Information we collect
Account information: When you register, we collect your organization name, administrator name, email address, and billing information.
Employee data: Administrators may enter employee names, employee IDs, email addresses, department, home campus, and the hours a full week is expected to be for that person. Employees authenticate with a PIN, and, where an organization has turned it on, with a badge. Badge codes are stored as a hash and never in a form we could read back.
Time records: The Service records punch-in and punch-out timestamps, device identifiers, and generates timesheets from this data.
Corrections and the reasons for them: An administrator can correct a punch, mark a day as out of office, or record a decision about a week that looks unusual. Every one of those asks for a written reason and stores it against the employee it concerns, together with who wrote it and when. Reasons are typed or chosen by an administrator, so they can contain whatever that person writes, including an explanation of an absence. This is what makes a disputed week answerable from the record, and it is also employee information your organization is responsible for.
Usage data: We collect standard server logs including IP addresses, browser type, and pages accessed to maintain and improve the Service.
Support requests: When you use the help button inside the Service, we collect your name, email address, role, organization name, the page you were on, and whatever you write in the message. The first four are filled in for you so you do not have to type them.
How we use your information
We use collected information to: (a) provide and maintain the Service; (b) process payments; (c) send transactional emails (password resets, billing notifications); (d) respond to support requests; (e) improve the Service.
Data storage and security
Your account information, employee data, and time records are stored on secure servers hosted by DigitalOcean in the United States. We use encryption in transit (TLS/SSL) and at rest. PINs and passwords are hashed using bcrypt. We implement access controls and audit logging to protect your data.
Two things live elsewhere, with the providers named in section 4: billing details are held by Stripe, and support requests you send through the help button are held by Formspree. We do not keep a copy of your card details at any point.
Data sharing
We do not sell your data. We share it only with the providers below, only for the purpose listed, and with law enforcement when required by valid legal process.
Stripe processes payments and holds your billing details.
Resend delivers transactional email, such as password resets and billing notices, and receives the recipient address and the contents of that email.
Formspree receives and stores support requests sent through the help button inside the Service, including the fields listed in section 1. It receives nothing unless you send a request.
Google receives analytics data from our public marketing pages, and only if you allow analytics in the cookie banner. This never includes anything from the kiosk, the employee app, or the admin dashboards, and it never includes employee or time record data. See our Cookie Policy for what that covers.
Data retention
We retain your data for as long as your account is active. If you cancel, your organization is deactivated and its data is kept, not deleted, so that you have at least 30 days to export anything you still need. After six months deactivated, an organization is archived and its subdomain released for reuse. We delete an organization’s data outright on request, and you can ask for that at any time using the contact details below.
Your rights
You have the right to: (a) access your data through the Service; (b) correct inaccurate data; (c) request deletion of your data; (d) export your data. Contact us to exercise these rights.
Cookies
Inside the Service we use essential cookies for authentication (session tokens, device tokens) and nothing else, with no analytics and no tracking on any screen where someone clocks in or where timesheet data is handled. On our public marketing pages we use Google Analytics, off by default and only enabled if you allow it. We never use advertising cookies anywhere. See our Cookie Policy for details.
Children's privacy
The Service is intended for use by education organization employees and administrators. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal information, contact us immediately.
Changes to this policy
We may update this Privacy Policy periodically. We will notify you of material changes by email or through the Service.
Contact
For privacy questions or data requests, contact us at [email protected].