About this app
Shofol Connect is published by Appifly BD Ltd. ("Appifly", "we"). It is used by employees of companies that run their HR on Shofol.
You cannot sign up in the app. Your account is created by your employer in their Shofol admin panel, which links the app to the employee record they already hold for you. Your employer decides which features are switched on for their staff — including whether clocking in requires your location or a photo.
What we collect
The app collects only what the features below need. There is no advertising, no analytics tracking and no crash-reporting SDK in the app.
| Data | What exactly | Why | Required? |
|---|---|---|---|
| Sign-in details | Your work email and password when you sign in. The app keeps a session token afterwards, not your password. | To show you your own records and nobody else's. | Always |
| Employee profile | Name, employee number, department, designation, work location and joining date — as entered by your employer. | Shown on your profile and used to apply the right attendance policy and shift. | Always |
| Attendance | The time you clock in and out, and the shift it counts against. | This is the app's purpose: your attendance record. | Always |
| Precise location | Your GPS coordinates at the moment you tap clock in or clock out. Nothing between punches, nothing in the background. | To record where a punch was made and, if your employer uses a work-location fence, whether it was inside it. | Employer policy |
| Selfie | A photo you take when clocking in or out. | To confirm the punch was made by you, where your employer requires it. | Employer policy |
| Leave requests | Dates, leave type and the reason you write. | To route the request to your approver and keep your leave balance. | When you apply |
| Payslips | Your salary components, deductions and net pay — displayed, and shareable as a file if you choose to. | So you can read and keep your own payslips. | Always |
| Push token | A device token issued by Firebase Cloud Messaging. | To deliver notifications about approvals, announcements and reminders. | If you allow notifications |
| App version | The installed version of the app. | To offer an update when a newer build is available. | Always |
The app does not read your contacts, calendar, messages or files, and does not collect device identifiers for advertising.
Device permissions
Each permission the app asks for maps to one feature, and you can decline it. What you lose is only that feature.
| Permission | Used for | If you decline |
|---|---|---|
| Location (while using the app) | Recording where you clock in or out. Requested only when you tap the button, never on launch. | You can still clock in unless your employer's policy requires location — then the app tells you so and asks you to turn it on. |
| Camera | Taking the clock-in selfie, where required. | A selfie-required punch cannot be completed without it. |
| Photos | Choosing a profile photo. | Your profile keeps its initials instead of a picture. |
| Notifications | Approval decisions, announcements, reminders. | Everything still works; you check the app instead of being told. |
| Internet | Talking to your employer's Shofol server. | Not optional — the app has no offline mode. |
Location and selfies
These two are the most sensitive things the app can collect, so here is exactly how they work.
- Location is read once per punch, at the moment you tap clock in or clock out. The app does not track you between punches, does not run in the background, and cannot see where you are when it is closed.
- Your employer can set two rules in their attendance policy: require location and require geofence. If neither is set, a punch is recorded without coordinates when you have not allowed location.
- With a geofence, the app sends your coordinates and the server decides whether you were inside your work location's radius. The distance is recorded with the punch; the app does not judge it.
- A selfie is taken only when your employer's policy requires it, and only at the moment of the punch. It is uploaded with that punch and stored against it. The app does not open the camera at any other time.
Notifications
If you allow notifications, the app registers a push token with Firebase Cloud Messaging, a Google service, and stores that token against your account so your employer's server can reach your device. Notifications carry the event — an approved leave, a new announcement, a reminder — not your payslip figures. Turning notifications off in your phone's settings stops delivery; the token is removed when you sign out.
Storage and transfer
- Everything the app sends goes over HTTPS to your employer's Shofol server, operated by Appifly at
accountra.appiflybd.com. - On your phone, the app keeps your session token in the operating system's secure storage (Keychain on iOS, Keystore-backed storage on Android). It does not store your password.
- Records you view — attendance, payslips, leave — are fetched when you open the screen and are not written to the phone's storage.
- Selfies are uploaded and then removed from the app's temporary files.
How long we keep it
Attendance, leave and payroll records are your employer's business records. They are kept for as long as your employer's policy and the law require — in Bangladesh, payroll records are commonly retained for several years after employment ends. Your employer sets the retention period in Shofol; Appifly deletes a company's data when that company ends its subscription and the contractual retention period has passed.
Push tokens are deleted on sign-out. Session tokens expire and are replaced on each sign-in.
Your rights and account deletion
You can see your own profile, attendance, leave and payslips in the app at any time. To correct a record, or to ask what is held about you, contact your employer's HR — they own the record and can change it.
Deleting your account
Because your account is part of your employer's HR system, it is closed by your employer, normally when your employment ends. Ask your HR department to deactivate your Shofol access. If you would rather ask us directly, email info@appiflybd.com from your work address with the subject "HRM account deletion"; we will confirm the request with your employer and act on it within 30 days. Signing out of the app removes the session and push token from your device immediately.
Children
This app is for employees and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes to this policy
When we change what the app collects or how it is used, we update this page and the effective date at the top. Where a change is significant, the app tells you the next time you open it.
Contact
- Publisher
- Appifly BD Ltd.
- info@appiflybd.com
- Service
- accountra.appiflybd.com
- App
- Shofol Connect — Android
com.appifly.atoz.appiflyhrm, iOScom.appifly.shofolconnect
This policy covers the Shofol Connect app only; the field-sales app and the web admin panel have their own notices.