Privacy Policy
Last Updated: April 7, 2026 | Version 2.0
Cruz IT Services LLC (“CITS,” “we,” “our,” or “us”) operates the CITS Time workforce management platform, which includes the CITS Time mobile application (“App”), the CITS Time Admin Portal (“Admin Portal”), and related backend services (collectively, the “Service”). This Privacy Policy explains how we collect, use, store, share, and protect information when you use any component of the Service.
Scope: This policy applies to all users of the Service, including employees and contractors who use the App, and company administrators who use the Admin Portal. If your employer or contracting company has not authorized your access, you may not use the Service.
1. Eligibility & Access
CITS Time is a business-to-business (B2B) workforce management platform. Access is restricted to:
- Employees and contractors whose employer (“Company”) has an active subscription and has issued login credentials.
- Company administrators authorized by their organization to manage workforce data through the Admin Portal.
The Service is not available to the general public. All data collected is managed on behalf of the subscribing Company.
2. Information We Collect
A. Shift & Work Activity Data
- Clock-in and clock-out timestamps
- Break start/end times and durations
- Fuel logs, meeting activity, and shift status
- Job/project selection and work assignments
- Employee-entered shift notes and comments
B. Delivery & Material Usage Data
- Delivery activity and routing information
- Customer/job drop-off details
- Material types, quantities, amounts, and notes
C. Photos & Media
- Photos captured through the App for job documentation, delivery verification, and shift reporting
- Photos may be stored in Company-designated cloud storage (e.g., Microsoft SharePoint) as configured by your Company administrator
D. Location Data
- GPS coordinates collected only while you are clocked in to an active work shift
- Used for job-site attendance verification, route tracking, delivery confirmation, and geofencing (arrival/departure detection)
- Location tracking stops automatically when you clock out — the App does not track your location outside of active shifts
- You may revoke location permissions at any time through your device settings, though this may limit certain features
E. Device & Technical Data
- Device model, operating system version, and app version
- Push notification tokens (Apple APNs, Google FCM, Web Push)
- Crash reports, performance metrics, and error logs
- Offline sync status and network connectivity data
F. Authentication & Account Data
- Email address and name (provided by your Company or identity provider)
- Authentication tokens from Microsoft 365 / Azure Active Directory (if used by your Company)
- Biometric authentication data (Face ID, fingerprint) is stored locally on your device only and is never transmitted to our servers
G. Admin Portal Data
- Administrator email addresses and access logs
- Company configuration settings, project/job definitions, and employee rosters
- Payroll reports, time summaries, and workforce analytics generated from shift data
3. How We Use the Information
Data collected through the Service is used exclusively for employment-related and business operational purposes:
- Time tracking, payroll processing, and labor compliance
- Delivery and material usage reporting
- Job/project management and operational efficiency
- Employee workflow auditing and regulatory compliance
- Safety, accountability, and job-site verification
- Offline-to-online data synchronization and integrity
- Push notifications for shift reminders, break alerts, and system updates
- Generating reports and analytics for Company administrators
We do NOT sell, rent, lease, or commercially share your personal data. Ever.
