Apporo platform Privacy Policy
Effective date: September 26, 2026 · Last updated: same as the effective date
This policy explains how the Apporo platform mobile app (the "App") handles your data. The App is offered under the brand of APPORO UNION INC. ("Apporo", "we" or "us"); Apporo is the App's brand and service provider and is responsible for data processing at the App level. The App is developed for Apporo by WOOW TECH CO., LTD. (the "Developer"), which publishes it on the App Store and Google Play under its own developer account. Data inside your organization's Odoo server is the responsibility of that organization.
This policy applies only to the Apporo platform app. Other Apporo products and web services have their own privacy policies.
The most important fact first: the App has no business-data backend of its own. It is a mobile client that connects to the Odoo server that your own organization hosts and manages. Everything you see, type or upload in the App lives on that server. For that business data, the party that decides how it is collected, processed and used is your organization — not Apporo and not the Developer. That also determines who ultimately carries out an access, correction or deletion request; see Account & data deletion.
1. How the App works, and who is responsible for what
The App is an interface to your organization's Odoo server. You enter the server address yourself, and the App connects only to the address you entered.
- Your organization owns and operates that Odoo server and decides what is stored in it, for how long, who may view it and when it is deleted. For personal data on that server, your organization is the party that determines the purposes of processing (the data controller).
- Apporo (us) is the App's brand and service provider and is responsible for data processing at the App level: the data the App keeps on your device, the handling of push tokens, and the support and request emails you send us. Once push notifications are available, Apporo will also provide the technical infrastructure they need (section 4). For those activities we process data within the scope described in this policy.
- The Developer (WOOW TECH CO., LTD.) builds the App software on Apporo's behalf and publishes the App on the app stores as the developer of record. On Apporo's behalf it also helps with technical support and account deletion work.
Apart from the push notifications described in section 4, data moving between your phone and your organization's server does not pass through servers operated by Apporo or the Developer.
2. Where accounts come from
The App has no sign-up function, and accounts cannot be created inside the App. Your account is created by your organization's administrator and is one of two kinds:
- Employee account (an Odoo "internal user"). This is the App's main audience, usually linked to an employee record and attendance features.
- Portal account (an Odoo "portal user"). Some organizations set up this kind of account for customers or partners.
If you do not have an account yet, contact your organization's administrator. The deletion path differs between the two; see Account & data deletion.
3. The paths your data travels
- App ⇄ your organization's Odoo: sign-in, browsing, uploads and clock-in location go only to the server address you entered.
- App ⇄ Google Firebase: to obtain a push registration token. The App uses a Firebase project dedicated to Apporo platform, separate from other apps. It embeds Firebase Cloud Messaging only (together with the Firebase Installations component it relies on); there is no analytics (such as Google Analytics), advertising or crash-reporting component. However, as stated in Google's SDK privacy disclosures, the Firebase Cloud Messaging and Installations components themselves may send Google an installation ID, the App version and technical diagnostic data (such as SDK version and operational status), and Google may use this data to operate its services, for analytics and to improve its products. This data is not used for advertising and is not linked to your Odoo account identity (row 23 in section 5).
- Your organization's Odoo → Google Cloud Messaging → (on iOS, also Apple Push Notification service) → your device (used only once push notifications are available): this path carries the actual content of the notification, not just an identifier. See section 4.
4. Push notifications (the part that involves third parties)
Current status: push notifications for Apporo platform are not yet available as of the publication of this page. The Apporo push authorization service described below is planned and not yet in operation, so no organization's Odoo server can currently send notifications through the Apporo platform push channel. When you allow it, the App still asks the system for notification permission and obtains a push registration token from Google Firebase (see section 3 and rows 7 and 23 in section 5) so that it is ready once push becomes available. The rest of this section describes how push notifications will work once available; we will update this policy before then.
The App registers your device with your organization's Odoo server only if that server has enabled Apporo platform push. Signing in does not mean push is available; if the server has not enabled it, the App does not register the device there and you will not receive push notifications from that server.
The content of a push notification — the sender's name and the first 200 characters of the message as plain text — is sent by your organization's Odoo server and passes in the clear (protected only by TLS in transit, not end-to-end encrypted) through Google's Cloud Messaging service, and on iOS additionally through Apple's Push Notification service. In other words, notification content does leave your organization's server and passes through third parties. If your organization handles sensitive message content, its administrator should assess whether to enable this feature.
On the device, the Android App marks notifications as private: if your system settings hide sensitive content on the lock screen, the notification text is not shown there. On iOS, whether previews appear on the lock screen follows your choice in the system Notifications settings.
