Vecto Solutions

Coming soon. “Evident” the way to work.

Last Updated: August 28, 2026

Effective Date: August 28, 2026

Privacy Policy for Evident

Last Updated: August 25, 2026 Effective: August 25, 2026

Evident is a workforce management application provided by Vecto Solutions, LLC ("Vecto Solutions," "we," "us," or "our"). This Privacy Policy explains what personal information Evident collects, why, who can see it, how long it is kept, and how you can have it deleted.

Looking for account deletion? Go directly to Deletion, Deprovisioning, and Partial Deletion, or use the public Account and Data Deletion Request page — no sign-in required.

Your use of Evident is also governed by our Terms of Service. Where those Terms describe the contractual relationship, this Policy describes the data practices; the two are intended to be read together and not to repeat each other.


1. Evident Is an Employer-Provided Application

This is the most important thing to understand about how your information is handled.

You have an Evident account because your employer or the organization you work with (your "Organization") has a services agreement with Vecto Solutions. Evident accounts are created, assigned, and administered by your Organization. Evident is not available for personal or consumer registration, and you cannot sign up for it yourself.

Because of that arrangement:

  • Your Organization is the owner and controller of your account record and of the work performed through Evident. It decides who gets an account, what that account can do, and when access ends.
  • Vecto Solutions acts in two roles. For the work records created through Evident, we act as a service provider (processor) on your Organization's behalf, handling that information on its instructions. For your account identity, platform security, and the operation of Evident itself, we act on our own behalf, which is why this Policy — and not only your Organization — sets retention periods and gives you rights you can exercise directly against us.
  • Some account lifecycle actions are governed by that agreement, including provisioning, deprovisioning, and the disposition of records when your Organization's contract ends, subject to the retention periods disclosed in Section 5.5 of this Policy.

This does not leave you without a route. You may request deletion of your own account and personal information directly from Vecto Solutions, and we will act on that request. We describe exactly how in Section 5. We will not ignore a request from you, and we do not require your Organization's approval to delete your identity data.

If you are unsure whether to contact us or your Organization: contact us for anything about the data Evident holds, and contact your Organization for anything about your job, your schedule, or your Organization's expectations for App use.


2. Information We Collect

2.1 Information Provided by Your Organization

When your Organization provisions your account, we receive and store:

  • Name — your given name and family name
  • Email address — used for account identity, sign-in, and account-related communication
  • Employment or assignment context — such as your team, work area, role, assigned operation or station, and any training or certification records your Organization tracks in Evident

2.2 Information Collected When You Sign In

Evident supports two sign-in methods. Which one you use depends on how your Organization configured its account.

Username and password

  • Your username or email address
  • Your password, which is stored only as a salted cryptographic hash. Your password is transmitted only over an encrypted connection, and we do not store it, or have any ability to recover it, in readable form.

Sign in with Google

If your Organization enables Sign in with Google, we request only non-sensitive identity scopes — openid, email, and profile. From those scopes we receive:

  • Your email address
  • Your display name (given name and family name)
  • Your Google account identifier (the sub claim), which we store to link your Google identity to your Evident account
  • Your Google profile picture URL

Evident does not request and does not receive access to Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google user data. The Google authentication scopes we use assert who you are and nothing more.

2.3 Information Collected Automatically From Your Device

When you use Evident on a mobile device, we collect:

  • Device identifiers — a unique installation or device identifier used to associate a session with a device
  • Push notification tokens — used to deliver work assignment and messaging notifications
  • Device and app diagnostics — operating system version, app version, and error or crash information
  • Session and access logs — sign-in and sign-out times, IP address, and records of activity within the App, used for security, auditing, and support

2.4 Location Information

Evident's core function requires location data. This section describes what we collect; Section 5 of the Terms of Service describes the consent and the employment context.

Background location. Evident collects precise (GPS-level) location while you are signed in, including while the App is running in the background. This is how the system determines your proximity to work assignments, routes assignments to the right person, and verifies that work was performed where it was recorded.

When collection happens. Location tracking is active only while you are signed in to Evident. It stops when you sign out or when you revoke location permission in your device settings.

Android foreground service. On Android, Evident uses a foreground service to maintain location tracking. You will see a persistent notification whenever location tracking is active, so it is always visible to you when your location is being collected.

Activity recognition. Evident uses your device's activity recognition capability (the ACTIVITY_RECOGNITION permission on Android) to detect whether you are stationary or moving, and to adjust how often it requests a location fix. This reduces battery consumption. Activity recognition data is used only to tune location polling and is not retained as a separate record of your movements.

Controls. You can stop location collection at any time by signing out of the App or by revoking location or activity recognition permission in your device settings. Doing so will prevent you from receiving work assignments and may affect your ability to perform your job as your Organization expects. Questions about your Organization's expectations should go to your Organization.

2.5 Work Content You Create in the App

  • Task and evidence records — the records you complete to show that an assignment was performed, including status entries, timestamps, reason codes, and any photos or files you capture in the App as proof of work.
  • In-app messages — the content of messages you send and receive through Evident's messaging feature, together with delivery and read receipts.

Work content is visible to your Organization through the platform.

2.6 Information We Do Not Collect

Evident does not collect your device's phone number, does not use advertising identifiers, does not serve advertising, and does not build advertising or marketing profiles. We do not collect biometric data, and we do not access your device's photo library, contacts, text messages, or call logs.


3. How We Use Your Information

We use the information described above to:

  • Create, administer, and secure your account
  • Route and assign work based on your real-time proximity to assignments
  • Record, verify, and report the work performed for your Organization
  • Deliver notifications and in-app messaging related to your work
  • Optimize location tracking to balance accuracy against battery consumption
  • Detect, investigate, and prevent fraud, misuse, and security incidents
  • Provide support to you and to your Organization
  • Maintain records that we or your Organization are required to keep
  • Meet our legal and regulatory obligations

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.


4. Who Can See Your Information

Your Organization. Work records, assignment history, hours and time active in the system, location data, task and evidence records, and in-app messages collected through Evident are visible to authorized administrators and supervisors at your Organization through the Evident platform. This is a core function of the App and the reason your Organization deployed it. Your Organization's own policies govern how it uses that information.

Our service providers. We use three vendors to run Evident: DigitalOcean provides the cloud hosting, database, storage, and backup infrastructure the Service runs on; Apple delivers push notifications to iOS devices through its Push Notification service; and Google delivers push notifications to Android devices through Firebase Cloud Messaging. Each processes data only on our instructions, only to provide its service to us, and is contractually bound to protect it and to delete it when we say so.

Our Subprocessor List gives the full detail — what each one processes, where, under what safeguards, and what deletion means at each. We give customer organizations at least 30 days' notice before adding or replacing a subprocessor.

Sign in with Google is not on that list, because Google is not acting on our behalf when you authenticate — you sign in with Google directly and Google returns the identity claims described in Section 2.2. Google appears on the subprocessor list for push notification delivery only.

Legal and safety. We may disclose information where we are required to do so by law, subpoena, or valid legal process, or where disclosure is necessary to protect the rights, property, or safety of Vecto Solutions, our customers, or the public.

Business transfers. If Vecto Solutions is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this Policy.

We do not sell, rent, or trade your personal information to third parties for their own purposes.


5. Deletion, Deprovisioning, and Partial Deletion

This section covers your right to have your account and personal information deleted, what we keep afterward, and why.

5.1 Three Different Things

Because Evident is an employer-provided application, three distinct things can happen to an account, and it matters which one you mean.

Who initiates What happens Reversible
Deprovisioning Your Organization Your access ends. Your account record and work history remain in the platform under your Organization's control. Yes — your Organization can restore access
Account deletion You, or your Organization on your behalf Your identity and personal profile are permanently erased. Retained business records are pseudonymized so they no longer identify you. No
Partial deletion You Specific categories of your personal data are erased while your account remains active. No

Deprovisioning is not deletion. When your employment or assignment ends, your Organization will normally deprovision your account. If you want your personal information deleted as well, submit a deletion request — it is a separate action and you can make it yourself.

5.2 How to Request Deletion

On the web (no sign-in required): Visit vecto-solutions.com/legal/delete-account. This page is publicly accessible, so you can use it even after you have uninstalled the App or lost access to your account.

In the App: Go to Settings → Account → Delete Account and follow the prompts.

By email: Write to [email protected] from the email address on your account. Tell us whether you want your entire account deleted or only specific data (partial deletion), and identify the Organization you worked with.

5.3 Verification

Before we delete anything, we verify that the request came from you. We do this by sending a confirmation link to the email address on the account.

If the address on your account is one your Organization controls, or you no longer have access to it, tell us that in your request and give us a personal email address instead. We will verify you another way — by confirming account details only you would know, or by contacting you at a phone number on the account — and send the confirmation link to the address you gave us. We will not route your verification through your Organization.

