Privacy Policy
This policy explains how TimeOff Manager and TimeOff Kiosk collect, use, and protect information across our web platform and mobile apps.
Effective date: September 14, 2026
1. Scope
This Privacy Policy applies to TimeOff Manager on the web, the Timeoff Manager employee/manager app on iOS and Android, and the TimeOff Kiosk clock-in app. It covers company administrators, managers, employees, and invited users who access our services.
2. Information We Collect
- Account and profile data: name, email, role, employee number, company assignment, and profile avatar.
- Workforce and HR data: schedules, time entries, leave requests, approvals, payroll-related records, and compliance workflow data entered by authorized company users.
- Clock-in/out data: timestamps, location coordinates, assigned work location, IP address, and related device/session metadata.
- Photos: selfie images for clock-in/clock-out verification when enabled by your company settings.
- Mileage data: trip locations, distances, optional trip photos/documents, and GPS points while a live mileage trip is running in the app.
- Live shift location: approximate GPS coordinates while an employee is clocked in, or in the 30 minutes before a scheduled start, when the employer enables live location and the employee consents in the app. The current map pin expires in about 45 seconds. A short on-shift trail (about 30 minutes) and a manager GPS history (about 45 business days) may be stored separately from payroll and leave records. Collection happens while the Timeoff Manager app is in use (not as always-on background tracking unless the device keeps the app running).
- Staff messages: text, optional links, and optional images that managers send to their team or company.
- Authentication/session data: login/session identifiers, IP and user-agent details, API access token data, optional Face ID unlock on device, optional Google sign-in identifiers, and push-notification device tokens.
- Support and communication data: information you provide when contacting support.
3. Mobile App Permissions (iOS and Android)
- Location: used to validate work-location attendance, geofence rules, location-based time records, live mileage trips, and (if enabled by the employer and consented to by the employee) to show approximate location on a manager map starting 30 minutes before a scheduled shift and while clocked in. Sharing stops at clock-out. The app requests location while it is in use.
- Camera: used to capture selfie photos during clock events when required.
- Face ID / biometrics: optional, on-device unlock after you have already signed in. We do not receive your biometric template.
- Notifications: optional push tokens so the app can deliver leave, time, mileage, and company-message alerts.
TimeOff Kiosk may ask for photo-library access only if someone attaches a screenshot when reporting a problem. Clock-in photos are taken with the camera, not the library. Permission prompts are managed by your device OS and can be changed in settings.
4. How We Use Information
- Provide time tracking, leave management, scheduling, payroll support, and reporting features.
- Verify attendance, apply company-configured policy rules, and support approval workflows.
- Maintain account security, prevent abuse, and troubleshoot technical issues.
- Operate, monitor, and improve platform reliability and performance.
- Respond to support requests and administrative communications.
5. Legal bases and roles (controller vs processor)
For workforce data your employer enters about you, the employer is generally the data controller and PositionMySite acts as a data processor operating TimeOff Manager on the employer’s instructions. Your employer configures product features (including GPS, geofencing, live shift location, staff messages, and photo verification) and determines how data is used.
See our Data Processing Addendum and Subprocessors list for more detail.
6. Sharing and Disclosure
We do not sell personal information. We may share data only as needed to operate the service, including:
- With your organization’s authorized admins/managers according to role-based permissions.
- With infrastructure and service providers supporting hosting, maps/geocoding, notifications, and platform operations.
- When required by law, legal process, or to protect rights, safety, and service integrity.
7. Data Retention
We retain information for as long as needed to provide the service, satisfy legal and accounting requirements, resolve disputes, and enforce agreements. Some data retention settings are controlled by your organization.
When photo verification is enabled, clock-in/out selfie images are retained for 30 days by default (employers may choose 7, 30, or 90 days) and then deleted from the service, while related attendance timestamps may be kept longer according to employer settings. Live-map “current location” pings expire in about 45 seconds. A short trail (about 30 minutes) and GPS history for authorized managers (about 45 business days) may be kept in a store separate from payroll and leave records.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information. No method of transmission or storage is 100% secure, but we continuously work to protect customer data. See our Security page for more information.
9. Your Choices and Rights
- You can update certain account/profile information through your account or administrator.
- You can manage app permissions (location/camera) in your device settings.
- Employees: If you want to access, correct, or delete personal data we process about you, contact your employer first. Your employer controls the account and most workforce records. They may use export tools or contact us for assistance under our Data Processing Addendum.
- Employer administrators may contact us directly at [email protected] for account-level requests.
10. Contact
If you have privacy questions, contact us: