ClockIn360

PRIVACY POLICY

Effective Date: June 18, 2026  ·  Last Updated: June 18, 2026
Template notice: This policy was drafted to match the features you described (multi-organization HR attendance app, continuous background location, Supabase + Firebase/FCM). It is a strong starting point for your Play Store submission, but it is not a substitute for legal review — please have a lawyer confirm it before treating it as final, especially regarding GDPR (if any users are in the EU/UK), local labor laws on employee monitoring, and your specific Terms of Service.

Contents

  1. 1. Introduction
  2. 2. Who This Policy Covers
  3. 3. Information We Collect
  4. 4. Background Location & Geo-Fencing
  5. 5. How We Use Your Information
  6. 6. Legal Basis for Processing
  7. 7. How Information Is Shared
  8. 8. Third-Party Services
  9. 9. Data Retention
  10. 10. Data Security
  11. 11. Your Rights & Choices
  12. 12. Role-Based Access
  13. 13. Children's Privacy
  14. 14. For Organizations Deploying ClockIn360
  15. 15. International Data Transfers
  16. 16. Changes to This Policy
  17. 17. Contact Us

1. Introduction

ClockIn360 ("the App," "we," "us," or "our") is a workforce attendance and human resource management application that organizations use to manage employee check-in/check-out, leave requests, attendance reports, holiday calendars, and team notifications. This Privacy Policy explains what information the App collects, how it is used, who it is shared with, and the choices available to you.

By creating an account or using ClockIn360, you acknowledge that you have read and understood this Privacy Policy. If you are an employee using ClockIn360 because your employer requires it for work purposes, please also see Section 14, which explains the relationship between you, your employer, and us.

2. Who This Policy Covers

ClockIn360 is offered to any organization that wishes to use it to manage their workforce. Within each organization, the App supports three roles:

Admin

Organization-level configuration, full visibility into all employee data within their organization, manages geo-fence zones and policies.

Manager

Approves/rejects leave requests, views attendance and reports for their direct team members.

Employee

Checks in/out, applies for leave, views their own attendance history and holiday calendar, receives notifications.

This policy applies to all three roles. Each organization's data is logically separated from other organizations using the App.

3. Information We Collect

3.1 Information you provide directly

CategoryExamples
Account & profileFull name, work email address, password (encrypted), job title, department, profile photo (if uploaded)
Organization dataCompany name, office address(es), designated geo-fence boundaries set by Admins
Attendance recordsCheck-in time, check-out time, work hours calculated from these timestamps
Leave recordsLeave type, dates requested, reason/notes provided, approval/rejection status and comments
CommunicationsAny messages, comments, or notes entered within the app (e.g. leave request notes)

3.2 Information collected automatically

CategoryExamples
Location dataPrecise GPS coordinates, collected continuously in the background while the app is installed and location permission is granted — see Section 4 for full detail
Device informationDevice model, operating system and version, unique device/installation identifiers, app version
Push notification tokensA Firebase Cloud Messaging (FCM) token used to deliver notifications to your device
Usage & log dataApp open/close events, feature usage, crash logs, IP address, timestamps of actions taken in-app

We do not knowingly collect financial/payment card information, biometric data, or government ID numbers through ClockIn360.

4. Background Location & Geo-Fencing

This is the most sensitive permission in the App — please read carefully. ClockIn360 collects precise location data continuously in the background, not only at the moment you check in or check out. This means your location can be recorded by the App even while you are not actively using it, as long as the App is installed, location permission is granted, and (depending on your device settings) location services remain enabled.

4.1 Why we collect background location

4.2 What this means for you

4.3 Retention of location data

Raw location coordinates collected for geo-fence verification are retained according to your organization's data retention configuration, and in any case no longer than necessary to support attendance verification, dispute resolution, and applicable legal/labor record-keeping requirements. See Section 9.

5. How We Use Your Information

6. Legal Basis for Processing

Where applicable data protection law (such as the GDPR) requires a legal basis for processing, we and/or your employing organization rely on one or more of the following:

7. How Information Is Shared

We do not sell your personal information. Information may be shared as follows:

We do not share employee location, attendance, or leave data with advertisers, data brokers, or unrelated third parties.

8. Third-Party Services

ServicePurposeData Involved
SupabaseDatabase, authentication, backend storageAccount data, attendance/leave records, organization data
Firebase Cloud Messaging (Google)Push notification deliveryDevice push token, notification content

These providers process data on our behalf under their own privacy and security commitments. We encourage you to review Supabase's Privacy Policy and Firebase/Google's Privacy Policy for details on how they handle data.

9. Data Retention

10. Data Security

We use industry-standard safeguards, including encrypted password storage, encrypted data transmission (HTTPS/TLS), and access controls that restrict data visibility based on organizational role. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Your Rights & Choices

Depending on your location and applicable law, you may have the right to:

Because ClockIn360 is deployed by your employer, many of these requests should first be directed to your organization's Admin or HR department, who controls your employment data. You may also contact us directly using the details in Section 17.

12. Role-Based Access Within the App

To limit unnecessary data exposure, ClockIn360 restricts visibility by role:

13. Children's Privacy

ClockIn360 is a workplace tool intended for use by employees who meet the minimum working age in their jurisdiction. It is not directed at children, and we do not knowingly collect personal information from individuals under the age of 16.

14. For Organizations Deploying ClockIn360

If you are an organization ("Customer") using ClockIn360 to manage your workforce, you act as the data controller for your employees' personal data, and we act as a data processor/service provider on your behalf. Customers are responsible for:

If your organization requires a separate Data Processing Agreement (DPA), please contact us using the details in Section 17.

15. International Data Transfers

Your information may be stored and processed in countries other than your own, including wherever our service providers (Supabase, Firebase/Google) operate data centers. Where required, we rely on appropriate safeguards such as standard contractual clauses to protect data transferred internationally.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the App, legal requirements, or our practices. We will update the "Last Updated" date above and, for material changes, provide additional notice within the App or to your organization's Admin.

17. Contact Us

If you have questions about this Privacy Policy or how your data is handled, please contact:

ClockIn360 Support
Email: mansoor.butt.offical@gmail.com
(Replace with your actual support email before publishing)