Privacy Policy
TGIF Panda is built around anonymity. This policy explains what we do — and deliberately do not — collect, and the limited, first-party usage data the app gathers to improve the product.
Effective June 18, 2026
This Privacy Policy describes how Panda ECS LLC. (“Panda ECS,” “we,” “us,” or “our”) handles information in connection with TGIF Panda — our anonymous employee-feedback platform, comprising the TGIF Panda mobile app for employees and the TGIF Panda web dashboard for employers (together, the “Service”). By using the Service you agree to the practices described here and in our Terms of Service.
The short version. Your feedback is anonymous. We do not ask employees for a name, email, or phone number, and we do not link your feedback to your identity. The app collects a small amount of anonymous usage data to help us fix problems and improve the product — never tied to who you are, and you can turn it off at any time.
1. Who this policy covers
TGIF Panda serves two kinds of people, and we treat their information differently:
- Employees who submit feedback through the mobile app. Employees use the app anonymously — no account, name, or contact details are required or collected.
- Employer administrators who view aggregated results in the web dashboard. Administrators create an account with a work email address to manage their organization.
2. How anonymity works
Anonymity is a core design property of the Service, not just a promise. Two technical safeguards make it real:
- No identity is attached to feedback. Employees sign in to the app anonymously. To prevent duplicate submissions, each device generates a random identifier (a “Panda ID”) that is stored only on the device. The Panda ID is a de-duplication key — it is never a login credential and is not connected to your name, email, or employer records.
- Results are only ever shown in aggregate. The employer dashboard shows combined scores and anonymized free-text quotes. To protect individuals, department and team labels are hidden until there are enough responses (a minimum threshold) to prevent any single person from being identified.
3. Information employees provide
When you use the app, you may provide:
- Your facility access code, which connects your device to your workplace. The code identifies a workplace, not a person.
- Your feedback — mood check-ins, survey answers, and any optional free-text notes you choose to write. Please do not include your name, a coworker’s name, or other identifying details in free-text; doing so could undermine the anonymity the platform is designed to protect.
- An optional department or team selection, used only to group results and subject to the minimum-threshold protection described above.
4. Anonymous usage data (product analytics)
To understand how the app is used, fix bugs, and improve the experience, the app collects limited, first-party analytics. This data is keyed to a randomly generated Analytics Install ID (AID) stored on your device. The AID is separate from your Panda ID and from your feedback — there is no link between them — and it is resettable (see Section 6). We collect:
Coarse device information
- Platform (iOS or Android) and operating-system version;
- A general device model class or marketing name (for example, “iPhone 15”) — never a serial number;
- App version and build number;
- Screen size, language/locale, and time zone.
Usage and engagement events
- App lifecycle events (session start and end, app foregrounded/backgrounded);
- Which screens are viewed and how long they are viewed (“dwell time”);
- Funnel milestones such as accepting these policies (version only), entering an access code, starting and submitting a check-in, and opening, starting, and completing a survey;
- If rewards are enabled, whether a reward spin was viewed or a reward was claimed.
Friction and diagnostics
- A signal that a screenshot was taken, tagged with the screen you were on (a “you wanted to keep this” signal). We never capture the contents of the screenshot itself, and this signal is reliably detectable only on iOS;
- Errors, crashes, failed validations, and when an action was queued offline.
What we deliberately never collect. No advertising identifiers, no device serial numbers, no precise location or GPS, no IP-based geolocation, no contacts, no microphone or camera access, and no inputs used for device fingerprinting. The Analytics Install ID is the only identifier on this data, and it is not connected to your feedback or your identity.
5. Information employer administrators provide
When an administrator signs up for and uses the dashboard, we process:
- Account details — a work email address (used to create the account and send a verification email) and organization/facility information;
- Authentication data — a session cookie that keeps the administrator signed in and scopes access to that organization’s facilities only.
Administrators only ever see aggregated, anonymized results — never an individual employee’s identity or raw, attributable feedback.
6. Your choices and controls
- Turn off analytics. Product analytics are on by default. You can opt out at any time from the app’s Privacy screen. Opting out halts data capture immediately, and turning sharing back on regenerates your Analytics Install ID so nothing carries across — there is no persistent fingerprint.
- Push notifications. If you enable notifications, the app stores a push token to deliver survey reminders. The token is associated with your facility, not your identity, and you can disable notifications in your device settings.
- Account data. Employer administrators can update or request deletion of their account information by contacting us.
7. How we use information
- To operate the Service and deliver anonymous feedback to employers in aggregate;
- To prevent duplicate or fraudulent submissions;
- To diagnose problems, improve reliability, and make product decisions;
- To send survey reminders where notifications are enabled;
- To secure the Service and comply with legal obligations.
We do not sell your information, we do not use it for third-party advertising, and we do not share product-analytics data with third parties for their own purposes.
8. Service providers
We rely on a small set of infrastructure providers who process data on our behalf, under contract, solely to run the Service:
- Google Firebase / Google Cloud — authentication, database, and cloud functions (data stored in the United States);
- Vercel — hosting for the website and employer dashboard;
- Expo — mobile app delivery and push-notification routing;
- Resend — sending administrator account-verification emails.
9. Data retention
Raw analytics events are automatically deleted after 90 days. Aggregated, anonymized results (which cannot be traced to an individual) and employer account records are retained for as long as the organization uses the Service or as required by law. You may request deletion of administrator account data at any time.
10. Security
We protect information with encryption in transit, strict server-side access controls, and database security rules that isolate each organization’s data. No system is perfectly secure, but anonymity-by-design means that even in the unlikely event of a breach, employee feedback is not tied to identifiable individuals.
11. Children’s privacy
The Service is intended for use by an adult workforce. It is not directed to children, and we do not knowingly collect information from anyone under 16.
12. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Effective” date above. If we make a material change, the app will ask you to review and acknowledge the updated policy before you continue using it.
13. Contact us
Questions about this policy or your data? Contact Panda ECS LLC. at privacy@tgifpanda.com.