Privacy Policy for Farm TimeCard
Effective Date: 2026-09-12 Last Reviewed: 2026-09-12
Change Log
- 2026-09-12 — Rewrote the location sections to match how the app works today: punch location is collected only when you turn on location sharing in the app (punches still save without it); described the Clock screen location reading, the one-time retry for a punch, the managers' field-mapping and weather tools (including rounded coordinates sent to weather data providers), when each use stops, and that manager-entered punches carry no worker location. Removed the statement that location is never read between clock events, which did not cover those tools. This revision describes features already in the app and adds no collection; it is announced in the app from 2026-09-14 to 2026-10-14, as Section 10 provides.
- 2026-05-05 — Consolidated contact to a single support email. Added concrete account-deletion path (in-app + web URL). Named the legal entity (Farm TimeCard LLC). Disclosed third-party SDKs (Sentry, Expo Push / FCM, Stripe). Added push notification token to data collected automatically.
- 2026-04-24 — Aligned with current app binary: removed background-tracking language (app captures GPS only at clock events). Added Oregon Consumer Privacy Act (OCPA), CCPA/CPRA, retention schedule tied to BOLI OAR 839-020-0080, ag-worker minors clause, and breach notification.
- 2026-01-15 — Initial release.
1. Introduction
Farm TimeCard LLC ("Farm TimeCard," "we," "our," or "us") operates a workforce time-tracking platform used by agricultural employers and their workers. This Privacy Policy describes what personal information we collect, why we collect it, how we use and share it, how long we keep it, and the choices and rights available to you.
If you are a worker using the mobile app at your employer's direction, your employer is the controller of your employment data; we are the processor. If you are an employer (farm owner, manager, bookkeeper) using our services, we are generally the controller for account-level data you provide directly.
2. Information We Collect
A. Information You Provide
- Identity data — name, date of birth, employee number, preferred language.
- Contact data — phone number, email address, emergency contact details.
- Employment data — role, pay rate, pay basis (hourly, day-rate, piece-rate), job titles, department or crew assignments, classification (agricultural non-exempt, salary-exempt, etc.).
- Authentication data — username, PIN (hashed, never stored in plaintext), multi-factor device registration details if enabled.
- Optional verification — clock-in photo if your employer has enabled photo verification for their farm.
B. Information We Collect Automatically
- Location — described in full in Section 2.D. In short: punch location is collected only when you turn on location sharing in the app, and the app reads location only while it is open. We do not track your location in the background, and we do not request or use the "Always" or background-location permission on iOS or Android.
- Clock-event timestamps — the device time and a server-verified timestamp at the moment each event is submitted.
- Device data — device model, operating-system version, app version, and a per-install identifier used to detect offline-sync issues and prevent duplicate submissions.
- Push notification token — when push notifications are enabled, an opaque device token issued by Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM) so we can deliver shift reminders, schedule changes, and other work-related notifications.
- Technical logs — API request metadata (endpoint, response code, latency), error reports, and minimized diagnostic context used to keep the service operating. Diagnostic identifiers can be pseudonymous; we do not describe all diagnostics as anonymous. API request-error diagnostics use route templates and opaque correlation values instead of raw user, farm, organization, IP, request-body, or query values.
C. Information From Third Parties
- Your employer — roster details, pay rates, schedule assignments, and classification decisions your employer enters or imports.
- Payroll providers (when your employer configures them) — read-only metadata needed to format exports; we do not receive your pay from these systems.
D. Location: when the app uses it, and when it stops
The app uses your device's location for a few separate purposes. Each one needs your device's location permission, and each one runs only while the app is open on your screen.
- Location with your punches (your choice) — the app records location with your punches only after you turn on location sharing in the app (the prompt on the Clock screen, or Settings → Permissions & privacy → Location consent). Until you choose, and whenever you decline, the app does not read your location for punches, and your punches still save, without location. On farms that review punches for location, a punch without location may be left for your manager to review.
- At each punch — when you tap Clock In, Clock Out, Start Break, or End Break, the app takes one location reading (latitude, longitude, and accuracy) and attaches it to that punch to confirm it happened at the work site. If no reading is available at that moment, the app may try once more for that same punch while it is open and sending the punch.
