Template notice: This policy was drafted to match the features you described (multi-organization HR attendance app, continuous background location, Supabase + Firebase/FCM). It is a strong starting point for your Play Store submission, but it is not a substitute for legal review — please have a lawyer confirm it before treating it as final, especially regarding GDPR (if any users are in the EU/UK), local labor laws on employee monitoring, and your specific Terms of Service.
1. Introduction
ClockIn360 ("the App," "we," "us," or "our") is a workforce attendance and human resource management application that organizations use to manage employee check-in/check-out, leave requests, attendance reports, holiday calendars, and team notifications. This Privacy Policy explains what information the App collects, how it is used, who it is shared with, and the choices available to you.
By creating an account or using ClockIn360, you acknowledge that you have read and understood this Privacy Policy. If you are an employee using ClockIn360 because your employer requires it for work purposes, please also see Section 14, which explains the relationship between you, your employer, and us.
2. Who This Policy Covers
ClockIn360 is offered to any organization that wishes to use it to manage their workforce. Within each organization, the App supports three roles:
Admin
Organization-level configuration, full visibility into all employee data within their organization, manages geo-fence zones and policies.
Manager
Approves/rejects leave requests, views attendance and reports for their direct team members.
Employee
Checks in/out, applies for leave, views their own attendance history and holiday calendar, receives notifications.
This policy applies to all three roles. Each organization's data is logically separated from other organizations using the App.
3. Information We Collect
3.1 Information you provide directly
| Category | Examples |
| Account & profile | Full name, work email address, password (encrypted), job title, department, profile photo (if uploaded) |
| Organization data | Company name, office address(es), designated geo-fence boundaries set by Admins |
| Attendance records | Check-in time, check-out time, work hours calculated from these timestamps |
| Leave records | Leave type, dates requested, reason/notes provided, approval/rejection status and comments |
| Communications | Any messages, comments, or notes entered within the app (e.g. leave request notes) |
3.2 Information collected automatically
| Category | Examples |
| Location data | Precise GPS coordinates, collected continuously in the background while the app is installed and location permission is granted — see Section 4 for full detail |
| Device information | Device model, operating system and version, unique device/installation identifiers, app version |
| Push notification tokens | A Firebase Cloud Messaging (FCM) token used to deliver notifications to your device |
| Usage & log data | App open/close events, feature usage, crash logs, IP address, timestamps of actions taken in-app |
We do not knowingly collect financial/payment card information, biometric data, or government ID numbers through ClockIn360.
4. Background Location & Geo-Fencing
This is the most sensitive permission in the App — please read carefully. ClockIn360 collects precise location data continuously in the background, not only at the moment you check in or check out. This means your location can be recorded by the App even while you are not actively using it, as long as the App is installed, location permission is granted, and (depending on your device settings) location services remain enabled.
4.1 Why we collect background location
- To verify that check-in and check-out events occur within your organization's configured geo-fence (office premises or approved work zones)
- To detect entry into or exit from a geo-fenced zone, which may trigger automated check-in/check-out reminders or notifications
- To support attendance accuracy and prevent location-spoofed or fraudulent check-ins
4.2 What this means for you
- Your organization's Admins and your direct Manager(s) may be able to see location data associated with your attendance activity, depending on the permissions your organization has configured
- Background location tracking continues even when the App is not visibly open on your screen, until you revoke location permission, disable background location at the OS level, or uninstall the App
- You can manage or revoke this permission at any time through your device settings (Settings → Apps → ClockIn360 → Permissions → Location). Note that revoking background location permission may limit or disable core attendance features such as automatic geo-fence verification
4.3 Retention of location data
Raw location coordinates collected for geo-fence verification are retained according to your organization's data retention configuration, and in any case no longer than necessary to support attendance verification, dispute resolution, and applicable legal/labor record-keeping requirements. See Section 9.