The device record held by your organization's Odoo contains only: the user, the push token, the device name, the platform, the app the record belongs to (Apporo platform), an active flag, the last-seen time and a consecutive-failure count. It holds no location, no IP address and no notification content. Each user keeps at most 10 active devices per server; beyond that, the oldest is deactivated automatically. When you sign out or remove a connection in the App, the App asks the server to delete this device's Apporo platform record.
The push token is sent by the App directly to your organization's Odoo and does not pass through servers operated by Apporo or the Developer. Apporo plans to operate a push authorization service (planned, not yet in operation) that only supplies enabled Odoo servers with short-lived sending authorization. That service never handles notification content; its audit log records server-deployment-level events only (deployment identifier, event type, source IP) and contains no end-user personal data. The service and its data are planned to be located in Google Cloud's Oregon, USA region (us-west1).
5. Categories of data we handle
This table maps onto both stores' privacy questionnaires: "Linked to you" corresponds to Apple's Linked to You and Google's "linked to the user's identity"; "Used for tracking" corresponds to Apple's Used for Tracking. The table scrolls horizontally.
| # | Data | When | Purpose | Where it goes | Linked to you | Used for tracking | Where it is kept |
|---|---|---|---|---|---|---|---|
| 1 | Server URL, database name | You type it when adding a connection | Decides the connection target | Your own Odoo only | Yes | No | Local device database |
| 2 | Odoo login (often an email address) | At sign-in | Authentication | Your own Odoo only | Yes | No | Local device database |
| 3 | Odoo password | At sign-in | Authentication; automatic re-authentication when a session expires | Your own Odoo only | Yes | No | Android: stored only if you tick "Remember me" at sign-in, in keystore-backed encrypted storage excluded from cloud backup; if not ticked it is not stored and you sign in again when the session expires. iOS: this-device-only Keychain, not synced to iCloud |
| 4 | Session cookie | Issued by the server after sign-in | Keeps you signed in | Returned only to the same Odoo | Yes | No | Same encrypted storage as row 3, plus the embedded browser's cookie store |
| 5 | Display name, Odoo user ID | Returned in the sign-in response | Account list and switching | Not transmitted | Yes | No | Local device database |
| 6 | Server identifier and device-record number | Issued by your organization's Odoo at push registration | When several servers are connected, routes a tapped notification back to the right server and account | Not transmitted; generated by that Odoo | Indirectly (bound to the connection) | No | Local device database |
| 7 | Push registration token (FCM) | At app start and on token refresh | Push addressing | (1) Google Firebase, which issues it (2) every Odoo you are signed in to that has enabled Apporo platform push, which registers it | Yes | No | Encrypted device storage, and your organization's Odoo device registry |
| 8 | Device name / model | At every push registration | Server-side device list and de-duplication | As row 7 (2) | Yes | No | Your organization's Odoo device registry. Android sends the model code; iOS sends the device name provided by the system: the App supports iOS 16 and later, where the system usually provides a generic name (e.g. "iPhone"); the App does not request permission to access the custom device name you set in the system settings |
| 9 | Platform (Android / iOS) and app (Apporo platform) | At every push registration | Determines the notification format; lets the server use the push channel dedicated to Apporo platform | As row 7 (2) | Yes | No | As above |
| 10 | Apple push device token (iOS only) | Provided by iOS after you allow notifications | Exchanged with Firebase for a push token | Apple ⇄ Google; not sent to your organization's Odoo | Indirectly | No | Not separately stored by the App |
| 11 | Location (precise; on Android possibly approximate) | Only when an Odoo web page actively requests it (in practice: attendance clock-in) | Adds the clock-in location to your attendance record | Handed only to your organization's Odoo page inside the embedded browser, which sends it to its own server | Yes | No | The App stores no coordinates. Server-side storage is in your organization's Odoo |
| 12 | Location toggle | When you change it in Settings | A second gate in the App; when off, every web location request is refused | Not transmitted | No | No | On the device |
| 13 | App Lock: PIN hash, biometric toggle, failure count | When you enable App Lock | Unlocking the App | Never transmitted | No | No | Encrypted device storage. Biometrics are handled by the operating system; the App never receives your fingerprint or face data |
| 14 | Appearance preferences (theme, light/dark, language, reduced motion) | When you change them | User interface | Not transmitted | No | No | On the device |
| 15 | Notification title and body (sender's name + first 200 plain-text characters) | When there is a message, @mention or activity assignment in your organization's Odoo | Displaying the notification | Your organization's Odoo → Google Cloud Messaging → (iOS: Apple Push Notification service) → your device | Yes | No | On the device, only the system notification tray. Retention at Google / Apple: see section 8 |
