Privacy Policy

Last updated: April 9, 2026

1. Overview

In short: You own your data. We don't sell it. We only collect what we need to run the service.

This Privacy Policy explains how Clockspot, Inc. ("Clockspot," "we," "us") collects, uses, shares, and protects your information when you use our time tracking platform (the "Service").

Key points:

  • You own your data. We never sell it.
  • We collect only what's needed to provide the service.
  • GPS is event-based — we record location at clock-in/out, never continuously.
  • You can export or delete your data at any time.
  • We don't use your data for advertising.

2. Who We Are

Clockspot is operated by Clockspot, Inc. For privacy questions, contact us at privacy@clockspot.com.

Our role: When an employer uses Clockspot to track employee time, the employer is the data controller (they decide what data to collect and why) and Clockspot is the data processor (we process data on the employer's behalf to provide the service).

3. Data We Collect

In short: We collect account info, time entries, optional GPS data, and basic usage data. Nothing more.

Account data: Name, email address, company name, and billing information when you sign up.

Employee profile data: Name, email, role, department, and pay rate — as provided by your employer's administrator.

Time tracking data: Clock-in and clock-out times, hours worked, breaks, job assignments, notes, and custom field entries.

Location data (optional): GPS coordinates recorded at the moment of a clock event (clock-in, clock-out, break start/end). This is only collected when the employer enables GPS features AND the employee grants device-level location permission. We do not track routes, continuous movement, or off-duty location.

Device and usage data: Browser type, operating system, IP address, pages visited, and feature usage. Collected automatically to maintain and improve the service.

Payment data: Processed by our payment provider. We do not store full credit card numbers on our servers.

Communications: Support tickets, emails, and feedback you send us.

4. How We Collect Data

In short: Directly from you, from your employer, and automatically when you use the service.

Directly from you: When you create an account, clock in/out, submit time entries, or contact support.

From your employer: When an administrator adds your profile to a workspace, configures jobs, or sets up teams.

Automatically: When you use the Service, we collect device and usage data through cookies and similar technologies.

5. How We Use Data

In short: To run the service, generate reports, send notifications, and improve the product. That's it.

We use your data to:

  • Provide the service: Process clock events, generate timesheets, calculate hours, and run reports
  • Send notifications: Timesheet reminders, approval requests, and account alerts via email and SMS
  • Process payments: Bill your account and manage subscriptions
  • Provide support: Respond to your questions and resolve issues
  • Improve the product: Analyze usage patterns to fix bugs and build better features
  • Comply with law: Respond to legal requirements, enforce our terms, and protect rights

We do not use your data for advertising, profiling, or automated decision-making that affects your employment.

7. How We Share Data

In short: Only with service providers that help us run Clockspot. We never sell your data.

We share data with the following categories of third parties, solely to provide the Service:

  • Cloud infrastructure: Hosting and database services
  • Payment processing: For subscription billing
  • Email and SMS: For notifications and communications
  • Analytics: To understand usage patterns and improve the product
  • Error tracking: To detect and fix bugs

We do not:

  • Sell personal data to anyone
  • Share data with advertisers
  • Use employee time data for any purpose other than providing the service to their employer

We may disclose data when required by law, court order, or government request. We may also share data in connection with a merger, acquisition, or sale of assets — in which case we will notify you in advance.

8. GPS & Location Data

In short: We record location only at clock events. Not continuously. Not off-duty. Two layers of consent required.

Clockspot offers optional GPS verification. Here is exactly what we do and don't do:

What we collect:

  • GPS coordinates at the moment of a clock event (clock-in, clock-out, break start, break end)
  • Approximate accuracy of the GPS reading
  • Timestamp of the reading

What we don't collect:

  • Continuous location or movement tracking
  • Routes or travel paths between locations
  • Off-duty location data
  • Location when the app is in the background

Two layers of consent:

  1. The employer must enable GPS features for their workspace (it is off by default)
  2. The employee must grant device-level location permission when clocking in

Employees can revoke device location permission at any time through their device settings. Without permission, clock events are recorded without location data.

Retention: Location data is retained as long as your account is active and for a reasonable period after, aligned with applicable record-keeping requirements.

9. For Employers vs. Employees

For employers (workspace administrators):

  • You are the data controller for your employees' data. Clockspot processes it on your behalf.
  • You decide what data to collect (which features to enable, which custom fields to create).
  • You are responsible for having a legal basis to collect data from your employees and for complying with applicable privacy and labor laws.
  • A Data Processing Agreement (DPA) is available upon request for GDPR compliance.