5. How We Use Your Information
- To provide core App functionality: authentication, check-in/check-out, leave application and approval workflows, attendance and holiday reports
- To verify check-in/check-out location against organization-defined geo-fence zones
- To send push notifications (e.g. leave approval/rejection, check-in reminders, holiday announcements, manager alerts) via Firebase Cloud Messaging
- To generate attendance, leave, and holiday reports for Admins and Managers within an organization
- To maintain the security, integrity, and proper functioning of the App, including detecting fraud or misuse
- To respond to support requests and communicate important service updates
- To comply with legal obligations, including employment and labor record-keeping requirements that may apply to your organization
6. Legal Basis for Processing
Where applicable data protection law (such as the GDPR) requires a legal basis for processing, we and/or your employing organization rely on one or more of the following:
- Performance of a contract/employment relationship — processing attendance and leave data necessary to administer your employment
- Legitimate interests — verifying attendance, preventing fraud, and operating the App securely, balanced against your privacy rights
- Legal obligation — where labor law requires attendance record-keeping
- Consent — for background location permission, which is requested explicitly via your device's permission system and can be withdrawn at any time
7. How Information Is Shared
We do not sell your personal information. Information may be shared as follows:
- Within your organization — your Admins and Managers can access attendance, leave, and (where configured) location data tied to your role, strictly for HR management purposes
- Service providers — we use Supabase (database, authentication, backend infrastructure) and Firebase/FCM (push notification delivery) to operate the App; see Section 8
- Legal requirements — if required by law, court order, or governmental request, or to protect the rights, property, or safety of our users or the public
- Business transfers — in connection with a merger, acquisition, or sale of assets, with notice provided as required by law
We do not share employee location, attendance, or leave data with advertisers, data brokers, or unrelated third parties.
8. Third-Party Services
| Service | Purpose | Data Involved |
| Supabase | Database, authentication, backend storage | Account data, attendance/leave records, organization data |
| Firebase Cloud Messaging (Google) | Push notification delivery | Device push token, notification content |
These providers process data on our behalf under their own privacy and security commitments. We encourage you to review Supabase's Privacy Policy and Firebase/Google's Privacy Policy for details on how they handle data.
9. Data Retention
- Account and profile data is retained for as long as your account remains active within your organization
- Attendance and leave records are retained per your organization's configured retention period, and in any case as long as needed to meet HR record-keeping and applicable labor law obligations
- Background location data used for geo-fence verification is retained only as long as necessary for attendance verification and dispute resolution, after which it is deleted or anonymized
- Upon account deactivation, your organization's Admin may request deletion of your personal data, subject to any legal retention requirements
10. Data Security
We use industry-standard safeguards, including encrypted password storage, encrypted data transmission (HTTPS/TLS), and access controls that restrict data visibility based on organizational role. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. Your Rights & Choices
Depending on your location and applicable law, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, subject to your organization's record-keeping obligations
- Withdraw consent for background location tracking at any time via device settings (noting this may limit App functionality)
- Object to or restrict certain processing
- Request a copy of your data in a portable format
Because ClockIn360 is deployed by your employer, many of these requests should first be directed to your organization's Admin or HR department, who controls your employment data. You may also contact us directly using the details in Section 17.
12. Role-Based Access Within the App
To limit unnecessary data exposure, ClockIn360 restricts visibility by role:
- Employees can view only their own attendance, leave, and location-related check-in history
- Managers can view attendance and leave data for employees who report to them
- Admins can view organization-wide data necessary for HR administration, including configuring geo-fence boundaries and generating reports
13. Children's Privacy
ClockIn360 is a workplace tool intended for use by employees who meet the minimum working age in their jurisdiction. It is not directed at children, and we do not knowingly collect personal information from individuals under the age of 16.
14. For Organizations Deploying ClockIn360
If you are an organization ("Customer") using ClockIn360 to manage your workforce, you act as the data controller for your employees' personal data, and we act as a data processor/service provider on your behalf. Customers are responsible for:
- Providing appropriate notice to their employees about the App's data collection practices, including background location tracking, before deployment
- Obtaining any consents required under applicable local labor or privacy law for employee monitoring
- Configuring geo-fence zones, retention settings, and access permissions appropriately
- Responding to data subject requests from their own employees in the first instance
If your organization requires a separate Data Processing Agreement (DPA), please contact us using the details in Section 17.
15. International Data Transfers
Your information may be stored and processed in countries other than your own, including wherever our service providers (Supabase, Firebase/Google) operate data centers. Where required, we rely on appropriate safeguards such as standard contractual clauses to protect data transferred internationally.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the App, legal requirements, or our practices. We will update the "Last Updated" date above and, for material changes, provide additional notice within the App or to your organization's Admin.