Tandem

Last updated June 24, 2026

Privacy Notice

This notice explains how Tandem handles personal data when companies use the Tandem web dashboard, worker mobile app, worker web routes, APIs, and any future desktop application.

These pages are product-specific starting documents, not legal advice. Replace bracketed business details and have counsel review them before selling Tandem or publishing them to customers. Remove this draft banner after legal sign-off.

Who we are

Tandem is operated by [legal entity name, company number, registered address]. For most customer workforce, scheduling, attendance, location, form, and safety records, the customer company is the controller and Tandem acts as its processor. Tandem is the controller for direct account administration, billing, support, security, product communications, and its own website/service operations.

Contact: [privacy email]. Data protection contact: [DPO or privacy lead, if appointed].

Product scope

Tandem is designed for field workforce scheduling, attendance, geofenced visit tracking, forms, job records, safety workflows, and operational reporting. Tandem is not intended for healthcare use and must not be used to store protected health information, patient medical records, or other healthcare-regulated data. Customer companies must configure Tandem for lawful workforce monitoring, including any required worker notices, consultation, impact assessments, or retention rules.

Personal data we process

CategoryExamplesTypical purpose
Account and identityName, email, role, phone, profile settings, company membershipAuthentication, access control, support, and account management
Workforce and scheduleJobs, assignments, teams, roles, skills, regions, holidays, absences, certificationsScheduling, dispatch, absence controls, workforce planning, and compliance records
Location and attendanceClock-in location, geofence enter/exit, site radius state, visit segments, route/navigation prompts, location permission stateArrival tracking, dynamic job duration, attendance audit, safety, and operational reporting
Job and form recordsJob notes, checklists, required forms, photos, PDFs, attachments, accident reportsWork execution, evidence capture, closeout, reporting, and customer record keeping
Device and communicationsPush tokens, app state, local app settings, support messages, logsNotifications, troubleshooting, security, and service reliability
Website and app usageStrictly necessary cookies, session storage, selected UI preferences, security logsAuthentication, fraud prevention, diagnostics, and service operation

Sources of personal data

  • Users and customer admins provide account, worker, role, job, site, form, and support information.
  • Mobile devices provide location, notification, device, offline queue, and app-state information when enabled by the user and customer company.
  • Customer companies may import or create worker, team, absence, holiday, certification, and schedule records.
  • Tandem and its providers generate logs, audit records, security events, and support diagnostics while operating the service.

How we use data

  • Provide the Tandem service and maintain customer workspaces.
  • Authenticate users and enforce tenant, role, and worker access.
  • Schedule jobs, teams, appointments, meetings, and worker visits.
  • Capture assigned job-site arrivals and exits for geofenced jobs where tracking is enabled and the worker is clocked in or otherwise authorized.
  • Manage forms, attachments, PDFs, certifications, breaks, absences, and safety workflows.
  • Send operational notifications such as priority jobs, clock reminders, site arrival, workflow, and lone-worker alerts.
  • Detect, investigate, and prevent security incidents, misuse, and service errors.
  • Meet legal, tax, accounting, and contractual obligations.

Mobile location and background processing

Tandem Mobile may collect foreground and background location data to enable assigned job-site geofencing, automatic arrival/departure visit records, clock and attendance controls, navigation prompts, and lone-worker alerts. Background location is intended to be used only for work-related Tandem functions where the customer company has enabled the feature and the worker is clocked in, available, or otherwise covered by an explicit company policy or override.

Tandem is not designed for covert monitoring or continuous tracking outside work duties. Workers can manage device permissions in system settings, but some mobile workflows may not work without location or notification permissions.

Legal bases

ProcessingTypical legal basis where UK/EU GDPR applies
Providing the Tandem service to customer companiesContract and legitimate interests
Customer workforce monitoring, attendance, location, forms, and safety recordsThe customer company's lawful basis, usually legitimate interests, legal obligation, contract, or consent where required by local law
Billing, tax, accounting, legal claims, and complianceContract, legal obligation, and legitimate interests
Security logs, abuse prevention, audit trails, and service diagnosticsLegitimate interests and legal obligation
Optional marketing or non-essential tracking if added laterConsent where required

Customer companies are responsible for selecting and documenting the lawful basis for their employment-related processing, including location and attendance data.

Sharing and subprocessors

Customer data is shared with authorized users in the same customer workspace according to their role. We also use subprocessors for cloud hosting, database, authentication, storage, maps, mobile push delivery, error monitoring, and support. The current list is maintained at /subprocessors.

Retention

Customer workspace data is retained while the customer account is active, unless the customer configures or requests deletion earlier and Tandem is allowed to delete it. Location, visit, clock, form, safety, and audit records may be retained for customer operational, employment, contract, dispute, safety, and compliance purposes. Backups, audit logs, security logs, and legal records may be retained for limited periods needed for security, recovery, legal, tax, and accounting purposes. Exact production retention periods must be added before paid sale.

Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data. If your employer or contracting company uses Tandem, contact that company first because it controls most workforce records. You can also contact [privacy email].

Data deletion, correction, export, and restriction request details are available at /data-deletion.

Selling personal data and targeted advertising

Tandem is not designed to sell worker personal data or share it for cross-context behavioral advertising. If analytics, advertising, session replay, or similar non-essential tracking is added later, this notice and the Cookie Notice must be updated before those technologies run.

Children

Tandem is intended for business use by customer-authorized users. It is not directed to children and must not be used to knowingly collect children's personal data.

Security

Tandem uses tenant scoping, role-based access controls, Supabase row level security, signed file URLs, transport encryption in production, and operational security controls appropriate to a production test service. Tandem should complete production monitoring, incident response, backup/restore, upload scanning, and secret rotation before paid sale.

Automated decisions

Tandem may calculate operational statuses such as onsite, late, clocked in, available, blocked, or complete from schedule, clock, geofence, visit, form, and workflow records. Tandem is not designed to make legally significant automated employment decisions without customer review.

International transfers

Tandem and its subprocessors may process data in the UK, EEA, United States, or other locations. Where required, transfers must be protected by appropriate safeguards such as standard contractual clauses, adequacy regulations, or equivalent contractual measures.

Changes to this notice

Tandem may update this notice as the product, subprocessors, retention periods, or legal requirements change. Material updates should be versioned and may require users to accept the updated notice before continuing to use the service.