Back to Shift Clock

ShiftClock Privacy Policy

Effective Date
June 19, 2026
Last Updated
June 19, 2026

ShiftClock is a workforce timekeeping and attendance platform operated by ShiftClock ("ShiftClock," "we," "us," or "our").

This Privacy Policy explains how we collect, use, disclose, retain, and protect information when individuals visit shiftclock.us, use the ShiftClock website, mobile experience, applications, services, and related features, or communicate with us collectively, the "Services."

ShiftClock is primarily provided to businesses and organizations that use the Services to manage their workforce. In many situations, an employer or other organization controls the employee information entered into ShiftClock. That organization is referred to in this policy as the "Customer."

1. Roles and Responsibilities

When ShiftClock processes employee or workforce information on behalf of a Customer, the Customer generally determines why the information is collected, how the Services are configured, which employees may use the Services, and how long information should be retained.

ShiftClock generally processes that information as a service provider, processor, or contractor on the Customer's behalf. Employees should direct requests involving employment records, timecard corrections, payroll, schedules, workplace monitoring, or employer-required data to their employer.

For information we collect for our own business purposes, such as website inquiries, billing contacts, account administration, security logs, and marketing preferences, ShiftClock acts as the business or controller of that information.

2. Information We Collect

Depending on how the Services are configured and used, we may collect the following categories of information.

  • Account and identity information, including name, email address, telephone number, username, authentication credentials, employee ID, job title, department, assigned location, role, employer name, and profile information.
  • Timekeeping and workforce information, including clock-in and clock-out times, breaks, schedules, hours worked, overtime, paid time off, corrections, approvals, manager notes, attendance exceptions, payroll-related calculations, export history, and audit records.
  • Location and geofence information when enabled by a Customer and permitted through the user's device, including coordinates, approximate location, worksite, geofence status, location accuracy, and related dates and times.
  • Device, browser, and technical information, including IP address, browser type, operating system, device type, session identifiers, login activity, pages or features accessed, error logs, security events, cookies, and diagnostic information.
  • Billing and subscription information, including billing name and address, subscription plan, payment status, transaction identifiers, invoice history, and limited payment-card details such as card brand and last four digits.
  • Communications and support information, including support requests, emails, contact forms, sales inquiries, demonstration requests, feedback, bug reports, account notices, and other communications.

3. Location and Geofence Information

Unless ShiftClock clearly states otherwise within the Services, ShiftClock is designed to use location information for legitimate timekeeping, attendance, fraud-prevention, security, and worksite-verification purposes, not for continuous off-duty tracking.

Device location permissions can normally be controlled through device or browser settings. Disabling location permissions may prevent certain clock-in, worksite, or geofence features from operating.

Customers are responsible for providing employee notices, obtaining required consents, and complying with workplace-monitoring, labor, privacy, and location-tracking laws that apply to their organization.

4. How We Use Information

ShiftClock will not use Customer workforce information to make independent hiring, firing, promotion, disciplinary, wage, or other employment decisions.

  • Create, authenticate, secure, and administer accounts.
  • Provide timekeeping, scheduling, attendance, geofence, approval, reporting, and payroll-export features.
  • Process subscriptions and payments.
  • Calculate or display hours, overtime, leave, and payroll-related estimates.
  • Generate reports and exports requested by Customers.
  • Maintain audit trails, detect missed punches or unusual activity, prevent fraud, and protect the Services.
  • Provide support, communicate about accounts and service changes, diagnose errors, and improve reliability.
  • Enforce agreements, comply with legal obligations, respond to lawful requests, and establish or defend legal claims.
  • Create aggregated or de-identified information that does not reasonably identify an individual.

5. Automated Calculations and Payroll-Related Information

The Services may automatically calculate or display totals involving hours, overtime, breaks, paid leave, gross-pay estimates, deductions, or payroll exports.

These outputs depend on information and settings supplied by the Customer and its users. They may not reflect every federal, state, local, union, contractual, tax, or industry-specific requirement.

The Customer is responsible for reviewing and verifying timekeeping and payroll-related information before relying on it, issuing wages, disciplining an employee, or submitting information to a payroll provider or government agency.

6. How We Disclose Information

  • To the Customer and its authorized users, including administrators, managers, payroll personnel, supervisors, and other users authorized by the Customer.
  • To service providers that help us provide hosting, storage, email delivery, messaging, authentication, customer support, monitoring, payment processing, security, analytics, and data backup.
  • As part of a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar business transaction, subject to applicable law.
  • For legal and safety purposes, including to comply with law, protect rights and safety, investigate fraud or abuse, and establish or defend legal claims.
  • With permission from the affected Customer or individual.

7. Sale, Sharing, and Targeted Advertising

ShiftClock does not sell employee timekeeping records or precise employee location information for monetary compensation.

