Privacy

How ShiftLog handles personal data, and — more importantly — biometric data.

Who holds what

Your company is the data controller for its employees' information. ShiftLog is the processor— we store and process it on your instructions, and we do not use it for anything else. We do not sell data, we do not train models on your employees' faces, and we do not share records between organisations.

Biometric data

This is the part that deserves your attention, so it is written plainly rather than buried.

What is actually stored

When an employee is enrolled, the tablet converts their face into a mathematical template — a list of 128 numbers. That template is what gets stored. It cannot be turned back into a photograph of their face.

Raw camera frames never leave the tablet and are never written to disk. Recognition happens entirely on the device.

A template is not anonymous. It identifies one specific person — that is its whole purpose — so it is personal data, and in most jurisdictions it is a specially protected category.

No images, ever

ShiftLog stores no photograph of anyone's face — neither at enrolment nor at clock-in. There is no face crop, no enrolment photo, and no snapshot kept for evidence. The mathematical template described above is the only thing ever derived from a face.

Consent is not optional

Biometric data is regulated under Zimbabwe's Data Protection Act (2021), the GDPR (Article 9), and statutes such as Illinois BIPA. These generally require informed consent before enrolment, a stated retention period, and a non-biometric alternative for anyone who declines.

ShiftLog records consent at enrolment, with a timestamp and the exact wording shown. PIN entry can never be disabled — it is deliberately not a configurable setting, so an employee who does not want their face scanned always has a way to clock in.

Whether your particular use is lawful where you operate is your responsibility as the controller. This is engineering, not legal advice — please take proper advice before enrolling staff.

Deletion

When an employee is archived, their biometric templates are deleted within 30 days. Their attendance history is retained, because it is the record of hours they worked and were paid for — but it no longer carries anything biometric.

Where data lives

Employee data is stored on Google Cloud, in the United States, and is encrypted at rest and in transit by Google.

Getting your data out

A full export is available at any time, including after a subscription lapses. We do not hold attendance records hostage against an unpaid invoice — your data is yours.

This page describes how the software is built. It is not a substitute for a privacy policy reviewed by a lawyer in your jurisdiction, which you should have before enrolling employees.