Warehaus Lab staff operations platform · Last updated 27 July 2026
Warehaus Lab is a staff operations platform for hospitality businesses: attendance, rosters, tasks, training, recipes and related workplace tools. It is used by employees of organisations that run Warehaus, on the web and through the Warehaus Lab Android app. This policy explains what personal data the platform handles, why, and who processes it.
| Data | When | Why |
|---|---|---|
| Email address and password | Login and password setup | Authentication. Passwords are stored only as secure hashes; we never see or store them in plain text. |
| 4-digit device PIN | Optional trusted-device setup | Faster unlock on a device you choose to trust. Stored only as a hash. |
| Device identifier | First use on a device | A random ID (not tied to your hardware) that lets us recognise a trusted device and show you where you are signed in. |
| GPS location (latitude, longitude, accuracy) | Only at attendance check-in and check-out, when you tap the button | Verifying you are at the venue when clocking in (an accurate-payroll control). Your position is shown to you on a map before it is recorded. Location is never collected in the background. |
| Profile and employment data (name, role, contact details, payroll information, documents) | Entered by you or your employer's HR/admin team | Payroll, rosters, leave and HR operations. Visibility is restricted by role-based access rules. |
| Photos and uploads (profile photos, bill scans, task photos) | When you choose to take or upload them | Feature content. The camera is used only when you actively start a photo or scan. |
| Push notification token | If you enable notifications | Delivering workplace notifications (tasks, roster changes, announcements) to your device. |
The public marketing site collects no personal data from visitors. The platform contains no advertising and no third-party analytics, and we do not sell personal data.
Attendance check-in reads your GPS position through the device's location service, only in the foreground and only when you initiate a check-in or check-out. The position is compared against your outlet's zone, shown to you on a map, and stored with the attendance record for payroll audit. If you decline the location permission, check-in via the app is simply unavailable; the rest of the app keeps working.
| Processor | What it handles | Purpose |
|---|---|---|
| Supabase | All platform data and authentication | Database, login, file storage and server functions. Access is restricted by row-level security rules. |
| Google Firebase Cloud Messaging | Push notification tokens | Delivering push notifications on Android. |
| jsDelivr CDN | IP address and browser signature (inherent to any web request) | Delivering integrity-pinned code libraries to the app. |
| Carto | IP address and approximate map area | Map tiles for the check-in map view. |
| DiceBear | A non-identifying request string | Generated fallback avatars for accounts without a photo. |
The platform stores a session token, the random trusted-device ID and your "remember me" preference on your device. There are no advertising or third-party analytics cookies.
All traffic is encrypted in transit (HTTPS). Data access is governed by per-role, per-outlet access rules enforced at the database layer. Passwords and PINs are stored only as hashes.
Employment and attendance records are retained while you are employed and for the audit period your employer is required to keep. Because accounts are created and managed by your employer, requests to correct or delete your data go to your employer's HR contact, or to us at the address below, and we will action them with your employer.
Privacy questions and data requests: operations@warehauslab.in