Legal / Privacy

Privacy Policy

EFFECTIVE SEPTEMBER 22, 2026

Alfahr records where and when your crew punches so employers can verify hours. This policy explains exactly what that means for your data — in plain language.

01

Overview

Alfahr Inc. (“Alfahr”, “we”, “us”) provides location-verified time and attendance software for employers and their crews. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices you have. It applies to:

  • The Alfahr web application and admin portal, including this website.
  • The Alfahr employee mobile app for iOS and Android (the “App”).
  • The Alfahr API and any related support services.

Together these are the “Service”. By using the Service you acknowledge the practices described here.

02

Our role: employers and workers

Alfahr is a workplace tool. In most cases your employer (or the organization that invited you) creates the workspace, decides which locations and schedules to configure, and controls the timecard data collected about its workers. For that data your employer is the data controller and Alfahr is a data processor / service provider acting on its instructions.

If you are a worker and have questions about why your employer collects certain information, how long it is retained, or want to exercise rights over it, please contact your employer first. We will assist them in responding.

For information we collect directly for our own purposes — such as account sign-up details for workspace owners, billing, website analytics, and support correspondence — Alfahr is the controller.

03

Information we collect

Information you or your employer provide

  • Account and profile details — name, email address, phone number, profile photo, employee number, job role, department, groups and tags, and your preferred time zone.
  • Workspace details — organization name, work locations (addresses and geofence radii), work schedules, and organization settings.
  • Time and attendance records — punches (clock in, clock out, breaks), timecards, edit and correction requests, time-off requests, approvals, and notes attached to any of these.
  • Communications — messages you send us for support, and in-app notifications generated by the Service.

Location information

The core purpose of Alfahr is to verify where a punch happened. When you clock in, clock out, or start or end a break in the App, we capture a single GPS fix at that moment — latitude, longitude, and horizontal accuracy — and attach it to that punch. Your employer can see this location alongside the punch, including whether it fell inside a configured geofence and, for workers currently on the clock, a map of recent punch positions.

We do not track your location in the background or between punches. The App requests “while using” location permission only, and location is read solely at the moment you take a punch action. If you deny location permission you may still be able to punch, but your employer will see that the punch has no location evidence and may reject it according to their own policies.

Information collected automatically

  • Device and app information — device model, operating system version, app version, and language, used for compatibility and troubleshooting.
  • Log and usage data — IP address, request timestamps, pages or screens viewed, and error reports generated when something goes wrong.
  • Cookies and similar technologies — on the web app we use strictly necessary cookies to keep you signed in and secure your session. We do not use third-party advertising cookies.

API usage

Workspace administrators may create API keys to integrate Alfahr with payroll or other systems. We record API key metadata (name, creation date, last-used time) and request logs (endpoint, timestamp, status) for security and rate limiting. We store only a hashed version of the key itself.

04

How we use information

We use personal information to:

  • Provide, operate, and maintain the Service.
  • Record punches, verify them against configured locations, and compute timecards and hour totals across time zones.
  • Let authorized administrators review, approve, correct, and export time and attendance data.
  • Send transactional notifications such as invitations, approvals, and password resets.
  • Authenticate users and protect against fraud, abuse, and unauthorized access.
  • Provide customer support and respond to requests.
  • Monitor performance, diagnose errors, and improve the Service.
  • Comply with legal obligations and enforce our terms.

We do not sell personal information, and we do not use location or timecard data for advertising or to build marketing profiles.

05

How we share information

We share personal information only in the following circumstances:

  • With your employer / workspace. Timecards, punch locations, schedules, and profile details are visible to the administrators of the workspace you belong to. Workers can see their own records.
  • With service providers that process data on our behalf under contract, including cloud hosting and database infrastructure, authentication, email delivery, and mapping and geocoding services used to display locations and convert addresses into coordinates. These providers may only use the data to deliver their services to us.
  • Through integrations you enable. If a workspace administrator exports data or connects a third-party system via the API, that data is shared with the destination they choose.
  • For legal reasons — to comply with applicable law, regulation, legal process, or enforceable governmental request, or to protect the rights, property, or safety of Alfahr, our users, or the public.
  • In a business transfer such as a merger, acquisition, or sale of assets, in which case we will notify affected customers before their data becomes subject to a different privacy policy.
06

Data retention

We keep personal information for as long as your workspace is active and as needed to provide the Service. Time and attendance records are typically retained for the duration of the customer relationship because employers are often required by wage-and-hour laws to keep them for several years.

When an employer deactivates a worker, the worker’s records remain in the workspace for the employer’s recordkeeping. When a workspace is deleted, or a customer requests deletion, we delete or anonymize its data within 90 days, except where we must retain it to comply with legal obligations, resolve disputes, or enforce agreements. Backups are purged on a rolling schedule.

07

Security

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS) and at rest, row-level access controls that scope every query to your workspace, hashed API keys and passwords, and least-privilege access for our staff. No system is perfectly secure, so we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at privacy@alfa.systems.

08

Your choices and rights

Location permission

You can change the App’s location permission at any time in your device settings. On iOS, go to Settings → Privacy & Security → Location Services → Alfahr. On Android, go to Settings → Apps → Alfahr → Permissions. Disabling location will prevent location evidence from being attached to future punches.

Access, correction, and deletion

You can view and update your profile in the App or web app. Workers can request corrections to timecards through the built-in request flow, which routes to their employer for approval. To request access to, correction of, or deletion of other personal information, contact your employer (for workspace data) or us at privacy@alfa.systems.

Account deletion

Workspace owners can delete their workspace from the admin portal or by contacting us. Anyone can request deletion of their own account and associated personal data — without signing in — from our account deletion page. Workers may also ask their employer to remove them from a workspace.

Regional rights

Depending on where you live you may have additional rights, such as the right to know what personal information we hold, to obtain a portable copy, to object to or restrict certain processing, to withdraw consent, or to lodge a complaint with a supervisory authority. Residents of California and other US states with comprehensive privacy laws may exercise their rights by emailing privacy@alfa.systems. We will not discriminate against you for exercising these rights.

09

Children

The Service is intended for use in the workplace and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

10

International transfers

Alfahr Inc. is based in the United States and our service providers store and process data in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US, which may have different data protection laws than your jurisdiction. Where required, we rely on appropriate safeguards such as contractual commitments with our providers.

11

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes we will update the effective date above and, where appropriate, notify workspace administrators by email or through the Service. Continued use of the Service after changes take effect means you accept the revised policy.

12

Contact us

Questions, requests, or concerns about this policy or our privacy practices can be sent to:

Alfahr Inc.
Attn: Privacy
Austin, TX, United States
privacy@alfa.systems