Back to home

Privacy Policy

Last updated: 16 August 2026 · Version 1.1

1. Who We Are

SnelScan (“we”, “our”, “us”) operates the SnelScan attendance management platform. We are committed to protecting the personal data of our customers, their employees, and all users of our Service.

Contact: privacy@snelscan.com

2. Data We Collect

We collect the following categories of data:

  • Account data: company name, administrator name, email address, phone number
  • Billing data: subscription plan, billing cycle, payment records (payment card details are processed by our payment provider and not stored by us)
  • Employee data: names, email addresses, employee IDs, work schedules, attendance records
  • Biometric templates: fingerprint templates generated and stored on ESP32 hardware devices and our servers solely for attendance matching
  • Usage data: login timestamps, IP addresses, device identifiers, feature usage logs
  • Mobile app data: an installation identifier, app version, platform, language, mobile session records, push token, and notification read state
  • Legal records: Terms of Service acceptance timestamp and IP address

3. How We Use Your Data

  • To provide and operate the attendance management Service
  • To verify identity and process clock-in/out events
  • To generate payroll reports and timesheets
  • To send transactional emails (account approval, invitations, password resets)
  • To maintain secure mobile sessions and deliver requested schedule, correction, leave, and salary notifications
  • To enforce subscription plan limits and billing
  • To comply with legal obligations and audit requirements
  • To improve and develop the Service

4. Biometric Data

Biometric fingerprint templates are particularly sensitive. We only collect biometric data with the explicit, informed consent of each employee. Biometric templates are:

  • Stored securely in our database and on hardware devices
  • Used solely to match attendance check-ins — never for identification in other contexts
  • Deleted upon employee termination or account cancellation upon request
  • Never sold or shared with third parties

5. Data Sharing

We share data only with:

  • Neon (database hosting) — cloud PostgreSQL provider, EU-compliant
  • Resend — transactional email provider
  • Google Cloud Platform — application hosting
  • Expo — iOS and Android build infrastructure and push-notification delivery
  • Apple and Google — App Store/Google Play distribution and APNs/FCM push delivery
  • Legal authorities — when required by law or valid legal process

We do not sell personal data to any third party.

6. Data Retention

We retain account data for the duration of your subscription plus 6 months after cancellation. Attendance records may be retained for up to 7 years to support payroll audits. Biometric templates are deleted within 30 days of an employee's termination or upon your written request. Mobile refresh sessions expire after 30 days of inactivity and no later than 180 days after creation. Push tokens are removed when an installation logs out, a session is rejected, or a provider reports the token as invalid.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access a copy of the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data (“right to be forgotten”)
  • Object to or restrict processing of your data
  • Data portability (receive your data in a machine-readable format)
  • Withdraw consent at any time where processing is based on consent

To exercise these rights, contact us at privacy@snelscan.com.

8. Security

We implement industry-standard security measures including TLS encryption in transit, optional AES-256 encryption at rest for biometric templates when enabled, JWT-based authentication, role-based access control, and audit logging of administrative actions. The mobile app stores its limited offline cache in a SQLCipher-encrypted database whose key is held in the operating system's secure credential store. Cached data is limited to recent dashboard, hours, schedule, and notification records, is timestamped, and is wiped on logout or rejected session refresh. Payslip PDFs are temporary and are deleted after viewing or sharing. However, no system is completely secure; you use the Service at your own risk.

9. Mobile App Choices

The SnelScan employee app does not contain advertising, cross-app tracking, in-app purchases, or account creation. Push notifications are optional and can be declined in the device permission prompt. Employees continue to clock in and out on their employer's SnelScan attendance device; the mobile app does not collect attendance from GPS, biometrics, or background location.

10. Cookies

We use only strictly necessary session cookies to keep you logged in. We do not use tracking or advertising cookies.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you by email at least 14 days before material changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

12. Contact

For privacy-related inquiries: privacy@snelscan.com