Privacy Policy
This policy explains how TimeOff Manager and TimeOff Kiosk collect, use, and protect information across our web platform and mobile apps.
Effective date: September 1, 2026
1. Scope
This Privacy Policy applies to TimeOff Manager on the web and the TimeOff Kiosk mobile app on iOS and Android. It covers company administrators, managers, employees, and invited users who access our services.
2. Information We Collect
- Account and profile data: name, email, role, employee number, company assignment, and profile avatar.
- Workforce and HR data: schedules, time entries, leave requests, approvals, payroll-related records, and compliance workflow data entered by authorized company users.
- Clock-in/out data: timestamps, location coordinates, assigned work location, IP address, and related device/session metadata.
- Photos: selfie images for clock-in/clock-out verification when enabled by your company settings.
- Mileage data: trip locations, distances, and optional trip photos/documents where used.
- Authentication/session data: login/session identifiers, IP and user-agent details, and API access token data.
- Support and communication data: information you provide when contacting support.
3. Mobile App Permissions (iOS and Android)
- Location: used to validate work-location attendance, geofence rules, and location-based time records.
- Camera: used to capture selfie photos during clock events when required.
The app does not require photo-library access for normal operation. Permission prompts are managed by your device OS and can be changed in settings.
4. How We Use Information
- Provide time tracking, leave management, scheduling, payroll support, and reporting features.
- Verify attendance, apply company-configured policy rules, and support approval workflows.
- Maintain account security, prevent abuse, and troubleshoot technical issues.
- Operate, monitor, and improve platform reliability and performance.
- Respond to support requests and administrative communications.
5. Legal bases and roles (controller vs processor)
For workforce data your employer enters about you, the employer is generally the data controller and PositionMySite acts as a data processor operating TimeOff Manager on the employer’s instructions. Your employer configures product features (including GPS, geofencing, and photo verification) and determines how data is used.
See our Data Processing Addendum and Subprocessors list for more detail.
6. Sharing and Disclosure
We do not sell personal information. We may share data only as needed to operate the service, including:
- With your organization’s authorized admins/managers according to role-based permissions.
- With infrastructure and service providers supporting hosting, maps/geocoding, notifications, and platform operations.
- When required by law, legal process, or to protect rights, safety, and service integrity.
7. Data Retention
We retain information for as long as needed to provide the service, satisfy legal and accounting requirements, resolve disputes, and enforce agreements. Some data retention settings are controlled by your organization.
When photo verification is enabled, clock-in/out selfie images are retained for 30 days by default (employers may choose 7, 30, or 90 days) and then deleted from the service, while related attendance timestamps may be kept longer according to employer settings.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information. No method of transmission or storage is 100% secure, but we continuously work to protect customer data. See our Security page for more information.
9. Your Choices and Rights
- You can update certain account/profile information through your account or administrator.
- You can manage app permissions (location/camera) in your device settings.
- Employees: If you want to access, correct, or delete personal data we process about you, contact your employer first. Your employer controls the account and most workforce records. They may use export tools or contact us for assistance under our Data Processing Addendum.
- Employer administrators may contact us directly at security@timeoffmanager.us for account-level requests.
10. Contact
If you have privacy questions, contact us: