Legal
Privacy Policy
Last updated: 7 July 2026
This Privacy Policy explains how Smart Solution Labz LLC ("Smart Solution Labz", "we", "us") collects, uses, shares and protects personal data when you use the Clocker application, websites and related services (the "Service"). It also explains your rights under the EU General Data Protection Regulation (GDPR) and Croatian data-protection law.
1. Who is responsible for your data
The data controller for the Service is:
Smart Solution Labz LLC
30 N Gould St, Ste R, Sheridan, WY 82801, USA
Privacy contact: info@s-labz.com
EU representative (Article 27 GDPR). Because we are established outside the European Union, we have designated Smartyn d.o.o., Vladimira Nazora 1b, 40317 Podturen, Croatia (email: info@s-labz.com), as our representative in the EU. You and supervisory authorities may contact the representative on all matters related to the processing of your personal data, in addition to or instead of contacting us directly.
Smartyn d.o.o. also acts as our authorised reseller and merchant of record: it processes billing, invoicing and support data on our behalf as our processor, and is an independent controller of its own statutory invoicing and accounting records under Croatian law.
2. Controller and processor roles
Clocker is a business tool. It matters in what role we process data:
- We are the controller for data about your account, billing and payments, your use of the Service, and our communications with you.
- We are a processor (you are the controller) for personal data that you or your Members enter into a Workspace about identifiable people - for example, employee time records, location check-ins, client (CRM) contact details, bookings, notes and attachments. We process that data on your documented instructions to provide the Service. As the controller of that data, you are responsible for having a valid legal basis and for informing the individuals concerned (for example, your employees about location tracking).
Who to ask for what. If you want your Clocker account itself deleted, or you have a question about sign-in, billing or the app, ask us - see Sections 9 and 10. If you want something changed or removed from the work records your employer keeps in Clocker - working hours, payroll figures, personnel documents, or the entries that record your name as the person who did or approved something - ask your employer. They decide what happens to those records; we act only on their instruction, and we will not delete or alter them because a Member asks us to. The Article 28 GDPR terms of that relationship are set out in our Data Processing Addendum.
3. Personal data we collect
You give us:
- Account data - name, email address, password (stored hashed), company/Workspace details, language and settings, and an optional home/postal address (country, city, postal code and street) that a Member may provide, and that their employer's Administrators may view and maintain, for the employer's payroll and work records.
- Content you submit ("Customer Data") - time records, work hours, work orders, reservations and events, client (CRM) records, notes, tasks, and any files or attachments you upload.
- Payment data - your subscription and billing details. Card payments are processed by Worldline; we receive limited data such as the fact of payment, amount, and a payment reference. We do not store full card numbers.
- Support and communications - messages you send us.
We collect automatically:
- Location data - if you use location-based check-in, the Service uses your device location to confirm you are within the allowed radius of a workplace. Location is used for this purpose and related records. On mobile devices you can control location permission in your device settings; disabling it may limit location check-in.
- Device and usage data - device type, operating system, app version, identifiers, log data, and how you interact with the Service.
- Push notification tokens - to deliver notifications (for example, invitations or reminders), if enabled.
- Cookies and similar technologies - see our Cookie Notice.
4. Why we use your data and our legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide, operate and secure the Service and your account | Performance of a contract |
| Process payments, subscriptions and invoicing | Performance of a contract; legal obligation |
| Provide support and respond to you | Performance of a contract; legitimate interests |
| Location check-in (confirming presence at a workplace) | Performance of a contract with the account holder; where you are a Member, the controller (your employer) is responsible for the legal basis, which may be legitimate interests, legal obligation or consent |
| Maintain security, prevent fraud and abuse | Legitimate interests; legal obligation |
| Diagnose crashes and keep the app stable (crash reporting) | Legitimate interests (you can opt out in the app) |
| Understand usage to improve the Service (analytics) | Consent (off by default; opt in in the app) |
| Send service and, where permitted, marketing messages | Legitimate interests or consent; you can opt out of marketing |
| Comply with legal, tax and accounting obligations | Legal obligation |
Where we rely on legitimate interests, we balance those against your rights. Where we rely on consent, you can withdraw it at any time without affecting prior processing.
