01 Who we are
Simplin, Inc. ("Simplin," "we," "us," or "our") provides scheduling, time-tracking, payroll export, and team-communication software for small businesses. This Privacy Policy explains how we handle information collected through our website (simplin.ai), mobile applications, NFC tags, and related services (collectively, the "Services").
This policy applies to both business customers ("Operators") and their employees whose information is processed through the Services ("End Users").
02 Information we collect
Account information
- Name (first and last)
- Email address
- Phone number (optional)
- Business name and address (for business owners)
Employment information
- Employee role and status
- Pay rate and pay type
- Start date
- Assigned store/location
- PIN code (used for kiosk clock in/out, stored securely)
Time and attendance data
- Clock in/out timestamps
- Break start/end times
- Gross and net hours worked
- Authentication method used (NFC, PIN, QR code)
Location data
When you clock in or out, we collect your GPS coordinates to verify that you are at your assigned workplace. This location data is collected only at the moment of the clock event and is not tracked continuously.
NFC data
We store NFC tag identifiers (UIDs) associated with your workplace to enable tap-to-clock functionality. NFC tag data is used solely for authentication purposes.
Device information
We may collect device type, operating system version, and device identifiers to ensure proper app functionality and security.
03 How we use information
We use the collected information to:
- Provide and maintain the Service.
- Process clock in/out events and calculate work hours.
- Generate payroll reports for your employer.
- Create and manage employee schedules.
- Verify your identity and workplace location during clock events.
- Send you notifications about your schedule and clock status.
- Translate messages in real time for multilingual teams.
- Improve and optimize the Service.
- Comply with legal obligations.
We do not sell personal information, and we do not use employee information to train third-party AI models.
04 How we share information
We share information only with:
- Your employer / Operator: if you are an End User, your Operator has access to your timesheets, schedule, and messages.
- Service providers: we use Supabase for data storage and authentication, and Google Maps for geocoding business addresses.
- Payroll providers: only when you or your Operator initiates an export.
- Legal compliance: when required by law, regulation, subpoena, or to protect the rights, safety, or property of Simplin or others.
- Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to affected users.
05 Data retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Time and attendance records are retained as required by applicable labor laws (typically 3–7 years depending on jurisdiction).
You may request deletion of your account at any time through the app. Upon deletion, your personal information will be removed, though anonymized aggregate data may be retained.
06 Your rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your account and personal data.
- Object to or restrict processing of your data.
- Data portability.
- Opt out of marketing communications at any time.
To exercise any of these rights, please contact us at support@simplin.ai.
07 Security
We implement industry-standard security measures to protect your data, including:
- Encrypted data transmission (HTTPS/TLS)
- Row-level security policies on all database tables
- Secure authentication with Supabase Auth
- AES encryption for NFC tag security keys
No system is perfectly secure — if we become aware of a breach affecting your information, we will notify you without undue delay as required by law.
08 International transfers
Simplin is based in the United States, and data is primarily processed in the U.S. If you access the Services from outside the U.S., your information will be transferred to, stored, and processed in the U.S. Where required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
09 Children's privacy
The Service is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us so we can delete it.
10 Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Material changes will be announced via email or in-app notice at least 30 days before they take effect.
11 Contact us
If you have any questions about this Privacy Policy, please contact us: