Who should read this
This notice is for employees, contractors, supervisors, managers, and other workers who use Tandem. Customer companies must provide their own worker privacy notice and monitoring policy before enabling monitoring features. This Tandem notice does not replace the customer company's employment, contractor, health-and-safety, or workplace monitoring notices.
Tandem Mobile may collect location data to enable assigned job-site geofencing, automatic arrival and departure visit records, clock and attendance controls, navigation prompts, and lone-worker alerts, even when the app is closed or not in use, where background location is enabled by the device and customer company.
What Tandem may monitor
| Feature | Data captured | When it is captured |
|---|---|---|
| Clock-in and clock-out | Clock times, late status, and clock-in GPS location where available | When a worker uses the clock controls |
| Geofence visit tracking | Assigned job-site enter and exit events, visit segments, source, pause reason, and timestamps | When tracking is enabled for assigned geofenced jobs and the worker is clocked in, available, or covered by an explicit override |
| Foreground location and navigation | Current location used to show nearby jobs, route prompts, and site arrival feedback | When the app is open and the worker uses location-enabled job or navigation features |
| Background location | Location events needed by the operating system to evaluate assigned geofences | When device permissions allow background location and geofencing is active |
| Forms and evidence | Checklist answers, notes, photos, files, generated PDFs, and related timestamps | When workers submit required or optional job forms |
| Breaks and attendance controls | Break start/end, allocated break policy, overage, absences, holidays, and manager overrides | When workers or managers use attendance controls |
| Lone-worker alerts | Alert status, location if available, responder actions, and event history | When a worker sends or opens a lone-worker alert flow |
| Device notifications | Push token and notification interaction data | When push notifications are registered or used |
What Tandem is not designed to do
- Tandem is not designed for covert monitoring.
- Tandem is not intended to track workers continuously outside work duties.
- Geofence visit tracking should not count unless the worker is clocked in and available, except where a manager has explicitly authorized an override.
- Tandem should not be used to make disciplinary, payroll, billing, or safety decisions without human review of the underlying records.
- Lone-worker alerts are not a guaranteed emergency response service.
When monitoring should be active
- During assigned work, travel, attendance, form, or safety workflows configured by the customer company.
- When a worker is clocked in and available for geofenced visit tracking, unless an authorized company override applies.
- When a worker opens a lone-worker alert, priority job, route, form, or navigation workflow that requires current location or notifications.
- Monitoring should be disabled or ignored when workers are off duty unless the customer has a specific lawful policy and the feature supports that use.
Who can see monitoring data
Worker monitoring data may be visible to authorized admins, schedulers, managers, supervisors, and other customer-approved roles in the same company workspace. Workers should only see their own jobs and related records unless the customer grants a broader role.
Worker choices and controls
- Workers can choose whether to grant device location permissions, but some mobile workflows may not work without them.
- Workers can disable geofencing in the app where the feature is available, subject to the customer company policy.
- Workers should report incorrect visit, clock, absence, or geofence records to their manager so records can be corrected.
- Workers can use device settings to revoke location or notification permissions.
- Workers can review privacy, monitoring, cookie, terms, and deletion request information from the Tandem account screen and public legal pages.
Customer responsibilities
Customer companies are responsible for telling workers why monitoring is used, what data is collected, the lawful basis relied on, retention periods, who can see the data, how corrections work, and how workers can raise concerns. Monitoring should be proportionate to the operational, attendance, safety, and compliance need.
Corrections and disputes
Device location, geofence, network, battery, operating-system, and offline sync behavior can create incomplete or incorrect records. Customer companies should give workers a practical way to challenge or correct visit, clock, break, absence, form, and safety records before relying on them for payroll, billing, disciplinary, safety, or contractual decisions.
