FieldClock Privacy Notice
This notice explains what FieldClock collects, how it is used, who can access it, and what workers and customers should understand before FieldClock is used in production.
Version 1.3
Last updated June 11, 2026
Canada / PIPEDA aware
For workers
Workers may be required to review and accept the in-app privacy and workforce-data agreement before using FieldClock. FieldClock is designed for timekeeping, payroll support, event-based location capture at punches and status changes, and job-site operations.
For employers
Your company is responsible for deciding how FieldClock is used in your workplace and for ensuring you give any employment, monitoring, or privacy notices and obtain any consents required by applicable law.
What FieldClock does not do
FieldClock does not sell personal information and does not use workforce data for advertising. Location features are intended for workforce operations, not consumer profiling.
1. Who this notice applies to
This notice applies to workers, managers, supervisors, company account owners, support users, and site visitors who interact with FieldClock.
FieldClock’s role
For most workforce records, the employer using FieldClock is the organization deciding why the data is collected and how it is used in the workplace. FieldClock provides and secures the platform, processes data to operate the service, and may also process billing, support, security, and platform-administration data directly.
If you are an employer, this notice helps you, but it is not a substitute for getting legal advice on workplace monitoring, employment consent, or provincial rules that may apply to your rollout.
2. Information FieldClock may collect
Account and workforce information
- Name, username, display name, company, role, and contact details provided by the worker or employer.
- Worker settings, pay settings, trade assignments, job assignments, route assignments, schedules, approvals, and account status.
Timekeeping and payroll information
- Clock-in and clock-out times, breaks, shift notes, worker notes, timesheets, pay calculations, mileage, overtime, approvals, and related payroll or export data.
Location and shift-verification information
- A single GPS coordinate (with accuracy and a timestamp) captured at each event: clock-in, clock-out, break start and end, task changes, and jobsite changes.
- A single GPS coordinate captured when a manager requests the worker's current location and the worker approves the request.
- FieldClock does not collect continuous location and does not track location in the background, when the app is minimized or closed, or after the worker clocks out.
Technical, notification, diagnostic, and security information
- IP address, session activity, device or browser user agent, push-notification subscription details, diagnostic reports, and security or abuse-monitoring logs.
Website analytics (visitors who are not signed in)
On our public website we keep a minimal, aggregate count of page visits — the page viewed, an approximate country, and the referring source (for example a social network or search engine, including any campaign tag in the link). This helps us understand how people find FieldClock. We use your IP address only briefly to derive an approximate country and then discard it; visit counts use a one-way keyed value, not your IP. We do not build visitor profiles, run ads, or track you across other websites. This applies only to anonymous visitors — it does not apply to signed-in users, whose use is governed by the agreement above. You can opt out at any time using the banner on our home page, and bots are not counted.
What FieldClock does not normally collect
- FieldClock does not normally collect camera, microphone, contacts, biometric, or photo-library data through ordinary use of the app.
- FieldClock is not designed to keep tracking workers after they clock out.
3. When location is collected
- At punches: when a worker clocks in or clocks out.
- At status changes: when a worker starts or ends a break, switches task, or switches jobsite.
- On an approved manager request: a manager can request the worker's current location; a single point is sent only when the worker approves it (for example, by tapping the notification).
- Never continuously or in the background: FieldClock does not track between these moments, while the app is minimized or closed, or after the worker clocks out.
4. How FieldClock uses the information
- To provide timekeeping, scheduling, job assignment, a record of where punches and status changes happened, and workforce-management features.
- To verify active-shift work locations, support payroll accuracy, calculate overtime, and maintain records.
- To support job-site safety, dispute resolution, and customer support.
- To protect the platform, investigate abuse, troubleshoot issues, and comply with tax, employment, legal, or audit obligations.
Payroll figures are estimates. All pay, tax, and deduction amounts FieldClock produces (including paystubs and exports) are estimates intended to assist the employer's payroll process. Employers can configure or adjust tax rates and tax lines for their company. The employer is solely responsible for verifying all amounts before paying workers or remitting to any tax authority. See the
Terms of Service for details.
