This Privacy Policy explains how ClockWay Workforce Solutions Inc. (“ClockWay,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with the ClockWay mobile application, the ClockWay Desktop application, our websites at clockwayapp.com, and related services (together, the “Services”).
ClockWay is a workforce time-tracking and job-costing product sold to businesses. It is used by two kinds of people: administrators, who set up and manage a business account, and employees and foremen, who are invited into that account by their employer to record their working time. This policy applies to both, but as explained in Section 2, our legal role differs between them.
ClockWay records the GPS location of the device at the moment an employee clocks in or clocks out, and can require that a punch happen inside an employer-defined job-site boundary. If you are an employee, we want you to understand exactly what is and is not collected. Section 4 describes this in plain language, including the important limits on it.
1. Who we are
ClockWay Workforce Solutions Inc. is a corporation formed under the laws of Ontario, Canada. We are the party responsible for the Services and the party you can hold accountable under this policy. Our contact details are in Section 22.
2. Our two roles
Privacy law distinguishes between an organization that decides why personal information is collected and one that merely handles information on someone else’s instructions. ClockWay acts in both capacities depending on whose information is involved, and this distinction determines who you should go to with a request.
Where we are the responsible organization
For the personal information of administrators and other people who deal with us directly — the person who signs up a business, people who email our support address, and visitors to our website — we decide the purposes of collection and we are the responsible organization (a “controller,” in the language of some laws). You can exercise your rights with us directly.
Where we act only on your employer’s instructions
For the personal information of employees and foremen — time entries, GPS punch locations, hours, wage rates, signatures, and timesheets — the employer that invited you is the responsible organization. That employer decides to use ClockWay, decides whether to require location-verified or geofenced punches, decides what wage information to enter, and owns the resulting records. We handle that information as a service provider (a “processor”) acting on the employer’s instructions, and we do not use it for our own purposes.
What this means practically: if you are an employee and you want to see, correct, or delete your time records, the fastest and most reliable route is to ask your employer, because they control the account and can act immediately. You can still contact us and we will help, but in most cases we are required to refer your request to your employer rather than change their records on our own initiative. We will tell you when we do that.
3. Information we collect
We collect only what the Services need in order to function. The table below lists every category of personal information the Services collect, where it comes from, and why.
| Category | What it includes | Why we collect it |
|---|---|---|
| Account and identity | Name, first and last name, email address, password, role (administrator, employee, or foreman), the business you belong to, and the invitation or sign-up PIN used to join. | To create and secure your account and to determine what you are allowed to see and do. |
| Time and attendance | Clock-in and clock-out times, exact and rounded timestamps, break deductions, hours worked, and the job site or project a punch is attributed to. | To provide the core time-tracking function and produce records your employer relies on for payroll. |
| Location | Latitude and longitude captured at clock-in and clock-out, the accuracy reading reported by your device, and a street address derived from those coordinates. See Section 4. | To let employers verify where work began and ended and to enforce job-site boundaries where the employer has enabled that. |
| Compensation | Hourly rate, pay-period type, calculated hours and amounts, and whether a pay period has been marked paid. | To calculate payroll totals and produce pay-period and job-costing reports for the employer. |
| Signatures | Handwritten signatures drawn on screen by a foreman and, where applicable, a contractor’s representative, stored as images attached to a daily timesheet. See Section 5. | To sign off daily timesheets, which is a contractual requirement in many construction and trades settings. |
| Timesheet and job-costing records | Daily timesheets, crew hours, work classifications, quantities of work completed by item, project and site names, contractor representative names, and generated timesheet documents and invoices. | To produce the operational records your employer uses to bill and manage projects. |
| Device and technical | A push-notification token issued by the operating system, your device’s time zone, a randomly generated session identifier, and a flag indicating whether you are currently signed in. | To deliver reminders you or your employer have configured, to display times correctly, and to enforce the one-device-at-a-time rule described below. |
| Security records | The email address used in a sign-in attempt, the time of the attempt, and whether it succeeded or failed. | To detect and block password-guessing attacks by temporarily locking an account after repeated failures. |
| Communications | The content of emails you send us and the email address, first name, and business name used to send an invitation. | To respond to you and to deliver account invitations. |
Information stored on your own device
The mobile app also stores some information locally on your phone so it can work offline and stay signed in: your sign-in tokens, a copy of your user profile, your most recent location reading, your current open time entry, and any punch that could not reach our servers and is waiting to be retried. Signing out clears this local data. Uninstalling the app removes it entirely.
