Legal
Privacy Policy
Last updated: 19 August 2026 · Applies to brickops.in, api.brickops.in, and the BrickOps Android app (com.brickops.app).
1. Who we are
BrickOps (“we”, “us”, “our”) provides construction operations software for companies in India — including web and mobile apps for procurement, attendance, inventory, approvals, and related site workflows.
For personal data of end users and workforce records stored in a customer’s workspace, the customer company is typically the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (DPDP Act). BrickOps acts as a service provider / Data Processor for that customer data, and as a Data Fiduciary for our own platform accounts, billing, and support communications.
2. Scope
This notice covers personal data processed when you:
- create or use a BrickOps company account on the web;
- sign in to the BrickOps mobile app;
- are invited as an employee, contractor, or site user by a customer company;
- contact us for support or sales.
It does not replace your employer’s own HR / privacy notices where they apply to workforce data they instruct us to process.
3. Data we collect
Account & identity: name, email, phone number, password (stored as a one-way hash), company details, role / permissions, and verification status (email / phone OTP).
Workforce & operations data (as entered by your company): employee or labourer profiles, site assignments, attendance, leave, expenses, payroll-related fields your company chooses to store, documents, and similar operational records.
Location: precise or approximate GPS location when you use geofenced attendance check-in / check-out or other features that require location (for example certain expense or petty-cash flows). Location is requested only when those features are used.
Photos & files: images and documents you or your company upload (for example GRN delivery photos, expense receipts, ID proofs, drawings).
Device & usage: app / browser type, IP address, approximate timestamps, and security / audit logs needed to operate and protect the service.
Sensitive identifiers that companies may store (for example Aadhaar last-4, PAN, bank account details) are handled with access controls and encryption safeguards as configured in the product. We do not sell personal data.
4. Why we use the data (purposes)
- provide and secure the BrickOps platform (authentication, RBAC, audit);
- enable construction workflows your company configures (attendance, materials, approvals, etc.);
- send transactional messages (OTP, invites, password reset, important account alerts);
- provide customer support and improve reliability and safety of the service;
- meet legal, tax, and regulatory obligations where applicable.
We process data for these purposes on the basis of contract performance with the customer, legitimate use for employment-related processing where applicable under the DPDP Act, and / or consent where your company or the product collects it for a specific purpose.
5. Sharing & processors
We do not sell personal data. We share data only as needed to run BrickOps, including with:
- cloud hosting / database providers that host the service;
- email and SMS delivery providers (for OTP and transactional mail);
- file / image storage providers used for uploads;
- professional advisers or authorities when required by law.
Customer administrators can see and manage data inside their own company workspace according to roles they assign.
6. Retention
We retain account and operational data for as long as your company account is active and as needed for the purposes above. Some records (for example financial or statutory payroll-related data) may be retained longer where law or the customer’s retention policy requires it. Expired OTPs, verification tokens, and similar ephemeral data are purged on a schedule. Customers may request anonymization / erasure of user records subject to legal holds and product capabilities.
7. Your rights
Subject to the DPDP Act and applicable law, you may request access, correction, erasure, or withdrawal of consent (where processing is consent-based), and raise a grievance. In many cases the fastest path is through your company administrator, who controls your workspace.
Platform account holders can also use in-product controls where available (for example profile updates) and contact us using the details below. If your company has appointed a grievance officer in BrickOps settings, that contact applies to company workforce grievances.
8. Security
We use industry-standard safeguards including encrypted transport (HTTPS / TLS), hashed passwords, role-based access control, tenant isolation, and audit logging. Sensitive fields may be encrypted at rest. No method of transmission or storage is 100% secure; please use a strong unique password and protect your device.
9. Children
BrickOps is a B2B workforce product intended for adults. We do not knowingly collect personal data from children.
10. International transfers
Primary service hosting is operated for customers in India. Some subprocessors (for example global cloud or media services) may process data in other regions. Where cross-border transfer occurs, we take contractual and organisational steps consistent with applicable law and our customer agreements.
11. Mobile app permissions
The BrickOps Android app may request:
- Location — for geofenced attendance and related site features;
- Camera / photos — to capture GRN, expense, petty-cash, or document images;
- Internet — to sync with your company’s BrickOps workspace at
api.brickops.in.
You can deny or revoke permissions in your device settings; some features will not work without them.
12. Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of BrickOps after an update means you acknowledge the revised notice. Material changes may also be communicated in-product or by email where appropriate.
13. Contact
Privacy questions or requests: hello@brickops.app
Website: https://brickops.in
If you are an employee or site user, please also contact your company’s BrickOps administrator, who controls your account inside the customer workspace.