NFC Attendance
Legal & Trust Center
Back to Home
Privacy & Trust•Effective Date: October 2, 2026

Privacy & Data Protection Policy

We believe privacy is a fundamental right. This policy outlines how NFC Attendance collects, protects, and handles personal data and geolocation records across our workforce tracking services.

Terms & ConditionsPrivacy Policy

Policy Summary & Key Parameters Matrix

Subject / DimensionPolicy StandardApplicability & Notes
Geolocation DataGPS latitude and longitude captured ONLY at the instant of check-in or check-out.No background or continuous route tracking is ever performed.
NFC IdentifiersPhysical NFC card serials/UIDs are mapped to worker profiles without storing biometric data.Tokens are cryptographically signed and organization-isolated.
Data RetentionAttendance logs and shift calculations retained for 3 years (customizable per company).Company admins can export complete audit logs via CSV at any time.
Payment SecurityAll payment card processing handled directly via Stripe (PCI-DSS Level 1).We never see or store your card number; we keep only invoice amounts, dates and payment status.
Compliance StandardsAligned with PIPEDA, GDPR, CCPA, and standard fair employment data practices.Workers have the right to request access and correction of punch logs.
Quick Navigation / Table of Contents
1. Introduction & Overview2. Information We Collect3. What We Do NOT Collect4. How We Use Information5. Data Retention Schedule6. Data Security & Storage7. Third-Party Service Providers8. Privacy Rights & Compliance9. Contact the Privacy Officer

1. Introduction & Overview

NFC Attendance (“we”, “us”, or “our”) provides workforce attendance solutions to employer organizations (“Customers”). This Privacy Policy explains our practices regarding the collection, use, disclosure, and protection of personal information when individuals interact with our applications, mobile check-in portals, and administrative services.

When processing employee attendance data on behalf of an employer, NFC Attendance acts as a Data Processor (or Service Provider), while the employing organization acts as the Data Controller.

2. Information We Collect

We collect only the minimum information necessary to authenticate workforce shifts and verify worksite presence:

  • Worker Profile Data: Full name, corporate email address, employee ID, phone number (optional), and assigned worksite.
  • Attendance Activity Records: Timestamp of check-in and check-out, duration of shift worked (in hours and minutes), punctuality status (on-time, late, early departure), and tag scan status.
  • Instantaneous Geolocation: Device GPS coordinates (latitude, longitude, and estimated accuracy in meters) recorded strictly at the second a check-in or check-out is submitted.
  • Device & Network Audit Metadata: IP address, user-agent string, and browser platform for anti-fraud detection and session security.

3. What We Do NOT Collect

Our Privacy Guarantee: We do not engage in continuous surveillance or invasive data harvesting.
  • No 24/7 Background Tracking: Location access is requested and queried only in response to a physical card tap or explicit check-in click. We do not track where employees travel before or after shifts.
  • No Biometric Templates: We do not capture or store facial recognition, iris scans, or fingerprint records. Physical NFC badges communicate standard cryptographic hardware identifiers.
  • No Personal Device Content: We have no access to personal photos, contacts, SMS messages, or private browsing history.

4. How We Use Information

We process collected data solely for the following legitimate business purposes:

  • Verifying employee presence within approved geographic perimeters (geofenced worksites).
  • Calculating accurate total shift duration and punctuality metrics for payroll reconciliation.
  • Alerting employers in real-time when workers arrive late or leave early (when alerts are enabled by the company).
  • Securing platform accounts and preventing buddy-punching or fraudulent remote check-ins.
  • Providing audit-ready exportable CSV reports for wage compliance and labor disputes.

5. Data Retention Schedule

We retain Customer Data in accordance with our standard data retention schedule or as directed by the employing Customer:

Data CategoryRetention PeriodDisposal Method
Attendance Logs & Duration3 years (active subscription)Cryptographic deletion
GPS Audit CoordinatesCo-terminus with attendance logAutomated secure deletion
Authentication Sessions24 hours or logout eventAutomated session expiration
Payment RecordsInvoice numbers, amounts, dates and payment status, kept for accountingCard details stay with Stripe; we never receive them
Ended or Cancelled SubscriptionsKept after the plan ends so the company can renew and export its records (read-only access)Deleted when the company asks, subject to payroll record laws

6. Data Security & Storage Architecture

We take administrative, technical, and physical precautions to safeguard employee records against unauthorized disclosure, alteration, or destruction:

  • Encryption in Transit: All HTTP traffic is forced over HTTPS with modern TLS 1.3 cryptographic suites.
  • Encryption at Rest: Database storage volumes and encrypted off-site backups are secured via AES-256.
  • Organization Data Isolation: Customer data is logically segregated with strict organization-level access controls, ensuring your company records remain private and accessible solely by authorized personnel.
  • Password Protection: Passwords are never stored in plaintext; they are hashed with bcrypt using high work-factor salts.

7. Third-Party Subprocessors

We work with trusted third-party service providers to deliver our software:

  • Stripe: Payment processing and subscription management. Stripe adheres to strict PCI-DSS Level 1 compliance.
  • Email delivery provider: Delivery of automated attendance alerts and account email confirmation links.

We do not sell, rent, or trade employee or customer personal data to third parties for advertising or commercial marketing purposes.

8. Privacy Rights & Legal Compliance

Depending on your jurisdiction, employees and account holders may have statutory rights regarding their personal data, including:

  • Right of Access: You may request a copy of all attendance records and punch coordinates logged for your identity.
  • Right to Rectification: Company administrators have the ability to review and rectify contested check-in records.
  • Right to Data Portability: Organizations can export historical data in standard CSV format at any time.
  • Right to Erasure: Organizations may request the deletion of historical workforce logs subject to statutory payroll retention laws.

9. Contact the Privacy Officer

If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact our Data Protection Officer at:

NFC Attendance Privacy Office
Location: Toronto, ON, Canada

Questions about our policies?

Contact our compliance and security team at [email protected]

Start Free Company Trial