Privacy Policy

Version: 1.7
Effective Date: March 29, 2026
Last Updated: April 30, 2026

1. Introduction

This Privacy Policy describes how the OnboardReady/ClockReady platform ("Platform," "we," "us," "our") collects, uses, and protects information when you use our workforce management services.

This Policy applies to:

  • Tenant administrators and authorized users ("Admins")
  • Workers whose information is entered into the Platform by Tenants
  • Visitors to our public-facing pages

2. Our Role in Data Processing

2.1 Tenants as Data Controllers

For data entered by Tenants about their workforce:

  • The Tenant is the data controller and determines what personal data is collected and how it is used
  • We act as a data processor/service provider, processing data on behalf of Tenants according to their instructions

If you are a Worker with questions about how your personal data is handled, please contact your employer (the Tenant) directly.

2.2 Direct Relationships

For data we collect directly (such as Tenant Admin registration), we act as the data controller.

3. Information We Collect

3.1 Tenant Account Information

When Tenants register, we collect:

  • Business name and contact information
  • Admin names and email addresses
  • Billing and payment information
  • Account credentials

3.2 Worker Information (Collected by Tenants)

Tenants may enter information about Workers, including:

  • Names and contact information
  • Work schedules and time records
  • Job assignments and locations
  • Profile photos
  • Documents and files (including onboarding documents, certificates, invoices, offer letters, and signed agreements)
  • Communication history within the Platform
  • Kiosk PIN data for shared device clock-in/out (stored as cryptographic hashes, not plaintext)

3.3 Usage Information

We automatically collect:

  • Device information (type, operating system, browser)
  • IP addresses
  • Access times and usage patterns
  • Feature usage and interactions
  • Error logs and performance data
  • Permission and role change records (who changed what permissions, when, and the before/after states)
  • Document access records (who accessed or downloaded which documents, when, and from where)

3.4 Location Information

With appropriate permissions:

  • GPS location for time clock and geofencing features
  • Location data for job site management

4. How We Use Information

4.1 Providing Services

We use information to:

  • Operate and maintain the Platform
  • Process time and attendance records
  • Facilitate scheduling and communications
  • Generate reports and analytics for Tenants
  • Provide customer support

4.2 Improving the Platform

We use information to:

  • Analyze usage patterns and improve features
  • Identify and fix technical issues
  • Develop new capabilities

4.3 Security and Compliance

We use information to:

  • Protect against unauthorized access
  • Detect and prevent fraud
  • Comply with legal obligations

4.4 Communications

We use contact information to:

  • Send service-related notifications
  • Provide support responses
  • Communicate important updates

5. Information Sharing

5.1 Service Providers and Subprocessors

We share information with service providers who help us operate the Platform:

ProviderPurposeData Processed
SupabaseDatabase and storageAll Platform data
Amazon Web Services (AWS)Encrypted backup storage (Canada)Database backups, uploaded files and documents
Google Maps PlatformLocation and mapping servicesAddresses, coordinates
StripePayment processingBilling information
TwilioSMS notificationsPhone numbers, messages
ResendEmail deliveryEmail addresses, content
OpenAIAI featuresContent submitted to AI features
FirebasePush notificationsDevice tokens, notification content

5.1.1 Tenant-Initiated Third-Party Integrations

Tenants may choose to connect external services through the Platform's Integrations settings. When a Tenant enables a third-party integration, data is shared with that service as necessary to fulfill the integration's purpose:

IntegrationPurposeData Shared
Intuit QuickBooks OnlinePayroll and time tracking exportWorker names, approved timesheet hours, work dates, job descriptions

When a Tenant connects QuickBooks Online:

  • We use Intuit's OAuth 2.0 authorization to establish a secure connection on the Tenant's behalf
  • Only approved timesheet data that the Tenant explicitly exports is sent to QuickBooks
  • Data is transmitted securely via Intuit's API using encrypted connections
  • The Tenant may disconnect the integration at any time, which stops all data sharing with QuickBooks
  • We store OAuth tokens securely and use them solely to facilitate the Tenant's requested exports
  • We do not access, read, or use any data from the Tenant's QuickBooks account beyond what is necessary to complete the export

Tenants are responsible for ensuring that their use of integrations complies with applicable laws, including obtaining any necessary consent from Workers whose data may be shared with third-party services.

5.2 Legal Requirements

We may disclose information when required by law, legal process, or government request.

5.3 Business Transfers

In the event of a merger, acquisition, or sale, information may be transferred to the acquiring entity.

5.4 With Tenant Consent

We may share information with Tenant permission for integrations or services requested by the Tenant.

6. Data Retention

6.1 Active Accounts

We retain data while Tenant accounts are active and as needed to provide services.

