Privacy Policy
How Preferred IT Systems collects, uses, shares, and protects personal data when you use GlobePunch.
Last updated August 10, 2026 · Preferred IT Systems
1. Who we are
GlobePunch is operated by Preferred IT Systems. For personal data relating to account holders and visitors to our website, we act as the data controller. Where a customer organization uses GlobePunch to record its employees' working time, that organization decides what is collected and why, and we act as a processor on its behalf and under its instructions.
Privacy questions and requests: hello@globepunch.com.
2. Personal data we collect and why
- Account and identity data — name, email address, login credentials, organization, role, and employee number. Used to create and secure accounts and to provide the service. Legal basis: performance of a contract.
- Time and attendance data — punch timestamps, shifts, breaks, payroll codes, time-off requests and balances, supervisor approvals, and notes. Used to provide time tracking, approvals, and reporting to the employing organization. Legal basis: performance of a contract and the organization's legitimate interest in accurate time records.
- Location data — the device's approximate latitude, longitude, accuracy, and distance from a configured job site, captured only at the moment a punch is submitted, and only where the organization has enabled job sites. There is no continuous or background tracking. Legal basis: the organization's legitimate interest in verifying attendance, and consent where required by local law.
- Technical and security data — IP address, device and browser user-agent, authentication events, passkey and two-factor enrolment records, and audit-log entries. Used for security, fraud prevention, and troubleshooting. Legal basis: legitimate interests and legal obligation.
- Support and contact data — messages you send us through the contact form or by email. Used to answer your enquiry. Legal basis: legitimate interests.
- Usage data — limited records of feature use and errors, used to keep the service working and to improve it. Legal basis: legitimate interests.
We do not sell personal data, and we do not use Customer Data to train machine-learning models.
3. Who we share data with
- Hosting and database providers — our cloud infrastructure and managed database provider, which store and serve application data on our behalf.
- Stripe — our payment processor. Stripe handles card payments, subscription billing, invoicing, and tax calculation, and receives the billing details necessary for those purposes. Card numbers are entered directly with Stripe and are never stored by us.
- Email delivery provider — used to send transactional messages such as invitations, password resets, and notification emails.
- Professional advisers — legal, accounting, and audit advisers, where needed.
- Authorities — where disclosure is required by law or legal process, or to protect rights and safety.
- Your organization — administrators, supervisors, and payroll users in your organization can see the time records and profile details of the employees they manage.
4. How long we keep it
We keep account and time-and-attendance data for as long as the organization's account is active, because time records generally need to be retained for wage-and-hour and tax purposes. After an account is closed, data remains available for export for 30 days and is then deleted or anonymised, unless a longer retention period is required by law. Support messages are kept for up to 24 months. Security and audit logs are kept for up to 24 months.
5. Your rights
Subject to applicable law, you may request access to the personal data we hold about you, ask us to correct it or delete it, ask us to restrict or stop processing it, object to processing based on legitimate interests, request a portable copy, and withdraw consent where processing is based on consent. Where your employer controls the data, we will refer your request to them.
To exercise any of these rights, email hello@globepunch.com. We will respond within the time required by applicable law, and within one month where the GDPR applies. If you are in the UK or EEA you also have the right to complain to your local data protection supervisory authority.
6. International transfers
Our infrastructure and some service providers are located in the United States, so personal data may be transferred outside your country. Where data is transferred out of the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or an applicable adequacy decision.
7. How we protect data
- All traffic between your device and our servers is encrypted with TLS, and data is encrypted at rest by our hosting platform.
- Each organization's records are isolated at the database level using row-level security policies tied to organization membership.
- Roles (admin, supervisor, payroll, employee) are enforced on the server, not just hidden in the interface.
- Accounts can be protected with passkeys (Face ID / Touch ID) and authenticator-app two-factor authentication, which administrators can require for chosen roles.
- Changes to time records are written to an append-only audit log with the actor and before/after values.
No system is perfectly secure, but we work to protect data with appropriate technical and organizational measures. More detail is on our security page.
8. Cookies and similar technologies
GlobePunch uses essential cookies and local browser storage only — to keep you signed in, remember your light or dark theme choice, and protect against cross-site request forgery. We do not use advertising cookies, and we do not run third-party analytics or marketing trackers on the app. You can clear or block this storage in your browser settings, but signing in will not work without it. If we add analytics in future, we will update this notice first.
9. Children
GlobePunch is a workplace tool sold to employers and is not directed at children. Where an employer records the time of a lawfully employed minor, that data is processed on the employer's instructions and under its responsibility.
10. Changes to this notice
We may update this notice as the service changes. The effective date at the top of this page will change, and material updates will be announced in the app or by email to account administrators.
This page is provided for transparency about how we operate and is not legal advice.
