoter — consumer leads: a name, phone number and stated interest.
  • Dispatch — the name and phone number of whoever received a delivery.
  • Van, Store and Access Management Retail Execution — the store manager's name, phone number and signature.
  • Store and outlet records — the shop owner or contact person's name and phone number.

Device and diagnostic information

With a check-in or clock-in, the apps send the device platform, brand, model, operating-system version and app version, and the device's own clock reading. Six apps also send a flag saying whether Android reported the location as coming from a mock-location provider; one also reports whether the device appears rooted or is an emulator. These are advisory signals used to spot falsified visits — they are recorded for a reviewer, and never block your work.

Signing in does not create a session record on our servers. Your session is a signed token held on your own device in the operating system's encrypted storage; the server keeps only a counter it can increase to invalidate every existing token at once.

Push notifications

Only the Access Management Retail Execution app registers for push notifications. It sends a device push token, which is stored against your profile and deleted when you sign out or when the push service reports that the app is no longer installed. The other thirteen apps register no push token at all.

What is not collected

None of the fourteen apps contains an advertising, analytics, attribution or crash-reporting library of any kind. There is no advertising identifier, no behavioural profiling, and no third-party tracking. No app requests access to your contacts, your call log or your SMS messages, and no app records audio or video.

How information is used

Information is used to operate assigned retail work, verify attendance and store visits, provide authorized management reporting, synchronize offline work, secure tenant access, investigate incidents, and maintain audit history. In Khata it is used only to run your own shop's till and credit ledger. Structured AI review may inspect submitted retail evidence and produce risk scores, explanations, or correction suggestions. AI cannot give final approval; an authorized human reviewer makes every final approval, rejection, or correction decision.

Who can access information

Field users can access their own assigned work and location history. Only authorized managers and supervisors within the same tenant and permitted organizational scope can access team location or review evidence. Database row-level security enforces this in the database itself rather than only in application code, and Khata shops are held in a separate isolation boundary again — one shop's data is not reachable from another shop's session, and Khata data is not visible to any company workspace. Personal information is not sold and is not shared for advertising.

Who information is shared with

The service runs on infrastructure the operator controls: photos and signatures are stored on the application server's own file system, not in a third-party media service, and are served only through short-lived signed links that expire after one hour. Beyond that hosting, information reaches these parties and no others:

  • Anthropic— when AI evidence review is switched on for a customer, the image itself is sent to Anthropic's vision API to be described and scored. If AI review is off, or the provider is unreachable, review falls back to rules that run locally and no image leaves the server.
  • Expo's push service and Google Firebase Cloud Messaging — deliver notifications for the Access Management Retail Execution app only, and receive the device push token and the notification text.
  • An SMS gateway — receives your phone number and the message when a text is sent to you: the Khata sign-in code, or messages a company chooses to send its outlets.

Information may also be disclosed where the law requires it. It is never sold, never used to build advertising profiles, and never shared with data brokers.

How long information is kept

This section is deliberately specific, including where the answer is uncomfortable. Only three categories of data are deleted automatically. Everything else is kept until someone deletes it.

DataHow long it is kept
Background location pointsDeleted 48 hours after they are recorded, by a job that runs every hour.
Khata sign-in codesDeleted within 72 hours of being used or expiring. The code itself is never stored — only a salted hash of it.
Answered data-deletion requestsDeleted 90 days after they are closed. Unanswered ones are kept until they are answered, deliberately.
Check-ins, attendance, task answers, photos, signatures, audit evidence, delivery proof, shelf and price observationsKept indefinitely. There is no automatic deletion. This evidence is deliberately append-only: a correction is recorded as a new entry rather than by changing or removing the old one, so that an audit trail cannot be quietly rewritten. It is removed only when someone asks and the request is carried out.
Khata shop, products, customers and sales ledgerKept indefinitely until you delete your account, which erases all of it immediately.
Accounts and profilesKept indefinitely while the account exists.
BackupsNightly database and file backups follow their own retention schedule, so deleted data can persist in a backup until that backup ages out.

Deleting your data

There are two paths, and which one applies depends on who created your account.

Khata — delete it yourself, immediately

Because you created your Khata account yourself, you can destroy it yourself. In the app, the delete option removes your shop and everything under it straight away and permanently: your shop record and phone number, your products, every customer in your ledger along with their names, phone numbers and outstanding balances, every sale, and every credit entry. It happens at once.

There is no undo, no grace period, and no export — your books are gone. If your shop's records matter to you, write down what you need before you delete. Deleting also signs out every device that was using the account.

The work apps — ask, and a person will handle it

In the other thirteen apps your account was issued by the business you work for or buy from, and the records attached to it — your attendance, your store visits, the evidence you submitted — are that business's operating and audit records, not solely yours. We cannot erase an employer's records because someone types a phone number into a public web page. The fastest route is to ask your organization administrator, who can deactivate your account and action your request directly.

You can also file a request with us directly, from outside the app and without signing in, using the form below. Because an anonymous form cannot prove that a phone number belongs to whoever typed it, submitting it does not delete anything by itself: it records your request, and a person contacts you on that number to confirm your identity before anything is removed. We commit to responding within 30 days. Some records may be kept where a law or a contractual obligation requires it, and we will tell you if that applies to you.

Request account and data deletion →

Your choices

  • Cancel the in-app location disclosure instead of starting a location-enabled shift.
  • Deny or revoke foreground or background location permission in device settings. Attendance and store verification may not work without it.
  • Clock out to stop work-shift background tracking.
  • Sign out to remove your device's push token.
  • Ask your organization administrator to review, correct, export, or delete account data, or use the deletion request form above.
  • Delete a Khata account outright from inside the Khata app.

Children

These are business tools. They are not directed at children, and no app is designed for or intended to be used by anyone under 16. We do not knowingly collect information from children.

Service operator and contact

Access Management Retail Execution is supplied to business customers under a service agreement. The legal platform operator is the developer identified in the applicable app-store listing and customer agreement. If your account was issued by your organization, that organization administers your account and access permissions, and privacy requests are fastest through your organization administrator. To reach the platform operator directly, use the deletion request form linked above, or the developer contact address shown on the app's Google Play listing.