Privacy Policy
Last updated: January 9, 2026
Table of Contents
- 1. Introduction
- 2. Company Information
- 3. Information We Collect
- 4. How We Use Your Information
- 5. Information Sharing and Disclosure
- 6. Data Storage and Security
- 7. Data Retention
- 8. Your Rights and Choices
- 9. Children's Privacy
- 10. Third-Party Links and Services
- 11. Push Notifications
- 12. Changes to This Privacy Policy
- 13. Contact Us
- 14. Summary of Data Practices
1. Introduction
Welcome to Quantra ("we," "our," or "us"). Quantra is a comprehensive workforce management mobile application developed and operated by LeadTitan LLC. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application ("App").
Please read this Privacy Policy carefully. By using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the App.
2. Company Information
LeadTitan LLC
Email: privacy@leadtitan.com
Website: https://quantra.app
For privacy-related inquiries, please contact us at: privacy@leadtitan.com
3. Information We Collect
We collect information that you provide directly to us, information collected automatically, and information from third-party services.
3.1 Personal Information
When you register for and use Quantra, we may collect the following personal information:
| Data Type | Purpose | Required/Optional |
|---|---|---|
| Full Name (First and Last) | Employee profile identification | Required |
| Email Address | Account authentication, communications | Required |
| Phone Number | Employee contact, emergency notifications | Optional |
| Home Address | HR records, payroll compliance | Optional |
| Emergency Contact Information | Workplace safety compliance | Optional |
| Profile Photo | User identification within the app | Optional |
| Job Title & Department | Organizational structure | Required |
| Employment Start Date | HR records | Required |
3.2 Financial Information
For workforce management purposes, we collect:
| Data Type | Purpose | Required/Optional |
|---|---|---|
| Pay Rate/Salary Information | Payroll processing | Required (for employers) |
| Expense Reports & Receipts | Expense reimbursement | Optional |
| Invoice Data | Business operations | Optional |
| Bank Account Information | Direct deposit (if enabled) | Optional |
Note: We do not directly process credit card payments. Any payment processing is handled by secure third-party payment processors.
3.3 Location Information
We collect location data to provide core app functionality:
| Data Type | Purpose | When Collected |
|---|---|---|
| Precise Location (GPS) | Time clock geofence verification | When clocking in/out |
| Approximate Location | Job site proximity detection | When using job site features |
| Location for Emergency Safety | Safety check-in, SOS features | During emergency features |
You can disable location services in your device settings, but this will prevent the use of location-based features such as geofenced time clock.
3.4 Photos and Media
We may access your device's camera and photo library for:
| Data Type | Purpose | Shared With Third Parties |
|---|---|---|
| Receipt Photos | Expense OCR and reimbursement | Yes - AI processing services |
| Document Scans | Digital document storage | No |
| Profile Photos | User identification | No |
| Photo Proof | Task completion verification | No |
3.5 Device Information
We automatically collect certain device information:
| Data Type | Purpose |
|---|---|
| Device Model | App optimization, support |
| Operating System & Version | Compatibility, security |
| Device Platform (iOS/Android) | Feature availability |
| Unique Device Identifiers | Multi-device session management |
| Push Notification Tokens | Delivering notifications |
3.6 App Activity and Usage Data
We collect information about how you use the App:
| Data Type | Purpose |
|---|---|
| Login/Logout Events | Security auditing |
| Time Clock Punches | Attendance tracking |
| Feature Usage | App improvement |
| Security Audit Logs | Fraud prevention, compliance |
| In-App Messages | Team communication |
3.7 Authentication Data
| Data Type | Purpose | Storage |
|---|---|---|
| Email/Password | Account authentication | Password hashed, never stored in plain text |
| OAuth Tokens (Google/Microsoft) | Third-party sign-in | Encrypted storage |
| Biometric Data | App unlock, security | Stored locally on device only - never transmitted |
| Multi-Factor Authentication Codes | Account security | Temporary, not stored |
4. How We Use Your Information
We use the collected information for the following purposes:
4.1 Core App Functionality
- Employee profile management
- Time and attendance tracking
- Scheduling and shift management
- Payroll processing and calculations
- Expense management and reimbursement
- Task assignment and tracking
- Team communication and announcements
- Document management
4.2 Security and Compliance
- Authenticating users and preventing unauthorized access
- Detecting and preventing fraud
- Maintaining security audit trails
- Complying with legal obligations
- Enforcing our Terms of Service
4.3 Communication
- Sending push notifications about schedules, tasks, and approvals
- Delivering in-app messages from team members
- Sending important account and service updates
- Responding to support requests
4.4 Service Improvement
- Analyzing usage patterns to improve features
- Debugging and fixing technical issues
- Developing new features based on user needs
5. Information Sharing and Disclosure
5.1 Third-Party Service Providers
We share information with the following categories of service providers:
| Service Provider | Data Shared | Purpose |
|---|---|---|
| Supabase (Database & Auth) | All user data | Backend infrastructure, authentication |
| OpenAI / Anthropic | Receipt images, expense descriptions | AI-powered receipt OCR and expense categorization |
| Google (OAuth) | Authentication tokens | Google Sign-In |
| Microsoft (OAuth) | Authentication tokens | Microsoft Sign-In |
| Expo | Push notification tokens | Push notification delivery |
5.2 Within Your Organization
Your employer/organization administrator may access:
- Your time and attendance records
- Your schedule and availability
- Tasks assigned to you and their status
- Your expense reports (if applicable)
- Your profile information (name, contact, job details)
- Messages sent in team channels
5.3 Legal Requirements
We may disclose your information if required to do so by law or in response to:
- Court orders or subpoenas
- Government or regulatory requests
- To protect our rights, privacy, safety, or property
- To investigate potential violations of our Terms of Service
5.4 Business Transfers
If LeadTitan LLC is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
5.5 With Your Consent
We may share your information for other purposes with your explicit consent.
