Privacy at a glance
- TaskTrail is a business operations service used by organisations and their authorised workers.
- We use personal data to provide accounts, job and task workflows, time records, work evidence, notifications, support and security.
- We do not sell personal data or use it for third-party advertising.
- The Employee Clock app does not request location or microphone access. Camera and notification access are optional.
1. Who we are and when this policy applies
TaskTrail provides job, workforce and time-management software. This policy applies to tasktrail.co.uk, the TaskTrail platform and the TaskTrail Employee Clock Android and iOS apps. Android uses package name uk.co.tasktrail.employeeclock; Apple platform wording applies only where the iOS app is installed and used.
For workforce, customer, job and task information entered by a subscribing organisation, that organisation will usually decide why and how the data is used. It is normally the data controller and TaskTrail acts as its service provider or processor. TaskTrail is the controller for data used to administer our own service, keep it secure, manage subscriptions and answer enquiries.
2. Personal data we collect
The data involved depends on how an organisation configures and uses TaskTrail.
Account and organisation data
Names, work email addresses, phone numbers where provided, organisation membership, job role, account settings and securely hashed account credentials.
Time and workforce records
Clock-in and clock-out times, shifts, attendance or availability status, leave information, explanations, changes and related audit history.
Jobs, tasks and work evidence
Job references, customer or site contact details entered by the organisation, assignments, descriptions, notes, dates, statuses, issue reports, files and photos.
Device and notification data
Android push-notification tokens and related app or device registration details needed to deliver requested remote notifications. On-device reminder preferences are used to schedule optional clock reminders on Android and iOS.
Technical and security data
IP address, browser or device information, session identifiers, request timestamps, authentication events and security or error logs.
First-party product analytics
We collect structured, pseudonymous usage events such as screen and feature usage, session activity, workflow outcomes, controlled error categories, onboarding progress and selected performance timings. Analytics uses authenticated server-session state only: it does not add an analytics cookie or local-storage entry, fingerprint a device, or identify an individual employee in the analytics dashboard.
We do not place prompts, AI responses, names, emails, or user-entered customer, job or task content in product analytics. Raw pseudonymous events are retained for up to 90 days and then deleted after useful daily aggregates are created. Longer-lived aggregates contain counts and categories and are not intended to identify individual users.
Subscription and support data
Subscription status and billing identifiers for organisation administrators, plus messages and information supplied when contacting us for support.
We receive data directly from users, from their organisation or administrator, and automatically when the service is used. Payment-card details entered during checkout are processed by our payment provider and are not stored as complete card details on TaskTrail systems.
3. How and why we use personal data
We use personal data to:
- create, authenticate and manage accounts and organisation access;
- provide clocking, scheduling, job, task, workflow, file and reporting features;
- send operational messages, push notifications and reminders selected by a user or their organisation;
- provide customer support and service communications;
- process subscriptions, maintain business records and meet legal obligations;
- monitor reliability, prevent misuse, investigate security events and improve the service.
- understand aggregate product usage and workflow adoption, including differences between employee and company-administrator usage, so we can improve features and reliability.
Where UK data-protection law applies, TaskTrail relies on the performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where consent is required. Customer organisations are responsible for establishing the appropriate lawful basis for the workforce and business data they place in TaskTrail.
5. Employee Clock app permissions
The Employee Clock apps do not request precise or approximate location, contacts, call logs or microphone access.
6. Retention and security
We retain data while it is needed to provide the service, follow a customer organisation's documented instructions, maintain legitimate business and security records, or meet legal obligations. As a UK default, necessary time, leave and employment evidence may be retained for up to six years after account deletion, subject to the organisation documenting the lawful reason and applying any shorter applicable period. Product analytics raw events are pseudonymous rather than anonymous, are retained for up to 90 days, and are deleted after aggregation. Data that is no longer required is deleted or anonymised; limited copies can remain temporarily in protected backups until the normal backup rotation removes them.
We use measures designed to protect data, including encrypted network connections, access controls, account authentication, credential hashing, tenant-level permissions, logging and backups. No internet service can promise absolute security, so users should protect their credentials and report suspected misuse promptly.
7. Your choices and data-protection rights
Depending on the law that applies, you may have rights to request access, correction, deletion, restriction or portability of personal data, or to object to certain processing. You may also withdraw consent where processing is based on consent.
If you use TaskTrail through an employer or another organisation, contact that organisation first because it usually controls your workforce records. TaskTrail will assist the organisation in responding to valid requests. You may also contact us using the details below and may complain to the data-protection regulator in your country.
8. Delete your account
Signed-in Employee Clock users can permanently delete their account in the app at Settings → Account → Delete account. The app asks for the current password, removes the sign-in, password, device registrations, notification tokens, preferences and other account-only data, signs the user out, and clears local app data and scheduled reminders.
Deleting the account does not erase an employer's historical time, leave, payroll-supporting, work-assignment, work-evidence or audit records where the employer has a documented lawful retention reason. In the UK, TaskTrail's default retention schedule for necessary time and leave evidence is up to six years, after which retained identity is anonymised or the record is deleted when no longer required. Retention is access-limited and may be shorter or different under the applicable law and the employer's documented schedule.
For a wider rights request, or if in-app access is unavailable, email privacy@tasktrail.co.uk with the subject TaskTrail account deletion request. Include the account email address and organisation name, but never send your password.
9. Children and changes to this policy
TaskTrail is a business service and is not directed to children. Organisations are responsible for ensuring they have authority to create accounts and process information for every worker they add.
We may update this policy when our service or legal obligations change. We will publish the revised version here, update the date above and provide additional notice where a material change requires it.
10. Contact us
For privacy questions, rights requests or concerns about the TaskTrail Employee Clock app, contact:
TaskTrailEmail: privacy@tasktrail.co.uk
Website: tasktrail.co.uk