Privacy policy
Last updated
PadClock is a time clock for New Zealand businesses that use Xero Payroll. This policy explains what personal information PadClock collects, what we do with it, who we share it with, how long we keep it, and the choices you have. It covers the PadClock website, the admin app and the kiosk app.
Who we are
PadClock is provided by Offshore Apps Limited, a New Zealand company (“we”, “us”). We are responsible for the personal information of the people who run PadClock accounts: business owners and the admins they invite. You can contact our privacy officer at support@padclock.com.
Businesses use PadClock to record their employees’ hours. For employees’ information, the business that employs them is in charge: it decides what is recorded and why. We hold and process that information on the business’s behalf, only to provide PadClock to it.
What we collect
Owners and admins
- Your name and email address.
- How you sign in: with Google, Apple or Xero, or with an email address and password. Passwords are handled by our sign-in provider, Firebase Authentication. We never see them.
- The business you belong to, and whether you are its owner or an admin.
- Whether you receive the daily open-shift email.
Your business
- The business’s name, phone number, address and contact email, which you enter when you set up PadClock or later in Settings.
- Its time zone, and the rules you set for breaks and shift lengths.
- When you connect Xero: your Xero organisation’s name and identifier, its pay calendars and pay periods, the earnings rate PadClock uses for timesheets, and the access tokens Xero issues to PadClock.
- Your subscription: its status and dates, and the identifiers Stripe gives your customer record and subscription.
Employees
Copied from the business’s Xero Payroll account when it is connected, and kept up to date from it:
- first and last name, email address, job title and department
- start and end dates, and whether they are currently employed
- their Xero employee identifier
Created in PadClock:
- a 4-digit PIN for clocking in and out, unique within the business
- every clock-in and clock-out: the time, the tablet it was recorded on, unpaid breaks, total hours, and any shift left open
- changes an admin makes to a timesheet, and which admin made each change and when
- whether each timesheet has been sent to Xero, and when
PadClock does not collect photos, fingerprints or any other biometric information, and it does not record anyone’s location.
Kiosk tablets
- A name for each paired tablet, who paired it, when it was last online, and how many clock-ins it is still waiting to send.
- So that it keeps working without an internet connection, a tablet keeps the business’s staff list (names, Xero employee identifiers and PINs) and any clock-ins waiting to be sent, in that tablet’s browser.
Technical information
- To stop abuse, we count how often each internet (IP) address uses some of our sign-in and pairing services. We store only a one-way scrambled form (a hash) of the address, never the address itself, and delete the count within a day of it expiring.
- Our hosting providers keep short-lived technical logs, such as IP addresses, browser types and the times of requests, to run and secure the service.
- PadClock has no analytics, advertising or tracking cookies or scripts.
How we use it
- To provide PadClock: signing you in, recording hours, working out unpaid breaks, showing the dashboard and timesheets, and letting you download your records.
- To keep employees and pay periods up to date from Xero, and to send timesheets to the business’s Xero Payroll account when an admin chooses to.
- To send PadClock’s emails: invitations to new admins, trial reminders to the account owner, the daily open-shift email to the admins set to receive it, and password-reset emails you ask for.
- To bill the subscription.
- To keep PadClock secure: protecting accounts, preventing abuse and investigating problems.
- To answer you when you contact us.
We don’t sell personal information, and we don’t use it for advertising.
Information from Google
If you sign in with Google, Google shares your name, email address, profile picture and Google account identifier with PadClock. That basic profile is all PadClock asks Google for. It does not ask for access to your Gmail, Google Drive, Calendar, contacts or any other Google data.
- How we use it: to create your PadClock account and sign you in, to show your name in the app, and to send you the PadClock emails this policy describes. We don’t use your profile picture.
- How we store it: in Firebase Authentication and in PadClock’s database, both run by Google Cloud, protected as described under “How we protect it”.
- Who we share it with: only the service providers that run PadClock for us, listed below, and only so they can do that. We don’t sell it, use it for advertising, or use it to train AI models.
- How long we keep it: until you delete your PadClock account. Deleting your account deletes it.
PadClock’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can remove PadClock’s access at any time from your Google Account’s third-party connections.
