Privacy Policy

Effective September 28, 2026 · Version 2026-09-28

On Post records working time for employers. That makes privacy part of the product, not a page about it: time records are append-only, photographs expire on a schedule the employer controls, and every change is audited. This Policy explains what we handle, in which role, and what we will never do with it.

1. Overview

This Privacy Policy describes how On Post LLC, a New Jersey limited liability company (On Post, we), handles information in connection with the On Post service at getonpost.app — a time, attendance, and compliance product used by employers (our Customers) and their employees. It applies to the service, its time-clock surfaces, the team app, and this website.

The short version: employers put their workforce’s time data in On Post; that data belongs to the employer and we process it on the employer’s behalf. We do not sell personal information, we do not run advertising, we do not train artificial-intelligence models on identifiable data, and we do not use facial recognition.

2. Our Two Roles

Service provider / processor. When an employer uses On Post to record and manage its employees’ information — punches, photographs, schedules, timesheets — the employer decides what is collected and why. We process that information on the employer’s behalf and under its instructions. The employer is responsible for the notices and consents its employees may be owed. If you are an employee with a question or request about your information in On Post, please contact your employer first; we support employers in answering such requests, and we act directly where the law requires us to.

Controller. For the account information of the people who sign up for and administer On Post, for billing, for support conversations, and for visitors to this website, we decide how information is used, and this Policy describes that use.

3. Information We Process for Employers

On the employer’s behalf, the service processes:

  • Workforce records — names (preferred and, for payroll export, legal), contact details, hire and termination dates, roles, and the employer’s payroll identifiers;
  • Credentials — badge identifiers, QR tokens, and PINs (PINs are stored hashed for verification and encrypted for display to the employer’s managers);
  • Time records — clock-in and clock-out events with timestamps, the device and site used, and correction history (time records are append-only: corrections are recorded alongside, never over, the original);
  • Time-clock photographs — see the dedicated section below;
  • Scheduling and requests — shifts, availability, time-off and swap requests, and manager decisions;
  • Computed outputs — timesheets, hours and overtime computations, and payroll export files.

4. Information We Collect as a Controller

Account holders. Name, email address, password (stored as a cryptographic hash — we cannot read it), optional two-factor enrollment, business details you provide at signup (business name, legal entity name, EIN last digits, address, timezone), and your acceptance of our terms (version and time).

Billing. When paid plans are in effect, billing is handled by a payment processor; we do not store full card numbers.

Support and communications. Messages you send us, and the email delivery records of messages we send you.

Device and usage data. IP addresses, browser and device information, sign-in events and security logs (including failed-attempt counters), and telemetry about service performance. Time-clock devices send periodic heartbeats (device identifier, queue status, version) so employers can see their clocks are healthy.

5. Time-Clock Photographs

When an employer enables photo capture, the time clock takes a photograph at each punch. The photograph is framed to show the person and the badge they are wearing, is kept in that employer’s attendance record, and is reviewed by the employer’s managers in a review queue (for example, to confirm a required name badge is worn). Photographs are stored encrypted, served only through short-lived signed links, and are never public.

On Post does not apply facial recognition, face matching, or any automated identity-verification technology to photographs. On Post does not create, collect, derive, or store a scan of face geometry, a faceprint, a facial template, a voiceprint, or any other biometric identifier or biometric information, as those terms are defined in the Illinois Biometric Information Privacy Act (740 ILCS 14/10), the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001(a)), and Washington’s biometric identifier law (RCW 19.375.010). A photograph in On Post is looked at by a person; it is never measured by an algorithm. The optional spoken greeting at the time clock is synthesized from the employee’s first name; no recording of any person’s voice is made.

The employer sets how long photographs are kept (default 730 days, minimum 90 days); expired photographs are deleted, not archived. The time record itself — who, when, where, and how — is retained separately from the photograph and does not expire with it.

6. How We Use Information

We use information to:

  • provide, operate, secure, and support the service;
  • authenticate people and devices, and prevent fraud and abuse;
  • send service communications (sign-in links, alerts employers configure, notices);
  • maintain audit records of changes, which is itself a feature of the product;
  • comply with law and enforce our terms;
  • improve the service using aggregated, de-identified information that does not identify any person or customer.

Where an employer enables spoken greetings at the time clock, employee first names are synthesized to audio by a speech provider; the audio is cached and the name is not used by the provider for any other purpose.

7. What We Do Not Do

We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not run advertising of any kind. We do not use identifiable Customer or employee data to train artificial-intelligence models. We do not build or sell data products from identifiable data. We do not apply facial recognition. Because we do not sell or share personal information for advertising, there is nothing to opt out of under state “do not sell or share” rights — the answer is already no.

