1. Who we are
PicAnchor ("PicAnchor", "we", "us") is a field-documentation application and web dashboard that lets organisations capture photos stamped with a verified time and location, and manage those photos across a team. This policy is published by Baturlabs Ltd, a company registered in England and Wales ("the Operator"), contactable at admin@baturlabs.com.
This policy applies to the PicAnchor mobile app, the PicAnchor web dashboard, and the picanchor.com website (together, the "Service").
2. The data we collect
We collect only what the Service needs to function. What is collected depends on how you use it.
| Category | What it includes | When |
|---|---|---|
| Admin account | Email address and password (stored encrypted), company name you enter. | When an admin signs up for the dashboard. |
| Worker identity | The display name your admin registers for you and a join code. Workers do not provide an email or password; sign-in is anonymous and linked only to a worker entry your admin created. | When a worker joins a company by name + code. |
| Photos & their stamp | The photos you capture, and the information stamped on them: date and time, GPS coordinates, a reverse-geocoded address, and any note you type. | Each time a photo is captured and synced. |
| Location | Device GPS location, used to stamp photos and detect falsified ("mock") location. Location is used at the moment of capture; we do not continuously track device location in the background. | While capturing a photo, with your permission. |
| Technical data | Basic app information needed to operate and secure the Service (e.g. app version and sync status). We use no analytics or crash-reporting services and collect no hardware identifier — no IMEI and no advertising ID; a worker's device is linked to their account only by a random, app-generated identifier that keeps one worker account bound to one device. | During normal use. |
The PicAnchor app works locally without an account. If you never sign in as an admin and never join a company as a worker, photos stay on your device and are not sent to our servers.
3. Who controls your data (controller and processor)
This is important for understanding your rights.
- When a business uses PicAnchor to document its team — the photos, worker names, and related records belong to and are controlled by that business (the admin's company). That business is the data controller. PicAnchor acts as a data processor, storing and processing the data on the business's behalf and under its instructions. If you are a worker, requests about your data (access, correction, deletion) are normally directed to your employer/the company that registered you, who decides how that data is used and retained.
- For your PicAnchor account itself — such as an admin's email used to sign in, and the website — the Operator is the data controller.
4. How we use data
- To provide the core function: stamping photos with verified time and location, and proving they have not been altered.
- To sync photos to a company's private storage and show them in that company's dashboard.
- To let admins manage workers, generate reports (PDF "laporan"), and apply a consistent stamp across a team.
- To operate, secure, and improve the Service, and to provide support.
- To process payments for paid plans (see Section 6).
We do not sell personal data. We do not use your photos or location to build advertising profiles, and the Service does not display third-party advertising.
5. Legal basis and consent
We process personal data where you (or the business you work for) have given consent, where it is necessary to provide a service you have requested, and where we have a legitimate interest in operating and securing the Service. For workers, the lawful basis for processing field documentation generally rests with the employing company that registers you and instructs the documentation. Because the Operator is established in the United Kingdom and our users are primarily in Indonesia, we handle personal data consistent with both the UK General Data Protection Regulation (UK GDPR) and Indonesia's Personal Data Protection Law (Undang-Undang Pelindungan Data Pribadi, UU PDP).
6. Sharing and third-party services
We share data only with service providers that help us run the Service, and only as needed:
- Cloud hosting and database — photos and records are stored with Supabase, our hosting and database provider, on our behalf, in private, access-controlled storage. Supabase runs on Amazon Web Services infrastructure in Tokyo, Japan (AWS
ap-northeast-1). Each company's data is isolated from every other company's data. - App distribution and payments — paid individual plans are processed through the Google Play billing system; we do not receive or store your card details. Fleet plans are billed directly by invoice.
- Maps / reverse geocoding — GPS coordinates may be sent to a mapping service to produce a human-readable address for the stamp.
- Legal — we may disclose data where required by law or to protect rights and safety.
7. Storage, location, and retention
Synced photos and records are stored in private cloud storage provided by Supabase, hosted in Tokyo, Japan (AWS ap-northeast-1). Supabase provides that storage on Amazon Web Services infrastructure, which acts as our sub-processor. Data is retained according to your plan: photos synced by a free-plan company are kept for 30 days, and photos synced by a paid-plan company for 365 days, after which they are automatically deleted from storage. A free-plan company may store up to 100 synced photos at a time; once that limit is reached, further photos remain on the worker's device and are not uploaded until space is freed or the plan is upgraded. Businesses that control their data may also delete workers and photos at any time from the dashboard. Photos that are deleted are removed from storage; photos kept after a worker is removed retain only the worker's name as recorded at the time of capture, so the documentation remains intact.
8. Security
We protect data with measures including isolated per-company access controls (so one company cannot see another's data), private storage that is not publicly accessible, encrypted transmission, and tamper-resistance features built into the stamp (network-derived time, mock-location detection, and a digital fingerprint on each photo). No system is perfectly secure, but we work to protect your data in line with industry practice.
9. Your rights
Subject to applicable law, you may request to access, correct, or delete your personal data, and to object to or restrict certain processing. Because much of the data is controlled by the business that uses PicAnchor (see Section 3), workers should usually direct these requests to their employer/the company that registered them. For data the Operator controls, or if you are unsure who to contact, write to admin@baturlabs.com and we will help route your request.
10. Children
PicAnchor is a tool for workplaces and is not directed to children. We do not knowingly collect personal data from anyone under the age of majority in their jurisdiction. If you believe a minor has provided data, contact us and we will remove it.
11. Changes to this policy
We may update this policy as the Service evolves or as the law requires. We will revise the "Last updated" date above and, for significant changes, provide a more prominent notice.
12. Contact
Questions about this policy or your data: admin@baturlabs.com.
Operator: Baturlabs Ltd, a company registered in England and Wales, registered address Unit 20 Yarrow Business Centre, Chorley PR6 0LP, United Kingdom.