You do not need to sign in to submit a request. Verification applies to the request, not to reaching the page.

5.4 What Happens, and When

  1. Within 2 business days of receiving your request, we acknowledge it and send you the verification link described above.
  2. On verification, we immediately terminate your active sessions, revoke any OAuth grant you gave through Sign in with Google, and end your access. Your account cannot be used from that point forward.
  3. Within 30 days, we complete the purge and pseudonymization described in the table below across our production systems, and we instruct our service providers to do the same in theirs. Section 6 of the Subprocessor List sets out what deletion means at each one.
  4. We confirm to you by email when the deletion is complete.
  5. We notify your Organization's administrator that the account was deleted at your request. We do this because your Organization needs to know its roster changed — but your Organization's approval is not required, and it cannot veto your request.
  6. Backups containing your data are overwritten on our normal backup rotation. We do not restore deleted data from backup except where a restore is necessary to recover from a system failure; our restore procedure requires that completed deletions be re-executed after any such restore.

We complete deletions within 30 days. Where a law that applies to you sets a shorter deadline, we meet that deadline instead. Our 30-day commitment is at or inside the response periods set by the GDPR (one month) and the CCPA/CPRA (45 days).

5.5 What Is Deleted and What Is Retained

Every category of data Evident collects resolves to an outcome below.

Data category Outcome on deletion Basis for any retention Period
Password hash Deleted — Immediate
Google OAuth grant and refresh tokens Revoked and deleted — Immediate
Google account identifier (the sub claim) Deleted — Immediate
Active sessions Terminated — Immediate
Device identifiers and push notification tokens Deleted — Immediate
Name, email address, profile photo, contact details Deleted — Within 30 days
App preferences and settings Deleted — Within 30 days
Diagnostic and crash data Deleted or dissociated — Within 30 days
Activity recognition signals Not retained — used only in the moment to tune location polling — Not stored
Training and certification records held in Evident Retained, pseudonymized Regulatory and customer qualification recordkeeping 4 years from the date of the record
Work and assignment records, time active in the system, task and evidence records Retained, pseudonymized Regulatory recordkeeping; obligation to the Organization under its services agreement 4 years from the date of the record
Location history, including points collected while signed in that are not tied to a specific assignment Retained, pseudonymized Verification of work performed; regulatory recordkeeping 4 years from the date of the record
In-app messages you sent or received Retained, pseudonymized Operational and incident recordkeeping 4 years from the date of the message
Billing and financial records Retained, pseudonymized Statutory financial and tax recordkeeping 4 years
Security, access, and audit logs Retained, pseudonymized Security and fraud prevention 1 years
Records subject to a legal hold Retained in original form, including identifiers Litigation hold or legal obligation — a hold requires that evidence not be altered Duration of the hold, then pseudonymized or purged
Backup and disaster-recovery snapshots Purged on rotation Operational integrity 35 days

Retention periods for records that are not deleted early run from the date of the record, not from the date of your deletion request. A work record created three years before your request is purged one year after it.

5.6 Why Some Records Are Kept, and How They Stop Being About You

Vecto Solutions and your Organization are required to be able to show what work was performed, by an authorized worker, at a given place and time. Those records support wage-and-hour compliance, customer service-level obligations, safety and incident investigation, and financial audit. Erasing them entirely on request would defeat obligations that exist independently of your account.

So we separate the record from the person. When we execute a deletion:

  • Your identity record — name, email address, profile photo, contact details, credentials — is erased.
  • In every retained business record, the reference to you is replaced with a non-reversible surrogate identifier. The record still says that a qualified worker completed a task at a time and place; it no longer says who.
  • Direct identifiers are stripped from the retained rows themselves, not merely hidden from view.
  • We do not keep a mapping table that would let us re-link the surrogate identifier back to you.

One exception: records under an active legal hold are preserved in their original form, including identifiers, because a hold requires that evidence not be altered. They are pseudonymized or purged when the hold lifts.

This is what reconciles "your account has been deleted" with "there is still a record that the work happened."

5.7 Deletion Is Permanent

Account deletion under this section is permanent and irreversible. It is not a deactivation, a suspension, a freeze, or an archive. Once the purge completes, we cannot restore your account, your profile, or your access, and you cannot recover them by signing in again. If your Organization gives you a new Evident account later, it will be a new account with no connection to the deleted one.

There is no cooling-off period during which the deletion can be reversed. Your access ends when we verify the request.

