About this app
Shofol GO is published by Appifly BD Ltd. ("Appifly", "we"). It is used by field staff of companies that run their business on Shofol.
You cannot sign up in the app. Your account is created by your employer and linked to the employee record they already hold for you. Your employer also decides who counts as field staff, whether location reporting is on, and how often it reports.
Location while you work
This is the part of the app that matters most, so it is described in full rather than summarised.
When it runs
- Only while tracking is switched on for you by your employer, in their Shofol settings. If they have not marked you as field staff, or have turned tracking off, the app reports nothing.
- The server confirms this on every upload. If your employer turns tracking off during the day, the app stops at the next upload — it does not wait for you to restart it.
- You must also grant background location on the phone itself. Declining it means the app only knows where you are while it is open.
What you will see while it runs
- Android: a permanent notification, "Sharing your location — your route is being recorded while you work." It cannot be swiped away while tracking is on. That is deliberate: somebody whose position is being recorded should be able to tell at a glance.
- iOS: the system's own blue location indicator, for the same reason.
What each reported point contains
| Field | What it is | Why |
|---|---|---|
| Latitude, longitude | Where the phone was. | To draw the route and place a visit. |
| Accuracy | The phone's own confidence, in metres. | A fix accurate to 500m proves nothing; recording it is what makes a later dispute answerable. |
| Speed, heading | How fast, and in which direction. | To tell travelling from stopped, so a route reads as a journey rather than a scatter of dots. |
| Battery level | The phone's charge, as a percentage. | So a gap in the day reads as a flat battery rather than as somebody switching the app off. |
| Time | When the point was taken, from the phone's clock. | The route is ordered by this, not by when it reached the server. |
How often
A point roughly once a minute and after about 25 metres of movement — your employer sets the interval, and the server sends the current one back with each upload. Points are uploaded in batches, about every five minutes or once twenty-five have collected, rather than one request per point: that is a battery decision as much as a data one.
The phone stays awake enough for its radio to report from a pocket. Without that, the system sleeps and delivers the whole morning at once when it wakes, which draws a straight line through the gap and makes a working rider look idle.
What we collect
Besides location, the app collects what the day's work needs. There is no advertising, no analytics tracking and no crash-reporting SDK in the app.
| Data | What exactly | Why | Required? |
|---|---|---|---|
| Sign-in details | Your work email and password when you sign in, and your employer's server address. The app keeps a session token afterwards, not your password. | To show you your own round and nobody else's. | Always |
| Route | Position points as described above. | To show your employer the day's route and coverage. | Background |
| Check in / check out | The time, your coordinates and their accuracy, and the moment you pressed the button. | A visit is proved by where and when you were. | Always |
| Visit photo | A photo you take at a visit. | Evidence of the call, where your employer asks for it. | When you take one |
| Visit outcome | The outcome and any notes you write. | What came of the call. | When you write it |
| Orders | Products, quantities and notes on an order you take. | To place the order against the customer. | When you take one |
| Expenses | Amount, notes and a receipt photo. | To claim the expense. | When you claim one |
| Push token | A device token issued by Firebase Cloud Messaging. | To deliver notifications about your round. | If you allow notifications |
The app does not read your contacts, calendar, messages or files, and does not collect device identifiers for advertising. It does not record audio or video.
Customer names, addresses and locations shown in the app are your employer's records, not yours and not ours.
Device permissions
| Permission | Used for | If you decline |
|---|---|---|
| Location (while using the app) | Check-in and check-out, and finding nearby customers. | You can still check in unless your employer requires a location; the app says so and offers to open Settings. |
| Location (background) | Reporting the route while the app is closed. | The app only reports while it is open. Everything else works. |
| Camera | Visit photos and expense receipts. | You cannot attach a photo. |
| Photos | Choosing a receipt from the gallery. | Take one with the camera instead. |
| Notifications | Round updates, and the notification that says tracking is on. | On Android the tracking notification is part of the foreground service and is shown regardless — it is what tells you tracking is running. |
| Internet | Talking to your employer's Shofol server. | Not optional. |
Working offline
Riders lose signal in stairwells and basements, so the app keeps working without one.
- Position points collect on the phone and upload when there is a connection.
- What you pressed — a check-in, a check-out — is kept with the time you pressed it, not the time it reached the server, and sent when the phone is back online. A visit recorded from the doorway is honest about when it happened.
- Both queues are capped, and the oldest go first, so a long outage cannot fill the phone.
- Once a queued item is sent it is removed from the phone.
Storage and transfer
- Everything the app sends goes over HTTPS to your employer's Shofol server, operated by Appifly.
- Your session token is kept in the operating system's secure storage (Keychain on iOS, Keystore-backed storage on Android). The app does not store your password.
- The offline queues are kept in the app's own private storage, readable only by the app.
- Photos are uploaded and then removed from the app's temporary files.
How long we keep it
Visits, orders and expenses are your employer's business records, kept for as long as their policy and the law require. Route history is kept for the period your employer sets in Shofol. Appifly deletes a company's data when that company ends its subscription and the contractual retention period has passed.
Push tokens are deleted on sign-out. Session tokens expire and are replaced on each sign-in.
Your rights and account deletion
You can see your own round, visits and expenses in the app. To correct a record, or to ask what is held about you, contact your employer — they own the record and can change it.
Turning tracking off
Only your employer can turn route reporting off for you. You can revoke background location in your phone's settings at any time, which stops reporting while the app is closed; the app keeps working for visits and orders.
Deleting your account
Because your account is part of your employer's system, it is closed by your employer, normally when your employment ends. Ask them to deactivate your Shofol access. If you would rather ask us directly, email info@appiflybd.com from your work address with the subject "Shofol GO account deletion"; we will confirm the request with your employer and act on it within 30 days. Signing out removes the session, the push token and anything queued from your device immediately.
Children
This app is for employees and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes to this policy
When we change what the app collects or how it is used, we update this page and the effective date at the top. Where a change is significant, the app tells you the next time you open it.
Contact
- Publisher
- Appifly BD Ltd.
- info@appiflybd.com
- Service
- accountra.appiflybd.com
- App
- Shofol GO,
com.appifly.shofolgo
This policy covers the Shofol GO app only; Shofol Connect and the web admin panel have their own notices.