Single-device sign-in
To prevent one employee’s credentials from being used to punch in from two places at once, the app generates a random session identifier when an employee signs in and checks periodically that it is still the newest one. If the same account signs in elsewhere, the earlier device is signed out. This identifier is a random value we generate. It is not a hardware serial number, an advertising identifier, or any permanent identifier assigned to your device, and it cannot be used to recognise you across other apps or services.
4. Location information
Because location is the most sensitive information the Services handle, we describe it separately and in detail. We treat precise geolocation as sensitive personal information and apply the limits below.
What we collect
When an employee clocks in or clocks out, the app reads the device’s current latitude and longitude and attaches those coordinates to that punch record. Our servers then send those coordinates to the Google Maps Geocoding service to convert them into a readable street address, so that a supervisor reviewing a timesheet sees a place name rather than raw numbers. Both the coordinates and the derived address are stored with the time entry and are visible to administrators of your employer’s account.
Job-site boundaries (geofencing)
An employer can define job sites with a centre point and a radius, and can require that specified employees be inside one of those areas in order to clock in. Where that setting is enabled, the app compares your current position against those boundaries and will refuse a punch made outside them. Whether this is turned on is your employer’s decision, not ours.
Important limits on location collection
We want to be precise about what the app does not do, because these limits are real and they matter:
- The app does not track you in the background. It requests only “while using the app” location permission and does not use the operating system’s background-location facilities. When the ClockWay app is closed or in the background, it is not reading your location.
- We do not build a location history or movement trail. Coordinates are stored against clock-in and clock-out events. While the app is open in the foreground it refreshes the single most recent reading it holds so that a punch is not delayed waiting for a GPS fix, but that reading is overwritten rather than accumulated, and only the value present at the moment of a punch is saved to your record.
- We do not use location for anything other than the punch record and boundary check. It is never used for advertising, profiling, or any purpose of our own.
- You can refuse. Location permission is controlled by your device’s operating system and you may decline or revoke it at any time in your device settings. Be aware that if your employer has required geofenced punches, declining permission may prevent you from clocking in through the app, and you should speak to your employer about an alternative.
5. Signatures
Foremen using the daily timesheet feature sign on screen with a finger or stylus, and may also capture the signature of a contractor’s representative to acknowledge the day’s work. The signature is saved as an image attached to that timesheet record and is reproduced on the timesheet document generated from it.
A handwritten signature captured this way is an image of writing. It is not a fingerprint, a face scan, a voice print, or any other measurement of your physical characteristics, and we do not derive any biometric template from it or use it to identify you. We note this because some privacy statutes define “biometric identifier” in a way that expressly excludes written signatures, and we want to be clear about which side of that line this feature falls on.
6. What we do not collect
The following statements describe the Services as they exist on the effective date of this policy. We consider them commitments, and if any of them changes we will update this policy before making the change live.
- No advertising or analytics tracking. The mobile app contains no third-party analytics, crash-reporting, attribution, or advertising software. We do not track you across apps or websites, and we do not participate in advertising networks.
- No biometric data. We do not collect or store fingerprints, face scans, or voice prints. If you unlock the app using your device’s own face or fingerprint unlock, that check happens entirely on your device under the control of its operating system and no biometric information is transmitted to or stored by us.
- No camera or photo access. The mobile app does not take photographs and does not read your photo library.
- No microphone, contacts, calendar, or message access.
- No government identifiers or financial account data. We do not collect Social Insurance or Social Security numbers, driver’s licence or passport numbers, dates of birth, bank account or routing numbers, or payment card numbers.
- No special-category information. We do not collect health or medical information, union membership, religious or political beliefs, racial or ethnic origin, sexual orientation, or genetic information.
- No screen recording, keystroke logging, or productivity surveillance. The Services record when and where a punch happened. They do not monitor what you do on your device.
- No IP address logging in our sign-in records. Our own record of a sign-in attempt contains the email address, the time, and whether it succeeded. Our infrastructure providers do process network information as described in Section 10.
