Privacy policy
Effective 29 August 2026
How Pushytap handles personal data for the field apps and the web portal. Workplace radio and operations — not advertising.
Who this covers
This policy covers the Pushytap mobile apps and the Pushytap web portal (together, “Pushytap”), and limited technical information from visitors to our websites.
Pushytap is a workplace radio and operations platform. Organisations use it to coordinate people on site — including security, facilities, retail, and other field teams. It is not a consumer social network and it is not an advertising product.
Accounts are created and closed by the organisation that issues them. There is no self sign-up in the field app.
Who is responsible
Your organisation decides why Pushytap is used and which operational records to keep. For that data, your organisation is the controller (or the equivalent under applicable law). Pushytap processes it to provide the service they have configured, on their instructions.
Pushytap is the controller only of a narrow set of data we need to run our own business: customer account administration, billing and contract contacts, website logs, and requests sent directly to us.
If you use Pushytap for work, requests about your work data should go to your organisation first. We will assist them. You can also contact us at the address below.
Information we process
What we process depends on how your organisation uses Pushytap and which features you use:
- Account and directory: name, work contact details (such as email and phone), role or job title, photo if one is uploaded, organisation, and permissions.
- Device and radio: device identifiers, push tokens, app version, and status used to keep the radio reachable (such as battery and connectivity).
- Location: precise location while you are on duty (clocked on), on a patrol or assigned round, or during an emergency alert (SOS). Not at other times. See Location below.
- Audio: microphone audio while you hold push-to-talk, record a voice memo, or an unresolved SOS ambient publish is live. Not captured while idle. If your organisation enables channel recording, that audio is stored as their operational record.
- Photos, video, and files: only when you capture or attach them as evidence or as part of a task, check-in, incident, or checkpoint.
- Work activity: talkgroup membership, floor (who is talking), notes and notifications, incidents, patrols, attendance or timesheets if used, and similar records of work done in the product.
- Support and reliability: crash and error diagnostics, and information you send to support or to privacy@pushytap.com.
We do not collect your handset contacts, calendar, SMS, or files unrelated to what you attach in the app.
How we use it
We use this information to provide the service your organisation has configured: push-to-talk radio, maps and dispatch, proof of presence, incident and task workflows, safety check-ins, emergency alerting, and account administration.
We also use it to keep the service secure and working (authentication, abuse prevention, diagnostics, and service communications) and to meet legal or safety obligations.
We do not sell personal data. We do not use it for advertising, credit scoring, or data-broker lists. We do not use automated decision-making that produces legal or similarly significant effects about you.
Location
The field app uses precise location so your organisation can see authorised people on a map, record patrol or checkpoint presence, and follow an emergency trail.
Background location runs only while you are clocked on, a patrol or assigned round is running, or an SOS is unresolved — and stops when that work ends. It also stops when you sign out.
On Android, background location is requested only after foreground location is granted, and only after an in-app disclosure.
Location is shared with your organisation’s authorised operators. It is not sold, not used for advertising, and not shared with third parties for their own purposes. Location history is deleted when the account is closed.
Sharing
Inside your organisation, data is available to administrators and other users they authorise (for example a dispatch desk or store operations team).
We use processors to run Pushytap — hosting and infrastructure, push-notification delivery, crash and error reporting, and communications services your organisation enables (such as telephony). They may process data only on our instructions.
We disclose information if required by law, to protect someone’s safety in an emergency, or to a successor if the business is transferred, under this policy.
We do not share personal data with third parties for advertising.
Cookies and similar technologies
The web portal uses cookies or local storage needed to sign you in, keep a session, and remember preferences. We do not use advertising cookies or third-party advertising pixels on the product.
Our public websites may record ordinary technical logs (for example IP address, browser, and pages requested) to operate and secure the site.
Security
Data in transit is encrypted. Access to the web portal is authenticated. We apply access controls inside the service. No method of transmission or storage is completely secure.
Retention
We keep personal data only as long as needed for the purposes above, including the period your organisation configures for operational records, and for a limited time in backups. Backups that still contain a copy are rotated out within 90 days.
When an account is closed, we delete profile data, devices and push tokens, presence, location history, and media that is not part of an operational record.
Your organisation may retain operational and legal records — for example incidents, completed patrols or forms, attendance and timesheets, and radio recordings they enabled. Those records follow their retention policy. We do not delete a customer’s required records solely because a user asked us to.
Deletion and your choices
Ask your organisation’s administrator to close the account, or use the process on the data-deletion page. We action verified requests within 30 days, subject to the retention rules above.
You can refuse or later revoke device permissions (location, microphone, camera, notifications). Features that need those permissions will not work without them.
Children
Pushytap is a workplace tool and is not directed at children. We do not knowingly collect personal data from children.
The organisation that issues an account is responsible for ensuring the account holder is eligible to use the service under applicable law. If you believe we have collected personal data from a child, contact us and we will delete it or work with that organisation.
International processing
We and our processors may process data in countries other than the one you are in. Where we do, we use contractual and technical safeguards appropriate to us as a provider.
Changes
We may update this policy. The effective date at the top will change. Material changes will be posted on this page.
Contact
Privacy requests: privacy@pushytap.com. We respond within 30 days.
Terms: Terms of service. Account and data deletion: Account & data deletion. Questions: privacy@pushytap.com