Legal
Privacy policy
Last updated July 2026 · Draft. Review by counsel before you rely on it
Who we are
Formclock is workforce scheduling, time tracking and coverage automation for businesses. The operating entity is [Formclock operating entity, to be completed]. Until that is filled in, treat this as a draft: it describes the product accurately, but it has not been reviewed by a lawyer.
This policy describes what the product does today. Where something is not built, it says so, rather than describing an intention as though it were a feature.
Who controls what
When a business uses Formclock, that business decides what goes into it. For workforce data (people, schedules, punches, timesheets, leave) the customer is the controller and we are their processor, acting on their instructions.
For our own account records (the person who signed up, their email address, their sign-in session) we are the controller.
The distinction matters when an employee asks us to delete their data. Usually we cannot. It is their employer's record, not ours to erase. We will forward the request and help the employer act on it.
What we collect
People: names, work email addresses, optional phone numbers and avatars, roles, employment type, and any notes a manager writes about them.
Work: schedules and shifts, clock-in and clock-out times, breaks, timesheets, pay rates and the labour cost computed from them, leave requests, availability, shift messages and announcements.
Clock-in location, only if your workspace enables geofencing and only if the browser grants permission. We record the coordinates at the moment of the punch, and whether they placed the person inside the workplace boundary.
Clock-in photos, only if your workspace enables them. They are stored in our own database, not handed to a third party.
Kiosk PINs, stored only as a keyed hash. We never store, and cannot recover, the PIN itself.
Sign-in identity: your email address and a session record. There are no passwords, because Formclock does not have passwords.
IP addresses, used solely as a rate-limiting key to stop brute-force attempts and abuse. They are kept only for the length of the rate-limit window, and they are not attached to your punches, your audit trail or your session.
We do not ask for special category data such as health information, and we do not want it. Be aware that a free-text field, such as the reason on a leave request, is somewhere a person could type one. Please treat those fields accordingly.
What we do not do
We do not use analytics or advertising cookies. There are none in the product, which is why you have not been shown a consent banner.
We do not sell personal data, and we do not share it for advertising.
We do not send your data to an external AI service. The coverage agent that ranks candidates and fills open shifts is ordinary code running on our own servers. Nothing your team types is sent to a model, by us or by anyone else, and none of your data is used to train one.
How long we keep it
Clock-in photos are deleted after 90 days, automatically. The punch remains. The picture does not.
Clock-in coordinates are erased after 90 days, automatically. We keep whether the punch was inside the geofence, because that is the record a manager may need to review months later. We discard the coordinates it was derived from, because they pinpoint a person at a minute and answer no question that the first answer does not.
Sign-in sessions expire after 7 days. Deactivating someone revokes their sessions immediately.
Everything else (people, schedules, punches, timesheets, the audit trail) is kept for as long as the workspace exists. Employment records are records: a business needs last year's timesheets, and expiring them on a timer would be the wrong default.
Archiving an employee inside the product is deliberately not erasure. It takes them off rotas and stops billing for them, and it keeps their pay history, because the business still needs it. If you want a person genuinely erased, ask us. See below.
Who else sees your data
Three services receive data when you use Formclock. Resend delivers our email, so it sees the recipient's address and the message. Sentry receives error reports, configured not to attach IP addresses, headers or cookies, with no session recording. Google sees your email address and name, but only if you choose to sign in with Google.
Two more host us, rather than being called by us: Vercel runs the application and Supabase runs the database.
The full list, with what each one receives, is on our subprocessors page. If we add another, we will update it.
Security
Formclock has no passwords. You sign in with a single-use link that expires in fifteen minutes, or with Google. There is no password to steal, reuse or leak.
Permissions are enforced on the server, not merely hidden in the interface, and every query is scoped to your workspace. Database-level row security policies are written and tested but are not yet switched on in production, so we will describe the protection you actually have rather than the one we are ready to turn on: application-level scoping on every read and every write.
Traffic is encrypted in transit. Encryption at rest is provided by our hosting platform. The application does not add a layer of its own, and we would rather tell you that than imply something we have not built.
Kiosk PINs are stored as keyed hashes and compared in constant time. Sensitive endpoints are rate limited in the database, so the limit holds across servers rather than per machine.
We do not offer multi-factor authentication, and we hold no security certifications. No SOC 2, no ISO 27001. You should know that now rather than discover it later.
Your rights, and how to use them
You can ask for a copy of your data, ask us to correct it, or ask us to erase it. Write to privacy@formclock.com and we will respond within 30 days.
Being straight about the mechanics: there is no self-service delete button and no one-click export in the product today. We handle these requests by hand, against a written procedure. It works, and we would rather say it is manual than let you assume it is automatic.
If you are an employee of a business that uses Formclock, send your request to your employer first. They control that data. If you send it to us, we will pass it on to them.
Deleting a workspace removes the workspace and everyone in it. Copies may survive for a limited period in our hosting platform's backups, which we cannot reach into and edit.
Where your data lives
The application runs on Vercel and the database runs on Supabase, which may mean your data is processed outside your own country. We rely on the standard contractual protections those providers offer.
We are not yet running a production deployment, so the production region is not fixed. This section will be updated with the specifics before we take a paying customer, rather than describing a setup we do not have.
Children
Formclock is a workplace tool. It is not intended for anyone under 16, and we do not knowingly collect their data.
Changes to this policy
We will post changes here and update the date at the top. If a change materially affects how we handle data, we will tell account admins rather than rely on you noticing.
Contact
privacy@formclock.com