7. How we use information
We use personal information only for the following purposes:
- To create, authenticate, and secure accounts, including preventing simultaneous sign-ins and blocking password-guessing attacks.
- To record working time and produce the timesheets, pay-period summaries, job-costing reports, invoices, and exports that our business customers use.
- To verify where a shift started and ended, and to enforce job-site boundaries where an employer has enabled them.
- To send the operational messages the Services depend on: account invitations, password resets, and the clock-in and clock-out reminders you or your employer configure.
- To provide customer support and respond to your enquiries.
- To maintain, troubleshoot, secure, and improve the Services, including diagnosing errors and preventing fraud and abuse.
- To comply with our legal obligations and to establish, exercise, or defend legal claims.
Under Canadian privacy law we rely on consent for our collection, use, and disclosure of personal information, which in an employment context is generally obtained by the employer from its employees. Where a law that uses a “legal basis” framework applies to you, our bases are the performance of our contract with our business customer, our legitimate interest in securing and operating the Services, and compliance with legal obligations.
We do not use personal information to train artificial intelligence or machine learning models, and we do not make automated decisions that produce legal or similarly significant effects about you. Calculations such as rounding a punch to the nearest quarter hour or deducting a scheduled break follow rules your employer configures, and your employer can review and adjust the result.
8. Employer responsibilities
Monitoring the location of workers is regulated, and the obligations fall on you as the employer, not on us. Depending on where you and your workers are located, you may be required to notify employees in writing before tracking their location, obtain their consent, maintain a written electronic-monitoring policy, or provide copies of that policy to staff within set time limits. Ontario employers above a certain size, for example, must maintain a written policy on electronic monitoring of employees. Several U.S. states separately restrict or require notice before tracking an employee’s location.
By using the Services you confirm that you have provided all notices and obtained all consents and authorisations required by the laws applicable to you before entering employee information into ClockWay or enabling location-verified or geofenced punches. You are responsible for the accuracy of the information you enter, for the lawfulness of the purposes for which you use it, for responding to your employees’ requests about their own records, and for how you configure the Services. We provide the tool; the decision to use it in a particular way, and the legal consequences of that decision, are yours.
9. When we disclose information
We disclose personal information only in these circumstances:
- Within your business account. Administrators of the business you belong to can see your profile, your time entries and their locations, your hours, your wage rate, and timesheets you are part of. Co-workers in the same business may see your name and hours where the feature requires it, such as on a crew timesheet.
- To service providers. To the vendors listed in Section 10, who process information on our behalf under contractual confidentiality and security obligations and who are not permitted to use it for their own purposes.
- Where you direct it. When an administrator exports data, generates a document, or connects an optional integration as described in Section 17.
- For legal reasons. Where we are required by law, regulation, legal process, or an enforceable governmental request, or where disclosure is necessary to investigate or prevent fraud or a threat to someone’s safety, or to establish, exercise, or defend legal claims. Where we are permitted to do so, we will notify the affected customer before disclosing their information.
- In a corporate transaction. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will require the recipient to honour this policy, and we will give notice before your information becomes subject to a materially different policy.
10. Service providers
We build on established infrastructure rather than operating our own data centres. The following are the service providers that may process personal information on our behalf, and what each receives.
| Provider | Function | Information processed |
|---|---|---|
| Google Cloud / Firebase | Authentication, database, application servers, file storage, and website hosting | All account, time, location, compensation, timesheet, and signature data; passwords are handled by Google’s authentication service and are never visible to us |
| Google Maps Platform | Converting coordinates into street addresses; address search and autocomplete | Latitude and longitude of punches; address text typed into a search box |
| SMTP2GO | Sending invitation and notification email | Recipient email address, first name, business name, inviting administrator’s name, and message content |
| Expo | Delivering push notifications, which are passed on to Apple Push Notification service or Google Firebase Cloud Messaging for final delivery | Push notification token and the text of the reminder being delivered |
| Cloudflare | Domain name service and inbound email routing for our support address | Network request information; the content of email you send to our published addresses |
| Fly.io | Hosting a real-time session-coordination server | User identifier, role, and session tokens while a session is active; this server holds information only in memory and does not store it |
| GitHub | Distributing the desktop application and its updates | No account information. Standard network information such as IP address is processed when your computer downloads a file or checks for an update |
We do not currently charge for the Services. If we introduce paid plans, card payments will be handled by a third-party payment processor, we will identify that processor in this policy before doing so, and we will not store full payment card numbers ourselves.