Analytics, crash reporting and your in-app controls
We use Google Firebase for optional, non-essential processing, and you control it in the app under Settings → Data & privacy:
- Analytics (Firebase Analytics) helps us understand how the app is used so we can improve it. It is off by default and only runs if you turn it on (opt-in). No analytics data is collected until you consent.
- Crash reporting (Firebase Crashlytics) sends diagnostic reports when the app crashes so we can fix problems. It is on by default as a legitimate interest in keeping the app stable and secure, and you can turn it off at any time in Settings.
- Mobile advertising identifier (iOS App Tracking Transparency). On iOS the system asks for your permission before any device advertising identifier can be used. We do not use your data for third-party advertising; if you decline, the app works the same.
5. Location data
Because Clocker offers location-based check-in, we want to be clear: location is collected to verify that a check-in happens within a workplace radius configured for a Member. If you are an employer using this feature, you are the controller of your Members' location data and must have a lawful basis and inform your Members. If you are a Member, your employer decides whether location check-in applies to you; direct questions about it to your employer.
6. Who we share data with
We do not sell your personal data. We share it only with:
- Service providers (processors) who help us run the Service under contract, including Google (Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, Cloud Messaging and analytics) for hosting and infrastructure, and Worldline for payment processing.
- Smartyn d.o.o. (Croatia), our authorised reseller, merchant of record and EU representative, for billing, invoicing, sales and support.
- Your Workspace - Customer Data you submit is visible to the Administrators and Members of your Workspace according to the permissions you set.
- Authorities or third parties where required by law, to protect our rights, or in connection with a merger, acquisition or sale of assets (with continued protection of your data).
A current list of our main sub-processors is available on request at info@s-labz.com.
7. Where your data is stored
The Service's primary data storage is hosted in the European Union (Google Cloud region europe-west3, Frankfurt): the database that holds Customer Data and the file storage that holds your uploads are both in that region. Backups and processing take place under appropriate safeguards.
Sign-in data is the exception. Firebase Authentication - the Google service that holds your email address, your password hash, your telephone number if you sign in with one, your Google or Apple sign-in identifier, and the IP addresses and timestamps of your sign-in events - is operated only in the United States, whatever region the database is in. Push notification delivery and crash diagnostics may also be processed outside the European Economic Area. Section 8 explains the safeguards we rely on for those transfers.
8. International transfers
We are a company established in the United States, and some of our providers (for example, Worldline and Google) may also process personal data outside the European Economic Area. Customer Data is stored in the European Union (see Section 7); where personal data is accessed from or transferred to the United States or another third country, we rely on appropriate safeguards under Chapter V of the GDPR, such as the European Commission's Standard Contractual Clauses and/or an adequacy decision, to protect your data. You can request more information about these safeguards at info@s-labz.com.
9. How long we keep data
- Account and Customer Data - for as long as your account is active. When a Free Trial expires or a Subscription ends, we keep your Workspace and its Customer Data for 80 days, so that you can subscribe (or resubscribe) within that window and continue exactly where you left off. After those 80 days we delete or anonymise Customer Data, subject to backups that are overwritten on a rolling basis. You can also ask us to delete it sooner (see Section 10).
- Billing and tax records - for as long as required by applicable accounting and tax law.
- Support communications - for as long as needed to handle your request and for our records.
You (or your Administrator) can delete much of your data directly in the Service, and you can request deletion as described below.
Deleting your Clocker account
You can delete your account in the app, or on our account deletion page, which accepts the request itself after you sign in.
