Privacy Policy
Effective September 28, 2026 · Version 2026-09-28
On Post records working time for employers. That makes privacy part of the product, not a page about it: time records are append-only, photographs expire on a schedule the employer controls, and every change is audited. This Policy explains what we handle, in which role, and what we will never do with it.
1. Overview
This Privacy Policy describes how On Post LLC, a New Jersey limited liability company (On Post, we), handles information in connection with the On Post service at getonpost.app — a time, attendance, and compliance product used by employers (our Customers) and their employees. It applies to the service, its time-clock surfaces, the team app, and this website.
The short version: employers put their workforce’s time data in On Post; that data belongs to the employer and we process it on the employer’s behalf. We do not sell personal information, we do not run advertising, we do not train artificial-intelligence models on identifiable data, and we do not use facial recognition.
2. Our Two Roles
Service provider / processor. When an employer uses On Post to record and manage its employees’ information — punches, photographs, schedules, timesheets — the employer decides what is collected and why. We process that information on the employer’s behalf and under its instructions. The employer is responsible for the notices and consents its employees may be owed. If you are an employee with a question or request about your information in On Post, please contact your employer first; we support employers in answering such requests, and we act directly where the law requires us to.
Controller. For the account information of the people who sign up for and administer On Post, for billing, for support conversations, and for visitors to this website, we decide how information is used, and this Policy describes that use.
3. Information We Process for Employers
On the employer’s behalf, the service processes:
- Workforce records — names (preferred and, for payroll export, legal), contact details, hire and termination dates, roles, and the employer’s payroll identifiers;
- Credentials — badge identifiers, QR tokens, and PINs (PINs are stored hashed for verification and encrypted for display to the employer’s managers);
- Time records — clock-in and clock-out events with timestamps, the device and site used, and correction history (time records are append-only: corrections are recorded alongside, never over, the original);
- Time-clock photographs — see the dedicated section below;
- Scheduling and requests — shifts, availability, time-off and swap requests, and manager decisions;
- Computed outputs — timesheets, hours and overtime computations, and payroll export files.
4. Information We Collect as a Controller
Account holders. Name, email address, password (stored as a cryptographic hash — we cannot read it), optional two-factor enrollment, business details you provide at signup (business name, legal entity name, EIN last digits, address, timezone), and your acceptance of our terms (version and time).
Billing. When paid plans are in effect, billing is handled by a payment processor; we do not store full card numbers.
Support and communications. Messages you send us, and the email delivery records of messages we send you.
Device and usage data. IP addresses, browser and device information, sign-in events and security logs (including failed-attempt counters), and telemetry about service performance. Time-clock devices send periodic heartbeats (device identifier, queue status, version) so employers can see their clocks are healthy.
5. Time-Clock Photographs
When an employer enables photo capture, the time clock takes a photograph at each punch. The photograph is framed to show the person and the badge they are wearing, is kept in that employer’s attendance record, and is reviewed by the employer’s managers in a review queue (for example, to confirm a required name badge is worn). Photographs are stored encrypted, served only through short-lived signed links, and are never public.
The employer sets how long photographs are kept (default 730 days, minimum 90 days); expired photographs are deleted, not archived. The time record itself — who, when, where, and how — is retained separately from the photograph and does not expire with it.
6. How We Use Information
We use information to:
- provide, operate, secure, and support the service;
- authenticate people and devices, and prevent fraud and abuse;
- send service communications (sign-in links, alerts employers configure, notices);
- maintain audit records of changes, which is itself a feature of the product;
- comply with law and enforce our terms;
- improve the service using aggregated, de-identified information that does not identify any person or customer.
Where an employer enables spoken greetings at the time clock, employee first names are synthesized to audio by a speech provider; the audio is cached and the name is not used by the provider for any other purpose.
7. What We Do Not Do
9. Data Retention
Retention is specific, not vague:
- Time records (punches, corrections, timesheets) are retained for the life of the employer’s account. They are wage records; the product deliberately does not let anyone edit or delete them, because employers must keep them under recordkeeping laws (for example, 29 C.F.R. Part 516).
- Time-clock photographs: employer-configured, default 730 days, minimum 90; deleted on expiry.
- Audit logs: life of the account (the audit trail is a feature).
- Security logs (sign-in attempts, tokens): short operational windows, typically days to months.
- Account deletion: when an employer deletes its account, the account and its data immediately become inaccessible, and are then permanently purged. Residual copies may persist in live systems for up to 30 days, and in bounded backup cycles, before destruction. If a deletion was a mistake, contact support@getonpost.app promptly.
- Closed (not deleted) employers retain their records in read-only form so wage records remain available for their legally required retention periods.
Employers are responsible for exporting anything the law requires them to keep before deleting data or their account.
10. Security
We encrypt data in transit and at rest; store passwords and PINs as argon2id hashes (with PIN display copies encrypted separately under keys held outside the database); use opaque, database-backed sessions that can be revoked instantly; isolate each employer’s data with per-tenant scoping enforced in the application and defended in depth with database row-level security; and record every change in an append-only audit log. Photographs are stored encrypted and served only through short-expiry signed links.
No security is absolute, and we do not promise that a breach can never occur. If a breach affects your information, we will notify affected customers without undue delay, consistent with applicable law, and tell them what we know, what we are doing, and what they can do.
11. Your Privacy Rights
Employees: your information in On Post is controlled by your employer — requests to access, correct, or delete it should go to your employer, and we help employers fulfill them. Where a privacy law grants you rights directly against us, we honor them as the law provides.
Account holders and visitors: you may request access to, correction of, or deletion of the personal information we hold about you as a controller by emailing privacy@getonpost.app. We verify requests, respond within 45 days (extendable where law allows), and do not discriminate against anyone for exercising rights.
California and other state residents: we collect the categories of information described in this Policy, for the purposes described; we do not sell or share personal information as those terms are defined in California law, and we have not done so in the preceding 12 months; we do not use or disclose sensitive personal information except to provide the service. Because our site does not track visitors across other sites, it does not respond differently to “Do Not Track” signals — there is no tracking either way. Where a state privacy law applies to us and grants you rights, submit requests to privacy@getonpost.app; authorized agents may act for you where the law provides.
12. Children and Minor Employees
On Post is a general-audience business service, not directed to children, and we do not knowingly collect information from children under 13. Employers may lawfully employ minors (for example, with working papers); their records in On Post are workforce records processed at the employer’s direction, and the employer is responsible for compliance with minor-labor laws.
14. International Visitors
On Post operates from and stores data in the United States. If you use the service from outside the United States, you understand your information is processed in the United States, where laws may differ from those of your jurisdiction.
15. Changes to This Policy
When we change this Policy, we will update the effective date and version above, and for material changes we will notify account owners by email or in the service before the change takes effect. Earlier versions are available on request.
16. Contact Us
On Post LLC, New Jersey, USA. Privacy requests: privacy@getonpost.app. Legal notices: legal@getonpost.app. Support: support@getonpost.app. See also our Terms of Service and Accessibility Statement.