11. No sale, no advertising
We do not sell personal information, and we never have. We do not share it for cross-context behavioural advertising or targeted advertising. We do not disclose it to data brokers, advertising networks, or list vendors. We do not use it to build advertising profiles. This applies to every category of information described in this policy, including location, and it applies to everyone regardless of where they live.
12. How long we keep information
Time and payroll records are business records that employers are typically required by employment standards and tax law to retain for a number of years. Because our business customers rely on ClockWay to hold those records, we retain the data in a business account for as long as that account remains active, and we do not automatically delete time entries, timesheets, or payroll records on a fixed schedule. Deciding how long to keep those records is the employer’s responsibility.
Some information has a defined lifespan:
- Employee invitation links expire seven days after they are issued.
- Employee sign-up PINs expire twenty-four hours after they are generated.
- Links to generated invoice documents expire seven days after they are created.
- Locally cached data on your device is cleared when you sign out.
- Real-time session information held by the session-coordination server is discarded when the connection ends and in any event within minutes.
When an administrator removes an employee from a business, we delete that person’s sign-in credentials, their user profile, and their individual time entries. Records that belong to the business as a whole and that reference their work — completed daily timesheets, including any signature on them, job-costing entries, generated documents, and sign-in attempt records — are retained as part of the employer’s business records unless the employer instructs us to remove them. If you want those records deleted as well, contact us and we will action a verified request as described in Section 14.
When a business closes its account, we will delete or irreversibly anonymise its data within ninety days of a written request from an authorised administrator, except where we are required to retain something by law. Backups may persist for a short additional period before being overwritten in the ordinary course.
13. Security
We use safeguards appropriate to the sensitivity of the information we hold. Data is encrypted in transit using current TLS standards and encrypted at rest by our infrastructure providers. Passwords are handled by Google’s authentication service, which stores them in salted and hashed form; we never see or store your password. Access to data is enforced at the database level by rules that confine each account to the business it belongs to and restrict administrative functions to administrators of that same business. Accounts are temporarily locked after repeated failed sign-in attempts. Access to production systems by our personnel is limited to what is needed to operate and support the Services.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your password confidential and for not sharing your account. If you believe your account has been compromised, or if you discover a security vulnerability in the Services, please tell us promptly at support@clockwayapp.com. If a breach of security safeguards creates a real risk of significant harm, we will notify affected individuals and the appropriate regulators as required by law.
14. Your privacy rights
Subject to the limits the applicable law allows, you may ask us to do any of the following:
- Access the personal information we hold about you, and be told how it is used and to whom it has been disclosed.
- Correct information that is inaccurate or incomplete.
- Delete personal information, where we are not required to keep it.
- Withdraw consent to our use of your information, on reasonable notice, understanding that doing so may mean we can no longer provide the Services to you.
- Receive a copy of information you provided to us in a portable format.
- Complain about how we have handled your information, without being penalised for doing so.
Write to support@clockwayapp.com to make a request. We will acknowledge it promptly and respond within thirty days, or tell you within that period why we need longer and how much longer we need. We may need to verify your identity before acting, and we will only ask for what is necessary to do that. Exercising these rights is free; if a request is excessive or repetitive we may charge a reasonable fee, but we will tell you the amount and give you the chance to withdraw or narrow the request first.
If you are an employee or foreman, please read Section 2. Your employer controls your time records. We will forward your request to them, tell you that we have done so, and assist them in responding, but we will not alter or delete an employer’s business records without their instruction except where the law requires us to.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, to the privacy regulator in your province, or to whichever authority supervises privacy where you live.
15. U.S. state privacy rights
If you live in a U.S. state with a comprehensive consumer privacy law, such as California, Colorado, Connecticut, Virginia, Utah, or Texas, you may have the rights to know what personal information is collected about you and how it is used and disclosed, to obtain a copy of it, to correct inaccuracies, to delete it, and not to be discriminated against for exercising those rights. We honour these requests through the same channel described in Section 14, and you may use an authorised agent to make a request on your behalf.
