Last updated: April 2026 | Version 1.0
Vantro is a product of CNNCTD Ltd (NI695071), operating as Scale 8 Digital. We provide workforce management software for construction and trades businesses. This policy explains how we collect, use, and protect personal data processed through the Vantro platform.
We collect the following categories of personal data:
Account data: Name, email address, company name, role.
Authentication data: Hashed PIN (we never store PINs in plain text).
Location data: GPS coordinates at sign-in, sign-out, and periodic breadcrumb logs while signed in to a job site. Location tracking only occurs during active work sessions.
Work activity data: Sign-in/sign-out times, hours worked, diary entries, QA checklist submissions, defect reports, and associated photographs.
Device data: Push notification tokens for work-related alerts.
We process personal data under the following lawful bases as defined by UK GDPR:
Legitimate interest (Article 6(1)(f)): GPS location tracking during work hours for the purposes of accurate payroll calculation, attendance verification, health and safety compliance, and prevention of time theft. We have conducted a Legitimate Interest Assessment confirming this processing is necessary, proportionate, and does not override the fundamental rights of data subjects.
Contract performance (Article 6(1)(b)): Processing necessary to fulfil the service contract between Vantro and the employer company.
Vantro collects GPS location data under the following conditions:
- Location tracking begins only when an installer signs in to a job site
- Location tracking stops immediately when the installer signs out
- GPS breadcrumb logs are recorded approximately every 30 minutes during active sessions
- Location data is used solely for attendance verification and payroll accuracy
- No tracking occurs outside of work sessions
- Installers are informed of tracking through an in-app acknowledgment screen before their first sign-in
- Location data is automatically deleted after the retention period set by the employer (default: 90 days)
We retain personal data only as long as necessary:
GPS breadcrumb data: Automatically deleted after the employer-configured retention period (default 90 days).
Sign-in/sign-out records: Retained for the duration of the employment relationship plus 6 years for payroll and legal compliance purposes.
Account data: Retained until the account is deactivated or deleted.
Photographs: Retained for the duration of the employer-configured retention period.
Under UK GDPR, you have the following rights:
Right of access: You can request a copy of all personal data we hold about you. Use the "My Data" section in the Vantro app or contact your employer.
Right to rectification: You can request correction of inaccurate data.
Right to erasure: You can request deletion of your data, subject to legal retention requirements.
Right to restrict processing: You can request that we limit how we use your data.
Right to data portability: You can request your data in a machine-readable format.
Right to object: You can object to processing based on legitimate interest.
To exercise any of these rights, contact your employer or email privacy@getvantro.com.
We implement appropriate technical and organisational measures to protect personal data:
- All data is encrypted in transit (TLS/SSL) and at rest
- Authentication uses cryptographically signed tokens (JWT)
- PINs are hashed using bcrypt and never stored in plain text
- Row-level security ensures companies can only access their own data
- API access is authenticated and authorised on every request
- Admin actions are recorded in an audit log
- Regular automated cleanup of expired data
We use the following third-party processors:
Supabase (AWS eu-west): Database hosting and authentication
Vercel: Application hosting and serverless functions
Expo/Google: Push notification delivery
Stripe: Payment processing (no access to location or work data)
All processors are GDPR-compliant and process data within the UK/EEA or under appropriate safeguards.
The data controller for employee data processed through Vantro is the employer company that has subscribed to the Vantro service. CNNCTD Ltd acts as the data processor on behalf of the employer.
For questions about this policy or to exercise your data rights, contact:
CNNCTD Ltd, privacy@getvantro.com
We may update this policy from time to time. Changes will be communicated through the Vantro app and on this page. Continued use of the service after changes constitutes acceptance of the updated policy.