Legal
Privacy Policy
Last updated 20 August 2026
This policy explains what personal data the TimeGate platform handles, why it is handled, and what rights you have over it. It covers the TimeGate web dashboard, the TimeGate mobile app, and the TimeGate API.
TimeGate is sold to employers. If you use TimeGate because your employer gave you an account, your employer decides what data is collected and how long it is kept. In data protection terms your employer is the controller and TimeGate is the processor acting on their instructions. Questions about your own record should go to your HR team first.
Data we collect
The platform holds the following categories of data.
- Account and identity data: name, work email, employee number, job title, branch, reporting line and role. This is supplied by your employer, not by us.
- Attendance records: check-in and check-out timestamps, the shift the punch belongs to, and any corrections or notes attached to a day.
- Location data: latitude, longitude and accuracy at the moment you punch, collected only when your employer has enabled geofence verification. The app requests location permission before this happens, and a punch is the only time it is read.
- Network data: the SSID and BSSID of the Wi-Fi network your device is joined to at the moment you punch, collected only when your employer has enabled Wi-Fi verification. We use it to confirm you are on the branch network. We do not read traffic on that network.
- Photos: a photo captured at the moment of a punch, collected only when your employer has enabled photo verification, plus a profile photo if you upload one.
- Leave and absence data: requests, dates, leave type, balances, supporting documents you attach, and the approval trail.
- Device data: a device identifier and a push notification token, used to deliver notifications and to flag when an account is used from an unexpected device.
- Support data: messages you send us and the records needed to answer them.
Why we handle it
Attendance, leave and scheduling data is handled so your employer can run its workforce: recording hours, approving leave, producing payroll input and meeting record-keeping duties under local labour law.
Location, network and photo data is handled for one narrow purpose, which is confirming that a punch was made by the right person at the right place. Each of these checks is optional and is switched on by your employer, not by us. Where the law requires consent for a check, your employer is responsible for obtaining it.
We also handle limited data to keep the service running and secure, including diagnosing faults and preventing unauthorised access.
What we do not do
We do not sell personal data. We do not share it with advertisers, and we do not use it to build advertising profiles.
We do not track your location in the background for its own sake. Location is read at the moment of a punch and not between punches.
We do not use your attendance or leave data to train machine learning models offered to other customers.
Who we share it with
Data is shared only where it is needed to run the service.
- Your employer, including the HR, payroll and management users your employer has authorised.
- Infrastructure providers that host the platform and its databases, under contract and bound to confidentiality.
- Authorities, where we are legally required to disclose.
- A successor entity, if the business is transferred, subject to this policy continuing to apply.
How long we keep it
Retention is set by your employer, because employment records are usually governed by local labour and tax law. When your employer deletes their account, we delete or irreversibly anonymise the data associated with it within 90 days, except where we must retain something to meet a legal obligation.
Backups are rotated on a fixed schedule, so a deleted record can persist in an encrypted backup for a short period after deletion before it is overwritten.
Security
Traffic between the apps and our servers is encrypted in transit. Credentials are stored using one-way hashing, and session tokens on mobile are kept in the operating system secure store rather than in general app storage.
Access to production data is limited to the people who need it to operate the service, and sensitive payroll fields are encrypted at rest with a key held outside the database.
No system is perfectly secure. If a breach affects your data, we notify the affected employer without undue delay so they can meet their own notification duties.
Your rights
Depending on where you live, you may have the right to ask for a copy of your data, to correct it, to delete it, to restrict or object to how it is handled, and to receive it in a portable format.
Because your employer controls the record, please raise these requests with your HR team. If you contact us directly we will forward the request to them and support them in answering it. You also have the right to complain to your local data protection authority.
International transfers
The platform is hosted on infrastructure that may be located outside your country. Where data moves across borders we rely on the safeguards our infrastructure providers offer, including standard contractual clauses where they apply.
Children
TimeGate is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16 other than through a lawful employment relationship.
Changes to this policy
If we change this policy we update the date at the top of the page. Where a change materially affects how personal data is handled, we tell the employers using TimeGate before it takes effect.
Contact
Questions about this policy can go to hello@timegate.me.
