Effective Date: September 1, 2025
Last Updated: October 7, 2026
KlockinTeam ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile apps, web app, and related services (together, the "Service").
When you grant location permission, we collect a location snapshot only at the moment someone takes one of these actions — not continuously, not in the background, and not when the app is closed:
We do not record a movement trail between those points. If location permission is denied, the related clock or message location fields may be empty or unavailable, and location-verification features will not work.
Note: We do not store complete credit card numbers. All payment processing is handled securely by Stripe, our PCI-DSS compliant payment processor. Credit card data is never stored on our servers.
We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:
We use Stripe as our payment processor. When you make a payment, your payment information is sent directly to Stripe and processed according to Stripe's Privacy Policy. We receive only limited information such as payment success/failure status and masked card details (last 4 digits).
Stripe Privacy Policy: https://stripe.com/privacy
If an organization owner or admin chooses to connect KlockinTeam to Intuit QuickBooks Online, we use Intuit’s OAuth 2.0 authorization so we never receive or store QuickBooks account passwords.
When connected, we may access and process the following QuickBooks data on behalf of that organization, solely to provide the integration features you enable:
OAuth access and refresh tokens are stored on our servers, encrypted at rest, and used only to call Intuit APIs for that organization. Tokens are not exposed to the mobile or web client. You can disconnect QuickBooks at any time from KlockinTeam Admin → QuickBooks, or from within QuickBooks Online; disconnecting revokes or clears the connection and removes stored tokens for that organization.
Intuit’s handling of data is described in Intuit’s privacy materials, including: https://www.intuit.com/privacy/
We implement reasonable technical and organizational measures intended to protect your information, including:
Payment Security: We never store complete credit card numbers. All payment card data is handled exclusively by Stripe, which is PCI-DSS Level 1 certified (the highest level of security certification in the payments industry).
We retain information for as long as needed to operate the Service and to meet legal, tax, accounting, and dispute-resolution obligations. Retention periods vary by data category and applicable law (for example, payroll-related and billing records are often subject to longer minimums). Location fields stored with time entries follow the same retention approach as the underlying timesheet records they support. Location fields stored with team messages follow the same retention approach as the messages they are attached to.
QuickBooks connection tokens are retained only while the organization remains connected. When you disconnect QuickBooks (in KlockinTeam or in QuickBooks Online), we delete those tokens. Employee-link and time-sync records created through the integration follow the same retention approach as other organization payroll/timesheet data unless you request deletion.
After cancellation or closure of an account, we retain company data for a limited period where appropriate to allow reactivation or export, then delete or anonymize it in the ordinary course except where a longer period is required by law or payment-processor rules. Contact support@klockinteam.com to discuss deletion or export requests.
You have the right to:
Account deletion: You can request deletion of your account and associated data by following the steps on our Delete Account & Data page.
Our apps use the device’s foreground location permission, when you grant it, to record the snapshots listed in Section 2.2. We do not request or use background location to follow a person through the day. You can disable location services in your device settings; clock-in and clock-out can still be recorded without a location, but location verification and message map pins will not be available.
Our services are not intended for individuals under 13 years of age. We do not knowingly collect personal information from children under 13.
When you register an account, your email address is added to our email communications. You will receive product onboarding guidance, feature updates, and occasional information about new products and services from Greg Martins Oji MD Inc. You can unsubscribe from these emails at any time using the unsubscribe link in each email.
We may update this Privacy Policy from time to time. We will notify users of any material changes through the app or via email. Continued use of our services after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or our data practices, please contact us:
Greg Martins Oji MD Inc
California, United States
Email: support@klockinteam.com
This Privacy Policy was last updated on October 7, 2026.