HelperPay
返回 · Back

私隱政策

生效日期:2026年9月8日 · 最後更新:2026年9月21日

HelperPay 是香港外籍家庭傭工 ID 407 薪酬及假期的本機參考記錄工具。本政策適用於 HelperPay 網頁、iOS 及 Android 版本。

請假記錄可包含類型(例如病假)、日期及時間,與薪酬資料一同存於本機,並會包含在你匯出或分享的薪酬備份內。請避免在備註填寫診斷或敏感醫療資料,並妥善保管匯出檔案。這些請假資料不會傳送給訂閱服務供應商。

儲存在裝置上的資料

外傭及僱主姓名、合約條款、薪金、日曆、備註、付款、確認記錄及設定均只儲存在你的裝置。付款截圖亦只保存在本機資料庫。HelperPay 沒有帳戶伺服器,開發者不能查看或復原這些資料。

每位外傭的「開始追蹤日期」是本機顯示選項,會隨薪酬備份保存,用於分開現在及歷史待辦;不會改動合約或付款,亦不會上傳。

合約日期及假日條款的更正會保留更改前後資料、原因及時間,並隨薪酬備份保存;此更正歷史不包含PIN。外傭核對收款時的語言及未提交姓名/PIN只在開啟的表格記憶體內使用,不會另存為語言偏好或傳送;實際確認後的姓名及時間仍屬收款記錄。

使用統計及技術診斷

iOS 及 Android App 的 Firebase Analytics 及 Crashlytics 預設啟用,用於了解 App 使用情況、改善功能及診斷故障。Google Firebase 會處理隨機產生的 App 安裝識別碼、App/裝置/作業系統資料、App 生命週期及一般功能事件、購買/訂閱事件、由遮蔽 IP 位址推算的大概位置,以及崩潰及其他技術診斷資料。資料可能在香港以外處理,並依 Google 的服務設定及法定要求保留。

手機 App 不會向 Firebase 傳送工人姐姐或僱主姓名、薪金、日曆日期、備註、付款內容、PIN、文件或截圖,也不收集廣告識別碼、不設定 Firebase 使用者 ID/使用者屬性,亦不作跨 App 或網站追蹤。你可在「設定 → 私隱控制」關閉往後的使用及崩潰報告。網頁版另用 GoatCounter;網頁統計維持預設關閉,只有主動啟用後才會傳送粗略事件。

分享、備份及外部連結

你的控制

你可以在設定中關閉手機 App 的使用及崩潰報告或網頁版的匿名統計、匯出完整備份,或選擇「清除所有資料」。關閉手機報告會重設裝置上的 Analytics 識別資料並刪除尚未送出的崩潰報告;已傳送的資料仍按 Google 的保留及刪除安排處理。清除所有資料會從目前裝置永久刪除所有 HelperPay 本機記錄及截圖;除非你另有備份,否則不能復原。移除 App 或清除網站資料也會刪除本機記錄。

保安及保留期限

資料會保留在裝置上,直至你刪除。可選 PIN 是應用程式內的共用裝置控制,並非裝置級加密。請使用裝置密碼保護手機,並妥善保管備份。

聯絡

私隱查詢:[email protected]

Privacy Policy

Effective: 8 September 2026 · Last updated: 21 September 2026

HelperPay is an on-device reference and record-keeping tool for Hong Kong ID 407 foreign-domestic-helper pay and leave. This policy covers the HelperPay web, iOS and Android apps.

Leave entries may include a category (such as sick leave), date and duration. They stay with your local payroll records and are included when you export or share a payroll backup. Avoid entering diagnoses or sensitive medical details in notes, and protect exported files. These leave details are not sent to the subscription provider.

Data stored on your device

Helper and employer names, contract terms, wages, calendar entries, notes, payments, approvals and settings stay on your device. Payment screenshots stay in the app’s local database. HelperPay has no account server, so the developer cannot view or recover this data.

Each helper’s tracking start date is a local display preference included in payroll backups. It separates current tasks from earlier history, does not change the contract or payments, and is not uploaded.

Corrections to contract dates and holiday terms retain before/after values, reasons and times in payroll backups; this correction history contains no PINs. During helper receipt review, the selected language and unsubmitted name/PIN are used only in the open form's memory, not saved as language preferences or transmitted. The name and time of a submitted acknowledgement remain part of the receipt record.

Usage statistics and technical diagnostics

Firebase Analytics and Crashlytics are enabled by default in the iOS and Android apps to understand app usage, improve features and diagnose faults. Google Firebase processes a randomly generated app-installation identifier, app/device/OS information, app lifecycle and general feature events, purchase/subscription events, approximate location derived from a masked IP address, and crash and other technical diagnostic information. Data may be processed outside Hong Kong and retained according to Google's service settings and legal requirements.

The mobile apps do not send helper or employer names, wages, calendar dates, notes, payment content, PINs, documents or screenshots to Firebase. They do not collect advertising identifiers, set a Firebase user ID/user properties, or track users across apps or websites. You can turn off future usage and crash reporting under Settings → Privacy controls. The web version separately uses GoatCounter; web analytics remain off by default and send coarse events only after opt-in.

Sharing, backups and external links

Your controls

In Settings you can disable mobile usage and crash reporting or web anonymous statistics, export a complete backup, or choose Erase all data. Disabling mobile reporting resets Analytics identifier data on the device and deletes unsent crash reports; information already transmitted remains subject to Google's retention and deletion arrangements. Erasing permanently removes all local HelperPay records and screenshots from the current device unless you kept a separate backup. Removing the app or clearing website data also removes local records.

Security and retention

Data remains on the device until you delete it. Optional PINs are shared-device controls inside the app, not device-level encryption. Protect the phone with a device passcode and keep backups secure.

Contact

Privacy questions: [email protected]