HoursDone

Last updated 2026-07-26

Privacy policy

This explains what HoursDone stores, why, and for how long. It is written to be read, not to be survived.

Who is responsible for what

If you are an employee whose hours are tracked here: your employer decides what is collected and why. They are the data controller. HoursDone stores it on their behalf as a processor, and acts on their instructions. Ask them first — but if you cannot get an answer, write to us and we will help.

If you run a business using HoursDone: you are the controller. That means it is on you to tell your staff they are being clocked and photographed, and to have a lawful basis for it. We give you the tools; we cannot give you the consent.

What we store about managers

  • Your name and email address.
  • If you sign in with Google: the account identifier Google returns. We never see your Google password.
  • If you sign in with a password: a hash of it, never the password itself.
  • A session cookie so you stay signed in for a week.

What we store about employees

Employees never have accounts, never sign in, and never give us an email address. What exists is only what an employer typed in and what a wall tablet recorded:

  • A display name, and which location they belong to.
  • A hash of their PIN. The PIN itself is never stored, is not recoverable from the hash, and cannot be read back by anyone — including us. Archiving an employee destroys the hash outright.
  • One row per tap: the time, whether it was in, out or a break, and which device sent it.
  • Optionally, a photograph taken at the moment of the tap.

Punch photographs

Photos are optional, and off unless an employer turns them on. When they are on, the tablet takes one frame at the moment of the tap. Nothing is recorded before or after it, and there is no video at any point.

Location, device and camera metadata are stripped from every image on our servers when it arrives — not on the device, and not only when the device forgot to. That happens unconditionally, on every upload.

Photos expire. Each account sets a retention window between 7 days and 2 years, 90 days by default, and a nightly job permanently deletes anything older. There is deliberately no option to keep them for ever.

The punch record itself is never deleted, so hours survive their photographs. An expired photo simply becomes a punch with no photo attached.

What we do not do

  • No advertising, ever, and we do not sell or share data with anyone for it.
  • No third-party analytics, no tracking pixels, and no advertising cookies. The public pages set no cookies at all.
  • No location tracking. We do not know or record where a tablet is, beyond the timezone an employer sets for the site.
  • No continuous monitoring, screenshots, keystrokes or productivity scoring. HoursDone records taps, not behaviour.
  • We do not use your data to train machine learning models.

Where it lives

Every account gets its own separate database, rather than sharing one with a column naming the tenant. Two customers' records are not in the same table, which removes the class of bug where a filter is forgotten.

Data is hosted on Cloudflare's network. Photographs are held in object storage; hours are held in the account's database.

Who else touches it

A short list, and it is the whole list:

  • Cloudflare — hosting, databases and photo storage.
  • Google — only if a manager chooses to sign in with Google, and only to confirm who they are.
  • Resend — delivery of the handful of emails we send: confirm your address, reset your password, you have been invited.
  • Polar — payments, but only if you subscribe to a paid plan. They are the merchant of record, which means they take the payment and issue the receipt.

Paying, and what we never see

We do not handle card details, and we never see them. Payments go through Polar, who take the payment and hold whatever the card network requires. What comes back to us is a customer reference, a plan, and whether the subscription is active — nothing that could be used to charge a card.

If you only use the free plan, none of this applies to you: no payment provider is involved and nothing about you reaches one.

Corrections and history

A recorded punch is never edited or deleted, by anyone, including us — the database physically refuses it. When a manager fixes a mistake, the fix is stored alongside the original with their name and a reason, and can be withdrawn later.

This is deliberate, and it cuts both ways: it means an employer cannot quietly rewrite an employee's hours, and it means a correction you asked for stays visible on the record.

Keeping and deleting

  • Photographs: deleted automatically at the end of the retention window the account has set.
  • Hours and punch records: kept while the account is active, because they are payroll records the employer is usually legally required to keep.
  • Close your account and we delete its database, and its photographs, within 30 days.
  • Ask us to delete something specific and we will, unless keeping it is required of your employer by law — in which case we will say so.

Your rights

Depending on where you are, you can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be deleted. Employees should ask their employer first, since it is their record; we will help if that goes nowhere.

Write to support@hoursdone.com. We answer within 30 days, usually far sooner.

Children

HoursDone is a tool for businesses and is not directed at children. Where a lawfully employed young person is clocked in by their employer, the same protections in this policy apply to their record as to anyone else's.

Changes

If this policy changes in a way that matters, we will email account owners rather than quietly changing the date at the top. The date above is the last substantive change.

Contact

support@hoursdone.com, or the contact form on this site. A person reads it.