Security and location privacy

Written by the GlobePunch team so employees, supervisors, and elected officials can see exactly what the time clock records. It is not a third-party certification.

What we record, in plain words

  • Location is recorded when someone clocks in or clocks out.
  • GlobePunch does not track employees all day and does not track them off duty.
  • Supervisors see their own people. Organizations are kept separate from each other.
  • Changes to a punch or a timesheet are written to an audit trail.

The vendor cannot browse your punches or GPS

  • GlobePunch staff have no way to open a customer workspace and read employee punches, GPS coordinates, timesheets, time-off records, or payroll exports. There is no impersonation feature and no support login.
  • Our own operations screens show only account-level facts: organization name, plan and status, sign-up date, and a count of users. No employee names, no emails, no hours.
  • Each organization is isolated at the database level. Location is stored for that employer's timekeeping only — it is never pooled, resold, or used for anything else.
  • If you need help inside your account, you invite us as a user in your own organization, with a role you choose, and you remove that access when the work is done.

Organizations are separated

Each organization is its own workspace. Every record is tagged with an organization and the database itself blocks a user from reading or writing records outside the organizations they belong to. One employer's hours never appear in another's.

Sign-in and who sees what

Sign-in is handled by managed authentication and checked on the server for every request. Roles — admin, supervisor, payroll, employee — are enforced on the server, not in the browser. Supervisors see their own department or team. Employees see their own hours.

Audit trail

Every punch added, edited, or deleted is recorded with who did it, when, the values before and after, and the reason given. An admin can pull the full history of any timesheet record.

Data in transit and at rest

All traffic between your browser and our servers is encrypted with TLS. Customer data is stored in a managed Postgres database with encryption at rest provided by the hosting platform.

Data portability & deletion

Admins can export all organization data as CSV at any time from the admin console. To delete an organization and all of its data, contact us and we will permanently remove the workspace within 30 days.

Shared responsibility

We secure the platform; you control who has access to your workspace. Use strong passwords, review your member list regularly, and remove access for people who leave your organization.

Need details for a bid, an RFP, or a data processing agreement?