Privacy Policy
Last updated: 9 July 2026
ClockBear is operated by LexKurion Group ("ClockBear", "we", "us"). We provide a time-and-attendance service that employers use to record their workers' working time. This policy explains what personal data we handle, why, and the rights you have.
1. Controller and processor roles
When an employer uses ClockBear, the employer is the data controller and ClockBear acts as a data processor that handles data on the employer's documented instructions. If you are an employee, please direct requests about your data to your employer first; we will assist the employer in responding.
2. Data we collect
- Account data: name, work email, role, and the company you belong to.
- Time records: clock-in/out and break punches, the server timestamp (UTC), the device's claimed time, timezone, and a device/browser identifier used for auditing and fraud prevention.
- Optional, consent-gated data โ off by default, collected only if your employer enables the feature and you consent:
- Location (approximate or precise) at the moment of a punch;
- Photo captured at punch time;
- Device attestation signals used to detect tampering.
- Biometric data (e.g. a facial or fingerprint template used to verify identity) โ never enabled by default. See Section 6.
- Time-off and approvals: leave requests, balances, and manager decisions.
- Billing data: plan, seat count, and billing contact. Card and payment details are collected and processed directly by our payment provider (see Section 8); we do not store full card numbers.
3. How we use data
- To record working time and produce timesheets, receipts, and payroll exports.
- To apply overtime, break, and retention rules for the relevant jurisdiction.
- To protect against fraud and clock manipulation and to maintain a tamper-evident audit trail.
- To provide support, secure the service, bill for paid plans, and comply with legal obligations.
We do not sell personal data, and we do not use employee time data for advertising.
4. Legal bases
Where the GDPR (EU/UK) applies, we and the employer rely on performance of a contract, the employer's legitimate interests in managing its workforce, compliance with legal obligations (e.g. labor and payroll law), and โ for optional sensitive features โ your explicit consent. Where US state laws (such as the CCPA/CPRA) or Brazil's LGPD apply, we process personal data to provide the service and meet legal obligations, and rely on consent for optional sensitive features.
5. Your rights (GDPR ยท CCPA/CPRA ยท LGPD)
Depending on where you live, you may have the right to access, correct, port, or delete your personal data, to object to or restrict certain processing, and to withdraw consent for optional features at any time. Under the CCPA/CPRA you also have the right not to be discriminated against for exercising these rights; we do not sell or "share" personal information as those terms are defined. Because we act on the employer's behalf, we route these requests through your employer. You can also contact us at contact@clockbear.com and we will forward your request to the responsible employer.
6. Biometric data (BIPA and similar laws)
Biometric features are off by default in every jurisdiction and are never turned on automatically. If an employer enables biometric verification, the employer is responsible โ before any biometric data is collected โ for informing each worker in writing of the purpose and retention period and for obtaining the worker's written consent, as required by laws such as the Illinois Biometric Information Privacy Act (BIPA) and comparable state laws.
When enabled, biometric templates are used only to verify the identity of the person punching. We do not sell, lease, or trade biometric data. Biometric data is stored using reasonable security measures and is permanently destroyed when the purpose for collection has been satisfied, when the employer disables the feature or closes the account, or within three (3) years of the worker's last interaction โ whichever occurs first.
7. Retention
Working-time records are retained while the account is active and for the period required by the applicable jurisdiction (for example, several years for payroll and labor-law purposes). Time entries are append-only: corrections are recorded as new entries and the original is preserved for audit. When an account is closed, we delete or return personal data within 90 days, except where a longer period is required by law or needed to resolve disputes, and except for biometric data, which follows Section 6.
8. Payments
Paid subscriptions are processed by Stripe, Inc., an independent third-party payment provider, under Stripe's privacy policy. Stripe collects and processes your card and billing details directly; ClockBear receives only limited billing metadata (such as plan, status, and the last four digits of a card). When you purchase through a mobile or desktop app store, the app store is not a party to the transaction.
9. Sharing and sub-processors
We share data with your employer, with infrastructure and service providers that operate the service on our behalf, and with payroll systems you choose to export to. Our main sub-processors are Cloudflare, Inc. (hosting, database, and content delivery) and Stripe, Inc. (payments). We require sub-processors to protect personal data under written agreements.
10. International transfers
Our infrastructure is operated primarily in the United States. Where personal data is transferred from the EU/UK or Brazil, we rely on appropriate safeguards such as Standard Contractual Clauses (or equivalent mechanisms) with our sub-processors.
11. Security
Data is encrypted in transit. Session and device secrets are stored in the device's secure keychain/keystore. Time records are hash-chained so that tampering is detectable. No system is perfectly secure, but we maintain safeguards appropriate to the sensitivity of the data.
12. Data breach notification
If we become aware of a personal-data breach affecting an employer's data, we will notify the affected employer(s) without undue delay and, where feasible, within 72 hours of becoming aware, providing the information needed for the employer to meet its own notification obligations.
13. Children
ClockBear is a workplace tool intended for use by employers and their workers. It is not directed to children and we do not knowingly collect personal data from anyone under 16.
14. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to account administrators.
15. Contact
Questions or privacy requests: contact@clockbear.com (LexKurion Group).