4. Third-Party Integrations
The Service may integrate with third-party platforms at the direction of your Company administrator. These integrations are optional and configured per-Company:
QuickBooks Online (Intuit)
- When enabled, time entry data (employee name, hours, project assignment, break durations) may be transmitted to QuickBooks Online for payroll and accounting purposes
- Data is sent via Intuit’s secure OAuth 2.0 API and is governed by Intuit’s Privacy Statement
- Your Company administrator controls which data is synced and when
- We do not store QuickBooks credentials — authentication uses industry-standard OAuth 2.0 tokens that can be revoked at any time
Microsoft 365 / Azure Active Directory
- Used for single sign-on (SSO) authentication if configured by your Company
- We receive only the minimum profile information needed (name, email)
- Governed by Microsoft’s Privacy Statement
Microsoft SharePoint
- Used for storing job-related photos and documents when configured by your Company
- Files are stored in your Company’s own SharePoint environment
Push Notification Services
- Apple Push Notification service (APNs) for iOS devices
- Firebase Cloud Messaging (FCM) for Android devices
- Web Push (VAPID) for browser-based notifications
- These services receive only device tokens necessary for delivery — message content is encrypted in transit
5. How Your Data Is Stored
- Data is stored on secure, access-controlled servers operated by CITS or our hosting providers
- Each subscribing Company’s data is logically isolated in a separate database (multi-tenant architecture with per-tenant isolation)
- Offline data is stored locally on your device and synchronized when connectivity is restored
- Data in transit is protected with TLS/SSL encryption
- Your Company determines data retention periods in accordance with applicable labor laws and company policy
6. Who Can Access Your Data
Access to your data is strictly limited to:
- Your employer — Company administrators authorized to manage workforce data
- CITS support staff — only when troubleshooting issues authorized by your Company, under confidentiality obligations
- Third-party integrations — only those explicitly enabled by your Company administrator (e.g., QuickBooks)
CITS does not grant data access to any unauthorized third parties. We do not share data across subscribing Companies.
7. Data Sharing
We do NOT share your data with advertisers, data brokers, or unrelated third parties. Data may be shared only with:
- Your employer, as the data controller
- Third-party integration platforms explicitly authorized by your Company administrator
- Infrastructure and hosting providers who process data on our behalf under strict data processing agreements
- Law enforcement or regulatory authorities, only when legally compelled (e.g., valid subpoena or court order), and we will notify the affected Company unless prohibited by law
8. Data Security
We implement industry-standard technical and organizational security measures:
- TLS/SSL encryption for all data in transit
- Encrypted storage for sensitive credentials and tokens
- Secure authentication with JWT tokens and OAuth 2.0
- Per-tenant database isolation
- Role-based access controls for administrative functions
- Audit logging of administrative actions
- Regular security reviews and dependency updates
No system is 100% secure. In the event of a security incident affecting your data, we will notify the affected Company promptly in accordance with applicable breach-notification laws.
9. User Rights
Because the Service is used in an employer-controlled environment, your Company acts as the data controller and CITS acts as a data processor. Requests regarding:
- Access to your data
- Correction or rectification of data
- Deletion or erasure of data
- Data portability
- Restriction of processing
should be directed to your employer. CITS will support employer-initiated requests promptly and in compliance with applicable privacy regulations (including GDPR, CCPA, and state privacy laws where applicable).
10. Children’s Privacy
The Service is not intended for use by individuals under the age of 16. We do not knowingly collect data from minors. The Service is used exclusively by authorized employees and contractors of subscribing Companies.
11. International Data
The Service is primarily operated in the United States. If you access the Service from outside the United States, you acknowledge that your data may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes:
- The “Last Updated” date at the top will be revised
- We will notify subscribing Companies of significant changes
- Continued use of the Service after changes are posted constitutes acceptance
13. Contact Information
End User License Agreement
Last Updated: April 7, 2026 | Version 1.0
This End User License Agreement (“Agreement”) is a legally binding contract between you (“User,” “you,” or “your”) and Cruz IT Services LLC (“CITS,” “we,” “our,” or “us”) governing your use of the CITS Time platform, which includes the CITS Time mobile application (“App”), the CITS Time Admin Portal (“Admin Portal”), and all related services, APIs, and backend systems (collectively, the “Service”).
By downloading, installing, accessing, or using any component of the Service, you acknowledge that you have read, understood, and agree to be bound by this Agreement and our Privacy Policy. If you do not agree, do not use the Service.
1. Acceptance of Terms
By using the Service, you represent that:
- You are at least 16 years of age
- Your employer or contracting company (“Company”) has an active subscription to the Service and has authorized your access
- You have the authority to agree to these terms on your own behalf
- You will comply with all applicable laws and regulations in connection with your use of the Service
2. Description of Service
CITS Time is a multi-tenant workforce management platform that provides:
- Mobile App: Time tracking (clock-in/clock-out), break management, job/project assignment, delivery tracking, material logging, photo documentation, GPS-based job-site verification, and offline functionality
- Admin Portal: A web-based dashboard for Company administrators to manage employees, review timesheets, generate reports, configure integrations (including QuickBooks Online), manage projects, and oversee workforce operations
- Backend Services: Secure data processing, synchronization, push notifications, scheduled reports, and third-party integration APIs
Features available to you are determined by your Company’s subscription plan and administrator configuration.