6. Data Storage and Security
6.1 Data Storage Location
Your data is stored on secure servers provided by Supabase, which uses:
- Amazon Web Services (AWS) infrastructure
- Data centers located in the United States
- Enterprise-grade security measures
6.2 Security Measures
We implement the following security measures:
| Security Measure | Implementation |
|---|---|
| Encryption in Transit | All data transmitted via HTTPS/TLS 1.3 |
| Encryption at Rest | AES-256 encryption for stored data |
| Secure Local Storage | Sensitive data stored in device SecureStore/Keychain |
| Biometric Authentication | Optional Face ID/Fingerprint unlock |
| Multi-Factor Authentication | Optional additional security layer |
| Session Management | Automatic session expiration |
| Access Controls | Role-based permissions |
| Audit Logging | All security events logged |
6.3 Biometric Data
Biometric data (fingerprint, face recognition) used for app authentication is:
- Processed entirely on your device
- Never transmitted to our servers
- Never stored in our databases
- Managed by your device's secure enclave
7. Data Retention
We retain your information for as long as necessary to:
| Data Type | Retention Period |
|---|---|
| Account Information | Duration of account + 30 days after deletion |
| Time & Attendance Records | 7 years (legal compliance) |
| Payroll Records | 7 years (legal compliance) |
| Expense Reports | 7 years (legal compliance) |
| Security Audit Logs | 2 years |
| Messages | 3 years or until deleted |
| Device Information | Until device is unregistered |
After the retention period, data is securely deleted or anonymized.
8. Your Rights and Choices
8.1 Access Your Data
You can access your personal data at any time through the App's Account/Profile section.
8.2 Update Your Data
You can update your profile information, contact details, and preferences within the App.
8.3 Export Your Data
You can request a complete export of your data in a portable format. To request a data export:
- Go to Account Settings>Privacy & Security
- Select Export My Data
- Your data will be compiled and sent to your email
8.4 Delete Your Data
You can request deletion of your account and associated data:
- Go to Account Settings>Privacy & Security
- Select Delete My Account
- Confirm the deletion request
Note: Some data may be retained for legal compliance purposes (e.g., payroll records for 7 years). Your employer may also retain employment records as required by law.
8.5 Opt-Out Options
| Feature | How to Opt-Out |
|---|---|
| Push Notifications | Device Settings> Notifications> Quantra |
| Location Services | Device Settings> Location> Quantra |
| Biometric Authentication | App Settings> Security> Disable Biometrics |
| AI-Powered Features | Contact your administrator |
8.6 California Residents (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect
- Request deletion of your personal information
- Opt-out of the sale of personal information (we do not sell personal information)
- Non-discrimination for exercising your rights
To exercise these rights, contact us at privacy@leadtitan.com.
8.7 European Residents (GDPR)
If you are located in the European Economic Area, you have the right to:
- Access your personal data
- Rectify inaccurate personal data
- Erase your personal data ("right to be forgotten")
- Restrict processing of your personal data
- Data portability
- Object to processing
- Withdraw consent at any time
Data Controller: LeadTitan LLC
Legal Basis for Processing: Contract performance, legitimate interests, legal obligations, and consent.
To exercise these rights, contact us at privacy@leadtitan.com.
9. Children's Privacy
Quantra is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information promptly.
10. Third-Party Links and Services
The App may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you access.
11. Push Notifications
We may send you push notifications regarding:
- Schedule changes and shift reminders
- Task assignments and deadlines
- Time off request approvals
- Team messages and announcements
- Security alerts
You can disable push notifications in your device settings at any time.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the "Last Updated" date at the top of this policy
- For significant changes, we will notify you via the App or email
- Your continued use of the App after changes constitutes acceptance of the updated policy
We encourage you to review this Privacy Policy periodically.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
LeadTitan LLC
Email: privacy@leadtitan.com
Subject Line: "Quantra Privacy Inquiry"
For data deletion or export requests, please include:
- Your full name
- Email address associated with your Quantra account
- Specific request (deletion, export, access, etc.)
We will respond to all privacy-related requests within 30 days.
14. Summary of Data Practices
| Category | Collected | Shared | User Control |
|---|---|---|---|
| Personal Info (Name, Email, Phone) | ✅ Yes | ❌ No | Edit/Delete |
| Location | ✅ Yes | ❌ No | Disable in Settings |
| Photos | ✅ Yes | ✅ Yes (AI OCR) | Optional |
| Financial Info | ✅ Yes | ❌ No | Managed by Employer |
| Device Info | ✅ Yes | ❌ No | Automatic |
| App Activity | ✅ Yes | ❌ No | Limited |
| Biometric | ✅ Local Only | ❌ Never | Enable/Disable |
| Messages | ✅ Yes | ❌ No | Delete |