6.2 Specific Retention Periods

Data TypeRetention Period
Active account dataDuration of subscription
Uploaded documents and filesDuration of subscription + 30 days post-termination
Document access audit logs90 days (automatically purged)
Permission and role change audit logsDuration of subscription (immutable, not deletable)
Archived records (soft-deleted)7 days before permanent deletion
Timesheet and attendance recordsDuration of subscription (exportable)
Communication messagesDuration of subscription
Session and device security logs90 days
Billing and payment recordsAs required by applicable tax and financial regulations

6.3 After Termination

Following account termination, we retain data for a reasonable period (typically 30 days) to allow for data export. Upon written request, we will delete Tenant data within 30 days of termination, except where retention is required by applicable law. Upon completion of deletion, we will provide written confirmation of data destruction upon request. Data may be retained longer for:

  • Legal compliance requirements
  • Dispute resolution
  • Aggregated analytics (de-identified)

6.4 Backups

We maintain automated backups of all Platform data, including the database and all uploaded files and documents, for disaster recovery and business continuity purposes. Backups are:

  • Performed multiple times daily on an automated schedule
  • Stored in encrypted form (AES-256 encryption at rest) on Amazon Web Services (AWS) infrastructure located in Canada (Montreal, ca-central-1) to maintain compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Retained for 30 days, after which they are automatically and permanently deleted
  • Accessible only to authorized Platform personnel for disaster recovery purposes

Residual copies in encrypted backups will be overwritten in the normal course of backup rotation.

6.5 Data Processing Agreement

The data processing obligations, sub-processor disclosures, and audit rights applicable to our handling of Tenant data are set forth in Section 5.7 of our Terms of Service. Tenants requiring a separately executed Data Processing Agreement (DPA) may contact us to discuss their specific requirements.

7. Data Security

7.1 Security Measures

We implement reasonable security measures including:

  • Encryption in transit (TLS 1.2+) and at rest (including AES-256 encryption for all backup data)
  • Time-limited signed URLs for document access (maximum 15-minute expiry) to limit exposure
  • Comprehensive audit logging of all document access events, including who accessed what, when, and from where
  • Granular role-based access controls (RBAC) with per-permission enforcement on sensitive operations such as document downloads, timesheet exports, and file access
  • Immutable audit trail of all permission and role changes, recording the actor's identity, the specific permissions granted or revoked, and full before-and-after permission state snapshots
  • Tenant-level data isolation ensuring one tenant cannot access another tenant's data
  • Multi-factor authentication support for administrative accounts
  • Device fingerprinting and session tracking for security monitoring
  • Regular security assessments
  • Employee training and access restrictions

7.2 Limitations

No system is completely secure. While we take reasonable precautions, we cannot guarantee absolute security of information transmitted to or stored on the Platform.

7.3 Breach Notification

In the event of a security breach involving personal information, we will notify affected Tenants without undue delay. We will provide sufficient information regarding the nature, scope, and likely consequences of the breach to enable Tenants to fulfill their own notification obligations under applicable privacy legislation, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and equivalent provincial privacy laws. We will cooperate with affected Tenants and take reasonable steps to contain and remediate the incident.

7.4 Your Responsibilities

Account security also depends on:

  • Maintaining confidential passwords
  • Using secure devices and networks
  • Reporting suspected security issues promptly

8. Your Rights and Choices

8.1 For Tenants

Tenants may:

  • Access and update account information
  • Export Platform data
  • Delete or modify Worker records
  • Close accounts

8.2 For Workers

Workers should contact their employer (the Tenant) to:

  • Access their personal information
  • Request corrections or deletions
  • Understand how their data is used

8.3 Communications

You may opt out of promotional communications but will continue to receive service-related notices.

8.4 Location Services

Mobile app users may control location permissions through device settings.

9. International Data Transfers

9.1 Processing Locations

Personal information may be processed or stored in Canada, the United States, and other jurisdictions where our service providers operate.

Personal information processed or stored outside Canada may be subject to the laws of those jurisdictions, including lawful access requests by courts, law enforcement, or national security authorities.

9.2 Safeguards

We remain responsible for personal information under our control, including information transferred to service providers for processing. We use contractual, technical, and organizational safeguards designed to provide a level of protection comparable to that required under Canadian privacy laws, including PIPEDA.

10. Children's Privacy

The Platform is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us.

11. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be indicated by updating the version number and effective date. Material changes will be communicated to Tenants through the Platform or email.

12. Contact Us

For privacy questions, data subject requests, or privacy-related complaints, please contact our Privacy Officer:

Email: privacy@onboardready.com

Address: Toronto, Ontario, Canada

For data subject requests related to Worker data, please contact your employer (the Tenant) directly.

13. Worker-facing consents (reference)

In addition to this Privacy Policy, Workers using the Worker app are presented with two specific consents that further describe how their personal information may be collected and used. The full text of each is published in the Terms of Service:

  • Worker Communication & Operational Consent — see Appendix A of the Terms of Service. Covers electronic signatures, and consent to receive operational communications by email, SMS, and push notification.
  • Worker Timeclock Consent — see Appendix B of the Terms of Service. Covers GPS location collection at clock-in / clock-out, optional background GPS route tracking during shifts, and timeclock-related push notifications.

Each consent is recorded with version, timestamp, IP address, timezone, device information, and (where the device permits) GPS coordinates at the moment of acceptance, and is downloadable as an audit PDF by the Customer's authorized administrators.

By using the Platform, you acknowledge that you have read and understood this Privacy Policy.