Before you publish this page
Every highlighted item below is a placeholder you must replace: legal entity name, postal address, contact email, and governing jurisdiction. Search the file for class="fill" to find them all.
This is a drafting starting point written to match how the app actually behaves — it is not legal advice. Workplace location tracking is separately regulated in many places, and the rules differ by state and country. Have a lawyer review this before you ship, particularly the location and employee-rights sections.
1. Who controls the information
Scan In is published by [Legal Entity Name] ("we", "us"), [Registered Address].
There are two kinds of people in the app, and the relationship differs for each.
Employers. When a manager creates a business, they decide who is added, where the punch zone sits, and how long records are kept. For the punch data belonging to that business, the employer is the data controller and we act on their instructions as a service provider.
Employees. If you punch in and out using Scan In, your employer decides what happens with your record. Requests to see, correct, or delete a punch record should go to your employer first. If you contact us directly, we will pass the request to them and help them act on it.
For the manager's own account information — the sign-up email, billing, support messages — we are the controller.
2. What we collect
We collect only what the time clock needs to work. There is no advertising SDK in the app, and we do not build profiles for marketing.
| Information | Where it comes from | Why |
|---|---|---|
| Manager name, email, password | Sign-up form | To create and secure the business account |
| Business name, store address or coordinates, punch radius | Entered in Settings | To define the zone where punches are accepted |
| Employee name and role | Added by the manager, or on joining with a code | To identify who a punch belongs to |
| Employee PIN (4 digits, stored hashed) | Set by the employee | To keep a profile from being opened by someone else |
| Punch records: in/out, date, time | Scanning the wall code | The core purpose of the app |
| Distance from the store at the moment of a punch | Device location, if permitted | To confirm the punch happened on site |
| Device model, OS version, app version, crash logs | Automatic | To diagnose faults and keep the app stable |
| Support messages | You, when you write to us | To answer you |
We do not collect photographs, contacts, microphone audio, health data, browsing history, or biometric identifiers. Scanning a wall code uses the camera to read the code; camera frames are processed on the device and are not stored or uploaded.
3. How location is used
This is the part employees ask about most, so it is worth being exact.
- Location is requested only at the moment you press clock in or clock out, while the app is open in front of you.
- There is no background location. The app does not run a location service between shifts, and it cannot see where you go after you clock out.
- What gets saved to the punch record is the distance in metres from the store and whether that fell inside the punch radius. Coordinates are used to compute that distance.
- If the punch is outside the radius, it is refused and the distance is recorded so the manager can see why.
- You can refuse the location permission in iOS Settings. A business that has set a punch radius may then be unable to accept your punch, and you will need to ask your manager to record it manually.
A note for managers
Telling your staff that punches are location-checked is not optional in many places. Several US states and most of Europe require clear advance notice before an employer records worker location, and some require written consent. Setting a punch radius in Scan In is your decision, and the notice obligation is yours.
4. Why we use it
We use the information above to run the time clock, to show managers who is working and how many hours have accrued, to produce the CSV export, to keep accounts secure and detect misuse, to fix crashes, and to answer support requests. Where the law requires a legal basis, ours is the performance of our contract with the business, our legitimate interest in keeping the service secure and working, and consent where consent is what applies — for example the iOS location permission.
We do not use punch data to train machine learning models, and we do not sell it.
6. App Store privacy summary
This mirrors the privacy label shown on the App Store listing.
| Category | Collected | Linked to you | Used to track you |
|---|---|---|---|
| Contact info (name, email) | Yes | Yes | No |
| Precise location | Yes, at punch time only | Yes | No |
| Identifiers (account ID) | Yes | Yes | No |
| Usage data and diagnostics | Yes | No | No |
| Contacts, photos, health, browsing | No | — | No |
Nothing in Scan In is used for tracking as Apple defines it. The app does not access the advertising identifier and contains no third-party ad networks.
7. How long we keep it
Punch records are kept for as long as the business keeps its account, because they are the employer's wage-and-hour records and are often required to be retained for several years. A manager can delete individual records and employee profiles at any time.
If a business closes its account, we delete or anonymise its data within [30] days, except where we must keep something to meet a legal, tax, or accounting obligation. Backups are purged on a rolling [35]-day cycle.
Crash and diagnostic logs are kept for [90] days.
8. How it is protected
Traffic between the app and our servers is encrypted in transit with TLS. Data at rest is encrypted by our hosting provider. Employee PINs are stored as salted hashes, not as readable digits. Access to production systems is limited to staff who need it and is protected by multi-factor authentication.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your information we will notify you and the relevant regulator as required by law.
9. Your choices and rights
Depending on where you live you may have the right to access a copy of your information, correct it, delete it, restrict or object to certain uses, port it elsewhere, and withdraw a consent you gave. Residents of California may also ask about the categories of information collected and disclosed in the past twelve months, and are entitled not to be discriminated against for exercising a right.
To exercise a right, write to [privacy@example.com]. We will verify your identity before we act. If your request concerns punch data held by your employer, we will forward it to them, since they control that record.
You can also, at any time: turn off the location permission in iOS Settings, change or reset your PIN in the app, or ask your manager to remove your profile.
If you are in the EU or UK and are unhappy with our response, you may complain to your local data protection authority.
10. If you run a business on Scan In
You are responsible for the following, and we cannot do them for you:
- Telling your employees, before their first punch, that time and location are recorded, and obtaining consent where your jurisdiction requires it.
- Adding only people who actually work for you, and removing profiles when someone leaves.
- Keeping the punch radius no larger than it needs to be for your site.
- Handling employee requests for access, correction, and deletion of their own records.
- Meeting the wage-and-hour record-keeping rules that apply to you.
11. Children
Scan In is a workplace tool and is not directed to children. We do not knowingly collect information from anyone under 16. Where a business employs a minor lawfully, that employee's profile is created and managed by the employer, who is responsible for any consent their local law requires. If you believe a child's information reached us in error, write to us and we will remove it.
12. International transfers
We operate from [the United States] and our service providers may process data there and in other countries. Where data moves out of the EEA or the UK, we rely on the European Commission's standard contractual clauses, together with the UK addendum where it applies.
13. Changes to this policy
If we change how the app handles information we will update this page and move the effective date at the top. For a change that materially affects you, we will also give notice inside the app before it takes effect. The version history is kept at the bottom of this page.
14. Contact us
Questions about this policy, or about your information:
This policy is governed by the laws of [State / Country].