1. Scope and Publishing Operator
This Privacy Policy governs the processing of personal and workforce data by the SlidesClock platform, encompassing our iOS mobile application, Android mobile application, web dashboard, and public website (collectively, the "Service").
The Service is operated and published by Chhunsour Seng ("SlidesClock", "we", "us", or "our"). We provide workforce attendance verification, shift scheduling, leave workflows, and optional payroll management tools to organizations and their authorized personnel.
2. Role of the Employer Organization
In the context of workforce operations, the employer organization (the company or business entity that establishes the SlidesClock workspace) acts as the controller, where that legal concept applies, for its employees' employment and attendance records.
SlidesClock operates accounts, billing, support, and service security, and processes workforce records to provide the tools selected by the organization. The organization must establish a lawful basis, give employees required notices, and handle employment decisions and retention instructions.
The organization decides which verification policies apply to each branch (such as GPS geofencing or office Wi-Fi verification), establishes work schedules and grace periods, reviews and approves leave or punch corrections, and determines whether to process payroll. Employees with inquiries regarding employment terms, disciplinary flags, or company-specific policies should contact their organization administrator directly.
3. Categories of Data Collected and Processed
We process the following categories of information to deliver the Service:
A. Identity and Profile Information
User full name, Khmer name, email address, phone number, profile photo (avatar), preferred application language (Khmer or English), and optional Telegram provider identifier, username, and avatar if Telegram sign-in is utilized. Within an organization, we store employee codes, job titles, department names, assigned supervisors, member roles (Owner, HR, Branch Manager, Supervisor, Payroll Admin, Employee), and employment active status.
B. Organization Branding Data
Organization legal or trade name, registered branches, and company logo images. Company logos are stored as public branding files accessible by exact URL to enable brand display on employee invitation links and mobile headers. Personal employee avatars and financial receipts are strictly stored in private, access-controlled storage buckets.
C. Attendance and Verification Evidence
When an employee slides to clock in or clock out, our backend processes:
- Server-authoritative timestamp: Recorded using database server time and displayed in the relevant workplace timezone, independent of local smartphone clock settings.
- GPS Location Evidence: Precise latitude, longitude, accuracy radius, distance to branch geofence, and mock location detection flags. The reported age of the location fix is checked during verification. Location coordinates are collected strictly point-in-time when sliding under a branch GPS policy, or when an authorized manager explicitly captures coordinates to establish a workplace geofence radius. SlidesClock never conducts continuous or background location tracking.
- Network Evidence: Public IP address observed by our server at the time of punch. On iOS, attendance check-ins do not transmit SSID or BSSID network identifiers due to operating system privacy controls. Android may transmit SSID/BSSID when accessible.
- Device Registration Identifiers: Identifier for Vendor (IDFV on iOS), device model, platform, operating system description, and application version. These identifiers support device registration and attendance verification; they do not prove who is holding the phone.
D. Operational and Roster Records
Shift schedules, assigned work hours, overnight shift markers, rest days, country-specific public holidays (obtained via public holiday APIs without transmitting personal data), leave requests, leave categories and mandatory employee reason notes, overtime requests, punch correction notes, supervisor review notes, and administrative audit logs.
E. Optional Payroll Records
If the organization chooses to enable optional payroll, we process compensation structures: base salary rates, hourly rates, allowances, bonuses, overtime premiums, deductions, tax withholdings, advance payments, and generated digital payslips, payroll issue messages and replies, and related approval records. Payroll features are strictly optional.
F. Push Notification Tokens and Outbox Records
Device push notification tokens (Apple Push Notification service and Firebase Cloud Messaging) and message records for shift reminders, leave updates, and payslips. Sensitive details, including salary numbers and free-text correction notes, are omitted from push payloads. Terminal-state outbox records older than 30 days are automatically pruned by daily background maintenance cron tasks.
4. Purposes of Processing
We process workforce and account data for the following purposes:
- Creating and authenticating accounts, delivering the service, responding to support requests, and protecting against fraud, abuse, and unauthorized access.
- Verifying employee attendance against company-established branch policies and shifts.
- Enabling managers to review attendance rosters, approve leave, and audit punch corrections.
- Providing employees with direct visibility into their own attendance history and scheduled shifts.
- Generating downloadable attendance reports and CSV data exports for organization management.
- Delivering timely push notifications regarding shift start times, approval decisions, and announcements.
- Processing in-app subscriptions and enforcing seat and branch entitlement limits.
5. Third-Party Infrastructure and Service Providers
The following services receive information needed for their functions. Their own privacy notices also describe how they operate:
- Database, Authentication & Storage: Supabase (PostgreSQL database, Row-Level Security, Edge Functions, and file storage).
- Hosting: Vercel (hosting for web dashboard and marketing website).
- Apple Services: Apple Inc. (Sign in with Apple, StoreKit In-App Purchase billing, and Apple Push Notification service).
