← Back to Clockie

Privacy Policy

Last updated: June 6, 2026

1. Who we are

Clockie is a multi-tenant HR and operations platform operated by [Shipcube Pvt. Ltd.] ("we", "us", "Clockie"). Our registered address is [REGISTERED ADDRESS]. For any privacy-related queries, contact our Data Protection Officer atprivacy@shipcube.com.

2. Roles

When you sign up your company on Clockie, your company (the "Customer") is the data controller for the employee personal data you upload, store, or process through the service. Clockie acts as the data processor, handling that data on your instructions to provide the service described in our Terms of Service.

For an individual employee using Clockie under their employer's account, your employer determines what data they collect and why. Direct questions about your data first to your employer's HR team; if they cannot resolve it, contact us.

3. Data we collect

  • Account data: name, work email, phone number, role, department, employee code, joining date, birthday.
  • Attendance: punch-in/out timestamps, location coordinates (when you grant permission), selfie photos (when you grant permission), shift assignment.
  • Leave data: leave applications, balances, policy assignments, approval history.
  • Payroll data (if your employer enables it):salary structure, tax fields, monthly entries.
  • Communication: messages and attachments you send through the in-app chat, announcements you read.
  • Device data: browser type, IP address, Firebase Cloud Messaging tokens (for push notifications), device class.
  • Audit logs: records of significant admin actions taken on your behalf (who changed what, when).

4. How we use your data

We process the data above to:

  • Provide the Clockie service as your employer has configured it.
  • Authenticate you and keep your account secure.
  • Send you operational notifications (leave decisions, chat messages, announcements).
  • Keep an audit trail of administrative actions for security and compliance.
  • Diagnose errors and improve the product (aggregated, non-identifying telemetry).
  • Comply with our legal obligations.

We do not sell your personal data. We do not use your data to train machine-learning models. We do not show third-party advertising in Clockie.

5. Where your data is stored

Clockie runs on Google Cloud Platform. Firestore (the database) is hosted in the [FIRESTORE_REGION] region. Cloud Storage (file uploads) is in [STORAGE_REGION]. Cloud Run (the application) is in us-central1. Push notifications are delivered via Google's Firebase Cloud Messaging and Apple Push Notification Service.

All data is encrypted in transit using TLS 1.2+ and encrypted at rest by Google Cloud's default storage encryption.

6. Who sees your data

Your data is accessible to:

  • You (your own profile, attendance, leave history, payslip).
  • Your employer's designated HR admins / super admins (workspace-scoped).
  • Clockie's engineering team only on an as-needed basis to provide support, with audit logging.
  • Sub-processors strictly required to run the service: Google Cloud (hosting + auth + push), [SENDGRID/RESEND] (transactional email).

We do not share data with any other party except when legally compelled (court order, subpoena), in which case we will notify the data controller (your employer) where lawful to do so.

7. How long we keep your data

While your employer is an active Clockie customer, your personal data is retained as long as it is needed to provide the service.

If your employer cancels: we retain a copy for 30 days after cancellation so the data can be restored in case of mistake. After 30 days, we permanently delete it from active storage. Backups containing the data are overwritten on a 30-day rolling cycle.

If an individual employee is deactivated:their account is locked immediately but the employer retains the data (it is the employer's record). The employee may request deletion from us, and we will forward the request to the employer.

8. Your rights

Under applicable law (India's DPDPA 2023, EU GDPR, etc.), you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request deletion (subject to your employer's record-keeping obligations).
  • Withdraw consent for processing where consent is the legal basis.
  • Lodge a complaint with your local data protection authority.

Exercise these rights by emailingprivacy@shipcube.com. We respond within 30 days. If your employer is the data controller, we may direct your request to them.

9. Security

We follow industry-standard practices: multi-tenant isolation enforced at the database and application layer, role-based access control, append-only audit logs, encrypted transit and storage, mandatory email verification for administrative accounts, and scheduled access reviews. See ourSecurity page for details.

Report security issues tosecurity@shipcube.comor via oursecurity.txt.

10. Changes to this policy

We may update this policy. Material changes will be announced in the product and emailed to your workspace admin at least 30 days before they take effect.

11. Contact

Questions? Emailprivacy@shipcube.comor write to us at [REGISTERED ADDRESS].

Pre-launch note:Items in [BRACKETS] must be filled in with real values before the first paying customer signs. Have a privacy lawyer review the full text against your jurisdiction's requirements (DPDPA in India, GDPR in EU, CCPA in California).