Legal
PMG app privacy.
Last updated September 2, 2026. This covers the PMG mobile app and the portal it displays, including the camera, photographs, notifications and biometric unlock.
Who this covers
This policy applies to the PMG mobile app for Android (package com.thisispmg.portal) and to portal.thisispmg.com, which the app displays.
The app is an internal business tool for Performance Marketing Group personnel and contracted sales representatives. It is not a consumer product, accounts are created by PMG rather than by self sign-up, and there is nothing in it to browse without an account.
What the app collects
Account information held for each person with a login: name, email address, phone number, role, job title, location and time zone, and optionally a short bio, areas of expertise, postal address, territory, links to professional profiles, a profile photograph and a start date.
Work you record in the app: the companies and contacts you add, opportunities and their stages, tasks, notes, invoices and payments, and commission records. This is business information about PMG clients and prospects, entered by you.
Photographs you choose to take or select. The app opens the camera only when you tap a capture button, and the photo library only when you tap to pick an existing image. It does not access either in the background.
A push notification token issued by Google Firebase Cloud Messaging, together with the platform name and app version. The token identifies the installation so a notification can reach it. It is not an advertising identifier and cannot be used to track you across other apps.
A session cookie that keeps you signed in, and standard server logs kept by our host for security and reliability.
What the app does not collect
No payment card numbers, bank account numbers or other payment credentials. The portal is deliberately built without anywhere to type them, and you should not enter them into it.
No advertising identifier, no advertising or analytics SDK, and no tracking across other apps or websites. Google Analytics is switched off on our Firebase project, which is used only to deliver notifications.
No location data. The app does not request location permission and cannot read your position.
No contacts, calendar, microphone, or files beyond the single image you explicitly choose.
Biometric unlock
If you switch on biometric unlock, your fingerprint or face is checked by Android itself. Your biometric data never reaches the app, never leaves your phone, and is never transmitted to us or stored on our servers. The app receives only a yes or no answer.
The setting is stored on that handset alone and is not synchronised to your account, so turning it on for one phone does not arm it on another.
Biometric unlock is a lock over a session you are already signed in to. It is not a substitute for signing out on a device you do not control.
Photographs, and what happens offline
A photograph you take is first saved into the private storage of the app on your phone, then uploaded when there is a connection. This is what allows the app to be used somewhere with no signal. Once a photo has uploaded successfully, the copy on the phone is deleted.
Uploaded photographs are held in a private store. They have no public web address: each time one is displayed, our server checks that the person asking is allowed to see that client before releasing the image.
Photographs are business records of client sites and work performed. Do not use the app to photograph people who have not agreed to it, identity documents, or anything you would not put in a client file.
Device permissions, and why each is asked for
Camera — to take a photograph when you tap the capture button.
Photos and media — to let you choose an image you have already taken.
Notifications — to deliver alerts about your work. Android asks separately, and declining does not affect anything else in the app.
Biometrics — to offer fingerprint or face unlock, if you switch it on.
Internet and network state — to load the portal, and to tell being offline apart from the server being unavailable.
Who processes it
Vercel hosts the portal and stores uploaded photographs, on servers in the United States.
Neon provides the PostgreSQL database holding accounts and business records, on servers in the United States.
Google Firebase Cloud Messaging delivers push notifications. It receives the notification and the device token needed to route it, and nothing else.
An email provider sends transactional messages such as notifications and invitations.
Each acts as a service provider to PMG and may use the information only to provide that service. We do not sell your information, rent it, trade it, or share it with advertising platforms.
How long it is kept
Account information is kept while your account is active, and afterwards for as long as our tax and legal obligations require.
Business records, including photographs attached to a client, are kept for the life of the engagement and the retention period that follows it.
Push tokens are removed when you sign out, when the app is uninstalled, or automatically once Firebase reports a token is no longer valid.
Deleting your data
You can ask us what information we hold about you, ask us to correct it, or ask us to delete your account and the personal information attached to it. Call (901) 316-7283 or use the contact form at thisispmg.com/contact, and we will action the request.
Business records that PMG is required to retain, such as invoices and commission records, are kept where the law requires it even after an account is closed. We will tell you if that applies to your request.
Uninstalling the app removes anything held on the phone, including any photographs still waiting to upload. It does not delete your account.
Security
Traffic between the app and our servers is encrypted with HTTPS. Passwords are stored only as salted scrypt hashes and cannot be read back by anyone, including us. Changing a password signs out every existing session.
Access follows role: a sales representative sees their own clients and records, not the whole company.
No system is completely secure. If a breach affects your personal information we will tell you, and the relevant authorities, as the law requires.
Children
The app is a workplace tool for adults employed or contracted by PMG. It is not directed at children and we do not knowingly collect information from anyone under 13.
Changes to this policy
Changes are posted on this page and the date at the top is updated. Material changes will be described plainly rather than slipped in, and where a change affects what the app collects it will be made here before that change ships.
Questions, or a data request
Call (901) 316-7283, or send us a message. For the website rather than the app, see our site privacy policy.
