SignBas3 Field privacy policy

SignBas3 Field is business software for sign companies. Customer organisations decide who may use their workspace and which business records their people can access. We handle that information to provide and protect the service—not to sell personal information or deliver advertising in the SignBas3 Field app.

Short versionThe mobile app uses an existing SignBas3 account. It can show assigned jobs and tasks, record timesheets, update eligible tasks and upload job photos. Camera, photo-library and foreground-location access are used only when the user starts the relevant feature.

Scope and operator

This release notice applies to the public website at signbas3.com, the SignBas3 Field apps for iOS and Android, and related support interactions. It is focused on the mobile companion and does not attempt to catalogue every data flow in the broader SignBas3 web application, which is also governed by customer agreements and any additional notices provided for those services.

SignBas3 is operated by Insigns Pty Ltd (ABN 49 058 136 931). While the Apple developer account is being converted to the company, Apple may display Callan Laughton as the app seller. He publishes SignBas3 Field on behalf of Insigns Pty Ltd; Insigns Pty Ltd remains the service operator and privacy contact.

A customer organisation is responsible for the business information it puts into its SignBas3 workspace and for assigning access to its users. Depending on the context, Insigns Pty Ltd may handle that information for the customer organisation or for its own legitimate service, security and support purposes.

Information we handle

Account and authentication information

We handle an email address or user identifier, display name, organisation membership, roles and permissions, and session information. A password and, when enabled, a two-factor code are sent to the SignBas3 service for authentication. The mobile app does not intentionally retain the password or one-time code after that request. It stores the active session token, session identifier, expiry and account context in the device's protected credential storage.

Customer, job and field-work information

Authorised users may access client and job names, job numbers and status, site addresses, site contacts and phone numbers, field notes, job specifications, materials or artwork references, assigned tasks, completion activity, photos, and OHS or SWMS documents. Access is limited by the organisation and the permissions attached to the signed-in user.

Timesheets and activity

Timesheet records can include the user or staff member, date, start and finish time, duration, selected job and task, and the required work description. Task, timesheet and photo actions may also create audit information such as the acting user, time, record identifiers and outcome.

Photos and location

When a user takes or selects a job photo, we handle the image, filename and type, related job or time-entry identifier, capture or upload time and creator. For a camera photo, the app may ask for foreground location and attach latitude, longitude and available accuracy only if the user grants permission. A library selection is decoded and re-encoded into a new app-owned image before staging; SignBas3 Field does not separately read or upload the original file's embedded EXIF location or capture-time metadata.

Device and diagnostic information

Expo Application Services supports delivery and recovery of app updates. It may receive a randomly generated installation identifier, device platform, runtime and update identifiers, identifiers for recent failed updates, and a limited excerpt of a previous fatal update error. We use this information for app functionality, update reliability and diagnostics, not for advertising.

Website and support information

If someone submits an enquiry or support request, we handle the contact details, organisation, message and related correspondence they provide. The public website uses essential storage and first-party analytics. Depending on site configuration and applicable consent requirements, measurement providers may include Google Analytics or Google Ads, Microsoft Clarity, Meta Pixel and LinkedIn Insight Tag. When consent is required, non-essential measurement waits for the visitor's choice; where consent is not required, configured measurement may load by default. Form details are not intentionally placed into the website analytics event stream.

Mobile permissions and storage

  • Camera. Used for supported SignBas3 job-sheet QR codes and user-initiated job photos.
  • Photo library. Used to select photos for the current job. Selected image pixels are re-encoded before the new app-owned file enters the upload queue.
  • Foreground location. Optional and used to geotag a camera photo when the user permits it. The app does not request background location.
  • Private device storage. Used for the secure session, cached job and task labels, timesheet drafts, and queued photo copies while work is synchronising.

Signing out removes the active credentials. To avoid silently losing work, tenant-and-user-scoped drafts, cached labels or unsent queued photos may remain in private app storage after sign-out. They remain isolated to that organisation and user identity and can persist until they synchronise, are discarded, the app's data is cleared or the app is uninstalled.

SignBas3 Field does not include advertising SDKs and does not request microphone, background-location, motion, notification or Face ID access in this release.

How we use information

We use information to authenticate users; show authorised jobs, tasks, documents and photos; record time and task changes; upload and retry job photos; provide directions or phone and document actions chosen by the user; maintain tenant isolation; deliver app updates; detect and resolve failures; provide support; protect the service; and meet legal or contractual obligations.

We do not sell personal information. We do not use SignBas3 Field data for cross-app or cross-site advertising, and the mobile app does not track users for advertising purposes.

Service providers and user-directed transfers

We use infrastructure and service providers to operate SignBas3. These include Amazon Web Services for application infrastructure and storage, and Expo Application Services for mobile build and update delivery. A customer organisation may connect its own Google Drive or Dropbox location for job documents and photos; those provider credentials remain server-side.

For public website analytics and marketing measurement, configured providers may include Google, Microsoft Clarity, Meta and LinkedIn. Those providers handle website measurement under their own terms and privacy policies; their measurement tools are not bundled into SignBas3 Field.

When a user chooses Directions, Call, or an external document link, the app hands the relevant address, phone number or URL to the device's Maps, dialler or browser service. Those services handle the information under their own terms and privacy policies.

Providers may process information in Australia and other countries where they or their infrastructure operate. We assess access according to the service, customer arrangements and applicable privacy obligations.

Retention, export and deletion

Customer organisations control their operational records and user access. We retain account, job, timesheet, photo, security and audit information for as long as needed to provide the service, follow the customer's instructions, protect the platform, resolve disputes, and meet contractual or legal obligations. The applicable period can vary by record type and the customer organisation's requirements.

Successfully synchronised records remain in the organisation's SignBas3 workspace or selected document provider according to those arrangements. Device drafts and queued photos follow the local-storage behaviour described above. Uninstalling the app removes app-owned local data through the operating system but does not delete information already synchronised to SignBas3 or a connected provider.

The mobile app does not create a SignBas3 account. A user seeking access, correction, export, restriction or deletion should first contact their organisation's SignBas3 administrator. They may also email hello@signbas3.com. We will verify the request and the user's authority, coordinate with the customer organisation where required, and explain any information that must be retained for security, audit or legal reasons.

Choices and rights

Users can decline camera, photo-library or foreground-location permission in device settings. Declining location prevents SignBas3 Field from attaching the current location to a camera photo; core job and timesheet access can continue. Users can choose whether to open Maps, make a call or open an external document.

Depending on applicable law and the relationship with the customer organisation, a person may have rights to access, correct, export, object to, restrict or request deletion of personal information. We will respond to verified requests and complaints in accordance with applicable obligations.

Security and audience

We use access controls, tenant context, protected credentials, private app storage, transport encryption and operational safeguards intended to protect information. No system can guarantee absolute security. Users should protect their device and credentials and report suspected unauthorised access promptly.

SignBas3 Field is an account-only business app for authorised workers of SignBas3 customer organisations. It is not directed to children and does not offer child-focused content.

Changes to this policy

We may update this policy when the service, providers or legal requirements change. The current effective date will appear at the top of this page. Material changes will be communicated through an appropriate service or customer channel.

Contact

For a privacy request or question, email hello@signbas3.com or use the SignBas3 contact form. Please do not send passwords, one-time codes or unnecessary customer records.