For California residents specifically: the categories of personal information we collect, our purposes, and the categories of recipients are set out in Sections 3, 7, 9, and 10 of this policy, which serve as our notice at collection. Precise geolocation is sensitive personal information under California law. We collect it only to perform the service you and your employer have asked for — recording and verifying a punch — and we do not use or disclose it to infer characteristics about you. Because our use is limited to purposes the statute permits, no separate right to limit its use arises; we nonetheless commit not to use it for anything beyond what Section 4 describes. We do not sell personal information and we do not share it for cross-context behavioural advertising, including for anyone we know to be under sixteen.
16. International transfers
We are based in Canada. Our application servers run in the United States, and our service providers may process information in the United States, Canada, or other countries where they or their own subcontractors operate. Wherever information is held, it is subject to the laws of that jurisdiction, which means courts, law enforcement, and national security authorities there may be entitled to obtain access to it under that country’s law. When we transfer personal information across borders we use contractual protections and require standards of protection comparable to those described in this policy. If you would like more detail about our practices concerning transfers or service providers, contact us at the address in Section 22.
17. Optional integrations
The ClockWay Desktop application can connect to Microsoft Excel through Microsoft Graph, and to Google Sheets and Google Drive, so that an administrator can import or export payroll and timesheet data. These connections are entirely optional and are established only when an administrator signs in to the third-party service and authorises access. When one is used, that provider receives the administrator’s identity with that service and whatever spreadsheet content is imported or exported, which may include employee names, hours, and pay information. The provider then handles that information under its own privacy policy and terms, not ours. You may revoke access at any time in your Microsoft or Google account settings.
18. Website and cookies
Our public website does not set cookies, does not use browser storage to track you, and does not load Google Analytics or any other analytics or advertising script. There is no tracking pixel and no advertising beacon.
The site does load two resources from third-party networks: a typeface from Google Fonts and an icon set from the Cloudflare CDN. Loading a file from another server necessarily reveals your IP address and basic browser information to that server, which those providers may log for security and delivery purposes. We receive nothing from them and they are not permitted to use these requests to track you across sites. Our web host also processes standard request information in order to serve pages and protect against abuse.
The account-setup page reached from an invitation email sends the invitation token and the password you choose to our servers so your account can be created. That page loads app-store badge images from Apple and Wikimedia, which likewise see your IP address as part of serving those images. The password you type is transmitted directly to our authentication provider over an encrypted connection and is never visible to us.
19. Push notifications
If you allow notifications, we store the token your device’s operating system issues so we can send you the clock-in and clock-out reminders configured for your business, together with your time zone so reminders arrive at the right local time. These are operational messages, not marketing. You can turn notifications off at any time in your device settings, which stops delivery; ask us and we will delete the stored token.
20. Children
The Services are workplace tools intended for use by employers and their workers. They are not directed at children, and we do not knowingly collect personal information from anyone under sixteen. Accounts are created only by an employer inviting a worker or by an administrator registering a business. If you believe a child has provided us with personal information, contact us and we will delete it. Where a young person is lawfully employed and their employer uses ClockWay, the employer is responsible for obtaining any consent required for a minor.
21. Changes to this policy
We may update this policy as the Services change or as the law requires. When we do, we will revise the “last updated” date at the top of the page. If a change materially reduces your rights or materially expands how we use your information — for example, if we began collecting a new category of information or added a service provider that receives sensitive information — we will give notice by email to account administrators or through the Services at least thirty days before the change takes effect, so that you have an opportunity to review it. Continuing to use the Services after a change takes effect means you accept the updated policy.
22. How to contact us
For any question, request, or complaint about privacy, including a request to exercise the rights in Section 14, contact our Privacy Officer:
ClockWay Workforce Solutions Inc.
Attention: Privacy Officer
30 Westwyn Court
Brampton, Ontario L6T 4T5
Canada
Email: support@clockwayapp.com
Please put “Privacy Request” in the subject line so we can route your message quickly. If you are an employee asking about your own time records, telling us the name of your employer will help us respond faster.