HCM

Privacy Policy

Last updated: [DATE — fill in when this is finalized]

[COMPANY LEGAL NAME] ("we," "us," or "our") provides a Human Capital Management (HCM) platform (the "Service") that organizations use to manage employee records, attendance, recruiting, performance, scheduling, and related HR functions. This policy explains what personal information we collect through the Service, how it's used, and the choices available to you.

1. Who this policy covers, and an important distinction

The Service is used by organizations ("Customers") — schools, companies, and other employers — to manage their own employees' HR data. If you are an employee of one of our Customers, your organization has entered its own agreement with you (e.g. your employment contract or staff handbook) governing how your data is used; this policy describes how we, as the software provider, handle that data on your employer's behalf.

In privacy-law terms: the Customer (your employer) is generally the data controller — they decide what employee information is entered into the Service and why. We act as a data processor, storing and processing that information only to provide, secure, and support the Service, and only under the Customer's instructions. If you have a question about your own data, your first point of contact should be your employer's HR team, who can reach us on your behalf.

2. Information we collect

Employee records, entered by your employer's HR/admin team or by you directly: name, employee ID, date of birth, personal and work contact details, address, emergency contact details, department, job title, employment dates and status, and uploaded documents (e.g. ID proof, certificates).

Attendance and location data: when you use the clock-in/clock-out feature, we record the date, time, and — if your browser grants permission — your device's GPS coordinates at that moment. Location is only captured at the instant you clock in or out; we do not track your location continuously or in the background.

Work activity content you or your organization create in the Service: leave requests, performance review content and ratings, shift schedules, recruiting/candidate records, peer recognition ("kudos") messages, and survey responses.

Account and security data: your login email, a securely hashed password (we never store your password in plain text), and a log of sign-in/sign-out events used for security auditing.

3. How we use this information

We use the information described above only to operate the Service on behalf of the Customer that added you: to display your records to authorized users at your organization, to power features like attendance tracking, scheduling, and performance reviews, to secure accounts and investigate suspicious activity, and to communicate service-related notices (such as account confirmation emails).

We do not sell personal information, and we do not use employee data to serve advertising.

4. Who we share information with

We share information with a small number of infrastructure providers ("subprocessors") who help us run the Service, under contracts that require them to protect it:

  • Supabase — database hosting, authentication, and file storage
  • Resend — transactional email delivery (e.g. account confirmation emails)
  • Vercel — application hosting

We do not share employee data with other Customers, or with any third party for their own marketing purposes. We may disclose information if required by law or to protect the rights, safety, or property of our Customers, our users, or ourselves.

5. Data security

Access to data within the Service is enforced at the database level using row-level security, so that each organization's data is isolated from every other organization's, and each user only sees the records their role permits (for example, an employee can generally see their own records and their own manager, but not the full company directory). All data is encrypted in transit (HTTPS). No method of transmission or storage is 100% secure, but we design the Service to limit access to the minimum necessary at every layer.

6. Data retention

We retain personal information for as long as the Customer's account is active, or as needed to provide the Service. If a Customer closes their account, we will delete or anonymize their data within a reasonable period, except where we're required to retain it for legal or legitimate business purposes (such as resolving disputes or enforcing agreements).

7. Your rights

Depending on where you're located, you may have rights to access, correct, or request deletion of your personal information. Because your employer controls what data is entered into the Service, the fastest way to exercise these rights is usually through your organization's HR team — they can update or remove your records directly, or route a request to us. You're also welcome to contact us directly using the details below, and we'll coordinate with the relevant Customer as needed.

8. Cookies

The Service uses a small number of strictly necessary cookies to keep you signed in and to remember your session. We don't use advertising or cross-site tracking cookies.

9. Scope

This Service is built for managing staff/employee records. If your organization is a school, this policy and the Service apply only to staff data — the Service does not collect or store student records.

10. Changes to this policy

We may update this policy from time to time as the Service evolves. We'll update the "Last updated" date above when we do, and for material changes, we'll notify our Customers directly.

11. Contact us

Questions about this policy or how your data is handled? Contact us at [PRIVACY CONTACT EMAIL].