Privacy Controls

Cookie preferences

Essential cookies keep Clockie secure and working. Optional cookies help us improve reliability and onboarding.

Skip to content
Back to home

Legal

Privacy Policy

Last updated: 1 July 2026

1. Scope

Clockie is operated by Kiwi Digital Ltd, a New Zealand company. This policy covers both:

  • Public website visitors who are not logged in.
  • Authenticated users and staff using product features (admin, kiosk, and personal clock).

2. Privacy Roles

Privacy responsibilities depend on the data type:

  • For workforce/time-tracking records, the customer business is typically controller, and Clockie acts as processor/service provider.
  • For our service operations (account admin, billing, support, website controls), Kiwi Digital Ltd acts as controller.

3. Information We Collect

Public website visitors

  • Technical data such as IP address, browser/device type, and timestamps.
  • Interaction data when optional analytics is enabled.
  • Contact details and message content you choose to send by email.

Logged-in users and account owners

  • Account/profile details (name, email, role, MFA state).
  • Business and billing data (plan, invoices, subscription status).
  • Support records (chat/email messages, ticket data, support metadata).
  • Security and activity logs, including device/user agent context.

Workforce/time-tracking records

  • Staff details entered by the customer (for example name, contact details, payroll fields, IRD number where provided).
  • Time entries, shift details, and related job/department/location references.
  • Optional verification data: location coordinates, photos, and face verification status/confidence.
  • Optional face-embedding templates used for identity verification where enabled.

On-device and offline storage

  • Local/session storage for session continuity, kiosk registration, and preferences.
  • IndexedDB offline queues that can temporarily hold unsynced events, photos, and location points.
  • Strict first-party kiosk credential cookie used for iOS/PWA install bridging.

4. How We Use Information and Legal Bases

We use personal information to operate, secure, support, and bill the service, and to meet legal obligations.

  • Contract performance.
  • Legitimate interests (security, reliability, support quality).
  • Consent (optional analytics and certain optional product features).
  • Legal obligations (tax, accounting, and regulation).

5. Cookies, Local Storage, and Consent

We use essential storage for core operation plus two optional cookie categories: analytics (measurement, e.g. Google Analytics and Microsoft Clarity) and marketing (advertising measurement and remarketing via the Meta Pixel). Essential storage is always on. Where prior consent is legally required — the EU, UK, and Switzerland — the optional categories stay off until you opt in through the consent controls; elsewhere they run unless you opt out. You can change either preference, or switch everything off, at any time.

Optional analytics events are designed to exclude sensitive fields (such as names, direct contact details, precise GPS coordinates, and free-text support content).

Your preference is saved in this browser and can be changed any time.

6. Third-Party Services and Disclosures

Key providers include:

  • Supabase (authentication, database, storage, edge functions).
  • Cloudflare (hosting, delivery, and platform security).
  • Resend (transactional email delivery).
  • ClickSend (SMS notifications, where enabled).
  • Stripe (subscription billing and payment processing).
  • Xero and Crystal Payroll (optional payroll/accounting integrations).
  • OpenStreetMap Nominatim (address search and reverse-geocoding for location setup tools).
  • Google Analytics 4 and Google Tag Manager (optional analytics).
  • Microsoft Clarity (optional product analytics and session replay).
  • Cloudflare Web Analytics (cookieless, privacy-first traffic and performance metrics).
  • Meta Pixel — Meta Platforms (advertising measurement and remarketing; loads only with marketing consent).
  • Anthropic (AI processing for enabled support/assistant features).

Payment card details are processed by Stripe. Clockie does not store full payment card numbers or card security codes.

We may also disclose data where required by law, to enforce terms, prevent abuse, or complete a corporate transaction. We never sell personal information. When you turn on marketing cookies, we share limited website-event data with Meta to measure ad performance and show you relevant Clockie ads; with marketing cookies off, we do not share personal information for cross-context behavioral advertising.

7. International Transfers and Data Residency

In Clockie's standard hosted configuration, primary application database and storage are set to Australia (Sydney). Some providers may process limited data in other countries depending on infrastructure and enabled features. Where cross-border transfers occur, we use safeguards intended to meet applicable law.

8. Retention

  • Core time, payroll, and billing/tax records are generally retained for up to 7 years.
  • Account and business records are retained while active and for a reasonable post-termination period.
  • Support/security logs are retained as needed for operations and legal purposes.
  • Local device/browser data persists until synced, cleared, overwritten, or removed.

Account owners can use Settings > Data & Privacy for export/deletion actions. Some records may be retained where legally required.

9. Security and Breach Handling

  • Encryption in transit and platform-level encryption at rest.
  • Role-based access controls and row-level data segmentation.
  • Operational logging for key administrative/security actions.

If a breach is likely to cause serious harm, we will notify affected individuals and the NZ Office of the Privacy Commissioner as required.

10. Your Rights

  • NZ: rights to request access and correction; we generally respond within 20 working days unless an allowed extension applies.
  • Workforce records: staff should usually contact their employer first (the controller for those records).
  • EEA/UK (where applicable): rights to access, correction, deletion, restriction, objection, portability, and complaint.
  • California (where applicable): rights to know, delete, correct, and limit sensitive information use; no sale of personal information.

11. Biometrics, Photos, and Location

Photo capture, GPS checks, and face verification are optional features controlled by customer settings.

  • Face verification uses embedding templates for match checking.
  • These features are for attendance verification, not advertising profiling.
  • Face-verification outputs are a support signal and should not be used as the sole basis for disciplinary or employment decisions.
  • Clock photos are stored in cloud object storage and referenced by URLs; anyone with a valid URL may view an image.
  • Business customers are responsible for obtaining required workforce notices/consents.

12. Children

Clockie is a business service and is not directed to children under 16. If we learn we have collected children's data inappropriately, we will take reasonable steps to delete it.

13. Policy Updates

We may update this policy for legal, operational, or product changes. Material updates will be posted in-product and/or on our website with a revised date.

14. Contact and Complaints

For privacy questions or requests:

Privacy Contact

Clockie, C/o Kiwi Digital Ltd

33 Havelock Road

Havelock North

Hawke's Bay 4130

New Zealand

Email: privacy@clockie.nz

NZ complaints: Office of the Privacy Commissioner.

California rights information: California Consumer Privacy Act resources.