Privacy Policy
Nexchain Driver App
1. Introduction
This Privacy Policy describes how the Nexchain Driver App ("the App"), developed and operated by SOSMED-ID (Smart Operational Systems & Management), collects, uses, stores, and shares information when you use the App.
By downloading and using the App, you agree to the practices described in this policy. If you do not agree, please do not use the App.
The App is designed exclusively for professional truck drivers to manage delivery trips, scan QR codes, and transmit real-time GPS location data to the fleet management system operated by your employer or logistics operator. This App is not a general consumer application.
2. Information We Collect
2.1 Device Identifier (UUID)
When you first install the App, a unique device identifier (UUID) is automatically generated and stored permanently on your device. This identifier is transmitted to our server on every app launch and with every API request to authenticate your device using HMAC-SHA256 request signing. This identifier persists until the App is uninstalled.
2.2 Driver Personal Information
The following personal data is stored on your device and transmitted to our server as part of trip operations:
- Driver name
- Driver phone number
This information is provided through the trip assignment system by your employer or logistics operator — it is not collected directly from you by the App.
2.3 Precise GPS Location
When a trip is active, the App collects your precise GPS location (latitude, longitude, and accuracy in meters) and transmits it to our server every hour. Location collection occurs while the App is running as a foreground service.
A persistent notification is displayed at all times during location tracking to inform you the service is active. Location collection stops automatically when you end the trip or close the App.
2.4 Battery Level
While a trip is active, the App transmits your device's current battery level to our server with each location ping (every hour). This is used by the fleet management system to monitor driver operational status.
2.5 Trip and Operational Data
The following trip-related data is collected and transmitted to our server during normal App use:
- QR code token (scanned from the physical trip document)
- Trip number, session ID, and trip ID
- Destination address and transporter name
- Vehicle plate number
- Trip start time and finish time
A local history of completed trips is also stored on your device, containing: trip number, destination, driver name, transporter, start and finish times, and POD upload status. This local history remains on your device until the App is uninstalled or you manually clear it.
2.6 Proof of Delivery (POD) Photos
At the end of a trip, you may upload up to 10 photos as Proof of Delivery. Photos are selected using the Android system photo picker and transmitted to our server along with the trip token and optional notes. The App does not store POD photos on your device beyond the upload session.
2.7 Camera Usage (QR Scanning)
The App uses your device camera exclusively to scan QR codes. Camera frames are processed entirely on your device using Google ML Kit's barcode scanning library. No camera images or video are stored on your device or transmitted to any server by the App.
3. How We Use Your Information
| Data | Purpose |
|---|---|
| Device ID (UUID) | Device authentication and HMAC-SHA256 request signing |
| Driver name & phone | Trip session identification and operational records |
| GPS location (every hour) | Real-time fleet tracking transmitted to your employer's management system |
| Battery level | Operational status monitoring by fleet management |
| Trip & QR data | Recording delivery workflow, audit trail, and trip verification |
| POD photos | Proof of delivery documentation uploaded to fleet management system |
We do not use your information for advertising, user profiling, marketing, or any purpose unrelated to fleet delivery operations.
4. Permissions Used
The following Android permissions are declared in the App. Each permission is used only for the purpose stated below.
| Permission | Reason |
|---|---|
| CAMERA | Scanning delivery QR codes on physical trip documents |
| INTERNET | Communicating with the fleet management server at systemapp.id |
| ACCESS_FINE_LOCATION | Collecting precise GPS coordinates during active delivery trips |
| ACCESS_COARSE_LOCATION | Fallback location accuracy when precise location is unavailable |
| FOREGROUND_SERVICE | Running the GPS location tracking service with a visible persistent notification |
| FOREGROUND_SERVICE_LOCATION | Declaring location as the foreground service type (required for Android 14+) |
| POST_NOTIFICATIONS | Displaying the mandatory persistent tracking notification (required Android 13+) |
| VIBRATE | Haptic feedback when a QR code is successfully scanned |
The App does not request access to your photo library, contacts, microphone, files, or any device data beyond the permissions listed above.
6. Data Storage and Retention
6.1 On-Device Storage
- Device ID (UUID): Retained permanently until the App is uninstalled
- Driver name and phone: Stored in device DataStore; persists across sessions until the App is uninstalled
- Active trip session data: Cleared automatically when a trip ends
- Local trip history: Retained on-device until manually cleared by the user or the App is uninstalled
- POD photos: Not stored on-device by the App beyond the upload session
6.2 Server-Side Storage
Data transmitted to the server (location pings, trip records, POD photos) is retained for as long as operationally required by your employer or logistics operator. For questions about specific server-side retention periods, please contact your employer or the system administrator of the fleet management system.
7. Data Security
All data transmitted between the App and the server at systemapp.id is encrypted in transit using HTTPS/TLS.
Device authentication uses HMAC-SHA256 request signing with the device's unique UUID and a timestamp included in every API request. This prevents unauthorized access and replay attacks.
Data stored locally on your device is protected by Android's application sandbox — other apps cannot access the App's stored data.
While we implement industry-standard security measures, no method of data transmission over the internet is 100% secure. We are committed to protecting your data and will notify affected parties in the event of a security breach as required by applicable law.
8. Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your data from our server
- Portability: Request your data in a portable format where technically feasible
To request data deletion or exercise any of your rights:
Email syukrisyahab@gmail.com with subject line "Data Request - Nexchain Driver App" and specify your request. We will respond within 30 days. Server-side data deletion will be completed within 30 days of a verified request.
On-device data: Uninstalling the App removes all locally stored data (Device ID, driver info, trip history) from your device immediately.
Data Deletion Request
Email: syukrisyahab@gmail.com
Subject: Data Deletion Request - Nexchain Driver App
Include your driver name and device identifier if known. Response within 30 days.
9. Children's Privacy
The App is intended solely for use by professional drivers in a commercial and occupational context. We do not knowingly collect personal information from anyone under the age of 13. If you believe a minor has used this App, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in the App's functionality, data practices, or applicable law. When material changes are made, we will update the "Last Updated" date at the top of this document.
Continued use of the App after changes take effect constitutes your acceptance of the updated policy. If you do not agree with changes, please discontinue use of the App.
11. Contact
For any questions, concerns, or data requests regarding this Privacy Policy:
SOSMED-ID
Smart Operational Systems & Management
Email: syukrisyahab@gmail.com
Website: https://sosmed-id.com
This policy is written to comply with Google Play Data Safety requirements (2026) and applicable privacy regulations.