PunchMan← Home

Privacy Policy

Effective 23 September 2026

This Privacy Policy explains how TriNect LLC ("TriNect", "we", "us") handles personal information in connection with the PunchMan website and service (the "Service"). We built PunchMan to hold as little personal data as possible and to protect what it does hold.

1. Two kinds of people, two roles

  • Account holders — the owners and managers who sign up and log in. For their information, TriNect is the "controller".
  • Employees — the staff whose hours are recorded. Their information is entered and controlled by their employer (our Customer). For that information, the employer is the controller and TriNect acts only as a processor on the employer's behalf. Employees with questions or requests should contact their employer.

2. Information we collect

From account holders

  • Name, work email and password (stored only as a secure hash — we never see it).
  • Company and property details you enter.
  • Billing information: when card payments are enabled, payments are processed by Stripe; we receive limited details (such as the last four digits and status) but do not store full card numbers.
  • Sign‑in and security records (times, IP address, two‑step settings) and an audit log of actions taken in the Service.

Employee information entered by Customers

  • Name, employee number, department, optional email, a PIN (stored hashed), and punch times / hours.
  • Employment records (Shield). What an employee chooses to answer at clock-out (whether they were hurt at work, got their breaks, or worked while not clocked in, with any note they add), their confirmation of each pay period's hours, written warnings and their comments on them, notice of leaving, no-show records, and claims made against the employer. Answering at clock-out is always optional. These records are the employer's employment records, kept to answer wage, injury and unemployment claims; an injury answer can be health information, so it is shown only to the employer's managers and owners. Each record is fingerprinted in a tamper-evident chain so later changes can be detected.
  • Biometric data (optional). If a Customer turns on fingerprint or face features, PunchMan stores a mathematical descriptor (a set of numbers) used to recognise a finger or face — never an actual fingerprint image or photograph. Descriptors are encrypted. Face matching runs in the browser on the kiosk device. Biometric features are off by default and are only used where the Customer has enabled them and obtained employee consent.

3. Cookies

PunchMan uses a single essential sign‑in cookie to keep you logged in. It is not used for advertising or cross‑site tracking. Kiosks use only local browser storage for convenience.

4. How we use information

  • To provide the Service: recording hours, producing timesheets and reports, and running the kiosk.
  • To secure accounts (sign‑in, two‑step verification, rate limiting, audit logs).
  • To bill for the Service and prevent abuse.
  • To send service messages, including the automatic bi‑weekly hours reports to the recipients a Customer configures, and password‑reset emails.
  • To provide support and to comply with law.

We do not sell personal information, and we do not use employee data for our own purposes beyond providing the Service to the employer.

5. Service providers we share with

We use a small number of trusted providers to run the Service, under agreements that require them to protect the data:

  • Hosting: Oracle Cloud Infrastructure (servers and storage).
  • Email delivery: Brevo (sending reports and account emails).
  • Payments: Stripe (card processing), where enabled.

We may also disclose information if required by law or to protect rights, safety or the integrity of the Service.

6. Security

We use HTTPS everywhere, hashed passwords and session tokens, encryption of stored secrets and biometric descriptors, strict access controls between customers, two‑step sign‑in for administrators, rate limiting and audit logging, and regular backups. No system is perfectly secure, but we work to protect your data and to notify affected parties as required if a breach occurs.

7. How long we keep data

We keep account and Customer Data for as long as your account is active and as needed to provide the Service. Employers control retention of employee time records and may need to keep them for several years to meet wage‑and‑hour laws. When a subscription ends, time clocks stop, but the Customer's records are kept and the account owner can still sign in to download all of them or to subscribe again. On request after account closure we delete or return Customer Data, subject to legal retention requirements and routine backup cycles. Biometric descriptors are deleted when a Customer removes an employee's enrolment or disables the feature. Shield records (clock-out answers, signed timecards, warnings, notices, claims) are kept with the time records they relate to, because they are evidence the employer may need for several years; they cannot be erased by a manager, and they are included when the account owner downloads their data.

Biometric data retention schedule

Where a Customer switches on fingerprint or face recognition, PunchMan destroys the stored descriptor at the earliest of:

  • immediately, when a manager removes that employee's enrolment;
  • immediately, when a manager switches the feature off for that location — every descriptor held for that location is destroyed at that moment;
  • 30 days (or the period the Customer sets, between 0 and 1095 days) after the employee is removed from the location or becomes inactive;
  • 30 days after the Customer's subscription ends — every descriptor the Customer holds;
  • three years after that employee last punched, whichever comes first, regardless of any longer period a Customer has set.

Destruction runs automatically every night and is recorded in the Customer's activity log. Descriptors cannot be recovered afterwards; an employee returning to work enrols again. Backups taken before destruction age out on their own retention cycle. Descriptors are stored encrypted, are never photographs, and are never shared with anyone.

8. Your choices and rights

  • Account holders can view and update their information in the Service, change or reset their password, enable two‑step sign‑in, and request deletion of their account by contacting us.
  • Employees should direct access, correction or deletion requests to their employer, who controls that data. We will assist our Customers in responding.
  • Depending on where you live, you may have rights to access, correct, delete or port your personal information, or to object to certain processing. Contact us and we will honour applicable rights.

9. Children

The Service is intended for workplace use by adults and is not directed to children under 16. We do not knowingly collect their information.

10. International

TriNect operates from the United States, and information is processed there. By using the Service you understand that your information will be handled in the United States.

11. Changes

We may update this Policy from time to time. We will post the new version here with a revised effective date and, for material changes, provide additional notice.

12. Contact

Questions or requests about privacy:
TriNect LLC — New Jersey, United States
support@trinect.org · trinect.org

Trinect

Software that brings people together.

PunchMan

  • Home
  • Log in
  • Get started
  • Support

Explore

  • Trinect
  • Products
  • About

Legal

  • Status
  • Policies
  • Privacy
  • Terms
  • Biometric data

© 2026 Trinect LLC. All rights reserved.

New Jersey, United States.