Privacy Policy for TracGo
Effective date: 18 August 2026
Last updated: 18 August 2026
TracGo is provided by B-Trac Solutions Limited, Plot 68, Road 11, Block H, Banani,
Dhaka 1213, Bangladesh (https://www.btracsolutions.com/). In this policy, “we”, “us” and
“our” mean that company.
TracGo is our mobile client for the Carcopolo TMS transport-management platform, which we
operate under the TracGo name. That is why the app communicates with servers at
tms.carcopolo.com.
For any privacy question or request, contact us at psd.btraccl@gmail.com.
Who this app is for
TracGo is an internal application for employees and authorised users of B-Trac Solutions
Limited and its affiliates. An account is created for you when you are hired — the app has
no sign-up screen and you cannot create an account yourself. If your organisation has not
issued you an account, you cannot use the app, and when you leave the organisation your
access is withdrawn by your administrator.
What we collect
Information you give us when you sign in
- Your work email address and password. The password is sent to our servers only to verify
who you are and is not stored on your device.
Information you give us when you reset a forgotten password
- Your work email address, before you are signed in. We send a six-digit one-time code to
that address; you send the code back with a new password, and we set it.
- The code is checked on our servers and expires. Completing a reset invalidates the
account’s access token everywhere, so every signed-in device — including this one — is
signed out and has to sign in again.
- The Change password button on your profile runs this same email-code flow. It never
asks for your current password.
Information from your employee record
- Your name, job designation, employee code, department, company, and phone number where
your organisation has recorded one.
Information you enter when you raise a vehicle requisition
- Pickup and drop-off locations, dates and times, purpose, number of passengers, vehicle or
load details, and any remarks you add.
- The colleagues you name as passengers. To pick them, the app shows you a directory drawn
from your organisation’s employee records — name, employee code, designation, department
and company. Whoever you select is submitted as part of your requisition, so you are
giving us information about them as well as about yourself. Name only the people who are
actually travelling.
- These locations are what you type. The app does not access your device’s location. It
holds no location permission and cannot determine where you are.
Information about assigned trips
- Once a requisition is assigned, the app displays the assigned vehicle, and the driver’s
name and phone number, so you can be reached and can reach them.
Diagnostic information
- If the app crashes or encounters an unexpected error, we receive a crash report through
Google Firebase Crashlytics. It contains the error and its stack trace, your device model,
operating system version, app version, and a record of the screens visited and server
responses received shortly before the problem.
- Crash reports identify you only by the internal account identifier your organisation’s
system assigns. Your name and email are never sent to Crashlytics.
- Crash reporting is disabled in development builds.
What we do not collect
- Your device’s location.
- Your contacts, calendar, photos, files, camera or microphone. The app requests none of
these permissions.
- Any advertising identifier. TracGo contains no advertising and no advertising or
marketing analytics software.
How we use it
- To let you sign in, to keep you signed in, and to let you recover access if you forget
your password.
- To create, display, edit and cancel vehicle requisitions, and to route them to the
approvers and transport staff who act on them.
- To diagnose crashes and errors so the app can be fixed.
We do not use your information for advertising, and we do not sell it.
Who we share it with
- Your organisation. Requisitions are business records. Your requests, and your identity
as the requester, are visible to the approvers, transport administrators and other
authorised staff who process them. The colleagues you name as passengers, and the driver
assigned to a trip, are identified in those same records.
- Google (Firebase Crashlytics and Remote Config). Google processes crash and diagnostic
data on our behalf as our service provider. Remote Config exists to send configuration
to the app: fetching it gives Google no personal information about you, but the request
does carry an identifier Firebase generates for this installation of the app, together
with the app version, device model and operating system version.
- Where the law requires it, or to protect our rights, safety, or those of others.
We do not sell your personal information or share it with third parties for their own
marketing.
Requisition and account data is held on our servers at tms.carcopolo.com. Crash and
diagnostic data is held by Google on infrastructure that may be located outside your
country. All communication between the app and our servers uses encrypted HTTPS
connections.
What is stored on your device
- Your sign-in session — an access token and your basic profile — is stored in the device’s
protected storage (the Android Keystore-backed store, or the iOS Keychain).
- Signing out deletes it from your device and revokes the token on our servers.
- On Android, the app’s data is excluded from cloud backup and from device-to-device
transfer. On iOS, the session is written so that it never leaves the device it was created
on and is not carried into an iCloud or computer backup. Either way your session cannot be
copied to another device — on a new device you sign in again.
- Uninstalling the app removes its local data on Android. On iOS the protected storage
outlives an uninstall, so the app deletes any session it finds the first time it is
reinstalled and opened, before anything can use it. A reinstall never resumes an old
session.
How long we keep it
- Requisition records are business records. We keep them for as long as our record-retention
requirements apply, and delete them when those requirements no longer do. There is no
fixed period.
- Crash and diagnostic reports are retained by Firebase Crashlytics for up to 90 days.
- Sign-in tokens expire automatically; an expired session is discarded by the app without
being used.
Your choices and rights
- Access or correction. Your account details come from your employer’s records. Ask your
IT or TMS system administrator to correct them, or write to us at the address below.
- Deletion. Because accounts are issued by your organisation rather than created by you,
ask your IT or TMS system administrator to close your account and remove your data. Where
we are required to keep a requisition as a business record, we may retain that record
after your account is closed.
- Signing out clears the session from your device at any time.
- Depending on where you live, you may have further rights over your personal data. Write to
the contact address below to exercise them.
Children
TracGo is a workplace application. Accounts are issued only to people the organisation has
hired, so the app is not directed at children, and we do not knowingly collect information
from anyone under 18.
Changes to this policy
If we change this policy we will update the date at the top of this page, and material
changes will be communicated through your organisation.
B-Trac Solutions Limited
Plot 68, Road 11, Block H
Banani, Dhaka 1213
Bangladesh
Email: psd.btraccl@gmail.com
Web: https://www.btracsolutions.com/