Legal

Privacy policy

Last updated July 2026

What this page covers

  • Who we are, and who controls your data.
  • What we collect, and why we collect it.
  • Who else can see it, and how long we keep it.
  • Your rights, and how to use them.

About 5 minutes to read.

Who we are

Formclock is workforce scheduling, time tracking and coverage automation for businesses.

Formclock is operated by Azeez A, an independent software provider based in Ilfov, Romania. When you use Formclock you are contracting with Azeez A.

We are the controller for the account records we hold about you, and you can reach us about this policy at privacy@formclock.com.

This policy describes what the product does today. Where something is not built, it says so, rather than describing an intention as though it were a feature.

Who controls what

When a business uses Formclock, that business decides what goes into it. For workforce data (people, schedules, punches, timesheets, leave) the customer is the controller and we are their processor, acting on their instructions.

For our own account records (the person who signed up, their email address, their sign-in session) we are the controller.

The distinction matters when an employee asks us to delete their data. Usually we cannot. It is their employer's record, not ours to erase. We will forward the request and help the employer act on it.

What we collect

Only what the product needs to do its job. In detail:

We do not ask for special category data such as health information, and we do not want it. Be aware that a free-text field, such as the reason on a leave request, is somewhere a person could type one. Please treat those fields accordingly.

People.
names, work email addresses, optional phone numbers and avatars, roles, employment type, and any notes a manager writes about them.
Work.
schedules and shifts, clock-in and clock-out times, breaks, timesheets, pay rates and the labour cost computed from them, leave requests, availability, shift messages and announcements.
Clock-in location.
only if your workspace enables geofencing and only if the browser grants permission. We record the coordinates at the moment of the punch, and whether they placed the person inside the workplace boundary.
Clock-in photos.
only if your workspace enables them. They are stored in our own database, not handed to a third party.
Kiosk PINs.
stored only as a keyed hash. We never store, and cannot recover, the PIN itself.
Sign-in identity.
your email address and a session record. There are no passwords, because Formclock does not have passwords.
IP addresses.
used solely as a rate-limiting key to stop brute-force attempts and abuse. They are kept only for the length of the rate-limit window, and they are not attached to your punches, your audit trail or your session.

What we do not do

We use no advertising cookies, and neither of our analytics tools tracks you across other sites. Vercel Web Analytics measures the site first-party and cookieless: it counts page views, with no cookie and no identifier. Google Analytics is optional and loads only if you accept the consent banner, with IP anonymisation and every advertising signal switched off. Decline and it never loads. The cookie policy lists exactly what each one sets.

We do not sell personal data, and we do not share it for advertising.

We do not send your data to an external AI service. The coverage agent that ranks candidates and fills open shifts is ordinary code running on our own servers. Nothing your team types is sent to a model, by us or by anyone else, and none of your data is used to train one.

How long we keep it

Most records live as long as your workspace does; the sensitive extras are deleted on a timer.

Archiving an employee inside the product is deliberately not erasure. It takes them off rotas and stops billing for them, and it keeps their pay history, because the business still needs it. If you want a person genuinely erased, ask us. See your rights below.

DataHow long we keep it
Clock-in photos90 days, then deleted automatically. The punch remains. The picture does not.
Clock-in coordinates90 days, then erased automatically. We keep whether the punch was inside the geofence, because that is the record a manager may need months later, but we discard the coordinates it was derived from.
In-app notifications180 days once you have read one, 365 days if you never did, then deleted automatically. A notification only points at something else: the shift, leave request or announcement it refers to is kept as long as your workspace is.
Files attached to messages and announcements365 days, then deleted automatically. The message or announcement itself stays; only the attached file expires. Download anything you need to keep.
Sign-in sessions7 days. Deactivating someone revokes their sessions immediately.
People, schedules, punches, timesheets, audit trailAs long as the workspace exists. Employment records are records: a business needs last year's timesheets, and expiring them on a timer would be the wrong default.
Billing records: invoices, receipts, what was chargedKept for as long as tax and accounting law requires, which is longer than the workspace itself. Deleting a workspace does NOT delete the invoices already issued to it: once we have taken a payment we are legally obliged to be able to show what it was for. These records hold the billing name, address and amount, never the card number.
A closed workspaceDeleting a workspace starts a 60-day recovery window: everything stays intact and any admin can reactivate it. After 60 days it is permanently erased, the workspace and every person, schedule and record in it, along with the sign-in identities behind them. The one exception is the billing records above, which tax law obliges us to keep.

