Ops Platform

Privacy Policy

OpsStrike Store Ops · Effective 12 August 2026

What OpsStrike Store Ops is

OpsStrike Store Ops is an internal store-operations tool operated by the OpsStrike team for CP Axtra / Makro. It is used by store employees to carry out and track operational work (for example, aisle gap-scan tasks). Signing in requires a company account issued by your employer — the app is not intended for, and cannot be used by, the general public.

Data we collect

  • Work identity. When you sign in through the company single sign-on (SSO), we receive your name, work email address, employee identifiers, role, and store/branch assignment. There is no public consumer sign-up. During staff self-enrolment, an employee confirms their existing employment record with an employee ID and SMS code, then registers their face; this creates or activates their OpsStrike SSO account. We never see or store a staff member's SSO password — staff sign in with face login and are never asked to type a password into the app. The only account that signs in with a password is a temporary review-only account we issue to an app store's review team for a single submission and disable afterwards. It belongs to us, not to any employee: we file its password with the app store reviewing the submission, and the app keeps it on the reviewer's own device so their review is not cut short.
  • Face data, used to confirm who you are. Each time you try to sign in — and each time you clock in or out — the app photographs your face with the front camera and sends it to your employer's sign-in service to be matched against the face they enrolled for you. If the match does not succeed the app retries automatically without you tapping anything, so one sign-in can take several photographs. See Face login and face data below for exactly what is collected, who processes it, how long it is kept, and how to have it deleted.
  • Location, only when you clock in or out. When you record the start or end of a shift, the app reads your device's precise location and sends it with that clock action to confirm you are at the store. It also takes an approximate reading on the home screen, before you clock in, to work out which of your stores you are at — that one stays on your phone and is not sent. Location is never read in the background. See Location and clocking in below for exactly what is collected, what is kept, and who can see it.
  • Operational activity. Tasks assigned to you and the actions you take on them — completions, timestamps, and the aisle/bay they relate to — are recorded as part of the work itself. Clocking in and out is recorded the same way: which store, which action, and when.
  • Photos you capture in the app. Gap-scan tasks ask you to photograph store shelving with the camera. These photos are uploaded to company systems as operational records. Some shelf photos are also sent through OpenRouter to an upstream AI provider selected by OpenRouter for automated shelf analysis. The requested model is Claude, but the upstream provider is not pinned. This transfer is used only to operate the shelf-workflow feature, not for advertising. The app does not browse or upload your personal photo library.
  • Device and notification data. A push notification token, and basic device information (model, operating system version) used to deliver task notifications and diagnose problems.

How data is used

Data is used solely to operate the store-task workflows: assigning and tracking tasks, verifying task completion, sending notifications about work assigned to you, and troubleshooting the service. Access is limited to your employer's operations teams and the people who run the service.

Face login and face data

Signing in to OpsStrike uses face login, against the face your employer enrolled for you in their single sign-on. This section describes how that face data is collected, used, shared, retained and deleted. It is required reading before you sign in for the first time.

Where face capture happens

When you tap Sign in — or start a clock-in or clock-out — OpsStrike opens a camera screen inside the app and shows you a live view from the front camera. It takes a photograph when the screen has counted down in front of you, or when you tap the button. If the match does not succeed, the app tries again by itself — one photograph per attempt — so one visit to that screen can take several photographs without you tapping anything. Ordinarily it makes three such attempts, spaced a few seconds apart, and then stops and waits for you to press the button. There is one case where it keeps going: if your employer's sign-in service is busy, the app pauses for about a minute and then tries again on its own, and that can repeat while you stay on the screen. Leaving the screen always stops it. Nothing is captured before you reach that screen, backing out of it captures nothing, and the app does not open a browser to sign you in.

That photograph is sent directly to your employer's sign-in service, which compares it with the face your employer enrolled for you and returns only whether it matched. It is never added to your photo library, and the app does not keep it, queue it, or hold on to it once the request finishes. What the sign-in service keeps is described under “How long it is kept” below.

To be precise about the device itself: taking the photograph writes it briefly to a private temporary file in the app's own storage — this is how the phone's camera works and it is not visible to other apps or to your photo gallery. The app reads the image from there and then erases the file immediately, before sending the image. If the app is force-closed or the phone shuts down in the moment between those two steps, that temporary file can be left behind in the app's private storage until the operating system clears it; nothing reads it, and it is not visible to other apps. Apart from that, the only lasting copy is your enrolled face record held by the matching service described below.

Older versions of the app, still in use until everyone updates, instead opened your employer's SSO page (sso.cpaxtra.io) in a secure system browser view and captured your face there. Everything else in this section — what is collected, who it is shared with, how long it is kept, and how to withdraw consent — applies the same way to both.

What is collected, and why

A photograph of your face is captured when you enrol, again on each attempt to sign in, and again each time you clock in or out, so it can be compared with the face enrolled for you. It is used for one purpose only: to confirm that you are the employee the account belongs to — including confirming that the person recording the start or end of a shift is the person that shift belongs to. It is not used for monitoring your movements, profiling, advertising, or to train face-recognition models.

To be plain about what that means for your working hours: your clock-in and clock-out times are a record of attendance, and the app asks you for a face match before it records one. What is stored against your shift is the store, the action, the time and the location described below — not the photograph, and not the result of the match, neither of which is attached to the attendance record.