Deletion is not instant. Your account is first deactivated and enters a grace period of 40 days: you immediately lose access to every Workspace you belonged to, and during that window you can change your mind and restore the account simply by signing in again. When the window expires, a scheduled job permanently deletes your sign-in credentials and the Clocker account behind them, your personal profile, and the contact details held about you on each employer's employee card - your email address, home address, telephone number, date of birth and gender.
What stays after that, and why. Your first and last name remain on the employee card in each Workspace you were a member of, and the records your employers keep about your work - working-hours records, payroll and payment data, personnel documents they uploaded, and the operational records that name you as the person who created, edited or approved something - are not deleted. Those are your employer's records, not ours: your employer is the controller, we are only its processor, and in most cases your employer is legally required to keep them for years after your employment ends. We are therefore neither entitled nor able to delete them because you ask us to. Section 10 explains where to take such a request.
When your employer removes you from a Workspace
An Administrator can remove you from a Workspace in one of two ways. Archiving withdraws your access and changes nothing else; the membership can be restored at any time. Deleting your data withdraws your access immediately and starts a cancellable window of 40 days, after which your personnel record in that Workspace is permanently deleted: profile fields, manager notes, uploaded personnel documents and the files behind them, and your own absence and leave requests. Your working-hours and payroll records are kept unless the Administrator explicitly switches that on as a separate, separately confirmed instruction.
After that deletion completes, a minimal record holding only your first and last name and technical flags remains in the Workspace, so that historical entries still display correctly. Your name also remains on the employer's operational records, shown in a muted style. Every removal, cancellation and permanent deletion is written to a log inside the Workspace that records who ordered it and when; that log is kept as evidence of the instruction and is deleted with the Workspace itself.
Removal from a Workspace does not delete your personal Clocker account. It stays yours, with your profile intact, and you can create your own Workspace or accept another invitation with it.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten") in certain circumstances;
- restrict or object to processing in certain circumstances, including objecting to processing based on legitimate interests and to direct marketing;
- data portability - receive your data in a structured, commonly used, machine-readable format;
- withdraw consent at any time where we rely on consent; and
- lodge a complaint with a supervisory authority, in Croatia the Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka - AZOP).
To exercise your rights, contact info@s-labz.com. If your request concerns data where your employer or another organisation is the controller (for example, Member or client data in their Workspace), we will direct you to, or notify, that controller. We respond within the time limits required by law (generally one month).
Requests about your work data. If you ask us to erase, correct or hand over the records an employer keeps about you in Clocker, we will confirm we received the request, tell you which organisation is the controller, and refer you to them; where we consider it appropriate we will also let them know that you asked. We will not act on the request ourselves, for two independent reasons: we process that data only as the employer's processor and may not act against the controller's instructions, and the right to erasure does not apply where processing is necessary for compliance with a legal obligation of the controller (Article 17(3)(b) GDPR) - which is usually the case for working-time, payroll and personnel records. This does not limit your rights against your employer, or your right to complain to a supervisory authority. It also does not stop you deleting your Clocker account itself at any time (Section 9).
11. Security
We use technical and organisational measures to protect personal data, including encryption in transit, access controls, authentication, and hosting on reputable cloud infrastructure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach is likely to result in a risk to your rights, we will notify the relevant authority and, where required, affected individuals in line with the GDPR.
12. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Features such as automatic classification of hours are calculation tools; they do not by themselves make decisions about individuals.
13. Children
The Service is intended for business use by people aged 18 or over and is not directed at children. We do not knowingly collect personal data from children.
14. Cookies
Our websites and the Service use cookies and similar technologies as described in our Cookie Notice.
15. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes we will provide notice (for example, by email or in the Service) before they take effect. The "Last updated" date at the top shows the latest revision.
16. Contact
For any privacy question or to exercise your rights:
Smart Solution Labz LLC
30 N Gould St, Ste R, Sheridan, WY 82801, USA
Email: info@s-labz.com
EU representative (Art. 27 GDPR): Smartyn d.o.o., Vladimira Nazora 1b, 40317 Podturen, Croatia, email: info@s-labz.com