Who we share it with
- Your business’s Xero account. When a business connects Xero, PadClock reads its employees and pay calendars, and writes timesheets to it when an admin sends them. Xero handles that information under its own privacy policy.
- Service providers that run parts of PadClock for us. They may use the information only to provide their services to us.
- Google Cloud and Firebase: our database, sign-in and server functions, and password-reset emails.
- Vercel: hosts the PadClock website and app.
- Stripe: takes subscription payments, and collects the card details and billing address it needs for them, and a GST number if you give one. We never see or store card numbers.
- Resend: sends PadClock’s emails.
- Migadu: hosts our support mailbox, so it holds the emails you send us.
- Sign-in providers. If you sign in with Google, Apple or Xero, that provider tells us who you are, and knows you have signed in to PadClock.
- When the law requires it, or when it is needed to protect someone’s safety, our legal rights, or the security of PadClock.
- If PadClock changes hands. A new owner would take on the information under this policy.
Outside New Zealand
Our service providers store and process information outside New Zealand, mainly in the United States, where PadClock’s server functions run. We use providers that protect personal information with safeguards comparable to those in the Privacy Act 2020, and that may use it only to provide their services to us.
How long we keep it
- A business’s records are kept while its PadClock account exists, including after a trial or subscription ends, so the business can still sign in and download them.
- When an admin deletes their own account (Settings → Account), their sign-in and membership are deleted. The business’s records stay with the business.
- When the last remaining admin deletes their account, the whole business is deleted with it: employees, PINs, timesheets, pay periods, tablets, invitations and settings. Xero is disconnected and PadClock’s access to it is revoked. Timesheets already sent to Xero stay in Xero.
- Invitations stop working 7 days after they are sent.
- Short-lived security records, such as pairing codes and the counters described above, are deleted automatically within a day of expiring.
- A clock-in waiting on a tablet is deleted from the tablet once PadClock has received it.
- Deleted information is removed from our database straight away. Our providers may keep backup copies for a limited time before they are deleted too.
- Stripe keeps payment records for as long as the law requires.
How we protect it
- A business’s information can be seen only by that business’s signed-in admins. The database’s security rules and our server functions both check this.
- Sensitive changes, such as PINs, the Xero connection, billing and ownership, go through server functions that check who is asking.
- Each kiosk tablet signs in with its own secret, which we store only as a hash. A lost tablet can be switched off from Settings → Kiosk.
- The admin PIN that guards leaving the kiosk is stored only as a salted hash, and repeated wrong guesses are locked out.
- Xero access tokens are stored where no browser can read them, and disconnecting Xero revokes them.
- Employee PINs are visible to the business’s admins, so they can tell staff their PIN. They are hidden on screen until an admin chooses to show one.
- Information is encrypted when it travels over the internet, and our hosting providers encrypt it where they store it.
- If a privacy breach is likely to cause anyone serious harm, we will tell the Privacy Commissioner and the people affected, as the Privacy Act 2020 requires.
Cookies and browser storage
PadClock doesn’t use advertising or analytics cookies, and doesn’t load tracking scripts. It keeps a few things in your browser so that it works:
- your sign-in session, a note that you are signed in, and the page to return to after you sign in
- preferences, such as the kiosk’s colour theme and how a list is displayed, and which one-off messages you have already seen
- on a kiosk tablet: its pairing, the staff list, and clock-ins waiting to be sent
Clearing your browser’s data removes them. You would then need to sign in again, and a kiosk tablet would need to be paired again.
Your rights
Under the Privacy Act 2020 you can ask for a copy of the personal information we hold about you, and ask us to correct it. Owners and admins can also delete their account in Settings → Account. An owner who has other admins transfers ownership to one of them first.
If you are an employee, your employer controls your time records and can see and correct them, so asking your employer is usually quickest. You can also ask us, and we will work with your employer to respond.
Email support@padclock.com. We will respond within 20 working days. If you are not happy with our response, you can complain to the Office of the Privacy Commissioner.
Changes to this policy
When PadClock changes how it handles personal information, we will update this page and the date at the top. If a change is significant, we will email account owners at least 30 days before it takes effect. The terms of service cover everything else about using PadClock.
Contact
Privacy officer, Offshore Apps Limited: support@padclock.com
