Privacy Policy

How PVcase Recharge collects, uses and protects your personal data — and the rights you have over it.

Last updated: 28 July 2026

Who we are

PVcase Recharge (“the app”) is an internal companion app for PVcase employees attending company off-sites. It shows your agenda, your travel itinerary, lets you book sessions, and gives you a direct SOS line to the Workplace Experience (WX) team while you are travelling.

PVcase, UAB, Bokšto g. 6, Vilnius, Lithuania (company registration code 304839853, VAT LT100011803019), is the data controller for the personal data described here.

Contact for anything in this policy, including privacy requests: privacy@pvcase.com

PVcase has not designated a Data Protection Officer, and is not required to: we do not carry out large-scale monitoring or process special categories of data as a core activity. Nor do we need an EU representative under Article 27 — PVcase, UAB is established in the European Union. Privacy questions go directly to privacy@pvcase.com, which is monitored by the team that handles these requests.

Because PVcase is established in the EU and our users are EU-based employees, the GDPR applies to everything described below.

The short version

  • We collect what we need to run an off-site: who you are, your agenda and room bookings, your travel itinerary, and your device’s push token.
  • Your location is read only on the SOS screen, and only ever sent to us when you actually send an SOS. There is no background or continuous location tracking of any kind.
  • When you send an SOS, its contents — your name, work email, message and exact coordinates — are posted into a Slack channel that PVcase operates, so the on-call WX team sees it immediately.
  • We do not run advertising, analytics or tracking SDKs. We do not sell or share your data for marketing. Nothing you do in the app is used to build a profile of you, and nothing is shared with data brokers.

What we collect, and why

1 Your account and profile

Collected when: you sign in with your @pvcase.com Google account. Only accounts on PVcase’s Google Workspace domain can sign in.

Signing in sends a Google ID token to our server, which verifies it with Google and reads from it:

Data Source
Work email addressGoogle ID token
Full nameGoogle ID token
Profile picture URLGoogle ID token
Google account identifierGoogle ID token
Whether Google has verified the emailGoogle ID token

We store these against your Recharge account, together with:

  • the time of your last sign-in;
  • the IP address you last signed in from;
  • your role in the app (employee or admin) and whether your account is active.

We do not receive or store your Google password. The app never sees it — sign-in happens inside Google’s own screen.

Why: to authenticate you, restrict the app to PVcase staff, show your name and photo to colleagues in shared agendas, and support the WX team when something goes wrong. The IP address of the last sign-in is kept as a basic security record.

2 Your work profile from Google Workspace

If PVcase enables the Google Workspace directory sync, we read your profile from the company directory using a read-only connection and copy the following onto your Recharge account:

  • first and last name, profile photo
  • job title, department, team / sub-department
  • employee ID, legal entity, work country
  • your manager’s email address (and their name, if they also use Recharge)

We also keep a copy of the raw directory record returned by Google so the sync can be debugged and corrected without re-querying Google. That copy is stored on the server only and is never sent to the mobile app.

The connection is one-way: Recharge never writes anything back to your Google Workspace profile.

Why: so the WX team can organise an off-site by team, department and region (for example “who from Sales is travelling to Barcelona”), and so travel records can be matched to the right person.

As at the date at the top of this policy, this sync is switched off, so none of the fields above are being copied today. It is described here because the connection is built into the app and PVcase can enable it.

3 Your device, for push notifications

Collected when: you allow notifications.

We send the following to our server and store it against your account:

  • the Expo push token for that device (an address for delivering notifications, not an advertising identifier)
  • the platform (iOS or Android)
  • the device model name (e.g. “iPhone 15”)
  • the operating system version
  • the app version
  • the device’s language/locale setting

Why: so the WX team can send you session reminders, announcements, and — most importantly — replies to your SOS. The model, OS and app version tell us which build a notification failed on when delivery breaks.

Notifications are delivered through Expo’s push service, which passes them to Apple Push Notification service (iOS) or Firebase Cloud Messaging (Android). The content of the notification — for example, an SOS reply from the WX team — passes through those services.

If you uninstall the app or turn off notifications, the delivery service tells us the token is dead and we delete it automatically.

4 Your location — SOS only

This is the most sensitive thing the app touches, so we are specific about it.

  • The app asks for location permission when you open the SOS screen, and reads your position once at that moment, so that the coordinates are ready the instant you need them in an emergency.
  • Your coordinates are only transmitted to PVcase when you actually send an SOS. If you open the SOS screen and leave without sending anything, nothing about your location leaves your phone.
  • If you deny location permission, SOS still works — it is simply sent without coordinates, and the screen tells you so.
  • The app requests foreground location only. It cannot and does not read your location while it is in the background or closed. There is no location history, no geofencing, no continuous tracking.