Who it is shared with

Face matching is performed by Tencent Cloud's face recognition service (IAI), hosted in the Bangkok, Thailand region. Your enrolled face record is stored in that service under an internal person identifier. Tencent Cloud processes this data only on our instructions, and is required to provide the same or equal protection for face data as described in this policy. Face data is not shared with any other third party, and is never sold or rented.

How long it is kept

  • Your enrolled face record is kept for as long as your account is active — that is, while you are employed and authorised to use OpsStrike.
  • Records of individual sign-in attempts — the account identifier, whether the match succeeded, a confidence score, the time and the IP address, but no face image — are automatically deleted after 90 days.

Deleting your face data and withdrawing consent

You can withdraw consent to face login at any time. Ask your store manager, or the OpsStrike support channel, to remove your face enrolment. Your account is deactivated and your enrolled face record is deleted from the face-recognition service; the sign-in attempt records described above are deleted along with it.

Please note: face login is currently the only way for staff to sign in to OpsStrike. Withdrawing consent therefore means you will no longer be able to use the app, and your store will record your work through another route.

Location and clocking in

OpsStrike records the start and end of your shift, and it uses your device's location to confirm that you are actually at the store when you do. This section describes exactly when location is read, what is sent, what is kept, and who can see it.

When location is read

Only for the purpose of clocking in and out, and only while the app is open in front of you. There are two moments, and no others:

  • On the home screen, while you are notclocked in, the app takes one approximate reading to work out which of your stores you are standing in, so it can offer you the right “clock in” button. This reading is used on your phone only and is not sent anywhere.
  • When you actually clock in or out, the app takes one precise reading, checks it against the store's location, and sends it with that clock action.

The app does notcollect location in the background, does not follow you between readings, and does not track your movements around the store or anywhere else. It holds no background-location permission on Android and asks only for “while using the app” access on iOS, so it is not technically able to read your location while it is closed. If you decline the permission, or your phone's location services are off, the app cannot clock you in — it collects nothing and records nothing instead.

What is collected, and why

With each clock-in and clock-out we store the latitude and longitude of the reading and its accuracy(how large an area the reading covers, in metres), attached to that clock event. If your phone is set to share only an approximate location — Android's “Approximate” option, or turning off Precise Location on iOS — the app records the less exact reading it is given instead, and the accuracy figure is what tells you which you got. The purpose is a single one: showing that a shift was started and ended at the store it was worked at. That is what makes the attendance record trustworthy to your store and to payroll, and it is why an out-of-area clock-in is refused rather than recorded.

One exception, and it is the only one: if you forget to clock out, the system closes the shift for you after 12 hours. That automatic clock-out involves no camera and no location — it records only that the shift was closed, and that the system rather than you closed it.

Nothing else is derived from it. It is not used for productivity monitoring, not compared between colleagues, not used to build a movement history, and never used for advertising or shared with advertisers.

Who can see it

The coordinates are kept as an audit record and are not shown on any screen. No manager screen, report or export in OpsStrike displays where you were: what your managers see is that you are clocked in, at which store, and since when. The coordinates themselves are reachable only by the small team who administer the service directly, and only for the purposes above — for example, investigating a disputed shift. They are stored on the same company-managed cloud infrastructure as the rest of the service and are not shared with any third party.

How long it is kept

The precise location recorded with a clock-in or clock-out is kept for 90 daysand then deleted. Your attendance record itself — that you clocked in at a store, and when — is kept for as long as employment records are kept under your employer's data-retention policy, because it is a record of your working hours. After 90 days that record no longer carries the coordinates.

Questions about your location data

Ask your store manager or the OpsStrike support channel, as for any other request under this policy. Because a location reading is the evidence that a shift was worked where it was recorded, it is kept for the 90 days above rather than removed on request; if you believe a clock-in was recorded incorrectly, raise it and it will be investigated.

What we do not do

  • No advertising, and no sale or rental of data to anyone.
  • No tracking across other apps or websites.
  • No collection of your location in the background, and no tracking of your movements. Location is only ever read for clocking in and out — once on the home screen to work out which store you are at, which stays on your phone, and once when you actually clock in or out, which is sent. See Location and clocking in.
  • No access to your contacts, messages, files, or personal photo library.

Storage, sharing, and retention

Data held by OpsStrike is stored on company-managed cloud infrastructure. Push notifications are delivered via Google Firebase Cloud Messaging, which processes the notification token for that purpose. When automated shelf analysis is enabled, shelf photos are also sent through OpenRouter to an upstream AI provider selected by OpenRouter. Those external recipients may process and retain copies under their own applicable retention terms; their copies are not stored on company-managed infrastructure and do not follow the company's retention schedule. Face data is handled separately and is described in Face login and face data above; clock-in/out location has its own retention period and is described in Location and clocking in. Data is otherwise retained for as long as it is needed for the operational and audit purposes above, in line with company data-retention policy, and employee identity data is governed by your employment relationship with CP Axtra / Makro.

App permissions

  • Camera — two things: to photograph your own face when you sign in, and to capture live aisle photos for gap-scan tasks. See Face login and face data for how the sign-in photograph is handled.
  • Location— to confirm you are at your store when you clock in or out. Requested as “while using the app” only; the app has no background-location access. See Location and clocking in.
  • Notifications — to alert you to tasks assigned to you.

Questions and requests

For questions about this policy, or to raise a request about your data, contact the OpsStrike team through your store manager or the internal OpsStrike support channel. You may use that same route to request deletion of your OpsStrike account and its associated data; the team will confirm the request and explain any employment records that must be retained under company policy or law.