8. How Information Is Shared; Subprocessors

We share information only with the service providers that run On Post, under contracts that limit their use of it to providing their service to us:

  • Neon — managed Postgres database hosting (primary data storage);
  • Cloudflare R2 — encrypted object storage for time-clock photographs, credential documents an employer uploads, and nightly database backups;
  • Amazon Web Services — application hosting, and the scheduled jobs that run the service (photo and account purges, credential checks, schedule emails), in the United States (N. Virginia);
  • Resend — transactional email delivery (recipient address and name, the employer’s name, and the message: sign-in links, password resets, invitations, request digests);
  • Sentry — error monitoring; reports are scrubbed before they leave (no cookies, request bodies, tokens, PINs, or email addresses; no IP address; an opaque user id only);
  • OpenAI — speech synthesis for the optional spoken greeting at the time clock (the employee’s first name and a short greeting phrase; the employer can switch the greeting off in Settings; no recording of anyone’s voice is made);
  • Cloudflare Turnstile — the bot check on the public signup form only (the visitor’s browser signals and IP address; no employee data);
  • Google Places — address, phone, and opening-hours lookup for the business name and address an account owner types at signup and on Business details (business data only; no employee data);
  • Have I Been Pwned — password breach screening: when a password is set, only the first five characters of a cryptographic hash are sent, never the password and never anything identifying you (k-anonymity);
  • GitHub — the nightly database backup runs on a GitHub-hosted runner; the dump exists on the runner only for the length of the backup job before it is stored in R2.

Beyond service providers: we disclose information if required by law, subpoena, or legal process (with notice to the affected employer where lawful); to protect the rights, safety, and security of the service and its users; in connection with a merger, acquisition, or sale of assets (your data remains subject to commitments at least as protective); and payroll export files go wherever the employer sends them. We will update this list when subprocessors change.

9. Data Retention

Retention is specific, not vague:

  • Time records (punches, corrections, timesheets) are retained for the life of the employer’s account. They are wage records; the product deliberately does not let anyone edit or delete them, because employers must keep them under recordkeeping laws (for example, 29 C.F.R. Part 516).
  • Time-clock photographs: employer-configured, default 730 days, minimum 90; deleted on expiry.
  • Audit logs: life of the account (the audit trail is a feature).
  • Security logs (sign-in attempts, tokens): short operational windows, typically days to months.
  • Account deletion: when an employer deletes its account, the account and its data immediately become inaccessible, and are then permanently purged. Residual copies may persist in live systems for up to 30 days, and in bounded backup cycles, before destruction. If a deletion was a mistake, contact support@getonpost.app promptly.
  • Closed (not deleted) employers retain their records in read-only form so wage records remain available for their legally required retention periods.

Employers are responsible for exporting anything the law requires them to keep before deleting data or their account.

10. Security

We encrypt data in transit and at rest; store passwords and PINs as argon2id hashes (with PIN display copies encrypted separately under keys held outside the database); use opaque, database-backed sessions that can be revoked instantly; isolate each employer’s data with per-tenant scoping enforced in the application and defended in depth with database row-level security; and record every change in an append-only audit log. Photographs are stored encrypted and served only through short-expiry signed links.

No security is absolute, and we do not promise that a breach can never occur. If a breach affects your information, we will notify affected customers without undue delay, consistent with applicable law, and tell them what we know, what we are doing, and what they can do.

11. Your Privacy Rights

Employees: your information in On Post is controlled by your employer — requests to access, correct, or delete it should go to your employer, and we help employers fulfill them. Where a privacy law grants you rights directly against us, we honor them as the law provides.

Account holders and visitors: you may request access to, correction of, or deletion of the personal information we hold about you as a controller by emailing privacy@getonpost.app. We verify requests, respond within 45 days (extendable where law allows), and do not discriminate against anyone for exercising rights.

California and other state residents: we collect the categories of information described in this Policy, for the purposes described; we do not sell or share personal information as those terms are defined in California law, and we have not done so in the preceding 12 months; we do not use or disclose sensitive personal information except to provide the service. Because our site does not track visitors across other sites, it does not respond differently to “Do Not Track” signals — there is no tracking either way. Where a state privacy law applies to us and grants you rights, submit requests to privacy@getonpost.app; authorized agents may act for you where the law provides.

12. Children and Minor Employees

On Post is a general-audience business service, not directed to children, and we do not knowingly collect information from children under 13. Employers may lawfully employ minors (for example, with working papers); their records in On Post are workforce records processed at the employer’s direction, and the employer is responsible for compliance with minor-labor laws.

13. Cookies

On Post sets cookies for two purposes: to keep you signed in (a session cookie that is httpOnly and secure, and that cannot be read by scripts) and to remember which location you are viewing. Interface preferences, such as a collapsed panel or a chosen tab, are stored in your browser’s local storage and never leave your device. We do not use advertising cookies, analytics cookies, or any cross-site tracking. One exception: the public signup form uses Cloudflare Turnstile to confirm that a person, not a bot, is submitting it; Turnstile sets its own cookie inside its frame on that page only and receives the visitor’s browser signals and IP address for that purpose. Because we do not track visitors across sites, the service does not respond differently to “Do Not Track” or Global Privacy Control signals; there is no tracking to opt out of. You can block or delete cookies in your browser; blocking the session cookie will sign you out.

14. International Visitors

On Post operates from and stores data in the United States. If you use the service from outside the United States, you understand your information is processed in the United States, where laws may differ from those of your jurisdiction.

15. Changes to This Policy

When we change this Policy, we will update the effective date and version above, and for material changes we will notify account owners by email or in the service before the change takes effect. Earlier versions are available on request.

16. Contact Us

On Post LLC, New Jersey, USA. Privacy requests: privacy@getonpost.app. Legal notices: legal@getonpost.app. Support: support@getonpost.app. See also our Terms of Service and Accessibility Statement.