Privacy Policy
This policy explains what personal data the service processes, why, and what you can do about it. It is written for the people whose data this is: employees and their managers.
Draft. Before launch this text must be reviewed by a lawyer and the controller details below filled in.
Who is responsible
The controller of your data is your employer — the company that invited you to the service. The service operator processes data on the employer's behalf as a processor. Operator: [COMPANY NAME], [REGISTERED ADDRESS], [CONTACT EMAIL].
What is collected
Identity and employment: full name, employee number, position, department, phone, email, hourly rate. Working time: clock-in and clock-out events, breaks, hours worked, overtime and night hours, manager corrections. Absences: leave and sick-leave requests with their dates and type. Location: coordinates at the moment of a clock-in or clock-out, and whether that point was inside the site's zone. Technical: session cookie, chosen language, push subscription of your device. To protect against brute force, the service counts sign-in attempts from one address. The address itself is not stored — only an irreversible fingerprint of it, and that is deleted within a day.
Why, and on what legal basis
Working time is recorded because the employer is required by law to keep such records, and because it is necessary to perform the employment contract — this is the legal basis under Article 6(1)(b) and (c) GDPR. Location at the moment of a clock-in serves the employer's legitimate interest in confirming presence at the site, Article 6(1)(f). Your data is not used for advertising, is not sold, and is not profiled.
Location, specifically
Coordinates are read only at the instant you press "start shift" or "end shift". There is no background tracking: between clock-ins the service does not know where you are and does not ask. A clock-in outside the site's zone is still accepted — it is marked for the manager, not blocked.
How long it is kept
Working-time records are kept for as long as employment law requires the employer to keep them — in Hungary this is generally three years. After you leave the company your profile is archived rather than deleted, because timesheets and payroll history must survive the end of employment. Full deletion happens on request, subject to those retention obligations.
Who else sees it
Data is stored with Supabase (Postgres hosting, EU region) and served through the hosting provider. Push notifications go through the push service of your device's browser vendor; the notification contains only the text you see on screen. There are no advertising or analytics trackers.
Your rights
You may request access to your data, correction of errors, deletion, restriction of processing, and a copy in a portable format. You may object to processing based on legitimate interest. If you believe your data is handled unlawfully you may complain to the supervisory authority — in Hungary this is NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság).
How to use them
Open Settings → My data in the app. There you can download everything the service holds about you as a file, and send a deletion request to your employer. Requests are answered within one month.
Cookies
Only two, both technical: the one that keeps you signed in, and the one that remembers your chosen language. There are no advertising or tracking cookies, which is why the service does not show a cookie banner.
Contact
Questions about your data: ask your manager first — they are the controller. For questions about the service itself: [CONTACT EMAIL].