Business IT projects · Across Québec Request a quoteFrançais

Mobile app

A mobile app is software installed on a phone or tablet, offered to your clients or used by your teams. Before writing code, you need to clarify who will use it, what it must let them do, what data it will process and who will maintain it after it is published.

Updated on

Developing an app that collects personal information must take into account section 3.3 of Quebec's Act respecting the protection of personal information in the private sector, which requires a privacy impact assessment for "any project to acquire, develop or overhaul an information system or electronic service delivery system" involving such information. On the security side, OWASP publishes the MASVS, a verification standard for mobile application security.

Short answer

You describe your idea, your users and the essential features: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The technical approach, steps and schedule are set with you.

What the quote should cover

  • The requirements workshop and the feature list for the first version
  • The technical approach: native or cross-platform, and why
  • Mockups and the user journey
  • The server, APIs and data hosting
  • Testing on different devices and the target security level
  • Publishing on the App Store and Google Play, and the developer accounts
  • Post-launch maintenance: OS updates, fixes, enhancements

The steps of a mobile app project

  1. Definition of users, needs and priority features
  2. Mockups and a prototype to validate the journey
  3. Choice of technical approach and data hosting
  4. Development in stages, with regular testing
  5. Publishing in the app stores
  6. Monitoring, fixes and later versions

Native or cross-platform

A native app is developed separately for iOS and Android, for example in Swift and Kotlin. A cross-platform approach, for example with Flutter or React Native, shares much of the code between the two. These technologies are only examples: the right choice depends on the features wanted, access to device functions, your budget and who will maintain the app.

A first version limited to essential features, often called a minimum viable product, lets you test the idea with real users before investing further. The schedule depends on the agreed scope and is to be set with you: be wary of a duration announced before the features are defined.

Publishing in the stores

The stores have their own rules. The App Store Review Guidelines require all apps to include a link to their privacy policy in the metadata and within the app (5.1.1 i). They also require an app that supports account creation to offer account deletion within the app (5.1.1 v). Google Play likewise requires an app that lets users create an account to let them request that their account be deleted.

Have the quote specify whose name the Apple and Google developer accounts will be opened in: ideally your company's, so you keep control of the app if you change providers. Also require access to the source code.

Personal data and security

If the app uses location or other functions that allow a person to be identified, located or profiled, section 8.1 of the Act requires informing the person beforehand, as well as of the means available to activate those functions. Section 9.1 requires that, by default, the privacy settings of a technological product offered to the public provide "the highest level of confidentiality" without any intervention by the person. If data is hosted outside Québec, section 17 requires an assessment and a written agreement.

The MASVS groups its controls by area: storage of sensitive data on the device, cryptography, authentication and authorization, network communication, interaction with the platform, code quality and updates, resilience to reverse engineering, and privacy. State in your request whether it should serve as a reference, and plan penetration testing if the app processes sensitive data. For incidents, Incident response describes the obligations to plan for.

Maintenance after launch

An app is never finished: iOS and Android evolve, and the stores impose their requirements. For example, Google Play sets target API level requirements: new apps and app updates must target a recent Android version, and an existing app that does not keep up stops being discoverable to users on newer devices.

The quote should therefore separate the cost of initial development from maintenance, and specify what is included: updates for new OS versions, security fixes, error monitoring, small enhancements, renewal of developer accounts.

Questions to ask yourself before requesting a quote

  • Who will use the app: your clients, your employees, both?
  • Which features are essential in the first version?
  • Must the app work without an Internet connection?
  • What personal information will it collect, and why?
  • Must it exchange data with your current software?
  • Who will maintain the app after launch?

Pitfalls to avoid

  • Wanting every feature in the first version
  • Developer accounts opened in the provider's name
  • Forgetting the account deletion required by the stores
  • Collecting location or other data without informing the user
  • A quote with no maintenance component
  • A project duration promised before the features are defined

What to specify in your request

  • The app's goal and its users
  • Essential features and those that can wait
  • Target platforms: iOS, Android or both
  • The software or services it must communicate with
  • The personal data planned
  • Your approximate budget and date constraints, if any

You can then describe your project: the team will contact you to clarify your needs and provide a quote.

Frequently asked questions

Should we develop for both iOS and Android?

That depends on your users. A cross-platform approach, for example with Flutter or React Native, covers both with much of the code shared. A native app may be justified for advanced device features.

How long does it take to build an app?

That depends on the features, integrations, number of platforms and your team's availability to approve each stage. The schedule is set with you once the first version's features are defined.

Do we need a privacy policy?

Yes. The App Store guidelines require a link to the privacy policy in the metadata and within the app, and Quebec's Act requires publishing a confidentiality policy when personal information is collected through technological means (s. 8.2).

Who owns the app?

That depends on the contract. Require ownership of, or full access to, the source code, and Apple and Google developer accounts opened in your company's name.

What is OWASP MASVS?

It is a standard published by OWASP for verifying mobile app security. It groups controls on storage, cryptography, authentication, network, platform, code, resilience and privacy. It can serve as a reference in your request.

Mobile app

Mobile and web apps, business software

Request a quote