Privacy policy
Last updated 10 October 2026
1. Who we are
StaffClock (staffclock.io) is run by [Company legal name], [registered address], [country] (“we”, “us”). Questions about privacy: privacy@staffclock.io.
2. Our role
For company accounts and visitors to our website, we decide how data is used (we are the controller). For employee information that a company adds to StaffClock, such as attendance, photos, locations and pay, the company is in charge of that data and we process it on its behalf under our Data Processing Agreement. Employees should contact their employer first about their records.
3. What we collect
- Account details: name, work email, phone (optional), company name, country and a hashed password.
- Billing: handled by our reseller Paddle. We see the plan, amount and the last 4 digits of a card, never the full number.
- Employee records added by employers: name, position, location, shift, salary, allowances and the last 4 digits of a bank account.
- Attendance: clock-in and clock-out times, GPS position at the moment of each punch, selfie photos, kiosk PIN use and device ID.
- Face ID (if the employer turns it on): a face template used only to confirm identity at a kiosk.
- Live location trail (if the employer turns it on): position every few minutes, only while the employee is clocked in.
- Website use: pages, clicks, referrer, device, browser and approximate city from IP address. Collected only if you accept analytics cookies.
4. How we use it
To run the service (attendance, leave and payroll calculations, pay stubs and e-signatures), keep accounts secure and prevent fraud, provide support, take payments, send service emails, and improve StaffClock using combined statistics. We send product news only to account owners, and every email has an unsubscribe link.
5. Photos, face data and location
Selfies and location trails are deleted after 90 days by default, and employers can choose a shorter period. Face templates are used for nothing except kiosk sign-in and are deleted when the employee is removed or face ID is turned off. Location is never collected when an employee is clocked out. Employees can see their own punches, photos and trails in the app.
6. Who we share it with
Only service providers that help us run StaffClock: hosting and database ([provider, region]), payments (Paddle), email delivery ([provider]), maps ([provider]), face matching ([provider]) and, with your consent, website analytics ([provider]). The current list is at staffclock.io/subprocessors. We do not sell personal data or use it for advertising.
7. International transfers
Data may be processed outside your country. Where the law requires it, we use approved safeguards such as standard contractual clauses.
8. How long we keep it
Account data is kept while the account is open and for 60 days after it closes, so you can come back or export. Pay stubs and payroll records are kept for as long as the employer’s local law requires. Invoices are kept as tax law requires.
9. Your rights
Depending on where you live, you can ask to see, correct, export or delete your data, object to some uses, and withdraw consent. Email privacy@staffclock.io and we’ll reply within 30 days. You can also complain to your data protection authority, for example the ICO in the UK, the UAE Data Office or SDAIA in Saudi Arabia.
10. Cookies
Necessary cookies keep you signed in, protect forms and remember your cookie choice. Analytics cookies show us how people use the website, and we set them only if you choose “Accept all”. You can change your choice at any time from “Cookie settings” in the footer.
11. Security
Data is encrypted in transit and at rest. Photos are stored privately and shown only to signed-in users with permission. We offer two-factor sign-in, keep an audit log of changes, and limit staff access to what support requires.
12. Changes
If we make an important change, we’ll email account owners at least 30 days before it takes effect.