Privacy Policy
Template: replace the bracketed details and have this policy reviewed by a qualified privacy lawyer before relying on it.
ClockIn is a time-clock and scheduling service operated by [Operator legal name] (“we”). Employers (“your employer”) use ClockIn to record when their employees work. For employee records, your employer decides what is collected and why, and is responsible for that information under privacy laws such as British Columbia’s Personal Information Protection Act and Canada’s PIPEDA. We process it on your employer’s behalf.
Information we collect
- Manager accounts: name, email address, role, and a salted hash of your password and management PIN. We never receive or store your password itself.
- Employee records entered by your employer: name, department, work location, pay rate, manager, optional contact details, and a keyed hash of the 4-digit kiosk PIN.
- Time records: clock-in, clock-out and break times, schedules, shift-swap requests, timecard corrections and the reasons given for them.
- Messages sent in the My Shifts app and the manager inbox: the text, who sent it and when, and when each person last read a conversation. Direct messages between two employees are visible only to those two employees; conversations with managers are visible to that employee and the employer’s managers; the team chat is visible to everyone at the company.
- Punch photos and location, only when your employer turns these checks on: a small photo taken at the kiosk and the device’s coordinates and distance from the workplace at the moment of the punch.
- Technical data: session cookies that keep you signed in, an audit log of changes, and error reports used to fix problems.
How the information is used
- To record attendance, calculate hours, overtime and holiday pay, and prepare payroll reports for your employer.
- To confirm that the right person punched at the right place, when photo or location checks are enabled.
- To secure accounts, prevent misuse, keep backups, and diagnose errors.
We do not sell personal information or use it for advertising.
Consent
Before the first punch that requires a photo or location, the kiosk shows a notice and records the employee’s acceptance. Employees who do not agree should ask their manager to record their time another way.
Retention
- Punch photos and locations are deleted automatically after the number of days your employer sets (90 days by default).
- Time records and employee profiles are kept while your employer’s account is active, or until your employer deletes them.
- Messages are deleted automatically 30 days after they are sent, and straight away when the sender deletes them or when the employer deletes that employee. Messages are not included in backups or data exports.
- Automatic daily backups are kept for 30 days. Error logs are kept for 30 days.
Where information is stored
ClockIn runs on Cloudflare’s network and database services. Data may be stored or processed in Canada, the United States, or other countries where Cloudflare operates. Data is encrypted in transit.
Security
Passwords and PINs are stored only as salted or keyed hashes. Management areas lock after inactivity, failed sign-in attempts are rate-limited, and every change to time records is written to an audit log.
Your rights
You can ask to see or correct personal information about you. Employees should contact their employer first, since the employer controls their records. You can also contact us at [privacy contact email].
Changes
We will update this page when our practices change and revise the date above.
Contact
[Operator legal name] · [mailing address] · [privacy contact email]