Legal
Privacy Policy
Last updated: 2026-09-05
This Privacy Policy explains how Smart Solution Labz LLC ("Smart Solution Labz", "we", "us") collects, uses, shares and protects personal data when you use the Clocker application, websites and related services (the "Service"). It also explains your rights under the EU General Data Protection Regulation (GDPR) and Croatian data-protection law.
1. Who is responsible for your data
The data controller for the Service is:
Smart Solution Labz LLC
30 N Gould St, Ste R, Sheridan, WY 82801, USA
Privacy contact: info@s-labz.com
EU representative (Article 27 GDPR). Because we are established outside the European Union, we have designated Smartyn d.o.o., Vladimira Nazora 1b, 40317 Podturen, Croatia (email: info@s-labz.com), as our representative in the EU. You and supervisory authorities may contact the representative on all matters related to the processing of your personal data, in addition to or instead of contacting us directly.
Smartyn d.o.o. also acts as our authorised reseller and merchant of record: it processes billing, invoicing and support data on our behalf as our processor, and is an independent controller of its own statutory invoicing and accounting records under Croatian law.
2. Controller and processor roles
Clocker is a business tool. It matters in what role we process data:
- We are the controller for data about your account, billing and payments, your use of the Service, and our communications with you.
- We are a processor (you are the controller) for personal data that you or your Members enter into a Workspace about identifiable people - for example, employee time records, location check-ins, client (CRM) contact details, bookings, notes and attachments. We process that data on your documented instructions to provide the Service. As the controller of that data, you are responsible for having a valid legal basis and for informing the individuals concerned (for example, your employees about location tracking).
Who to ask for what. If you want your Clocker account itself deleted, or you have a question about sign-in, billing or the app, ask us - see Sections 9 and 10. If you want something changed or removed from the work records your employer keeps in Clocker - working hours, payroll figures, personnel documents, or the entries that record your name as the person who did or approved something - ask your employer. They decide what happens to those records; we act only on their instruction, and we will not delete or alter them because a Member asks us to. The Article 28 GDPR terms of that relationship are set out in our Data Processing Addendum.
3. Personal data we collect
You give us:
- Account data - name, email address, password (stored hashed), company/Workspace details, language and settings, and an optional home/postal address (country, city, postal code and street) that a Member may provide, and that their employer's Administrators may view and maintain, for the employer's payroll and work records.
- Content you submit ("Customer Data") - time records, work hours, work orders, reservations and events, client (CRM) records, notes, tasks, and any files or attachments you upload.
- Payment data - your subscription and billing details. Card payments are processed by Worldline; we receive limited data such as the fact of payment, amount, and a payment reference. We do not store full card numbers.
- Support and communications - messages you send us.
We collect automatically:
- Location data - if you use location-based check-in, the Service uses your device location to confirm you are within the allowed radius of a workplace. Location is used for this purpose and related records. On mobile devices you can control location permission in your device settings; disabling it may limit location check-in.
- Device and usage data - device type, operating system, app version, identifiers, log data, the date of your last activity and the platform you used, and, only with your consent, how you interact with the Service (see Section 4, Analytics).
- Push notification tokens - to deliver notifications (for example, invitations or reminders), if enabled.
- Cookies and similar technologies - see our Cookie Notice.
4. Why we use your data and our legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide, operate and secure the Service and your account | Performance of a contract |
| Process payments, subscriptions and invoicing | Performance of a contract; legal obligation |
| Provide support and respond to you | Performance of a contract; legitimate interests |
| Location check-in (confirming presence at a workplace) | Performance of a contract with the account holder; where you are a Member, the controller (your employer) is responsible for the legal basis, which may be legitimate interests, legal obligation or consent |
| Maintain security, prevent fraud and abuse | Legitimate interests; legal obligation |
| Diagnose crashes and keep the app stable (crash reporting) | Legitimate interests (you can opt out in the app) |
| Understand usage to improve the Service (analytics, in the app and on the website) | Consent (off by default; one question after sign-up in the app, the cookie banner on the website; withdraw at any time) |
| Keep aggregate service statistics (how many workspaces, invitations or records are created per day, how many devices of each platform are active) | Legitimate interests (counts only, no identifiers) |
| Send service and, where permitted, marketing messages | Legitimate interests or consent; you can opt out of marketing |
| Comply with legal, tax and accounting obligations | Legal obligation |
Where we rely on legitimate interests, we balance those against your rights. Where we rely on consent, you can withdraw it at any time without affecting prior processing.