Who else sees your data

Three services receive data when you simply use Formclock. Resend delivers our email, so it sees the recipient's address and the message. Sentry receives error reports, configured not to attach IP addresses, headers or cookies, with no session recording. Google sees your email address and name, but only if you choose to sign in with Google. A fourth, Stripe, is involved only if you buy a paid plan; it is described below.

Two more host us, rather than being called by us: Vercel runs the application and Supabase runs the database.

When you buy a paid plan, Stripe processes the payment on our behalf and receives the data needed to take it, manage the subscription, and calculate tax: your name, email, billing address and payment details. Your card details go to Stripe directly and are never seen or stored by us. Stripe acts as our payment processor, and also as a controller of that data for its own fraud-prevention and legal obligations; how Stripe handles it is set out in Stripe's own privacy policy.

The full list, with what each one receives, including the consent-based Google Analytics, is on our subprocessors page. If we add another, we will update it.

Security

Formclock has no passwords. You sign in with a single-use link that expires in fifteen minutes, or with Google. There is no password to steal, reuse or leak.

Permissions are enforced on the server, not merely hidden in the interface, and access is scoped to your workspace in two independent layers. Every read and every write is scoped to your workspace in the application, and Postgres row-level security policies gate each tenant table in the database itself. A query that ever slipped past the application layer would still return nothing that is not yours.

Traffic is encrypted in transit. Encryption at rest is provided by our hosting platform. The application does not add a layer of its own, and we would rather tell you that than imply something we have not built.

Kiosk PINs are stored as keyed hashes and compared in constant time. Sensitive endpoints are rate limited in the database, so the limit holds across servers rather than per machine.

We do not offer multi-factor authentication, and we hold no security certifications. No SOC 2, no ISO 27001. You should know that now rather than discover it later.

Your rights, and how to use them

Under the GDPR you can ask us to give you a copy of your data, correct it, erase it, restrict or object to how we use it, or hand it over in a portable form. Where we rely on your consent, you can withdraw it at any time. Write to privacy@formclock.com and we will respond within 30 days.

If you are in the EEA and believe we have handled your data wrongly, you also have the right to complain to your local data protection authority. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro).

Being straight about the mechanics: an admin can permanently delete an entire workspace from its settings, which starts the 60-day recovery window described above. There is no one-click data export, and no self-service way to erase a single person while keeping the workspace, so we handle those by hand, against a written procedure, and would rather say it is manual than let you assume it is automatic.

If you are an employee of a business that uses Formclock, send your request to your employer first. They control that data. If you send it to us, we will pass it on to them.

Deleting a workspace removes the workspace and everyone in it after the 60-day recovery window, along with the sign-in identities behind it. Two things outlive it, and we would rather name them than let you discover them: invoices and receipts for payments already taken, which tax law obliges us to keep, and copies in our hosting platform's backups, which we cannot reach into and edit and which age out on their own.

Where your data lives

Formclock runs on Vercel (the application) and Supabase (the database), sends email through Resend, monitors errors through Sentry, offers optional sign-in through Google, and takes payment for paid plans through Stripe. Some of these providers process data on servers outside the European Economic Area, including in the United States.

Where data is transferred outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses, or an equivalent adequacy decision, which each of these providers offers as its safeguard under the GDPR. You can ask us for more detail at privacy@formclock.com.

Children

Formclock is a workplace tool. It is not intended for anyone under 16, and we do not knowingly collect their data.

Changes to this policy

We will post changes here and update the date at the top. If a change materially affects how we handle data, we will tell account admins rather than rely on you noticing.

Contact

Questions about your data or this policy: privacy@formclock.com.