Use the evidence required for verification; do not continuously track people.
MesaiGo’s privacy approach is based on data minimization, purpose limitation, employee visibility, retention, and auditable change.
Last updated: July 24, 2026Scope of this page
This page explains the technical privacy approach of the MesaiGo product. Controller identity, legal bases, recipient groups, international transfers, and data-subject request channels will also be published in activity-specific privacy notices once the service entity and deployment model are finalized.
Data we do not collect
MesaiGo does not collect, store, or send face images, fingerprints, or biometric templates to the server. Access and attendance decisions are not based on GPS coordinates, and background location tracking is not performed.
Evidence data we process
Device and credential identifiers, organization and entry-point context, challenge, mobile evidence and gateway-witness summaries, assurance result, policy version, time, and audit fields are processed only as necessary to operate the product securely.
On-device user verification
When a supported version and organization policy require it, a High Assurance transaction may be approved through the operating system PIN or local biometrics. The biometric template is not transferred to MesaiGo; the app uses only the result that the relevant cryptographic operation completed after local approval.
Employee visibility and corrections
Employees can view their own attendance events, calculated hours, exceptions, and correction history. The original business event is not changed silently; an administrative correction is stored separately with actor, time, reason, and approval chain. Raw protocol evidence is retained only when needed under a separate, encrypted, narrowly authorized, and time-bound lifecycle.
Retention and access
Retention is defined by organization policy according to data class, purpose, contract, and legal assessment. Users outside the required role and scope cannot access sensitive employee or security data.