Privacy Policy for Field Visitor Mobile Application
1. Introduction
This Privacy Policy outlines how the Field Visitor Mobile Application ("the Application"), operated by NCRi Solutions / Partner Financial Institutions ("we", "us", or "our"), collects, uses, stores, and protects information when authorized officers and collection agents ("Field Agents" or "Collectors") use our mobile application.
The Application is an internal enterprise tool designed exclusively for authorized bank field officers and collection personnel to manage assigned account visits, record field dispositions, navigate routes, and upload visit documentation.
2. Information We Collect
To provide core field management and credit recovery services, the Application collects the following categories of information:
A. Location Data
- Precise GPS Location: We collect precise geographical coordinates (latitude and longitude) while the Application is in use.
- Purpose: Location data is used to plot assigned customer addresses on Google Maps, provide route navigation, and verify that field visits are conducted at the designated customer locations.
B. Audio Recordings
- Microphone Access: With user permission, the Application accesses the device microphone to record voice notes and audio logs.
- Purpose: Audio files are recorded during field visits as proof of customer interaction and evidence of disposition records.
C. Camera, Photos & Document Files
- Camera & Storage Access: The Application accesses the camera and local device storage.
- Purpose: Allows collectors to capture photos of visited sites, scan visit notices, and attach PDF or image proof of field visits.
D. User Account & Authentication Information
- Officer Credentials: Collector ID, full name, username, and encrypted JSON Web Tokens (JWT) for secure authentication.
- Purpose: To manage user authorization, verify identity, and attribute field visit records to the responsible officer.
E. Financial Visit & Loan Data
- Case Records: Loan account numbers, Customer Identification File (CIF) details, payment collection amounts, disposition status codes, and visit remarks.
- Purpose: To update bank collection records and synchronize offline field visit logs with the central enterprise server.
F. Device & Technical Information
- Technical Logs: Device model, operating system version, network connectivity status, and API request logs.
- Purpose: Used for app stability, troubleshooting, network state monitoring, and security auditing.
3. How We Use Information
We use the collected information solely for enterprise field collection operations, including:
- Verifying and logging officer field visits to customer addresses.
- Navigating officers to assigned locations via integrated map tools.
- Storing field evidence, visit reports, and payment details securely.
- Synchronizing offline visit records when internet connectivity is restored.
- Ensuring security, preventing unauthorized access, and maintaining audit trails.
4. Data Sharing and Disclosure
We do not sell, rent, or trade any personal or operational data to third-party advertisers or data brokers.
Information collected within the Application is disclosed only to:
- Partner Banks & Financial Institutions: Field visit records, disposition status, and uploaded documents are shared with the originating bank/financial institution managing the account.
- Authorized Service Providers: Encrypted data is transmitted to secured enterprise backend servers solely for API operations and database synchronization.
- Legal & Regulatory Compliance: Information may be disclosed if required by applicable law, court orders, or banking regulatory authorities.
5. Data Security & Protection
We implement strict administrative, technical, and physical security measures to protect your data:
- Encryption in Transit: All communications between the Application and enterprise servers are transmitted using Secure Sockets Layer (SSL) / Transport Layer Security (TLS) HTTPS encryption.
- Secure Storage: Account tokens and offline queued data are stored in local encrypted app databases.
- Access Control: App access is restricted to authenticated enterprise users with valid credentials.
6. Data Retention & Deletion
- Field visit logs, audio recordings, and attached documents are retained in accordance with bank data retention policies and regulatory guidelines.
- Local temporary files on the device are cleared automatically upon successful synchronization with the central server.
- Authorized users or account administrators may request data review or deletion by contacting our privacy officer.
7. Permissions Required
The Application requests the following permissions on your mobile device:
- Location Permission (
ACCESS_FINE_LOCATION): Required for map navigation and visit coordinate verification.
- Microphone (
RECORD_AUDIO): Required to record audio evidence during field visits.
- Camera & Media Storage (
CAMERA, READ_EXTERNAL_STORAGE): Required to take photos and upload document attachments.
- Internet & Network State (
INTERNET, ACCESS_NETWORK_STATE): Required to check connectivity and synchronize data with enterprise servers.
8. Children’s Privacy
The Application is an enterprise business application intended exclusively for professional personnel aged 18 and older. We do not knowingly collect or solicit data from individuals under the age of 18.
9. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in legal, regulatory, or operational requirements. Any updates will be posted on this page with an updated "Effective Date."
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or data handling practices, please contact us at:
- Organization: NCRi Solutions / Field Collection Division
- Email: itasia@ncri.com
- Address: Galaxy Business Center Street 9, i9/3 Islamabad, Pakistan