1. Who we are
Smartclocksystems ("we", "us", "our") operates the Smartclocksystems platform available at smartclocksystems.com. We act as a data processor on behalf of the employers ("Tenants") who subscribe to our service, and as a data controller for our marketing site, account signups, and billing.
2. Data we collect
- Account data: name, work email, phone, company, role, hashed password.
- Workforce data on behalf of Tenants: shift schedules, clock-in/out timestamps, GPS coordinates at punch time (when geofencing is enabled), photos taken at punch time (when photo verification is enabled), biometric templates derived from facial recognition (stored as one-way templates, never raw images), PTO balances, pay rates, and timesheet records.
- Billing data: handled by Stripe; we never store full card numbers.
- Communications: SMS sent through Twilio (with quiet-hours respect) and transactional email.
- Device & log data: IP address, browser, operating system, and audit-log entries for sensitive actions (create / update / delete).
3. How we use your data
- Operate the time-tracking, scheduling, payroll, and HR features your employer enabled.
- Verify clock-in identity and geofence compliance.
- Send notifications about shifts, timecard approvals, PTO requests, and account security.
- Bill your employer (we never sell your data).
- Detect abuse, prevent buddy-punching, and meet labor-law audit requirements.
4. Legal basis
For employees of our Tenants, processing is performed under your employer's legitimate interest in operating their workforce, contractual necessity, and where required, your consent (for facial / biometric enrollment, which is always optional and can be withdrawn).
5. How we share data
- Within your Tenant: data is strictly partitioned by tenant via Row-Level Security at the database layer. Other companies on Smartclocksystems cannot see your data.
- Sub-processors: Supabase (hosting & database, US), Stripe (payments), Twilio (SMS), Resend (email), Mapbox (geofencing). Each is bound by a DPA.
- Gusto: only when your employer connects Gusto for W-2 payroll, we send approved hours, OT and PTO. We do not retrieve tax data back.
- Legal requests: only when compelled by valid legal process and after notifying the affected Tenant where allowed.
6. Biometric & facial-recognition data
Facial recognition is opt-in. We store mathematical templates only — never raw images of your face — and the templates are scoped to a single tenant. You can request deletion at any time and the system will fall back to PIN or photo verification.
7. Retention
Active workforce records are retained for the life of your employer's subscription plus a 30-day grace period. After that, data is purged unless a longer retention is required for tax, payroll, or labor-law compliance (typically 7 years for payroll records under US federal law).
8. Your rights
You may request access, correction, export, or deletion of your personal data. If you are an employee of a Tenant, please contact your employer first; if they cannot help, email us. We respond within 30 days.
9. International transfers
Data is stored in the United States. If you are accessing the service from outside the US, you consent to the transfer of your data to the United States, subject to the safeguards above.
10. Children
The service is not directed to children under 16 and we do not knowingly collect data from them.
11. Changes
We will post material changes to this policy at this URL and notify Tenant administrators by email at least 14 days before they take effect.
Questions about this policy? Email support@smartclocksystems.com.