When an SOS is sent, we store: latitude and longitude, your message, the time, who on the WX team picked it up, and the conversation that follows.

Why: so the WX on-call team can find you in an emergency in a city you may not know.

5 Your agenda and room bookings

When you book a spot in a session or a room, we store your account, the session and the room.

Please note: who has booked a session is visible to other attendees in the app. Colleagues browsing the agenda see the names and profile photos of people signed up for the same session. This is deliberate — it is how people decide what to join — but it means your session choices are not private from your colleagues.

6 Your travel itinerary

If PVcase books your travel through Navan, we pull your itinerary hourly and show it in the app:

  • traveller name, work email and employee ID as recorded by the travel provider
  • booking type (flight, hotel, shuttle, car, rail) and its status
  • a summary line — for example the route, airline and flight number, or the hotel name
  • origin, destination, start and end times
  • the booking reference / confirmation number

The full raw record from the travel provider is kept on our server for support and debugging. The mobile app only ever receives the summarised fields above.

Admins can also add or import an itinerary by hand for people whose travel was booked outside the provider.

Why: so you can see your own trip in one place, and so the WX team knows who is arriving when.

7 Notifications and messages you receive

Announcements, session reminders and SOS replies are stored with their content and whether you have read them, so your inbox works across devices.

8 Administrative activity log

Actions taken in the app — bookings, SOS alerts, and changes made by admins to users, events and content — are written to an audit log recording who did what, when, what changed, and the IP address the action came from.

Why: accountability and security. If someone’s account or itinerary is changed, we can see who changed it.

9 What is stored on your phone

  • Your access token, in the iOS Keychain / Android Keystore.
  • A copy of your own profile, and cached copies of the agenda, your inbox, help articles and emergency contacts, so the app works with no signal.
  • Your light/dark theme preference.

Signing out deletes the token and the cached profile from the device.

10 What we do not collect

  • No advertising identifiers (no IDFA, no Android Advertising ID).
  • No analytics or crash-reporting SDK, and no behavioural tracking.
  • No contacts, photos, camera, microphone, calendar, or health data.
  • No background location.
  • No payment or financial data.

Who we share it with

We do not sell your data and we do not share it for advertising. We share it only with the following, and only for the purposes described.

PVcase’s own Slack workspace — SOS content

When you send an SOS, the following is posted into #recharge-sos-message, a channel in PVcase’s own Slack workspace, so the on-call WX team is alerted immediately:

  • your full name and your work email address
  • your SOS message
  • your coordinates, as a clickable Google Maps link
  • a link to the alert in the admin panel

Every subsequent message in that SOS conversation — from you or from the WX team — is mirrored into the same Slack thread, so the whole exchange is visible there. Replies typed by the WX team in Slack are delivered back into your app, and we store the Slack display name of the person who replied.

This means: anyone with access to #recharge-sos-message can see your SOS, including where you were when you sent it. The channel is read by the Workplace Experience (WX) team, who staff the on-call rota.

The Slack thread lives in PVcase’s Slack workspace under Slack’s own retention settings, not Recharge’s. Deleting an SOS from Recharge does not remove the Slack copy — email privacy@pvcase.com if you need that done too.

Service providers

Provider What they receive Why
Google (Google Ireland / Google LLC) Sign-in verification; your directory profile when the Workspace sync is enabled Authentication and profile data
Slack (Salesforce) SOS content, as described above Emergency alerting to the WX team
Expo (Expo, Inc.) Push tokens and the content of notifications; the app also checks Expo’s servers for over-the-air updates when it launches Notification delivery and app updates
Apple (APNs) and Google (Firebase Cloud Messaging) Push token and notification content Delivering notifications to your device
Navan — we read from Navan, we do not send them your data Travel itineraries
Gravatar (Automattic) A one-way hash of your email address, when you have no Google profile photo and the app falls back to a default avatar Default avatar images
PVcase’s hosting provider — the server and database behind recharge-requests.pvcase.com Everything stored by the app, as the host of the server and database Hosting

Transfers outside the EEA

PVcase, UAB is established in Lithuania, and Recharge’s own server and database are run for us by our hosting provider under a written data processing agreement.

Four of the providers above are US-headquartered, so data reaching them may be processed outside the EEA: Google (sign-in, and the Workspace directory if that sync is enabled), Slack (SOS content), Expo together with Apple and Google (push tokens and notification content), and Automattic (the hashed-email avatar lookup). In each case the transfer safeguards are the ones set out in that provider’s data processing agreement with PVcase — in practice either an adequacy decision, such as the EU–US Data Privacy Framework, or the European Commission’s Standard Contractual Clauses.

We deliberately do not state which of those two applies to which provider here: it is a per-contract fact, and naming the wrong one would be worse than describing it accurately. If you need the specific mechanism for a particular provider — for a supplier review, a works council, or a data subject request — email privacy@pvcase.com and PVcase’s legal team will confirm it from the agreement itself.

Other people in the app

  • Colleagues see your name and profile photo next to sessions you have booked.
  • PVcase admins (the WX team) can see your profile, your travel itinerary, your bookings and your SOS history.

We may disclose data if we are legally required to, or to establish, exercise or defend legal claims.

How long we keep it

Recharge is an app for running an off-site, so almost nothing in it is worth keeping once the off-site is over. Operational records are deleted on a 60-day schedule by a job that runs daily, which is why the table says within 60 days rather than naming an exact hour.

Data How long we keep it
Account and profile Your account exists for as long as you use the app. It is removed when you delete it yourself in the app, or when PVcase IT removes it as part of offboarding. This one is not on a timer.
SOS alerts, including location and messages Deleted within 60 days of the alert being resolved
Bookings and agenda Deleted within 60 days of the event ending
Travel itineraries Deleted within 60 days of the trip ending
Device / push tokens Until you sign out, uninstall, or the token stops working — then deleted automatically
Notifications Deleted within 60 days
Audit log Deleted within 60 days

Two things sit outside this schedule. Deleting your account removes the data listed above straight away, without waiting for the 60 days. And the Slack copy of an SOS lives in PVcase’s Slack workspace under Slack’s own retention settings, which Recharge does not control.

Your rights

Under the GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected. Note that most profile fields come from PVcase’s HR and Google Workspace records, so corrections are usually made there and flow into Recharge on the next sync.
  • Erasure — ask us to delete your data, subject to any legal obligation to keep it.
  • Restriction — ask us to stop processing your data while a dispute is resolved.
  • Portability — receive the data you gave us in a machine-readable format.
  • Object — object to processing based on our legitimate interests, on grounds relating to your particular situation.

To exercise any of these, email privacy@pvcase.com. We will respond within one month.

You also have the right to complain to a data protection authority. PVcase, UAB is established in Lithuania, so our supervisory authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, Vilnius, Lithuania — vdai.lrv.lt. You can also complain to the authority in the EU country where you live or work.

Deleting your account

You can delete your Recharge account from inside the app: open the profile menu (tap your avatar in the top-right), choose Delete account, and confirm.

Deletion is immediate and permanent — there is no recovery window. It removes your Recharge profile, your session bookings, your travel itineraries, your SOS conversations, your notification inbox, your device/push registrations, and your sign-in sessions. Where a travel booking is shared with a colleague, your details are also stripped out of their copy of that booking.

Two things deliberately survive. Audit-log entries are kept but anonymised — the record that an action happened remains, with the identifying fields cleared. And if the travel sync runs again while a trip you were booked on is still active, that itinerary can reappear; contact us and we will remove it at source.

Full step-by-step instructions, including what to do if you no longer have the app installed, are on our account deletion page.

Deleting your Recharge account does not delete your PVcase Google Workspace account, your Slack account, or your travel bookings with the travel provider — those are separate company systems. It also does not remove messages already posted into the WX Slack channel by an SOS you sent; contact privacy@pvcase.com if you need those removed.

Signing out, by contrast, only removes the app’s data from your phone and leaves your account intact.

Security

  • All traffic between the app and our servers uses HTTPS.
  • Your access token is stored in the iOS Keychain / Android Keystore.
  • Sign-in is restricted to PVcase Google Workspace accounts. There is no password-based login for the mobile app.
  • Admin access to the panel is restricted by role and requires Google SSO.
  • Disabling an account immediately revokes its mobile access tokens.

Children

The app is for PVcase employees and is not directed at, or intended for use by, anyone under 16.

Changes to this policy

If we make a material change we will update the “last updated” date at the top and, where the change is significant, notify you in the app.

Contact

privacy@pvcase.com — privacy requests and anything in this policy.

support@pvcase.com — help with the app itself.

PVcase, UAB
Bokšto g. 6, Vilnius, Lithuania
Company registration code 304839853 · VAT LT100011803019