Privacy Policy
Coll Timeclock — last updated August 30, 2026
Coll Timeclock is a work-hours tracking service used by employers ("companies") and their
employees. This page explains what information we collect through the employee app and the
employer (admin) app, and how it's used.
Information we collect
- Account info: employee name, email address, and a PIN (stored as a one-way
hash — we never store or can see your actual PIN). Company admins provide a business email and
password (also stored as a one-way hash).
- Time records: clock-in and clock-out timestamps, break times, job/location
labels, and hours submitted for payroll. If a company sets a break-length or long-shift alert
preference, that setting is stored to time the "break ending soon" and "still clocked in"
notifications described below.
- Compensation info: if a company chooses to set hourly pay rates for its
employees, that rate is stored and used only to calculate that company's own labor cost and
profit reports. It is not shown to the employee it belongs to inside the app.
- Location data: Coll Timeclock collects location data to enable automatic
clock-in/out even when the app is closed or not in use, for employees whose company has turned
this feature on. The app checks the device's GPS location against the company's registered shop
address to detect arrival and departure, and this check can run in the background so an employee
doesn't have to keep the app open on their screen all shift. Your employer only sees the
resulting clock-in/out time entry from this check — not a continuous location trail. Separately,
if a company builds an optimized multi-stop route for a job, its customers' addresses are
converted to map coordinates (geocoded) to plan and display that route, and — only while an
employee is clocked in and assigned to that specific route — an admin can see that employee's
live location so the route and arrival times stay accurate. This location-sharing stops the
moment the employee clocks out.
- Time off requests: the dates and optional note an employee submits when
requesting time off, along with their employer's approve/deny decision on that request.
- File attachments: photos, PDFs, and documents a company chooses to attach to
a scheduled job or an invoice — stored directly in our database, capped at 10MB per file, and
visible only to that company's own admin account and (for job attachments) the employees assigned
to that job.
- Payroll contact info: each company sets its own payroll inbox address, used
only to email that company's submitted timesheets.
- Customer records: if a company adds its own customers to the app, we store
the name, phone number, email, mailing address, and notes the company enters, along with a
history of that customer's scheduled appointments, quotes, and invoices. This is the company's
own business data about its customers, not information we collect directly from those
customers.
- Billing records: quotes, invoices, line items, payment status (including an
optional check number for invoices paid by check, entered for the company's own recordkeeping),
business expenses, and an optional company logo image, all entered by a company to run its own
billing and profit tracking. A company's uploaded logo is also shown inside its own employees'
app, alongside the company's own branding.
- Payment information: a company that wants to accept online payments
connects its own Stripe account, and its customers' payments are collected and processed
directly by Stripe into that account — the money never passes through Coll Timeclock, and we
never receive or store full card numbers or bank account numbers. We store only the payment
status, amount, date, Stripe's own transaction reference, the processing fee and our platform
fee for that transaction (used only to calculate that company's own profit reports), and the
email address used to send that customer an automatic payment receipt.
- Subscription billing information: to bill your own company's $9.99/month
subscription to use Coll Timeclock, we store a Stripe customer and subscription reference, your
subscription status (for example, trialing, active, or past due), and your trial end date. As
with the customer payments above, your card details are collected and stored by Stripe
directly — we never receive or store your card number.
- Team messages: chat messages sent between a company's admin and its
employees, and messages employees at the same company send directly to each other or in a group
thread, all within the app.
- Push notification data: if an employee or admin enables notifications, we
store a device push subscription token, used only to deliver that company's own schedule, chat,
break, long-shift-alert, and inventory pull-sheet notifications to that device.
- Inventory and catalog data: if a company tracks inventory, we store the item
names, quantities on hand, barcodes, and "pull sheets" (a list of items a job needs, and how much
of each has been pulled) that company enters or generates. This is the company's own business
data about its own stock, not information about any individual person.
