HammerTime Privacy Policy
This Privacy Policy describes how HammerTime (web and mobile apps) accesses, collects, uses, stores, and shares personal information. It is written to meet Google Play User Data and Privacy Policy requirements and applies to the HammerTime Android and iOS apps and related web services. We place particular emphasis on precise location / GPS data (including background location), camera and photo data, account information, and device identifiers.
1. Who this applies to
HammerTime is a workforce timekeeping, site compliance, and project task tool used by organisations and their workers. If you use HammerTime through your employer or another organisation, that organisation’s own policies and instructions may also apply alongside this notice. In many cases your organisation is the primary controller of workplace records created in its HammerTime account; Lit Solutions operates the platform that processes those records.
2. Categories of personal data we process
Depending on the features your organisation enables and how you use HammerTime, we may process the following categories (aligned with common app-store data-safety taxonomies):
| Category | Examples | Typical purpose |
|---|---|---|
| Precise location | GPS latitude, longitude, accuracy (metres), capture time; geofence enter/exit events; background location while organisation features require monitoring | Timekeeping verification, site attendance, geofencing, safety / compliance workflows |
| Approximate location | Coarser device location where the OS provides it; map display context | App functionality (maps / nearby site context) |
| Photos and videos / images | Camera captures and user-selected photos (proof of work, certifications, hazards, incidents, fleet, receipts, journals, signatures drawn in-app) | Operational proof, compliance, finance, safety records |
| Personal info | Name, email, phone number, employer/company affiliation, profile details (and date of birth if stored on your account) | Account login, membership, communications, records |
| Financial info | Expense amounts, suppliers, receipt images (where enabled) | Expense capture and related finance workflows |
| Files and documents | Employment contracts, project documents, toolbox / form attachments | HR, project, and site compliance workflows |
| Device or other IDs | App installation ID, server device ID, device name/model, platform, app version, push (FCM) token | Authentication, sync, notifications, security, support diagnostics |
| App activity / submissions | Time entries, site check-in/out, hazards, incidents, toolbox talks, task journals, biometric confirmation flags (not biometric templates) | Core product functionality and audit trails |
We do not use advertising identifiers for ads, do not sell personal information, and do not use collected data to build advertising profiles.
3. Location, GPS, and geofencing
The HammerTime mobile app may request access to your device location, including precise location from GPS and related positioning services (and approximate location where provided by the operating system). Location is used only for workplace attendance, timekeeping, geofencing, and related operational / safety / compliance features that your organisation enables.
3.1 When location is accessed or collected
Depending on settings and the feature you use, we may access or collect location when you:
- Clock in or clock out (or start/stop work on a task, including breaks or task switches) where GPS verification or geofence checks apply;
- Check in or check out of a site (site attendance), including prompts that match your position to a nearby site;
- Use geofencing features that compare your position to a site or project boundary (radius in metres configured by your organisation);
- Submit optional GPS with a task journal entry or similar workflow;
- Submit site compliance records (for example hazards or incidents) that attach a mobile submission including GPS; or
- Use other organisation-configured features that require or record location for operational, safety, or compliance purposes.
A typical location record may include latitude, longitude, optional accuracy (approximate metres), and the time the fix was captured on the device.
3.2 Geofencing
A geofence is a virtual boundary around a site or project. HammerTime may compare your device’s current position to that boundary to:
- verify you are on or near site before allowing check-in, clock-in, or clock-out;
- suggest or confirm the nearest matching site for attendance; and
- where enabled by your organisation, help the app end or restart a live clock, or check out / prompt check-in, when you leave or re-enter a configured work geofence.
Geofence rules are set by your organisation. We do not use geofencing for advertising or unrelated consumer tracking.
3.3 Foreground and background location
Location is used while you are actively using HammerTime (foreground / when-in-use). If your organisation enables features that monitor arrival at, leaving, or re-entering a geofence while you are checked in, on the clock, or enrolled in site auto check-in monitoring, the app may need background or “Always” location permission (where the operating system allows it) so those checks can continue when the app is not in the foreground.
Background location may be used to:
- detect geofence enter / exit events for optional auto clock-out, auto clock-in, or site check-out flows;
- run periodic location updates (for example balanced accuracy polling while site auto check-in monitoring is active) and, on Android, show a foreground-service notification while monitoring is running; and
- confirm whether you are inside or outside configured site boundaries before applying organisation rules.
Location permissions are requested through the operating system’s prompts (and, for background location, through an in-app disclosure before “Always” access where required). If you deny permission, features that require GPS may be unavailable or blocked until permission is granted (where your organisation enforces it). You can change location permissions in your device settings; doing so may disable those features.
3.4 Upload, storage, sharing, and who can see location
When location is submitted with a time entry, site attendance event, journal entry, compliance submission, geo site-match request, or similar record, it is transmitted over HTTPS to HammerTime servers for your organisation’s account and stored with that operational record. Authorised users for that company account (such as owners, managers, or administrators) may be able to view location-related fields for payroll, audit, safety, or compliance purposes, subject to roles and product settings.
We do not sell location data and do not use it for advertising or marketing profiles. We do not share location with unrelated third parties for their own marketing. Service providers that help us operate HammerTime (for example cloud hosting) may process location data only to provide the service under appropriate agreements. Map display may use Google Maps services, which can receive map requests necessary to show maps.
