Skip to content

Acceptable use policy

LinkSync exists to prove that real people really visited. Everything in this policy protects that: the people at the places visited, the honest staff who visit them, and the organisations that rely on the evidence.

Drafted for review by a solicitor; not yet in force.

Last updated [date]

In short

  • Only record visits that really happened, on your own phone, at the real GeoSync.
  • Never share your account or phone for LinkSync, and never clock in for someone else.
  • Leave GeoSyncs where they are fitted. Report any that are damaged, missing or moved.
  • Look at personal information only when your work needs it, and use it only for its purpose.
  • Don’t try to break into, overload, copy or get round LinkSync. If you find a security problem, tell us.
  • If someone breaks these rules, we act proportionately, tell them why where we can, and let them ask us to look again.

1. Who this applies to

This policy applies to everyone who uses LinkSync: every organisation that subscribes (“customers”), and every person they give access to, including workers, managers, administrators, staff who fit GeoSyncs, and guests such as commissioners or auditors. It forms part of our Customer Agreement and our Terms of use.

Customers are responsible for making sure their users follow it. The examples below are not a complete list. Use common sense: if something would undermine trust in the evidence, or harm someone, don’t do it.

2. Keeping evidence honest

You must not:

  • record, or try to record, a visit that didn’t happen, or that didn’t start or end when recorded;
  • clock in or out for anyone else, or let or ask anyone to clock in or out for you;
  • fake, alter or hide your phone’s location, for example with location-faking apps, developer settings, emulators or modified phones;
  • pretend to be a GeoSync, copy one, or relay one from somewhere else so that a tap appears to happen where it didn’t;
  • try to get round the face check, for example with a photo, video, mask, or someone else’s face, or by tampering with the camera;
  • modify, intercept, replay or forge anything the app sends to us;
  • try to change, delete or hide a visit record, check result or audit entry;
  • pressure, encourage or reward anyone to do any of the above.

3. Accounts and phones

You must not:

  • share your account, your sign-in codes, or your registered phone for LinkSync, or unlock it for someone else to use LinkSync;
  • register anyone else’s face or fingerprint on the phone you use for LinkSync;
  • use LinkSync on a phone that has been jailbroken, rooted or modified to remove its built-in protections;
  • create, or try to create, more than one account or register more than one phone;
  • use another person’s account, or access LinkSync after your access has been removed;
  • approve, or try to approve, anything about yourself, such as your own phone change or the review of your own visit;
  • give anyone more access than their job needs, or keep access for people who have left.

4. GeoSyncs

You must not:

  • move, remove, cover, open, damage, copy or tamper with a GeoSync, or fit one somewhere other than where it was approved;
  • fit a GeoSync at a place where people live without the recorded agreement of the people who live at or occupy it, or a lawful decision made for them;
  • fit a GeoSync at an address you live at or are connected to;
  • reuse a GeoSync that has been decommissioned, or use one supplied to a different organisation;
  • photograph people, private documents or anything other than the GeoSync and its position when the app asks for photos.

Report a damaged, missing or moved GeoSync to your manager the same day. Damage caused by someone at the place visited is not your misconduct, and your organisation can record it as such.

5. Respecting people and their information

You must not:

  • look at, copy or share personal information in LinkSync unless your work needs it;
  • use LinkSync, or anything you see in it, to monitor, track, harass, stalk, intimidate or discriminate against anyone;
  • use a worker’s location route for anything other than the purposes your organisation has told its staff about;
  • treat a flagged visit as proof of wrongdoing, or take action about someone’s pay or conduct based on an automated result alone;
  • use LinkSync data to rank or score workers’ performance in ways your organisation has not told them about;
  • export or download personal information to personal accounts or devices, or keep it longer than needed;
  • use face check images or results for anything other than confirming someone’s identity at a visit;
  • use LinkSync to collect information about people who are not part of your organisation’s work.

6. What you put into LinkSync

LinkSync is a proof-of-presence clock, not a record of the work you do. You must not put into LinkSync:

  • notes about the people you visit, clinical or medication information, details of concerns about someone’s welfare or safety, or other special category information, except in fields designed for it;
  • information you have no right to use, or that is inaccurate, misleading or out of date when you add it;
  • anything unlawful, defamatory, discriminatory, threatening or obscene, including in names, labels or custom fields;
  • malicious code, or files or links intended to cause harm.

7. Security and the service

You must not:

  • access, or try to access, any part of LinkSync, any account or any information you are not authorised to;
  • probe, scan or test the security of LinkSync, except in line with our responsible disclosure rules;
  • interfere with or disrupt LinkSync, or place an unreasonable load on it, for example by flooding it with requests;
  • use automated tools to access LinkSync, except through our published API within its limits;
  • copy, take apart, decompile or reverse-engineer the app, the web admin or a GeoSync, except where the law allows it despite this policy;
  • remove or get round any security, usage limit or access control;
  • use LinkSync to build a competing product, or to benchmark it for publication without our agreement;
  • resell, rent or provide LinkSync to anyone who is not part of your organisation’s work.

8. Integrations and the API

  • [Planned: keep the keys and secrets you use to connect your own systems confidential, store them securely, and replace them straight away if you think they have been exposed.]
  • Only connect systems you are entitled to send the information to, and make sure they protect it properly.
  • Stay within the rate limits and usage rules in our Documentation.
  • Don’t use the API to get information you couldn’t see in the web admin with the same role.

9. The law

You must not use LinkSync to break the law, including data protection, employment, equality, computer misuse and fraud law, or to help anyone else break it.

10. Reporting a problem

Never delay emergency help, or reporting a concern about someone’s welfare or safety, to deal with LinkSync. People’s safety comes first.

11. What happens if rules are broken

Customers deal with their own users under their own policies. Breaking this policy may be treated by your organisation as misconduct, including gross misconduct.

We may also act ourselves where we reasonably believe this policy has been broken. Depending on how serious it is, we may:

  • contact the customer and ask them to deal with it;
  • block a registered phone, or suspend a user’s access;
  • deactivate a GeoSync;
  • suspend or restrict a customer’s access, as set out in the Customer Agreement;
  • report suspected crime to the police or other authorities, where the law allows or requires it.

We act proportionately and keep evidence of what we do and why. Where it is safe and lawful, we will tell the person and their organisation why we acted, and they can ask us to look again by emailing hello@linksync.co.uk. Evidence of an attempt to fake a visit stays in the organisation’s visit records and audit trail, because evidence can’t be altered.

12. Changes to this policy

We may update this policy, for example to deal with new kinds of misuse. The date at the top shows the latest version. We will tell customers about significant changes in advance, as the Customer Agreement sets out.