Skip to content

Privacy policy

What we collect, why we have it, where it lives, and how to take it back or delete it.

Last updated: 10 September 2026

1. Who is responsible

The controller of your personal data is BrewGig. Contact us about anything on this page at support@brewgig.in.

2. What we collect

Four kinds of information, and no more than we need for each.

Account details

  • Your email address, used to sign you in and to reach you about your account.
  • Your name, if you give one, so the app can address you.
  • A password, stored only as a hash — we cannot read it. If you sign in with Google we never see a password at all.
  • Your plan, and the record that you accepted these policies.

The records you enter

  • Jobs and shifts: platform, client, pay, hours, dates, notes and tags.
  • Trips: distance or odometer readings, dates, purpose, and the vehicle.
  • Expenses, fuel fill-ups, other income, and the receipt images you attach.
  • Clients, invoices, goals and vehicles.
  • A profile photo, if you upload one. Unlike your receipts, it is stored so that it can be fetched without a signed link — anyone who knows its address can view it — so treat it as public. You can remove it at any time from your profile.
  • Your settings, including country, currency, distance unit and any tax rate you enter.

Location — only if you turn tracking on

  • Precise GPS location, used for one thing: measuring and recording your drives. It is read while a trip is being tracked — which you can start by hand, with the app open — and, if you switch automatic trip detection on, in the background, so that a drive can be detected and measured without you opening the app.
  • The driven route of each recorded trip, stored with the trip as the evidence behind its distance.
  • Places you choose to name — home, a regular workplace — used to label trips automatically. Searching for one sends what you type, and roughly where you are, to Google Places so it can suggest addresses.
  • On Android, if you allow Physical activity: your phone’s own signal that you are in a vehicle, read only to notice a drive starting and to keep a stop at a light or in a queue inside one trip. It is a vehicle-motion flag, not health or fitness data. It is not stored with your trips, and it is not sent to us on its own: the only way it leaves the phone is as the tracker’s note that the phone reported vehicle travel, inside the tracking diagnostics described next — which the same switch turns off.
  • The Android app’s tracking diagnostics: a log of each decision the tracker made — a trip started, continued or stopped, whether by the tracker or by you, and why, with the values behind it — and the conditions it was made under: the GPS fix where there was one, battery level and battery-saver state, network state, whether the app was open or in the background, location permission status and, on Android, whether the phone’s vehicle sensor had reported a drive. Each upload also carries your phone’s model and Android version, the app version, the tracker’s current state (armed or recording, and your work mode) and its check of the phone settings that can stop tracking: location services, background permission, precise location, Physical activity, battery optimisation and the vendor’s autostart setting. The app sends it to us when it opens, when a trip ends and when that check finds something blocking tracking, so that support can work out why a trip started, stopped or vanished when you ask. A switch in the app’s Settings turns the sending off on this phone, and the app never shows the log itself.

Nothing is read until you grant location permission, and which permission you grant decides what BrewGig can do: foreground access is enough to track a trip while the app is open, and background access — “Allow all the time” — is what lets a drive be detected and recorded with the app closed. Automatic detection stays off until you turn it on. The Android app shows a visible status whenever it is watching or recording, you can stop it at any time in Settings, and location is never used for advertising and never collected when neither a trip nor automatic detection is running.

Technical information

  • Standard server logs from requests to the service, including IP address and timestamps, kept for security and debugging.
  • Authentication tokens and a theme preference stored in your own browser or device.
  • A device push token, if you enable notifications on the phone — used only to deliver the notifications you asked for, and deactivated when you sign out.

We do not connect to your bank, we do not import transactions from your accounts, and we do not track you across other websites.

3. Why we have it

  • To run the service you signed up for — storing your records and computing figures from them. This is performance of our contract with you.
  • To keep the service secure and working: logs, abuse prevention, backups. This is our legitimate interest in a service that stays up and stays private.
  • To take payment for a paid plan, and to keep the records tax law requires us to keep. This is a legal obligation.
  • To email you about your account. Marketing email, if we ever send it, is consent-based and unsubscribable.

We do not sell your data. We do not use the contents of your records — what you earned, where you drove, what you spent — to profile you or to target advertising.