- Google Services: Google LLC (Google Sign-In, Firebase Cloud Messaging for Android push delivery, Google Fonts for dashboard fonts (which receives the connection IP and browser request information), and Google Cloud Translation API for interface text in additional languages).
- Telegram: Telegram authentication is available where configured; choosing it shares authentication information with Telegram and returns the linked profile information to SlidesClock.
- Public Holiday Data: Nager.Date (retrieves Cambodian national public holiday dates without transmitting any personal or company information).
No Advertising Trackers: Our public website and applications contain no advertising networks, behavioral tracking pixels, or third-party marketing cookies in the audited implementation. Language preference is preserved directly in the URL structure (/km). The dashboard and mobile app store essential authentication sessions and local preferences. Hosting and backend services also process connection and operational logs; no dedicated third-party analytics or crash-reporting SDK is configured. Diagnostic performance logging in development or explicitly enabled test builds is local.
6. Data Retention and Pruning
We retain personal data while an account remains active and as required to provide the Service. Specific retention practices include:
- Notification Outbox: Processed terminal-state push notification records older than 30 days are automatically deleted during daily maintenance by an automated database pruning cron function (
app_prune_notification_outbox). - Account Deletion: When an employee or manager deletes their account, personal authentication credentials, profile data, private avatar files, registered device records, and push tokens are removed from the active service when deletion succeeds.
- Employer Operational History: Original attendance timestamps, GPS evidence, supervisor approvals, leave records, and payroll histories are retained by the employer organization under a detached, inactive member record to maintain historical accounting and labor record integrity. These records may still contain names, employment details, and other information that identifies you; detaching a login is not anonymization. There is no automated age-based deletion schedule for employer organizational records; retention is governed by the employer organization subject to applicable legal requirements.
- Backups and other logs: Deletion from active systems does not establish immediate erasure of existing provider backups. SlidesClock has not established a single published backup, audit-log, payroll, or organization-record retention deadline. Requests concerning retained records require a case-specific review with the organization and service operator; records must not be kept indefinitely merely because storage is available.
7. User Rights and Account Deletion Procedures
Users can initiate account deletion at any time directly within the SlidesClock mobile application:
How to Delete Your Account:
- Open the SlidesClock mobile application on your smartphone.
- Navigate to the Profile tab and tap the Settings (gear icon) in the top corner.
- Scroll to Delete Account.
- If you are an organization owner with active coworkers, transfer ownership to another coworker before proceeding.
- Re-authenticate your identity (including fresh Apple Sign-In authorization for Apple-linked accounts) and type DELETE to confirm.
For complete step-by-step instructions and deep-linking, see our Data Deletion Instructions page .
You can view your attendance and available payslips in the app, edit supported profile fields, and ask your organization administrator for access to or correction of workplace records. Use the correction workflow to contest an attendance entry. Contact the service operator about account information, privacy requests, or requests that your organization cannot resolve. We may need to verify your identity before disclosing or deleting data.
You can turn off location or notifications in iOS Settings. A workplace rule that requires location may then prevent verified attendance; ask your administrator about an appropriate alternative. Turning off a permission stops future access and does not itself erase existing evidence.
Depending on where you live and the processing involved, you may have rights to access, correction, erasure, restriction, objection, portability, withdrawal of consent, and a complaint to your privacy regulator. Where consent is the legal basis, withdrawal does not affect earlier lawful processing. We do not sell personal information or share it for cross-context behavioral advertising. Applicable mandatory rights remain available even if an organization retains employment records.
International processing: Hosting and authentication providers may process information outside your country. We do not promise that every part of the service stays in a particular region. Applicable transfer requirements and contractual safeguards must be addressed for each organization's use; this policy does not assert GDPR, UK GDPR, or other certification.
Subscription Cancellation Notice: Deleting your SlidesClock account or company does not cancel an active Apple App Store subscription. Subscriptions must be cancelled in your Apple ID settings (iOS Settings → Subscriptions).
8. Workforce Eligibility and Children
The Service is an enterprise workforce management tool designed solely for authorized employees and managers who are legally eligible for employment under applicable labor laws. SlidesClock is not directed to children, does not market to children, and does not knowingly collect personal information from individuals under the legal minimum employment age.
9. Technical Security Safeguards
We implement technical and organizational controls to protect workforce data, including:
- Strict PostgreSQL Row-Level Security (RLS) enforcing tenant isolation across different organizations.
- HTTPS connections to the hosted website and service endpoints.
- Private storage bucket access controls for user avatars and receipts.
- Restricted attendance write functions (
check_in_out) enforcing server-authoritative timestamps and distance verification.
10. Policy Changes and Inquiries
We may update this Privacy Policy to reflect operational or regulatory changes. Any updates will be posted on this page with a revised effective date. Where a material change requires notice or consent, we will provide the required notice or obtain consent before applying it. A policy update does not remove statutory rights.
For privacy inquiries, account deletion support, or questions regarding data processing, users can consult their company administrator, access the in-app Help & Guide, or contact us:
Platform Operator: Chhunsour Seng
Website Contact: slidesclock.com/contact