3. User Accounts & Authentication
- You are responsible for maintaining the confidentiality of your login credentials
- You must not share your account with others or allow unauthorized access
- You agree to notify your supervisor or Company administrator immediately if you suspect unauthorized use of your account
- Biometric authentication data (Face ID, fingerprint) is stored locally on your device and is never transmitted to our servers
- If your Company uses Microsoft 365 / Azure AD for authentication, your sign-in is governed by both this Agreement and your organization’s identity policies
4. Location Data & GPS Tracking
- The App collects continuous GPS location data while you are clocked in to an active work shift
- This data is used to verify job-site attendance, record your route, track deliveries, and support geofencing (automatic arrival/departure detection at designated sites)
- Location tracking starts when you clock in and stops when you clock out — the App does not track you outside of active shifts
- You may revoke location permissions through your device settings at any time; however, this may limit or disable certain features required by your Company
- Your Company administrator determines whether location features are enabled for your organization
5. Camera & Device Permissions
- The App may request access to your device camera for QR code scanning (initial setup) and job-related photo documentation
- Camera access is used only for the specific feature being accessed and is not used for surveillance or continuous capture
- Photos taken through the App are transmitted to your Company’s designated storage and are managed according to your Company’s data policies
- You can manage all device permissions through your device settings at any time
6. Push Notifications
- The Service may send push notifications for shift reminders, break alerts, schedule changes, and system updates
- Notifications are delivered via Apple Push Notification service (APNs), Firebase Cloud Messaging (FCM), or Web Push, depending on your device
- You may disable notifications through your device settings, though this may cause you to miss time-sensitive work communications
7. Data Collection & Use
We collect work-related data as described in our Privacy Policy, including: clock-in/clock-out times, break durations, task completion records, delivery information, GPS coordinates (while clocked in), photos, and device information necessary for Service functionality.
- This data is processed on behalf of your Company for workforce management purposes
- Your Company acts as the data controller; CITS acts as the data processor
- We do not sell your personal data to third parties
- Data retention is determined by your Company’s policies and applicable labor laws
8. Third-Party Integrations
Your Company administrator may enable integrations with third-party services. By using the Service with these integrations active, you acknowledge:
- QuickBooks Online: Your time entries, hours worked, break durations, and project assignments may be transmitted to Intuit’s QuickBooks Online for payroll and accounting purposes. This data transfer is initiated by your Company administrator and is governed by Intuit’s terms and privacy policy.
- Microsoft 365 / Azure AD: Your authentication and basic profile information (name, email) may be exchanged with Microsoft’s identity platform.
- Microsoft SharePoint: Job-related photos and documents may be stored in your Company’s SharePoint environment.
CITS is not responsible for the privacy practices or security of third-party services. We encourage you to review their respective privacy policies.
9. Acceptable Use
You agree to use the Service only for its intended workforce management purposes. You must not:
- Attempt to manipulate, falsify, or fraudulently alter time records, location data, or any other data
- Reverse-engineer, decompile, disassemble, or attempt to derive the source code of the Service
- Circumvent, disable, or interfere with any security features or access controls
- Use the Service to harass, threaten, or harm others
- Attempt to access data belonging to other users, Companies, or tenants
- Use automated tools, bots, or scripts to interact with the Service without authorization
- Transmit malware, viruses, or any harmful code through the Service
- Use the Service for any purpose that violates applicable local, state, national, or international law
Violations may result in immediate termination of access and may be reported to your employer and, where appropriate, law enforcement.
10. Admin Portal — Additional Terms
If you are a Company administrator using the Admin Portal, the following additional terms apply:
- You are responsible for managing user access within your organization and ensuring only authorized personnel have admin privileges
- You are responsible for the accuracy of employee data, project configurations, and integration settings you manage
- When enabling third-party integrations (e.g., QuickBooks), you represent that you have the authority to authorize data transfers on behalf of your Company
- You must not use the Admin Portal to access, modify, or export data in a manner inconsistent with your Company’s policies, applicable labor laws, or employee privacy rights
- Administrative actions (including data exports, integration changes, and sync operations) are logged for audit and compliance purposes
11. Offline Functionality
The App supports offline use for certain features. Data entered while offline is stored locally on your device and synchronized with the server when connectivity is restored. While we make every effort to ensure data integrity during sync, you should verify that offline entries have been properly recorded when you regain connectivity.
12. Intellectual Property
- The Service, including all software, designs, text, graphics, and other content, is the property of Cruz IT Services LLC and is protected by copyright, trademark, and other intellectual property laws
- This Agreement grants you a limited, non-exclusive, non-transferable, revocable license to use the Service solely for its intended purpose as authorized by your Company
- You may not copy, modify, distribute, sell, or lease any part of the Service
- Data you enter through the Service (time entries, notes, photos) remains the property of your Company
13. Service Availability & Disclaimers
The Service is provided “AS IS” and “AS AVAILABLE” without warranties of any kind, whether express, implied, or statutory, including but not limited to implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
- We strive for high availability but do not guarantee uninterrupted, error-free, or secure service at all times
- Scheduled maintenance, updates, and unforeseen technical issues may temporarily affect availability
- We are not responsible for data loss caused by your device malfunction, loss, or theft
- The Service is not a substitute for your Company’s independent record-keeping obligations under applicable labor laws
14. Limitation of Liability
To the maximum extent permitted by applicable law:
- CITS and its officers, directors, employees, and agents shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from or relating to your use of (or inability to use) the Service
- This includes, without limitation, damages for lost profits, lost data, business interruption, or any other commercial damages or losses
- Our total aggregate liability for any claims arising under this Agreement shall not exceed the amount paid by your Company for the Service in the twelve (12) months immediately preceding the event giving rise to the claim
- These limitations apply regardless of the legal theory (contract, tort, negligence, strict liability, or otherwise) and even if we have been advised of the possibility of such damages
15. Indemnification
You agree to indemnify, defend, and hold harmless CITS and its officers, directors, employees, contractors, and agents from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising out of or relating to:
- Your violation of this Agreement
- Your misuse of the Service
- Your violation of any applicable law or regulation
- Any data you submit or transmit through the Service that is inaccurate, fraudulent, or unlawful
16. Changes to This Agreement
We may update this Agreement from time to time. When we make material changes:
- We will update the “Last Updated” date and version number
- We will notify subscribing Companies of significant changes
- For App users, material changes may be communicated through in-app notifications
- Continued use of the Service after changes are posted constitutes acceptance of the revised Agreement
17. Termination
- Your access to the Service may be terminated by your Company or by us at any time, with or without cause
- Upon termination, your right to use the Service ceases immediately
- We may suspend or terminate access immediately if we reasonably believe you have violated this Agreement
- Provisions that by their nature should survive termination (including intellectual property, limitation of liability, indemnification, and dispute resolution) shall remain in effect
18. Governing Law & Dispute Resolution
- This Agreement shall be governed by and construed in accordance with the laws of the State of Maine, United States, without regard to conflict of law principles
- Any disputes arising under or in connection with this Agreement shall first be attempted to be resolved through good-faith negotiation
- If negotiation fails, disputes shall be resolved through binding arbitration administered in accordance with the rules of the American Arbitration Association, conducted in the State of Maine
- Nothing in this section prevents either party from seeking injunctive relief in a court of competent jurisdiction to prevent irreparable harm
19. Severability
If any provision of this Agreement is found to be unenforceable or invalid by a court of competent jurisdiction, that provision shall be modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall continue in full force and effect.
20. Entire Agreement
This Agreement, together with our Privacy Policy and any Company-specific terms agreed to by your employer, constitutes the entire agreement between you and CITS regarding your use of the Service. This Agreement supersedes all prior agreements, understandings, and communications, whether written or oral.
21. Contact