Privacy Policy
MilaoHR ("MilaoHR", "we", "us") is a payroll and HR management service for Indian companies, built and operated by CA Meet Dhrangadhariya (CSM & Co LLP, Rajkot, Gujarat). This policy explains what information we collect through the MilaoHR web portal and the MilaoHR Android app, why we collect it, and how it's protected.
MilaoHR is a workplace tool. A company ("the Employer") signs up, adds its employees, and uses MilaoHR to run payroll and track attendance. If you're an employee using the self-service portal or app, your Employer — not MilaoHR — controls what information about you is entered into the system; MilaoHR processes it on the Employer's behalf.
1. Information we collect
Account information. When you sign in (via Google or email/password), we collect your name, email address, and profile photo. You may optionally add a mobile number, city, and address to your profile.
Employee & payroll records. Your Employer's HR/admin team may enter the following about you to run payroll and manage HR: employee code, designation, department, date of joining, employment type, work location, gender, date of birth, blood group, marital status, PAN number, last 4 digits of Aadhaar (we never store the full Aadhaar number), bank account number, IFSC, bank name, PF number, UAN, ESIC number, emergency contact details, current/permanent address, education and work history, salary structure, and generated salary slips.
Attendance, location & photos. When you check in or out (via the web portal or the Android app), we capture:
- A timestamped selfie photo, used to verify that the person checking in is physically present
- Your device's GPS location at the moment of check-in/check-out only — we do not track location in the background or at any other time
- The IP address your request came from
Biometric app-lock. If you enable the optional fingerprint/face-unlock app lock in the Android app, your device's biometric authentication is handled entirely by Android's own Biometric API. MilaoHR never receives, transmits, or stores your fingerprint or face data — it stays on your device and is managed by your phone's operating system.
Push notification tokens. The Android app registers a Firebase Cloud Messaging (FCM) token with us so we can deliver notifications (e.g. leave approval status). This token identifies your device installation, not you personally.
Audit & security logs. Login activity and certain admin actions are logged with IP address, approximate city/region (derived from IP, not GPS), device type, and browser — used to maintain an audit trail for the Employer and to detect misuse.
Communications. If we send you an email (e.g. a salary slip, an invitation, an attendance alert), we log the recipient, subject, and delivery status.
2. How we use this information
- To run payroll: calculate salary, statutory deductions (PF/ESI/Professional Tax/TDS), and generate salary slips
- To record attendance and verify check-in/check-out
- To manage leave requests and balances
- To operate self-service features (viewing your slips, attendance, and profile)
- To send transactional notifications (slip issued, leave approved/rejected, invitations)
- To secure accounts and investigate suspicious activity
We do not use your personal data for advertising, and we do not sell it.
3. Android app permissions
| Permission | Why we ask for it |
|---|---|
| Camera | To capture the selfie photo used for attendance verification at check-in/check-out |
| Location (foreground only) | To record the location of a check-in/check-out. We never request background location access |
| Notifications | To deliver push notifications (e.g. leave decisions) |
| Biometric (USE_BIOMETRIC) | To let you lock the app behind your device's fingerprint/face unlock — processed entirely on-device, never sent to us |
4. Who we share data with
We do not sell your data. We share information only with the service providers that help us run MilaoHR, and only as needed:
- Google Firebase — sign-in authentication and push notification delivery
- Cloudflare — hosts the public website and protects it from abuse
- Your Employer's email provider, or our platform email provider (Resend) — used only to deliver transactional emails like slips and invitations
- ip-api.com — used to resolve an approximate city/region from an IP address for audit-log purposes only (no GPS data is sent here)
Within MilaoHR, data is strictly scoped to your Employer's company account — no other company on the platform can see it. Role-based access controls limit who within your own company can view sensitive fields (e.g. bank details, PAN).
5. Data retention
We retain payroll and attendance records for as long as your Employer's account is active, and afterward for as long as needed to meet standard Indian statutory record-keeping practice. Historical salary slips are never altered once issued, even if your salary structure later changes. If your Employer removes you as an employee, your historical payroll records are retained (for compliance and audit purposes) but your active access is revoked.
6. Data security
- All traffic between your device and MilaoHR is encrypted in transit (HTTPS/TLS)
- Sensitive credentials (e.g. SMTP passwords) are encrypted at rest (AES-256-GCM)
- Access is governed by role-based permissions (Admin / HR / Viewer / Employee) and is scoped per company
- Attendance selfies are stored only as part of the attendance record they belong to, and are never exposed in bulk list views — only in the detail view of that specific record
7. Your rights & choices
- Access & correction: you can view your own profile, attendance, leave history, and salary slips at any time through self-service. If you don't have edit access, you can submit a profile change request for your HR team to approve.
- Leave & attendance control: you can cancel your own pending leave requests and discard same-day attendance entries you made in error.
- Account deletion: you can delete your account and personal data directly from the app (Profile → Danger zone → Delete), or via our account deletion page. Employer payroll/attendance records are retained for statutory compliance. See our deletion page for full details.
8. Changes to this policy
We may update this policy as MilaoHR evolves. Material changes will be reflected by updating the "Effective date" above. Continued use of MilaoHR after a change means you accept the updated policy.
9. Contact us
Questions about this policy or how your data is handled: [email protected] · WhatsApp: +91 73839 99929