| 16 | Notification routing data (record type, record ID, target URL, event type, server identifier, device-record number) | As above | Opens the correct record when you tap the notification | As above, travelling with the notification through Google / Apple | Indirectly | No | As above |
| 17 | Camera photo, gallery item or file (Android) | When a web page shows a file-upload field and you choose a file | Upload to your organization's Odoo | Handed by the embedded browser to that page → your organization's Odoo | Yes | No | A photo taken with the camera inside the App leaves a copy in the App's private storage, removed when you uninstall the App. The uploaded original lives in your organization's Odoo |
| 18 | Camera, photo library, files (iOS) | As above, handled by the system's built-in web file picker | As above | As above | Yes | No | The App contains no camera or photo-library code of its own; it only declares the permission purpose strings |
| 19 | Embedded-browser cookies, local storage and cache | Created by your organization's web pages as you browse | Determined by your organization's Odoo website | Stays on the device, returned to the same Odoo with each request | Depends on the page | No (third-party cookies are disabled) | On the device; web data of different accounts is isolated or cleared before switching |
| 20 | The content of your organization's Odoo pages (ERP / CRM / messages / attendance, etc.) | As you browse or work in the App | Determined by your organization's Odoo | Stays in your organization's Odoo. The App only displays it in the embedded browser; it does not parse, store or forward page content | Determined by your organization | No | Your organization's Odoo |
| 21 | The App's own diagnostic logs | At runtime | Debugging | Not sent anywhere. No crash reporter, no remote log collection | — | No | Android release builds produce none; iOS writes to the on-device system log with content redacted by default |
| 22 | IP address, user-agent string | On every network request (technically unavoidable) | Network transport itself | Your organization's Odoo (and any proxy in front of it), Google Cloud Messaging, Apple Push Notification service | Determined by the recipient | No | Each recipient's own server logs; the App has no visibility into them |
| 23 | Firebase installation ID and similar SDK identifiers, the App version, plus technical diagnostic data from the Firebase components | Obtained or sent by the Firebase Cloud Messaging and Installations components themselves (regardless of whether push notifications are available) | Token issuance; operation and reliability of the components. As stated in Google's SDK privacy disclosures, Google may also use this data to operate its services, for analytics and to improve its products; not used for advertising | No: the App does not link this data to your Odoo account identity and does not send it to your organization's Odoo (the push token derived from the installation ID and registered with Odoo is covered in row 7) | No | At Google, retained under Google's terms | |
| 24 | Advertising identifiers (IDFA / GAID), analytics data about how you use the App | Never collected. The App contains no advertising and no analytics (such as Google Analytics) or crash-reporting component, and does not record how you use the App for analytics; on iOS the Firebase configuration has analytics and ads disabled. Technical data that the Firebase components themselves send to Google, which Google may use for analytics and product improvement, is described in row 23. We do not track you for advertising and perform no cross-app or cross-site tracking. | |||||
6. Third-party services and recipients
| Recipient | Data | Notes |
|---|---|---|
| Your organization's Odoo server | Sign-in data, push token and device information, everything you type or upload in a page, clock-in coordinates | The destination the App connects to, managed by your organization |
| Google Firebase Cloud Messaging (Android, iOS) | Push token, Firebase installation ID, App version and technical diagnostic data, notification title and body | Required for push delivery. Google acts as a service provider under its Firebase data processing terms, published at firebase.google.com/terms/data-processing-terms (the version accepted for this project governs). In addition, as stated in Google's SDK privacy disclosures, Google may use the installation ID, App version and technical diagnostic data sent by the Firebase components to operate its services, for analytics and to improve its products, but not for advertising (row 23 in section 5) |
| Apple Push Notification service (iOS only) | Device push token, notification title and body | Required for iOS push, handled under the Apple Developer Program terms |
| Apporo push authorization service (planned, not yet in operation; Google Cloud, us-west1) | Short-lived sending authorization and server-deployment-level audit events; never notification content | Once in operation, supplies enabled Odoo servers with the authorization needed to send push — see section 4 |
| The Developer (WOOW TECH CO., LTD.) | Only the data needed to perform technical support, account deletion work (and, in future, operation of the push authorization service) on Apporo's behalf | The App's developer and store publisher; acts on Apporo's instructions within the scope of this policy |
We do not sell personal data and do not share any data for advertising or cross-app tracking. There are no data brokers, ad networks or analytics services (such as Google Analytics) in the App; technical data that the Firebase components themselves send to Google is described in row 23 of section 5. We may disclose data where required by law, court order or a lawful request from a public authority, to the extent required.
