Privacy Policy for TMSX Hub
This Privacy Policy explains how PT Tani Mandiri Sukses, operating the TMSX Hub application (referred to as “TMSX Hub,” “we,” “us,” or “our”), collects, uses, stores, and protects information when authorized users access and use the TMSX Hub mobile application and its connected business systems.
TMSX Hub is a business and enterprise application intended for authorized employees, contractors, or business users. It is used to access operational information and features connected to our ERPNext/Frappe system.
1. Information We Collect
Depending on the features you use and the permissions you grant, we may collect or process:
- Account and identity information: username, email address, employee or user identity, role, and authentication information required to sign in.
- Business and operational information: sales, purchasing, stock, warehouse, customer, supplier, attendance, task, approval, or other ERP records that an authorized user creates, views, or updates.
- Location information: precise or approximate device location when a location-based work feature is activated.
- Background location information: when the user deliberately starts a location-tracking work feature, the application may collect location while the application is not visible or the screen is off. Location may be recorded periodically, including approximately every five minutes, until the user stops the feature or the service is otherwise ended.
- Camera and image information: photos or images captured or selected by the user when required to attach evidence, scan information, document work, or support another application feature.
- Device and technical information: device model, operating system version, application version, IP address, timestamps, network information, error information, and technical logs needed to operate, secure, and troubleshoot the service.
- Notification information: notification tokens and notification preferences used to deliver operational alerts, approval notices, or other relevant application messages.
2. How We Use Information
We use information only for legitimate application and business purposes, including to:
- authenticate users and control access based on assigned roles;
- provide ERP, warehouse, sales, purchasing, stock, task, approval, attendance, and other operational features;
- record and verify work-related location when an authorized location feature is started;
- attach photographs or supporting documents to business records;
- send operational notifications and service-related communications;
- protect accounts, investigate misuse, and maintain application security;
- diagnose errors, maintain reliability, and improve application performance; and
- comply with legal, regulatory, audit, and contractual obligations.
3. Location Permission and Background Location
Location is not collected merely because the application is installed. The user can choose whether to grant location permission and can stop the applicable tracking feature. The user can also revoke location permission through the device settings. Disabling location may prevent location-dependent features from working.
We do not use location data for advertising, profiling for advertising, or selling user data.
4. Camera and Photo Access
Camera or photo access is used only when the user chooses a feature that requires an image or supporting document. The application does not activate the camera without a user action. Permission can be denied or revoked through the device settings, although image-dependent features may then be unavailable.
5. How Information Is Shared
We do not sell personal information. Information may be shared only as necessary with:
- Authorized organizations and administrators: the employer, company, or business entity that provides the user’s account and manages the relevant ERP data.
- Service providers: hosting, infrastructure, notification, security, maintenance, and technical service providers that process information on our behalf and are subject to appropriate confidentiality and security obligations.
- Google Play services: certain device or service information may be processed by Google Play services as part of Android application distribution and platform functionality. Google’s privacy practices are described in its own privacy policy.
- Legal and safety recipients: government authorities, regulators, courts, or other parties when disclosure is required by law or reasonably necessary to protect rights, security, users, or the public.
6. Data Storage and Security
Data may be stored on systems operated by us or by service providers supporting our ERP and application infrastructure. We use reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, alteration, disclosure, loss, or misuse. These safeguards may include access controls, authentication, encrypted network transmission where supported, logging, backups, and role-based permissions.
No electronic storage or transmission method is completely secure. We therefore cannot guarantee absolute security.
7. Data Retention
We retain information only for as long as reasonably necessary to provide the application, maintain business and accounting records, fulfill the purposes described in this policy, resolve disputes, enforce agreements, and comply with legal, audit, tax, employment, or regulatory requirements.
Retention periods may differ depending on the type of record and the organization responsible for the user account. When information is no longer required, it will be deleted, anonymized, or securely retained where deletion is not technically or legally possible.
8. User Choices and Permissions
Users may:
- deny or revoke camera, notification, foreground location, or background location permission through device settings;
- stop a user-initiated location-tracking feature within the application where that control is provided;
- request access to or correction of personal information, subject to authorization and applicable law; and
- request deletion of an account or associated personal information as described below.
9. Account and Data Deletion
To request deletion of a TMSX Hub account or associated personal data, email tmsx.system@gmail.com using the email address associated with the account. Please include the application name, your username or registered email, the organization associated with the account, and a clear description of the deletion request.
We may need to verify the requester’s identity and authority before processing the request. Some information may be retained when required for legal, accounting, audit, security, fraud-prevention, employment, or legitimate business recordkeeping purposes. Deleting an account may remove access to TMSX Hub but may not require deletion of business transaction records that the relevant organization is legally or operationally required to retain.
10. Children’s Privacy
TMSX Hub is an enterprise application and is not directed to children. We do not knowingly allow children to create accounts or knowingly collect personal information from children through the application. If you believe a child has provided personal information, contact us so that we can investigate and take appropriate action.
11. International Processing
Information may be processed or stored in locations where we or our service providers operate. When required by applicable law, we use appropriate safeguards for cross-border transfers of personal information.
12. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to the application, our data practices, legal requirements, or service providers. The current version will be published on this page with an updated effective date.
13. Contact Us
For privacy questions, permission concerns, account deletion requests, or complaints, contact:
PT Tani Mandiri Sukses / TMSX System
Email: tmsx.system@gmail.com