Privacy policy
Last updated [date]
Who we are
PadClock is run by [company legal name], a New Zealand company (NZBN [number]), at [address]. When this policy says “we”, it means us. You can contact our privacy officer at [privacy email].
PadClock is used by businesses (our customers) to record their employees' hours. For employee time records, the business that employs you decides what is recorded and why. We hold that information on the business's behalf.
What we collect
- Admin accounts: name, email address and sign-in details for the owner and any admins, and which organisation they belong to.
- Employee details from Xero: names, job titles, whether they're active, and their Xero employee identifiers. These come from the business's Xero Payroll account when it's connected.
- Kiosk PINs: a 4-digit PIN for each employee, used to clock in and out.
- Time records: each clock-in and clock-out, the tablet it was made on, unpaid breaks, and any changes an admin makes, including who made them and when.
- Xero connection: the access tokens Xero gives us when a business connects, plus pay calendar and pay period details.
- Kiosk devices: a name and identifier for each paired tablet.
- Billing: subscription status and dates. Card payments are handled by Stripe. We never see or store card numbers.
- Email settings: who has chosen to receive the daily open-shift email.
How we use it
To run the service: record hours, work out unpaid breaks, show the dashboard, send timesheets to the business's Xero Payroll account when an admin pushes them, send the emails a business has turned on (such as trial reminders and the daily open-shift email), and bill the subscription. We don't sell personal information and we don't use it for advertising.
Who we share it with
- Xero, when a business connects its account and pushes timesheets.
- Stripe, for subscription payments.
- Google Cloud / Firebase, which hosts the app and its data. [Confirm data region, e.g. australia-southeast1]
- [Email delivery provider, if any]
Some of these providers store data outside New Zealand. [Describe the safeguards relied on under IPP 12.]
How long we keep it
We keep a business's records while its account exists, including after a subscription ends, so the business can still download them. When the owner deletes the account as its only member, the organisation and its data are deleted. [Confirm backup retention period.]
Security
Access is limited to signed-in admins of each organisation. Kiosk tablets use a device token rather than an admin login, and leaving the kiosk needs the admin PIN. [Add encryption, access-control and breach-notification details.]
Your rights
Under the Privacy Act 2020 you can ask to see the personal information we hold about you and ask us to correct it. If you're an employee, it's usually quickest to ask your employer, who can see and correct your time records. You can also contact us at [privacy email]. If you're not happy with our response, you can complain to the Office of the Privacy Commissioner.
Changes
If we change this policy we'll update the date above, and tell account owners by email about anything significant.