7. Permissions
7.1 Location (while using the App only)
Location has exactly one purpose: when you clock in or out on an Odoo web page and that page requests your position, so the attendance record carries the coordinates.
- The App has no background location permission and no background location service. Android declares only foreground precise and approximate location; iOS declares only "While Using the App".
- Every web location request must first pass four checks inside the App: (1) the page origin must be HTTPS; (2) the origin host must match the Odoo server you are currently signed in to; (3) the location toggle in App settings must be on; (4) the operating-system permission must allow it. Failing any one refuses the request.
- The App itself stores no coordinates and never sends them to Apporo, the Developer or any third party. The page returns them to your organization's own Odoo, where they become part of the attendance record.
- You can turn location off at any time in App settings or system settings. When it is off, the App refuses every web location request.
- The platforms behave differently: on iOS, every web location request re-runs all four checks; on Android, the system remembers your grant for a given origin, so later requests may not prompt again (you can revoke it at any time in system settings).
- Whether you can still clock in after refusing location depends on your organization's Odoo configuration — ask your administrator.
7.2 Camera and photo library
Used only when a page in your organization's Odoo presents a file-upload field and you actively choose to take a photo or pick a file. On Android, a photo taken with the camera inside the App leaves a copy in the App's private storage. That copy is not deleted automatically; it is removed when you uninstall the App.
7.3 Notifications
Used to display messages and activity notifications from your organization's Odoo. You can turn them off in your phone's system settings. Refusing or disabling notifications does not affect sign-in or other features.
7.4 Biometrics
Used only to unlock the App itself. Verification is performed entirely by the operating system; the App never receives or stores your fingerprint or face data.
8. Retention
8.1 On your phone
Local connection settings, passwords, sessions, preferences and web cache remain until you remove that connection, sign out or uninstall the App. When you sign out or remove a connection in the App, the App immediately asks the server to delete this device's push record (see 8.2). Uninstalling removes all of the App's local data, including the camera photo copies described above.
8.2 On your organization's Odoo server
Retention of that data is decided by your organization under its own policies and applicable law; the App neither configures nor can read those settings. This covers attendance records, messages, uploaded attachments and push device records. Ask your organization's administrator which retention policy applies to you.
The App attempts to delete the push device record when you sign out or remove a connection, but if there is no network connection at that moment the attempt fails and is not retried automatically. You can complete it by signing in and out again once you are back online, or ask your administrator to delete the record in Odoo.
8.3 At Google and Apple
Notification content is handled by Google and Apple during delivery. Their retention periods and processing locations are determined by their own terms and cannot be specified by the App. The same applies to the installation ID, App version and technical diagnostic data that the Firebase components send to Google (row 23 in section 5), which are retained under Google's terms.
8.4 At Apporo
- Push authorization service audit log (no end-user personal data): the service is not yet in operation, so no such log exists; before it starts, we will state its retention period in this policy.
- Support, access or deletion requests you email to us, and records of how we handled them: kept until the request is completed and then for as long as needed to demonstrate that we handled it lawfully, after which they are deleted. They are used only to answer your request and to demonstrate that we handled it lawfully.
- Backups of our systems: kept for at most 30 days on a rotating cycle and used only for disaster recovery. Deleted data disappears from backups as they rotate.
8.5 Data we are required by law to keep
Where applicable law (for example accounting, tax or employment rules) requires data to be kept, it is not deleted before the statutory period expires and is not used for any other purpose. Most such data lives in your organization's own Odoo, and that organization meets the obligation.
9. International transfers
The location of your organization's Odoo server is chosen by that organization. The App is offered in the United States, Taiwan, Hong Kong, Singapore, Malaysia, Thailand, Indonesia and the Philippines. Once push notifications are enabled, Google and Apple may process push-related data — including notification titles and bodies — on servers outside your country, including in the United States. In addition, whether or not push notifications are available, the installation ID, App version and technical diagnostic data sent by the Firebase components may be processed by Google on servers in the United States and elsewhere. The planned Apporo push authorization service will be located in the United States. Using push notifications means that data is transferred to the countries or regions where those providers operate.