3.5 Retention of location data
Location attached to timekeeping, attendance, or related records is retained with those records for as long as needed to operate HammerTime for your organisation and to meet legitimate business, legal, or contractual requirements. Retention and deletion may also depend on your organisation’s policies. Contact your organisation’s HammerTime administrator and [email protected] where applicable.
4. Camera, photo library, and images
The mobile app may request access to your device camera and, where supported, your photo library / media picker so you can:
- Time-entry photo proof — capture an image when a project task requires photo proof at clock-in, clock-out, start of work, end of work, or task switch;
- Task journal / instruction images — attach optional photos to notes, journals, or task instructions when your workflow allows it;
- Certification evidence — photograph license or certification cards (for example front and back);
- Site safety records — attach photos to hazards, incidents, or related site reports;
- Fleet / equipment logs — attach photos to usage, maintenance, compliance, or incident logs where enabled;
- Expense receipts — capture or choose receipt images where expenses are enabled; and
- Signatures — capture a drawn signature image for check-in or compliance workflows when that method is used.
The camera is not used for unrelated purposes such as general background scanning, advertising profiling, or third-party analytics from the camera feed. Images are captured or selected when you initiate an action in the app.
Before upload, images are typically normalised on the device (for example resized or re-encoded as JPEG) to meet technical limits. When you submit a photo, it is transmitted over HTTPS to HammerTime servers for your organisation’s account and stored as part of the relevant record. Authorised company users may view or download images for operational, audit, or compliance purposes. We do not sell images or use them to build advertising profiles.
5. Account, device, biometrics, and other data
- Account & identity — email and/or phone login, password or one-time codes, SMS multi-factor authentication where enrolled, profile name and contact details, company memberships and roles.
- Device & push — installation/device identifiers, device name/model/platform, app version, and Firebase Cloud Messaging (FCM) tokens so we can deliver notifications (for example site alerts or check-in prompts).
- Biometrics — Face ID / fingerprint may be used on your device to confirm certain actions (for example clock or check-in attestation). We receive a confirmation flag (for example that biometric authentication succeeded), not your biometric templates or face/fingerprint data.
- Offline queues — to support offline work, the app may temporarily store pending time entries, GPS fields, photos, and compliance submissions on the device until they can sync to HammerTime servers.
- Bot protection — phone OTP / login flows may use Cloudflare Turnstile.
6. How we use personal data
We use personal data to:
- provide, operate, and improve HammerTime app functionality (timekeeping, site compliance, tasks, fleet, expenses, documents);
- verify attendance and geofence rules configured by your organisation;
- authenticate users and secure accounts;
- send operational push notifications and in-app alerts;
- support audit, payroll, safety, and compliance needs of your organisation; and
- meet legal obligations and enforce terms where applicable.
Purposes are limited to app functionality, account management, security, and related workforce operations — not advertising.
7. Sharing and service providers
Personal data may be shared with:
- Your organisation — authorised owners, managers, and administrators on the same company account, as configured by roles and product settings;
- Lit Solutions / HammerTime hosting and infrastructure — to store and process data for the service;
- Google Firebase Cloud Messaging — to deliver push notifications (device push tokens and notification payloads);
- Google Maps — to display maps and related map tiles when you use map features (for example site geometry editing);
- Cloudflare — Turnstile bot protection and related CDN delivery where used; and
- Other subprocessors (for example cloud hosting, storage, or email delivery) that process data only to operate the service under appropriate agreements.
We do not share personal data with advertising networks for their own marketing. We do not sell personal data.
8. Security
We use industry-standard measures appropriate to the service, including encryption in transit (HTTPS), to protect information. Access within an organisation is controlled by account roles and product settings. No method of transmission or storage is completely risk-free.
9. Retention and deletion
We retain personal data for as long as needed to operate HammerTime for your organisation and to meet legitimate business, legal, or contractual requirements (for example timesheet, safety, and compliance records). Retention and deletion of specific records may also depend on your organisation’s policies and actions (for example removing a task, certification, or account data where the product supports it).
To request deletion or correction of personal data: contact your organisation’s HammerTime administrator first (they often control workplace records), and contact us at [email protected]. We will respond consistent with applicable law and our agreements with your organisation. Account closure or data deletion may be limited where records must be retained for legal or contractual reasons.
10. International transfers
If you or your organisation use the service from different countries, data may be processed in jurisdictions where we or our subprocessors operate, subject to applicable law and safeguards we put in place.
11. Children
HammerTime is intended for workplace use by adults and is not directed at children. We do not knowingly collect personal information from children for the service.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict processing of personal data, or to object to certain processing. To exercise rights, contact your organisation’s administrator and [email protected]. We will respond consistent with applicable law.
13. Where to find this policy
This Privacy Policy is published at https://hammertime.build/privacy.html and is also linked from the HammerTime mobile app (Settings → App Info → Privacy Policy) and from the app’s Google Play / App Store listing where applicable.
14. Changes
We may update this policy from time to time. The effective date at the top will change when we do. Continued use of the service after updates may constitute acceptance of the revised policy where permitted by law. Material changes relevant to app-store disclosures (especially location or camera practices) will be reflected on this page before or when those practices change in the product.