For employees:

  • Your employer has engaged Clockspot to track time on their behalf.
  • Your employer controls what data is collected and how it is used.
  • You can view your own time data through the Service.
  • For data access, correction, or deletion requests, contact your employer first. If your employer is unresponsive, contact us at privacy@clockspot.com.

10. Data Retention

In short: We keep your data as long as your account is active, and for a reasonable period after to meet legal and business requirements.

We retain data for as long as your account is active and for a reasonable period after, based on the type of data and applicable legal requirements:

  • Time records: Retained to meet federal and state record-keeping requirements (e.g., FLSA, IRS)
  • GPS/location data: Retained to support applicable wage dispute and compliance timelines
  • Account and profile data: Duration of your account. You can export your data at any time.
  • Payment records: As required by tax law and our payment processor
  • Usage and analytics data: Retained for product improvement, periodically purged
  • Support communications: Retained for quality and reference

You may request deletion of your data by contacting us. Deletion requests are subject to applicable legal record-keeping requirements. Aggregated, de-identified data may be retained indefinitely.

11. Your Rights

In short: You can access, correct, export, or delete your data. Just ask.

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request that we correct inaccurate data
  • Deletion: Request that we delete your personal data
  • Export: Request your data in a portable, machine-readable format
  • Restriction: Request that we limit how we process your data
  • Objection: Object to processing based on legitimate interest
  • Withdraw consent: Where processing is based on consent, withdraw it at any time

CCPA/CPRA rights (California residents): You have the right to know what data we collect, request deletion, request correction, and opt out of the sale of personal data. We do not sell personal data.

To exercise any of these rights, email privacy@clockspot.com. We will respond within 30 days (GDPR) or 45 days (CCPA). For employees, please contact your employer first, as they are the data controller.

12. International Data Transfers

In short: Data is stored in the United States. EU transfers use Standard Contractual Clauses.

Clockspot's servers and data are located in the United States. If you are accessing the Service from outside the U.S., your data will be transferred to and processed in the U.S.

For transfers of personal data from the European Economic Area, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. A copy is available upon request.

13. Data Security

In short: Encryption in transit and at rest, access controls, and regular security reviews.

We protect your data with:

  • Encryption in transit (TLS) and at rest (AES-256)
  • Role-based access controls
  • Regular security assessments and code reviews
  • Logging and monitoring for suspicious activity
  • Incident response procedures

No system is 100% secure. If we discover a data breach that affects your personal data, we will notify you and applicable authorities as required by law.

14. Cookies

In short: We use essential cookies to keep you logged in and optional analytics cookies to improve the product.

We use the following types of cookies:

  • Strictly necessary: Session and authentication cookies required for the Service to function. These cannot be disabled.
  • Functional: Preference cookies that remember your settings (e.g., sidebar state, theme).
  • Analytics: Usage tracking to understand how the Service is used and where to improve.

We do not use marketing or advertising cookies.

EU visitors: Non-essential cookies require your consent before activation.

Global Privacy Control: We honor GPC signals from your browser. If your browser sends a GPC signal, we treat it as an opt-out of non-essential cookies.

15. Children's Privacy

Clockspot is not directed at children under the age of 16. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 16, we will delete it promptly.

16. California Residents

In short: Additional disclosures required by the California Consumer Privacy Act (CCPA/CPRA).

If you are a California resident, the following additional disclosures apply under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA):

Categories of personal information collected in the last 12 months:

  • Identifiers (name, email, IP address)
  • Professional information (employer, role, department)
  • Geolocation data (GPS coordinates at clock events, if enabled)
  • Internet activity (usage data, feature interactions)
  • Commercial information (subscription and billing data)

Categories of personal information sold: None. We do not sell personal information.

Categories of personal information shared for cross-context behavioral advertising: None.

You have the right to request access, deletion, and correction of your data, and to opt out of the sale of personal information (which we do not engage in). To make a request, email privacy@clockspot.com. We will not discriminate against you for exercising your rights.

17. Changes to This Policy

In short: We'll email you about material changes at least 30 days in advance.

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Email account administrators at least 30 days before the changes take effect
  • Post a notice within the Service
  • Update the "Last Updated" date at the top of this page

We encourage you to review this policy periodically.

18. Contact Us

For privacy questions, data requests, or concerns, email us at privacy@clockspot.com.

For general support, visit our contact page.

Clockspot

The simplest way to track employee time.
Since 2007.

© 2026 Clockspot