5. Who information may be shared with
- Authorized employer personnel such as managers, supervisors, payroll staff, admins, and owners.
- FieldClock platform staff when reasonably necessary for support, onboarding, maintenance, security review, or legal compliance.
- Browser or device push services when notifications are enabled. This can include vendor push infrastructure such as the browser/device push provider, which processes push endpoints, cryptographic subscription keys, and notification-delivery metadata needed to deliver alerts.
- Configured email providers or relays when FieldClock sends invites, password resets, or other emails. This generally means the recipient email address, subject line, and message content are processed by the configured email provider.
- PayPal if billing is enabled. FieldClock sends billing and subscription checkout data such as the selected plan, company identifier in custom checkout metadata, return/cancel URLs, and optional billing email. PayPal then handles the payment flow and account/payment instrument data on its own platform.
- OpenStreetMap Nominatim when a user performs map or address search. FieldClock sends the typed search query and service user-agent needed to return search results.
- ip-api.com for security-dashboard IP geolocation lookups. FieldClock may send logged source IP addresses there to enrich suspicious-activity investigations with country, city, and network-organization data.
- Other legal recipients such as regulators, courts, law enforcement, or counterparties where required by law or reasonably necessary to protect rights, safety, property, or the platform.
FieldClock does not sell personal information and does not use workforce data for advertising.
6. Cross-border processing
Some service providers or integrations may process data outside your province, territory, or country, depending on the provider involved.
7. Retention
FieldClock is a tool for operating workforce timekeeping. It is not a long-term system of record or a backup service. While a company account is active, FieldClock retains workforce records so the employer can use them.
The employer is responsible for retaining its own payroll and timesheet records for as long as tax and employment record-keeping rules require (often several years), and for keeping its own independent copies or backups. FieldClock provides one-click CSV, QuickBooks IIF, and PDF exports for this purpose; employers should download and store their records on their own systems.
FieldClock does not guarantee long-term or indefinite retention and is not responsible for loss of data, including loss resulting from account closure, from worker or company deletion performed by the employer, or from hardware or service failures. Operational, support, billing, security, and diagnostic records may be retained as long as reasonably necessary to operate, secure, support, and document the service and to meet FieldClock’s own legal obligations.
8. Safeguards
FieldClock uses reasonable administrative, technical, and physical safeguards to protect data, including password hashing, session controls, access restrictions, and request-protection measures. No internet or mobile service is perfectly secure, so FieldClock cannot promise absolute security.
9. Rights, choices, and updates
- You may request access to your personal information and request corrections if information is inaccurate.
- You may withdraw consent where consent is the legal basis for use, but doing so may limit or prevent use of FieldClock in the workplace.
- You can decline optional permissions such as notifications or location, but some features may not work properly and your employer may not be able to use FieldClock as intended.
- Workers should usually contact their employer first for workplace records. You may also contact FieldClock directly for platform-level privacy questions.
- If you believe a privacy concern has not been handled properly, you may contact the Office of the Privacy Commissioner of Canada.
- FieldClock may update this notice from time to time. If the changes are material, workers may be asked to accept an updated in-app agreement before continuing to use the service.
10. Data deletion
You can ask for your FieldClock data to be deleted at any time:
- Workers: contact your company owner or manager, since they control your workplace timekeeping records and decide what is kept or removed. A manager or admin at your company can deactivate your account — which immediately ends your access — and permanently remove your worker record and its shift data. FieldClock does not delete an employer’s workforce records on a worker’s behalf.
- Employers and account owners: you control your company’s data. Managers and admins can deactivate and permanently delete worker records directly in FieldClock, and you can email [email protected] to request deletion of your whole company account.
- Anyone: send a platform-level deletion request to [email protected] and it will be actioned within a reasonable time.
Deletion in FieldClock is permanent and is the employer’s decision. Because the employer is responsible for its own tax and employment record-keeping, employers should export and keep their own copies (for example via CSV, QuickBooks IIF, or PDF export) before deleting worker or company data. FieldClock does not retain a separate copy on the employer’s behalf after deletion.
11. Contact
Privacy questions, access requests directed to FieldClock, unresolved concerns, or general business questions can be sent to [email protected].