ShiftClock does not use Customer workforce information for cross-context behavioral advertising.

If our practices change in a way that legally constitutes a sale or sharing of personal information, we will update this policy and provide legally required notices and opt-out mechanisms before applying the changed practice.

8. Cookies and Similar Technologies

ShiftClock may use cookies, local storage, session storage, and similar technologies to keep users signed in, maintain sessions, remember preferences, protect accounts, prevent fraud, understand performance, diagnose errors, and improve the Services.

Browser settings may allow users to block or delete cookies. Certain features may not work correctly if required cookies or storage are disabled.

9. Data Retention

ShiftClock retains information for only as long as reasonably necessary to provide the Services, fulfill Customer instructions, maintain business and legal records, resolve disputes, enforce agreements, prevent fraud, and comply with applicable law.

Customer workforce records may be retained during the subscription term and for a limited period after termination to allow account recovery, export, legal compliance, backup rotation, or dispute resolution.

Deleted information may remain temporarily in encrypted backups or system logs until those backups or logs are overwritten under normal retention schedules.

10. Data Security and Security Incidents

ShiftClock uses reasonable administrative, technical, and organizational safeguards designed to protect information, including access controls, authentication measures, encrypted communications, restricted administrative access, logging, monitoring, backups, software maintenance, vendor controls, and incident-response procedures.

No website, application, transmission method, or storage system is completely secure. We cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.

When required by law or contract, ShiftClock will notify affected Customers of confirmed security incidents involving Customer information. Customers are responsible for determining whether notices must be sent to employees, regulators, or other individuals unless applicable law assigns that responsibility directly to ShiftClock.

11. Individual Privacy Rights

Depending on the individual's state of residence and the law that applies, an individual may have rights to confirm whether personal information is being processed, access personal information, correct inaccurate information, request deletion, obtain a portable copy, opt out of certain sales, sharing, targeted advertising, or profiling, limit certain uses of sensitive personal information, appeal the denial of a request, and avoid unlawful discrimination for exercising privacy rights.

These rights are not absolute and may be subject to exceptions, identity verification, employment-data exclusions, legal retention requirements, and the relationship between ShiftClock and the Customer.

When ShiftClock processes information for a Customer, privacy requests should normally be submitted to that Customer. ShiftClock will reasonably assist the Customer as required by contract and applicable law.

Requests concerning information controlled directly by ShiftClock may be submitted by email to sender.shiftclock@gmail.com with the subject line "Privacy Request."

12. California Privacy Disclosures

California residents may have rights under the California Consumer Privacy Act, as amended, when that law applies.

During the preceding 12 months, ShiftClock may have collected the categories described in this policy, including identifiers, commercial information, internet or electronic-network activity, geolocation information, professional or employment-related information, and inferences or account-security information.

We collect and use these categories for the business and commercial purposes described in this policy. ShiftClock does not sell employee timekeeping records or precise employee location information and does not use Customer workforce information for cross-context behavioral advertising.

13. Children's Privacy

The Services are intended for businesses and working-age users authorized by a Customer. They are not directed to children under 13.

ShiftClock does not knowingly collect personal information directly from children under 13 through a general-consumer service. If we learn that we collected such information without legally required permission, we will take reasonable steps to delete it.

Customers that employ minors are responsible for complying with applicable child-labor, consent, privacy, and employment laws.

14. Biometric Information

ShiftClock does not collect biometric identifiers unless a specific biometric feature is expressly introduced and separately disclosed.

Location coordinates, ordinary photographs, usernames, PINs, passwords, and time punches are not represented by ShiftClock as biometric identifiers.

Before enabling any future fingerprint, face-geometry, voiceprint, palm, or similar biometric feature, ShiftClock and the Customer may need separate written notices, consent, retention rules, and state-specific compliance measures.

15. Interstate and International Use

ShiftClock is operated from the United States. Information may be processed and stored in the United States and other locations where our service providers operate.

Customers are responsible for determining whether the Services meet any international, state, local, union, public-sector, or industry-specific requirements applicable to them.

16. Third-Party Services and Links

The Services may link to or integrate with third-party services, including payroll providers, payment processors, map providers, identity providers, and export destinations.

Third parties process information under their own terms and privacy policies. ShiftClock is not responsible for the privacy or security practices of unaffiliated third parties.

17. Changes to This Privacy Policy

We may update this Privacy Policy periodically. When changes are material, we may provide notice through the Services, by email, or through another reasonable method. The "Last Updated" date identifies when this policy was most recently revised.

Continued use after the effective date of an updated policy constitutes acknowledgment of the updated policy to the extent permitted by law. Where consent is legally required, we will request it separately.

18. Contact Us

Questions or requests concerning this Privacy Policy may be sent to ShiftClock at sender.shiftclock@gmail.com.