- Camera access for barcode scanning: if a company or an employee it has
authorized uses the barcode-scanning feature to look up or add an inventory item, the device
camera — either a live in-app preview or a photo taken with your device's own camera app — is
used only to read the barcode in view. That image is processed entirely on your device and is
never uploaded, stored, or sent to us.
How we use this information
- To record and report hours worked, for the employee and their employer.
- To optionally automate clock-in/out based on arrival at a company's job site.
- To send account-related emails: password/PIN reset links and submitted timesheets.
- To let a company's admin view their own employees' time records and overview dashboard.
- To let a company manage its own customers, schedule jobs, and send quotes and invoices.
- To plan and display optimized multi-stop routes for a company's own jobs, and let an admin
see where an assigned, clocked-in employee currently is along that route.
- To let employees request time off and let their employer review and approve or deny it.
- To let a company attach and view reference files (photos, PDFs, documents) on its own jobs
and invoices.
- To calculate a company's own labor cost, expenses, and Gross/Net Profit reports.
- To deliver chat messages and schedule/job push notifications within a company's own
account.
- To process online invoice payments through Stripe and email the paying customer an
automatic payment receipt.
- To let a company track its own inventory, build pull sheets for jobs, and use its camera to
scan barcodes and look up items.
What we don't do
- We don't sell or share your data with advertisers or unrelated third parties.
- We don't track location outside of the clock-in/out check described above.
- We don't capture, store, or transmit any image or video from a device's camera — whether
it's a live preview or a photo taken to scan a barcode, that image stays on your device and is
only used to read the barcode in view.
- Each company's data — employees, time records, pay rates, customers, quotes, invoices,
expenses, routes, file attachments, time off requests, chat messages, and inventory/catalog data —
is only visible to that company's own admin account, never to other companies using Coll
Timeclock.
Service providers we use
Running Coll Timeclock means a few outside services process data on our behalf, each only for
the specific job described:
- Stripe — processes online invoice payments (card and bank transfer/ACH)
through each company's own connected Stripe account, and separately processes your own
company's $9.99/month subscription payment to Coll Business Solutions. Stripe collects and
stores the actual payment details in both cases; we only receive the payment status, amount,
fees, and a transaction or subscription reference.
- Resend — delivers the emails Coll Timeclock sends (timesheets, password/PIN
resets, quotes, invoices, and payment receipts).
- Railway — hosts our servers and database.
- OpenStreetMap (Nominatim) — converts a customer's street address into map
coordinates so a company can build an optimized multi-stop route to them. Only the address text
is sent, and only when a company adds/edits a customer or builds a route.
- Google Maps — turn-by-turn directions links open Google Maps directly on
your own device; we don't send Google any data ourselves, the link is just a destination address
your device passes along when you tap it.
- Sentry — helps us catch and fix errors in the app; it may receive technical
details about a request that failed (such as which page or action triggered it), but is used for
troubleshooting, not tracking.
These providers don't get to use your data for their own purposes — they process it only to
provide the service described above.
How data is stored and secured
Data is stored in a managed Postgres database and transmitted over encrypted (HTTPS)
connections. Passwords and PINs are hashed before storage. Access to admin and employee accounts
is controlled through authenticated, time-limited login sessions.
Data retention
We retain account and time-record data for as long as a company's account is active, since
historical hours are part of payroll recordkeeping.
Request account or data deletion
Any employee or admin can request deletion of their account and associated data — whether or
not you still have the app installed — by emailing
jeremymcollins89@gmail.com
with the email address on the account and which company it belongs to. An admin can also request
deletion of their entire company's account and all its data the same way. We'll confirm by email
once it's done. Some records (for example, payroll time records or payment records a company is
legally required to keep for tax purposes) may be retained for the period required by law even
after an account deletion request, and this is disclosed to the requester at the time.
Children's privacy
Coll Timeclock is a workplace tool intended for employees of subscribing companies and is not
directed at children.
Changes to this policy
If this policy changes, the updated version will be posted on this page with a new "last
updated" date.
Contact
Questions about this policy or your data can be sent to
jeremymcollins89@gmail.com. See also our
Terms of Service.