10. Children
The App is business software for workplace use. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe that personal information of a child under 13 has been provided to us through the App, email us and we will help delete it or pass the request to the relevant organization.
11. Security
- Passwords, sessions and push tokens are stored on Android in keystore-backed AES-256-GCM encrypted storage excluded from cloud backup, and on iOS in a this-device-only Keychain not synced to iCloud.
- The App disables unencrypted HTTP and mixed content entirely and accepts HTTPS servers only.
- Web location requests must pass origin matching and two independent switches (see 7.1).
- Third-party cookies are disabled in the embedded browser, and web data of different accounts is kept separate.
- The App contains no analytics (such as Google Analytics), advertising or crash-reporting components; technical data that the Firebase components themselves send to Google is described in row 23 of section 5.
These are statements of technical measures. They are not a guarantee of absolute security and not a claim of end-to-end encryption. To report a security vulnerability, email us with "Security" in the subject line.
12. Your rights: access, correction and deletion
Depending on the law that applies where you live, you may have the right to access your personal data, obtain a copy, have it corrected or completed, object to or restrict its processing, have it deleted, and withdraw consent.
- Data on your organization's Odoo (most of the data): ask your organization's administrator first, because your organization holds it. You can also view and correct much of it (such as your name and contact details) yourself in Odoo under "My Profile" or "My Account".
- Data on your device: remove the connection in the App or uninstall the App at any time.
- Data held by Apporo (support correspondence, request records, etc.): email [email protected]. If you are not sure whom to contact, write to us anyway; we will help work it out and, where needed, pass the request to your organization.
Who handles requests: Apporo receives and handles requests; the Developer (WOOW TECH CO., LTD.) assists on Apporo's behalf with technical matters and deletion work.
Identity verification: the request must come from the same email address that is registered on your account; if you cannot send it from that address, we will ask your organization's Odoo administrator to confirm your identity. We will never ask for your password.
Response time: we will reply within 5 business days of receiving your request and complete it within 30 days. If the request concerns data on your organization's server, we will forward it to your organization within that time and keep you informed of progress.
We will not discriminate against you for exercising these rights. The full deletion process and its exceptions are on the Account & data deletion page.
13. Additional information for California residents
If the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies to our handling of your personal information, the following additional information applies to California residents:
- Categories of personal information collected: identifiers (login, user ID, push token, Firebase installation ID, device name or model); technical diagnostic data (such as the App version, sent to Google by the Firebase components); geolocation data (at clock-in only); electronic information you create at work (message and notification content, uploaded photos and files); internet activity information (IP address, logged by the recipient). Details are in section 5.
- Sources and purposes: provided by you and your device, used to provide App features, authentication, push notifications and security; never for advertising. As stated in Google's SDK privacy disclosures, Google may use the installation ID, App version and technical diagnostic data sent by the Firebase components to operate its services, for analytics and to improve its products, but not for advertising, and this data is not linked to your Odoo account identity.
- Sale and sharing: we do not sell personal information and do not share it for cross-context behavioral advertising. We have no actual knowledge of selling or sharing the personal information of consumers under 16.
- Sensitive personal information: account log-in credentials and precise geolocation are used only to provide the features you request, not to infer characteristics about you.
- Retention: see section 8.
- Your rights: to know, delete and correct, to opt out of sale or sharing, and not to be discriminated against for exercising them. Email [email protected]; you may also use an authorized agent. We will verify requests as described in section 12.
14. "Do Not Track" signals
The App and this website do not track you across third-party websites or apps, and do not allow third parties to collect personal information about your activity across websites through the App. We therefore handle your data the same way whether or not your browser or device sends a Do Not Track or Global Privacy Control signal.
15. Availability and languages
The App is distributed in the United States, Taiwan, Hong Kong, Singapore, Malaysia, Thailand, Indonesia and the Philippines. This policy is available in English and Traditional Chinese; if the versions differ, the English version prevails.
16. Changes to this policy and notification
If this policy changes, we will update the effective and last-updated dates on this page. For material changes (for example new data categories, new recipients or new purposes), we will notify you before they take effect through an in-App notice or an announcement on this website.
17. Contact us
APPORO UNION INC.Address: 10050 Garvey Ave Suite 207, El Monte, CA 91733, USA
Email: [email protected]
Website: www.apporo.ai
App development and store publishing: WOOW TECH CO., LTD. Please send every privacy question about the App to the email address above.
Apporo platform · Effective September 26, 2026
Apporo platform is not affiliated with, sponsored or endorsed by Odoo S.A. Odoo is a trademark of Odoo S.A.