Privacy Policy
Effective July 29, 2026
What this policy covers
This policy explains how ClockBase handles personal information when you visit our website or use the ClockBase time tracking, workforce, payroll review, and payment-preparation services. If your employer or another organization provides your ClockBase workspace, that organization controls how your employment information is used and ClockBase processes it to provide the service.
Information we collect
- Account and identity details, such as your name, work email, employee number, contact details, country, and sign-in records.
- Work records, including shifts, breaks, departments, schedules, leave, notes, tasks, status updates, presence responses, and survey responses.
- Employment and payroll details, including placement dates, compensation terms, payout currency, pay frequency, paystubs, tax setup, deductions, and payment status.
- Technical and security information, such as IP address, browser and device information, notification subscriptions, audit events, and service logs.
- Information you send when you contact support or request access.
- Enquiry details if you submit the contact form on our public site — your name, email, and anything you choose to add — together with the referring page and any campaign tags in the link you followed. Submitting that form does not create an account.
How we use information
We use personal information to:
- authenticate users and provide the ClockBase workspace;
- record and review time, work status, schedules, leave, and employee feedback;
- prepare payroll records, paystubs, exports, and authorized payment instructions;
- send service, security, registration, password-reset, and notification messages;
- protect accounts, investigate errors, maintain audit records, and meet legal obligations; and
- operate, troubleshoot, and improve the service.
ClockBase does not sell personal information or use employee work records for advertising.
Who can access information
Authorized administrators in your workspace can access employee records as needed to manage time, work, payroll, and account settings. We also use service providers that process information for us under their own contractual and security obligations:
- Vercel for application hosting and delivery, and for cookieless aggregate analytics on the public marketing pages only;
- Supabase for authentication and database services;
- MailerSend for transactional email;
- Sentry for error monitoring, which receives technical fault reports configured to exclude personal data — no request contents, no account identity, and no session recording;
- Wise when an administrator uses an enabled payout or payment-preparation workflow; and
- browser and device push-notification services when you choose to enable notifications.
We may disclose information where required by law, to protect rights and service security, or as part of a business transaction subject to appropriate safeguards. Providers may process information outside your province or country, where it can be subject to local law.
Cookies and local storage
ClockBase uses strictly necessary authentication cookies and local browser storage for sign-in, security, interface preferences, notification state, and reliable operation. We do not use advertising cookies, marketing pixels, or session replay anywhere.
The public marketing site measures aggregate visits using Vercel Web Analytics. It is cookieless: it sets no cookie, stores nothing on your device for this purpose, assigns you no persistent identifier, and cannot follow you across other websites. It records page views and coarse signals such as referrer, country, and device type, and Vercel does not retain the full IP address. Because no personal data is stored and nothing is placed on your device, this measurement runs without a consent banner.
Analytics is deliberately limited to the public marketing pages. The signed-in ClockBase application — your dashboard, timesheets, payroll, paystubs, and every administrative screen — carries no third-party analytics, no product telemetry, and no session recording. Your working hours and pay information are never sent to an analytics provider.
If a workspace form asks for your details, only what you type is submitted. The marketing contact form additionally records the referring page and any campaign tags in its link so we know which post or advert an enquiry came from, plus a one-way hashed form of the request IP used solely to rate-limit abuse. The address itself is never stored.
If we ever add advertising, cross-site tracking, or analytics inside the signed-in application, this policy and any required consent controls will be updated before those tools are enabled.
Retention and safeguards
We keep information only for as long as needed to provide the service, meet the workspace administrator's documented requirements, resolve disputes, maintain security and audit records, and satisfy payroll, tax, accounting, or legal obligations. Retention periods vary by record type. We use access controls, encryption in transit, database security rules, server-side authorization, audit logging, and restricted administrative access appropriate to the sensitivity of the information.
Your choices and rights
You can review and update certain account information in ClockBase. For access, correction, deletion, or questions about an employment record, contact your workspace administrator first. You may also contact ClockBase. We will verify requests and respond as required by applicable law. Some records may need to be retained for payroll, tax, security, or legal reasons.
Contact
Questions or privacy requests can be sent to info@getclockbase.com. ClockBase is operated from British Columbia, Canada.