5.8 Partial Deletion

You can ask us to delete specific categories of your personal data without deleting your account. Submit a partial deletion request through the same channels in Section 5.2 and tell us what you want removed.

We will honor a request covering any of the following:

  • Your profile photo
  • Diagnostic and crash data
  • Device identifiers and push notification tokens for a device you no longer use
  • Location points collected while you were signed in that are not tied to a work assignment
  • Any work, location, or message record that has already passed the retention period in the table above but has not yet been purged on our regular schedule

We cannot delete a record that is still inside its retention period in the table above, or that is subject to a legal hold. If we cannot delete something you asked about, we will tell you which category it falls into, why, and the date it will be purged.


6. Retention While Your Account Is Active

The "Period" column in Section 5.5 describes two different things, depending on the row. For the rows marked Deleted, it is how quickly we act once you request deletion. For the rows marked Retained, it is how long the record lives regardless of any request.

While your account is active, we keep your profile, credentials, and settings for as long as your Organization maintains the account. The records in the Retained rows of Section 5.5 are purged at the end of the periods stated there, measured from the date of each record, whether or not you have ever made a deletion request.


7. Your Other Rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you and receive a copy of it
  • Correct inaccurate personal information
  • Delete your personal information, as described in Section 5
  • Restrict or object to certain processing
  • Data portability — receive your information in a portable format
  • Withdraw consent where processing is based on consent
  • Not be discriminated against for exercising these rights

To exercise any of these, contact [email protected]. We respond within 30 days, or sooner where the law requires.

Because your Organization controls the work records associated with your account, some requests — particularly access to or correction of work records — may need to be coordinated with your Organization, and we will tell you when that is the case and help route the request. Requests to delete your identity data do not require that coordination.

If you are in the EEA or the UK and believe we have not handled your request properly, you have the right to complain to your national data protection authority.


8. Data Security

We maintain a written information security program aligned with SOC 2 Type II trust services criteria. It includes encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent), salted password hashing, role-based access controls with unique user identification and multi-factor authentication for administrative access, personnel security measures including confidentiality obligations and security awareness training, hosting in a data center that maintains SOC 2 Type II attestation, and vulnerability management with periodic penetration testing. Location data is transmitted over encrypted connections.

No method of transmission or storage is completely secure, and we do not claim otherwise. If a breach affects your personal information, we will notify you and the relevant authorities as required by applicable law.


9. Children's Privacy

Evident is a workplace application and is not directed to children. Accounts are issued only to individuals aged 13 or older who have been provisioned by an Organization. We do not knowingly collect personal information from anyone under 13. If we learn that we have, we will delete it promptly.


10. International Data Transfers

Vecto Solutions operates in the United States, and information collected through Evident is stored and processed in the United States. If you access Evident from outside the United States, you understand that your information will be transferred to and processed there, where data protection laws may differ from those in your country. Where a transfer mechanism is required by law, we rely on the appropriate safeguards under our agreement with your Organization.


11. Changes to This Policy

We may update this Policy. When we do, we post the updated version at this URL and revise the "Last Updated" date. Where a change is material — in particular any change that expands what we collect, or lengthens a retention period in Section 5.5 — we will provide notice through the App or through your Organization before the change takes effect.

The version of this Policy in effect at the time governs; we keep prior versions available on request.


12. Contact Us

Privacy requests, deletion requests, and data rights: [email protected]

General questions about this Policy: [email protected]

Vecto Solutions, LLC Columbia, South Carolina, United States

Canonical URLs. These are the addresses to use in the Google Play listing, the Google OAuth consent screen, the in-app login screen, and the Play Console Data safety and deletion fields. They must match exactly in all four places.

Purpose URL
Privacy Policy https://vecto-solutions.com/legal/privacy-policy/
Deletion section (anchor) https://vecto-solutions.com/legal/privacy-policy/#account-deletion
Account deletion request page https://vecto-solutions.com/legal/delete-account/
Partial ("some data") deletion request https://vecto-solutions.com/legal/delete-account/#partial
Terms of Service https://vecto-solutions.com/legal/terms-of-service/
Subprocessor List https://vecto-solutions.com/legal/subprocessors/

Questions about your Organization's use of Evident, your work assignments, or your employment should be directed to your Organization.


By using Evident, you acknowledge that you have read and understood this Privacy Policy. If you are an employee user, you understand and consent to continuous location tracking while signed in, as a condition of using this employer-provided application.

Questions About This Document?

If you have questions or concerns, please contact us:

[email protected]