Privacy Policy
Last updated: 27 July 2026
1. Who we are
StaffRegister is a staff attendance and payroll platform operated by StaffRegister ("we", "us"). This policy explains what the StaffRegister app and website collect, why, and what rights you have under India's Digital Personal Data Protection Act, 2023 (DPDP Act).
2. Our role, and your business's role
When a business signs up, that business decides what employee data to record and is the Data Fiduciary for it. We process that data on the business's instructions as its Data Processor, and we are the Data Fiduciary for the business owner's own account details. If you are an employee with questions about your records, contact your employer first — they control the account.
3. Information we collect
Business account: business name, owner name, email address, phone number, and — where you provide them for billing and trial verification — GST and PAN identifiers.
Employee records you create: names, phone numbers, designation, department, salary settings, join date, attendance timestamps, leave requests, and any identity or proof documents you choose to upload.
Face data (only if you use face attendance): at enrolment we derive a numerical face template from the enrolment images. The template is computed on our server and stored separately from the employee record, where no app or browser client can read it. It is used only to match a face at check-in, and it cannot be reversed into a photograph.
Attendance photos: each time an employee checks in with face attendance, the photo captured at that moment is stored as part of the attendance record, so an employer can review a disputed or manually-approved entry. These photos are readable only by the employing business and are kept for 90 days by default (configurable per business, capped at 365 days), after which they are deleted automatically. They are deleted immediately if the employee withdraws biometric consent, and when the employee leaves.
Precise location: when an employee checks in or out using face or QR attendance, the app reads the device's location and sends it with the check-in so we can confirm the employee is at the shop (geofencing, 200 metres by default, configurable per shop). Location is captured at the moment of check-in only — the app does not track location in the background or when it is closed.
Device information: a device identifier used to bind a staff account to a single phone, to prevent one employee marking attendance from another's device.
Diagnostics: we use Google Firebase Crashlytics and Google Analytics for Firebase to record crashes, errors and basic usage of app screens, so we can find and fix faults. Crash reports carry an anonymous installation identifier and your account identifier, never your PIN, face template or documents.
We do not knowingly collect data from anyone under 18.
4. Consent for biometrics and location
Before any face enrolment, the app shows the employee a notice and records their affirmative consent, together with the version of the notice shown. Face attendance and geofencing do not operate for an employee who has not consented. Consent can be withdrawn — see section 8.
5. How we use it
Solely to provide the service: marking and verifying attendance, calculating salaries, generating salary slips and reports, sending the notifications you configure, processing subscription payments, and detecting fraud and abuse of free trials. We do not sell your data, and we do not use it for advertising or to train any machine-learning model.
6. Who else processes your data
Google Firebase (Firestore, Cloud Storage, Cloud Functions, Crashlytics, Analytics) hosts the service and stores your data. Razorpay processes subscription payments — payment card details are entered with Razorpay directly and we never see or store them. If you enable WhatsApp notifications, message content is delivered through Meta's WhatsApp Business Platform. We do not share your data with anyone else except where the law requires it.
7. Data security, isolation and location
Data is held on Google Firebase with server-side security rules that isolate each business's records, so one business can never read another's. Face templates, PIN hashes and QR secrets are held in storage that no client application can read — only our server-side functions can. PINs are stored as bcrypt hashes, never in readable form. Traffic is encrypted in transit (HTTPS). Our primary database region is asia-south1 (Mumbai); some Google infrastructure services may process data in other regions.
8. Retention and your rights
Under the DPDP Act you may access your data, ask us to correct it, ask us to erase it, and withdraw consent you previously gave. In the app:
- An employee can delete their own face data from their profile at any time. This also deletes every stored attendance photo of them. Face attendance then stops working for them until they re-enrol; attendance can still be marked manually.
- When an employee is marked as having left, their face template is deleted automatically.
- Deleting an employee removes their profile, photo, uploaded documents and face template.
Attendance and salary records are retained as the business's statutory employment records after an employee leaves, because the business needs them for wage and tax compliance. To delete an entire business account and everything in it, contact us at the address below and we will act within 30 days.
9. Grievances
If you are unhappy with how your data has been handled, contact our grievance contact at staffregister666@gmail.com and we will respond within 30 days. If you remain dissatisfied, you may complain to the Data Protection Board of India.
10. Changes
If we change this policy we will update the date above, and where the change is significant we will ask for fresh consent inside the app.
11. Contact
Questions about this policy: staffregister666@gmail.com.