4. Where it is stored, and who processes it

Your records live in a Postgres database and a private object store operated by Supabase, in the region chosen for this deployment. We use these processors, and only for the purposes described:

  • Supabase — database, authentication and receipt storage.
  • Dodo Payments — payment processing for paid plans, as merchant of record. Card details go directly to them; we never receive or store a card number.
  • Google — to confirm a Google sign-in if you use one; to turn trip coordinates into place names when tracking records a drive; to suggest addresses when you search for a place to name, which sends the text you type and an approximate location; and to serve the web app itself (Firebase Hosting).
  • Expo — delivery of push notifications to the Android app, using the device token above and nothing else.

Where data is transferred outside your country, it is done under the safeguards the relevant processor publishes for such transfers.

5. Who can see your records

Every table carries a row-level security policy tying its rows to the account that owns them, so a query issued by the app can only ever return your own rows. This is enforced by the database, not by application code that could be bypassed.

Receipt images are held in a private bucket. They are served through short-lived signed links generated for you at the moment you view them; there is no permanent public URL to guess, share by accident, or index.

A small number of administrators can reach the underlying infrastructure for support and maintenance. We do not read your records for any other reason, and we will not hand them to anyone else except where the law compels us to.

Tracking diagnostics are the one record you cannot open yourself: the app never displays them and they are not part of the export. They can be opened only by the administrator role, only to work out why a trip started, stopped or vanished when you ask, and by nobody else. Write to us and we will send you a copy.

6. How long we keep it

  • Your records are kept while your account is open, because their value is the history they build up.
  • Deleting your account deletes your records and your receipt files. Your trips, expenses, invoices, receipts and profile go, and they are not recoverable.
  • One record does outlive deletion: a one-way fingerprint of your email address, the date and number of deletions, whether the free trial and the one automatic refund had already been used, and — if you ever paid — the reference our payment provider knows you by. It holds none of the records you created: no trips, expenses, invoices or receipts, and nothing in it can be used to sign in as you. We keep it so that deleting and recreating an account cannot claim a second free trial or a second automatic refund.
  • Backups roll off on their own schedule, so deleted data can persist in a backup for a short window before it ages out.
  • Invoicing and payment records are kept for as long as tax law requires us to keep them, independent of your account.
  • Server logs are kept only as long as they are useful for security and debugging.
  • Tracking diagnostics from the Android app are kept for 60 days and never beyond the latest 30 uploads per account. A daily sweep deletes anything older whether or not the phone still uploads, and deleting your account removes them at once. Deleting a trip does not remove fixes already inside a diagnostics upload; those age out on the same 60-day schedule.

7. Your rights

You can, at any time:

  • Get a copy — export everything you entered as a formatted Excel workbook on any plan including the free one, or as a branded PDF summary on paid plans. The Android app’s tracking diagnostics are not in the export; ask and we will send them to you.
  • Correct anything wrong, by editing the record.
  • Delete your account and its data from account settings.
  • Object to or restrict a particular use, or ask us to explain one.
  • Complain to your local data protection authority if you think we have got this wrong.

Export is built into the product rather than being a request you have to make of us — the diagnostics log above is the one exception — which is deliberate: a right you have to ask permission to exercise is a weaker right.

8. Cookies and local storage

There are no advertising or analytics cookies. What the app stores on your device is limited to:

  • Your authentication session, so you stay signed in — deleted when you sign out.
  • Your light or dark theme choice, so the page does not flash the wrong palette before it loads.

Both are strictly necessary for the service to work as you asked it to, and neither is shared with anyone.

The Android app keeps a little more on the device itself: the tracking engine’s working state, trips recorded offline and waiting to upload, its diagnostics log (a copy of which is sent to us as section 2 describes, unless you switch that off in Settings), and your haptics and biometric-lock preferences. If you enable the biometric lock, your face or fingerprint never reaches us — the check happens inside your phone’s operating system, which only tells the app “unlocked”.

9. Children

The service is for people old enough to work and to enter a contract, and is not directed at children under 16. If you believe a child has created an account, tell us and we will remove it.

10. Changes to this policy

When this policy changes the date at the top changes with it. Material changes are announced by email or in the app before they take effect. Previous versions are available on request.

11. Contact

Write to support@brewgig.in with any question about this policy or to exercise any of the rights above. The terms of service cover the rest of the agreement.