Privacy Policy
Last updated: 2026-08-07
This Privacy Policy explains how HourMark (“we,” “us”) collects, uses, and stores information when you use HourMark (the “Service”).
1. Information you provide
- Account details: display name, username, optional account email, and password (stored as a secure hash — we cannot read your password). If you use Google sign-in, we also store your Google account id and Google email for that link.
- Time records: clock-in/out times, breaks, lunch, notes, and any extra pay you enter.
- Pay settings: hourly rate, break defaults, time zone, and pay-period dates you choose.
- Assent records: when you accepted the Terms and Privacy Policy (and which version).
2. Information collected automatically
- Basic technical data needed to run and secure the Service (for example IP address used for rate-limiting sign-in attempts, and session cookies to keep you signed in).
- We do not use third-party advertising trackers in the app.
3. How we use information
- To provide clock, pay-estimate, and account features you request.
- To secure the Service (fraud/abuse prevention, CSRF protection, rate limits).
- To communicate about the Service if you contact us.
4. Where data is stored
Data is stored on the server that hosts this instance of HourMark (typically a SQLite database outside the public web root). If you self-host or a third party hosts for you, that operator controls the server environment.
5. Sharing
We do not sell your personal information. We may share information only: (a) with service providers who help host or secure the Service under confidentiality obligations; (b) if required by law or legal process; or (c) to protect rights, safety, or security.
6. Google sign-in
Google sign-in is optional. If you choose Continue with Google or Link Google, we receive a Google subject id, verified email, and display name from Google to sign you in or attach Google to your existing HourMark account. We do not receive your Google password. Linking keeps one HourMark account; we do not merge punches from two HourMark accounts into one.
7. Retention
We keep account and time data while your account remains active. You can delete your account anytime in the app (Profile → Delete my account). That removes your account, punches, and settings from this Service. Some security logs may be retained for a limited period. You may also email kaleb@scorptech.it.com with questions.
8. Security
We use industry-reasonable measures (hashed passwords, CSRF tokens, security headers, access controls). No method of transmission or storage is 100% secure.
9. Children
The Service is not directed to children under 13 (or the minimum age required in your region). Do not create an account if you are under that age.
10. Your choices
- Update settings and punches inside the app.
- Delete a shift from its detail screen on Check.
- Link or unlink Google in Profile (when enabled).
- Sign out on shared devices.
- Delete your account in Profile, or contact us where applicable law provides access, correction, or deletion rights.
11. International users
If you use the Service from outside the United States, you understand your information may be processed in the U.S. or where the host server is located.
12. Changes
We may update this Policy. The “Last updated” date will change when we do. Continued use means you accept the updated Policy.
13. Contact
Privacy questions: kaleb@scorptech.it.com.
This Policy is a protective template and is not legal advice for your specific situation.