Privacy Policy — Proprely Android app
Effective date: 26 June 2026 · Application: com.proprely.app · Publisher: Proprely (France).
This privacy policy describes how the ProprelyAndroid app (the "App") collects, uses, and shares personal information when used by field agents and property-management staff. The App is a companion to the Proprely SaaS platform. By using the App you agree to this policy. For the broader SaaS privacy policy (data controller, retention, GDPR rights) see /confidentialite.
1. Data we collect from your device
The App requests the following Android permissions and collects the listed data.
- Precise & approximate location (
ACCESS_FINE_LOCATION,ACCESS_COARSE_LOCATION) — used only when an agent checks in / checks out of a mission, to record the location where the work was performed. Location is sent to our backend and attached to that mission record. It is not collected in the background and is not used for advertising. - Camera (
CAMERA) — used only when the user explicitly takes a photo from inside the App (mission report, "before/ after" pictures, signature capture). Photos are uploaded to our backend and associated with the corresponding mission. - Photos and media (
READ_MEDIA_IMAGES,READ_MEDIA_VIDEO,READ_MEDIA_AUDIO) — used only when the user picks an existing file from their gallery to attach to a mission. Only the selected files leave the device. - Bluetooth (
BLUETOOTH,BLUETOOTH_ADMIN,BLUETOOTH_CONNECT) — reserved for future integration with mobile printers / scanners used on missions. The App does not currently transmit any Bluetooth data off-device. - Push notifications (
POST_NOTIFICATIONS) — used to alert agents about newly assigned missions, reminders and updates. We rely on Google Firebase Cloud Messaging (FCM). A Firebase device token is generated by the operating system and stored on our backend, linked to your user account, so we can deliver notifications targeted at you. The token is deleted when you log out. - Internet access (
INTERNET) — the App is a web client that loads its UI fromhttps://app.proprely.frand communicates with our backend athttps://api-app.proprely.frover HTTPS.
2. Account data we process
When you sign in, the App receives and stores in encrypted browser cookies (httpOnly):
- Your authentication tokens (JWT access & refresh tokens).
- Your account profile already created in the Proprely SaaS: name, professional email address, role, and the company you belong to.
Through normal use you will also create or view business data: missions, time entries, sites, properties, reports, photos. This data is stored on our backend under your company's account.
3. Data we do NOT collect
- We do not access your contacts, SMS, call logs, or microphone.
- We do not collect location in the background.
- We do not show third-party ads. We do not use advertising identifiers.
- We do not sell personal data to third parties and we do not share data for third-party advertising.
4. How we use the data
- To authenticate you and keep your session active.
- To deliver the Proprely service: show your missions, record location at check-in/out, attach photos to reports, send mission notifications.
- To send transactional notifications you have not opted out of.
- To diagnose crashes and improve reliability — limited technical telemetry only (no personal content from your screen is sent), via Sentry.
5. Sharing with third parties (sub-processors)
We share the minimum necessary data with the following sub-processors, all bound by GDPR-compliant data-processing agreements:
- OVH / our European VPS provider — application and database hosting in the European Union.
- Google Firebase Cloud Messaging — delivery of push notifications. Device push tokens and notification payloads are processed by Google as our sub-processor.
- Apple Push Notification service — (when the iOS version ships) delivery of push notifications on Apple devices.
- Resend — transactional email (login links, invitations, alerts).
- Sentry (EU region) — error and crash diagnostics.
- Amazon CloudFront / S3 — storage and delivery of user uploaded images (mission photos).
- DocuSeal — electronic signature of quotes (only when the feature is used).
6. International transfers
Our primary hosting and database are located in the European Union. Some sub-processors (Google FCM, Sentry, AWS) may process data in regions outside the EEA; in that case transfers are covered by the European Commission's Standard Contractual Clauses (SCCs).
7. Data retention
- Mission data, photos, time entries: kept for the duration of your company's subscription, plus a retention period required by French accounting law where applicable.
- Authentication cookies: short-lived access token, longer-lived refresh token; both deleted when you log out.
- Device push token: deleted from our backend when you log out or uninstall the App and re-open the web version.
- Crash logs (Sentry): 90 days.
8. Your rights (GDPR)
You have the right to access, correct, delete, restrict, port, and object to the processing of your personal data, and the right to lodge a complaint with the French data-protection authority (CNIL — cnil.fr/plaintes). To exercise any of these rights, contact privacy@proprely.fr.
9. Account & data deletion
To request deletion of your account and all associated personal data, send an email to privacy@proprely.fr from the email address tied to your account. We will confirm the request and delete (or irreversibly anonymise) your data within 30 days, unless legally required to retain specific records (e.g. accounting). You can also uninstall the App at any time; uninstalling stops further data collection from the device but does not by itself delete the data already stored in our backend — use the email procedure above for that.
10. Children
The App is intended for professional use by adult employees of our customer companies. It is not directed to children under 16 and we do not knowingly collect personal data from children.
11. Security
- All communications between the App, our backend, and sub-processors use TLS.
- Authentication uses short-lived JWT access tokens with rotating refresh tokens, both stored as httpOnly cookies.
- Multi-tenant isolation enforced at the application and database layer.
- Encrypted daily backups stored in the European Union.
12. Changes to this policy
We may update this policy to reflect changes in the App or in applicable law. When we do, we will update the "Effective date" at the top of this page and, for material changes, notify account owners by email.
13. Contact
Privacy / GDPR requests: privacy@proprely.fr
General support: support@proprely.fr