Analytics, crash reporting and your in-app controls
We use Google Firebase for optional, non-essential processing, and you control it in the app under Settings > Data & privacy:
- Analytics (Google Analytics for Firebase) helps us understand how the app is used so we can improve it: which screens are opened, which features are used, where people get stuck. It is off by default. We ask you once, when you first sign in, with two equal choices, and you can change your answer at any time in Settings; declining changes nothing about how the app works for you. When it is on, the app sends a random app-instance identifier (in a browser, the analytics cookie described in the Cookie Notice and the address of the page you are on), the names of the actions we measure, the device model, operating system, app version, language and an approximate country, plus three general facts about your context: your role in the Workspace (owner, manager or employee), the size band of your team, and the language you use the app in. It never sends your name, e-mail address, phone number, your company's name, or the content you put into the app - your working hours, clients, notes and files. Everything it does send is a fixed label or a number from a short, predefined list, so no free text can reach it. We never use it for advertising and we do not collect the device's advertising identifier.
- Website analytics (Google Analytics) on clocker.cloud runs only after you choose "Accept all" in the cookie banner. It records the addresses of the pages you open (which also tells us which language version you read), how far you scroll, which links into the app and which trade categories you click, and which questions you open in the frequently asked questions, together with a random visitor identifier stored in a cookie, your browser and device type, and an approximate country. It never contains your name, e-mail address or anything you type. See the Cookie Notice.
- Crash reporting (Firebase Crashlytics) sends diagnostic reports when the app crashes so we can fix problems. It is on by default as a legitimate interest in keeping the app stable and secure, and you can turn it off at any time in Settings.
- Service statistics. We keep daily counts of how many accounts, workspaces, invitations, time records, reservations, notes and clients are created, how quickly invitations are accepted, which answer new workspaces gave to "how did you hear about us", and how many devices of each platform are active. These are aggregate numbers with no identifiers, kept to run and plan the Service, and unlike analytics they are counted whether or not you consent. To count active devices, your profile stores the date of your last activity and the platform you used; nothing else about your activity is recorded for this purpose.
5. Location data
Because Clocker offers location-based check-in, we want to be clear: location is collected to verify that a check-in happens within a workplace radius configured for a Member. If you are an employer using this feature, you are the controller of your Members' location data and must have a lawful basis and inform your Members. If you are a Member, your employer decides whether location check-in applies to you; direct questions about it to your employer.
6. Who we share data with
We do not sell your personal data. We share it only with:
- Service providers (processors) who help us run the Service under contract, including Google (Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, Cloud Messaging and analytics) for hosting and infrastructure, Worldline for payment processing, E-RAČUNI d.o.o. (Croatia) for issuing and fiscalising invoices as a certified e-invoicing intermediary, and Scaleway S.A.S. (France) for sending email from the Service (reminders, invoices, payment notices).
- Smartyn d.o.o. (Croatia), our authorised reseller, merchant of record and EU representative, for billing, invoicing, sales and support.
- Your Workspace - Customer Data you submit is visible to the Administrators and Members of your Workspace according to the permissions you set.
- Authorities or third parties where required by law, to protect our rights, or in connection with a merger, acquisition or sale of assets (with continued protection of your data).
A current list of our main sub-processors is available on request at info@s-labz.com.
7. Where your data is stored
The Service's primary data storage is hosted in the European Union (Google Cloud region europe-west3, Frankfurt): the database that holds Customer Data and the file storage that holds your uploads are both in that region. Backups and processing take place under appropriate safeguards.
Sign-in data is the exception. Firebase Authentication - the Google service that holds your email address, your password hash, your telephone number if you sign in with one, your Google or Apple sign-in identifier, and the IP addresses and timestamps of your sign-in events - is operated only in the United States, whatever region the database is in. Push notification delivery, crash diagnostics and usage analytics (Google Analytics, only with your consent) may also be processed outside the European Economic Area. Section 8 explains the safeguards we rely on for those transfers.
8. International transfers
We are a company established in the United States, and some of our providers (for example, Worldline and Google) may also process personal data outside the European Economic Area. Customer Data is stored in the European Union (see Section 7); where personal data is accessed from or transferred to the United States or another third country, we rely on appropriate safeguards under Chapter V of the GDPR, such as the European Commission's Standard Contractual Clauses and/or an adequacy decision, to protect your data. You can request more information about these safeguards at info@s-labz.com.
9. How long we keep data
- Account and Customer Data - for as long as your account is active. When a Free Trial expires or a Subscription ends, we keep your Workspace and its Customer Data for 80 days, so that you can subscribe (or resubscribe) within that window and continue exactly where you left off. After those 80 days we delete or anonymise Customer Data, subject to backups that are overwritten on a rolling basis. You can also ask us to delete it sooner (see Section 10).
- Billing and tax records - for as long as required by applicable accounting and tax law.
- Support communications - for as long as needed to handle your request and for our records.
- Usage analytics (only with your consent) - event-level data is kept in Google Analytics for 14 months; crash reports for 90 days. The aggregate service statistics described in Section 4 contain no identifiers and are kept for as long as the Service exists.
You (or your Administrator) can delete much of your data directly in the Service, and you can request deletion as described below.
Deleting your Clocker account
You can delete your account in the app, or on our account deletion page, which accepts the request itself after you sign in.
Deletion is not instant. Your account is first deactivated and enters a grace period of 40 days: you immediately lose access to every Workspace you belonged to, and during that window you can change your mind and restore the account simply by signing in again. When the window expires, a scheduled job permanently deletes your sign-in credentials and the Clocker account behind them, your personal profile, and the contact details held about you on each employer's employee card - your email address, home address, telephone number, date of birth and gender.
What stays after that, and why. Your first and last name remain on the employee card in each Workspace you were a member of, and the records your employers keep about your work - working-hours records, payroll and payment data, personnel documents they uploaded, and the operational records that name you as the person who created, edited or approved something - are not deleted. Those are your employer's records, not ours: your employer is the controller, we are only its processor, and in most cases your employer is legally required to keep them for years after your employment ends. We are therefore neither entitled nor able to delete them because you ask us to. Section 10 explains where to take such a request.
When your employer removes you from a Workspace
An Administrator can remove you from a Workspace in one of two ways. Archiving withdraws your access and changes nothing else; the membership can be restored at any time. Deleting your data withdraws your access immediately and starts a cancellable window of 40 days, after which your personnel record in that Workspace is permanently deleted: profile fields, manager notes, uploaded personnel documents and the files behind them, and your own absence and leave requests. Your working-hours and payroll records are kept unless the Administrator explicitly switches that on as a separate, separately confirmed instruction.
After that deletion completes, a minimal record holding only your first and last name and technical flags remains in the Workspace, so that historical entries still display correctly. Your name also remains on the employer's operational records, shown in a muted style. Every removal, cancellation and permanent deletion is written to a log inside the Workspace that records who ordered it and when; that log is kept as evidence of the instruction and is deleted with the Workspace itself.
Removal from a Workspace does not delete your personal Clocker account. It stays yours, with your profile intact, and you can create your own Workspace or accept another invitation with it.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten") in certain circumstances;
- restrict or object to processing in certain circumstances, including objecting to processing based on legitimate interests and to direct marketing;
- data portability - receive your data in a structured, commonly used, machine-readable format;
- withdraw consent at any time where we rely on consent; and
- lodge a complaint with a supervisory authority, in Croatia the Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka - AZOP).
To exercise your rights, contact info@s-labz.com. If your request concerns data where your employer or another organisation is the controller (for example, Member or client data in their Workspace), we will direct you to, or notify, that controller. We respond within the time limits required by law (generally one month).
Requests about your work data. If you ask us to erase, correct or hand over the records an employer keeps about you in Clocker, we will confirm we received the request, tell you which organisation is the controller, and refer you to them; where we consider it appropriate we will also let them know that you asked. We will not act on the request ourselves, for two independent reasons: we process that data only as the employer's processor and may not act against the controller's instructions, and the right to erasure does not apply where processing is necessary for compliance with a legal obligation of the controller (Article 17(3)(b) GDPR) - which is usually the case for working-time, payroll and personnel records. This does not limit your rights against your employer, or your right to complain to a supervisory authority. It also does not stop you deleting your Clocker account itself at any time (Section 9).
11. Security
We use technical and organisational measures to protect personal data, including encryption in transit, access controls, authentication, and hosting on reputable cloud infrastructure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach is likely to result in a risk to your rights, we will notify the relevant authority and, where required, affected individuals in line with the GDPR.
12. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Features such as automatic classification of hours are calculation tools; they do not by themselves make decisions about individuals.
13. Children
The Service is intended for business use by people aged 18 or over and is not directed at children. We do not knowingly collect personal data from children.
14. Cookies
Our websites and the Service use cookies and similar technologies as described in our Cookie Notice.
15. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes we will provide notice (for example, by email or in the Service) before they take effect. The "Last updated" date at the top shows the latest revision.
16. Contact
For any privacy question or to exercise your rights:
Smart Solution Labz LLC
30 N Gould St, Ste R, Sheridan, WY 82801, USA
Email: info@s-labz.com
EU representative (Art. 27 GDPR): Smartyn d.o.o., Vladimira Nazora 1b, 40317 Podturen, Croatia, email: info@s-labz.com