- On the Clock screen — while the Clock screen is open, the app also reads your location when you open or return to it, to show your current position on that screen. That on-screen reading stays on your device; it is not added to your time records.
- Who sees it — the location attached to a punch is shared with your employer and kept with that time record.
- Turning it off — declining or resetting in Settings stops punch location right away, including a reading already in progress, and removes location from punches still waiting on your device to be sent. Punches already sent keep their location as part of the time record. Our servers also check a punch's location against your current choice and drop it if you have declined, or if it was captured under an earlier choice.
- Clock status — clocking in does not start continuous tracking, and nothing is read in the background, whether you are on or off the clock.
- Punches your manager enters for you — when a manager records a punch on your behalf, no location is recorded for you, and the manager's device location is not saved on your time record.
- Field mapping (farm staff who set up fields) — when you choose to walk a field boundary, the app follows your device's location while the walk is running, so the path becomes the field's boundary. It uses foreground location only: it pauses if the app goes to the background or the screen locks, and it stops when you stop the walk or leave the map. The walked points are saved as your farm's field boundary, not as a record of where you were; until the field is saved or discarded they are kept on the device, encrypted, for at most 12 hours. When you ask the map to center on your position, or to use your current position for a field, the app takes one location reading for that request.
- Weather (manager dashboard) — when the dashboard cannot get weather for your farm's saved locations, the app may use your device's location, rounded to four decimal places (about 11 meters), to request current weather and air quality. The rounded coordinates are sent to our servers and passed to our weather data providers (Open-Meteo and AirNow) only to get that reading; they are not saved with time records or your profile. This is separate from the punch location choice above — it relies on your device's location permission, which you can turn off at any time.
3. How We Use Your Information
- Timekeeping verification — confirm that clock events correspond to authorized shifts at designated work sites.
- Payroll processing — calculate hours worked, overtime under applicable state and federal law, piece-rate earnings, and required wage-statement line items.
- Compliance and audit readiness — maintain the records your employer needs under Oregon BOLI recordkeeping rules, federal FLSA 29 CFR 516, and tax-credit programs such as Oregon's Agricultural Employer Overtime Tax Credit (ORS 315.133).
- Communication — send work-related notifications, schedule reminders, and service announcements.
- Security and fraud prevention — detect attempts to bypass clock-in location checks, duplicate submissions, device-clock tampering, and unauthorized account access.
- Service reliability — diagnose outages, prevent data loss during offline periods, and improve app stability.
4. Data Sharing
We do not sell personal data. We do not share personal data for cross-context behavioral advertising. We share data only as described below.
- Your employer — your farm manager or employer has access to your time logs, the location attached to punches you made with location sharing on (see Section 2.D), pay records, and profile information for the purpose of operating the workplace.
- Service providers — we use vetted third-party processors to host our database, send emails and push notifications, process payments (employer-side), and monitor service errors. Each provider operates under a data-protection agreement limiting their use to our instructions. The third-party SDKs and services currently embedded in the app are:
- Sentry — crash and error diagnostics (device model, OS version, app version, stack traces; no clock-event location data is sent to Sentry).
- Expo Push / Firebase Cloud Messaging (FCM) — delivers push notifications using the opaque device token described in Section 2.B.
- Apple Push Notification service (APNs) — iOS-side push delivery.
- Stripe — processes employer-side subscription payments. Stripe never receives worker time, location, or payroll data; it receives only the billing identifiers needed to charge the employer's account.
- Weather data providers (Open-Meteo, AirNow) — our servers request weather and air quality for your farm's saved locations and, in the case described in Section 2.D, for device coordinates rounded to about 11 meters. Those requests carry only the coordinates (and our own access key); no name, account, or time-record data is sent.
- Payroll providers — when your employer exports payroll to ADP, Gusto, Paychex, QuickBooks, or another supported processor, we transmit the fields required to produce that export.
- Legal authorities — we disclose data when required by subpoena, court order, or other enforceable legal process, and we resist overbroad requests where permitted.
- Business transfers — if the company is sold or merged, account data may transfer with the business. We will notify affected users before any such change takes effect.
5. Retention
We retain data for the periods required by labor and tax law and by our service agreements with employers.
- Hours-worked and pay-period records — retained at minimum for the durations required by Oregon BOLI (OAR 839-020-0080) and federal FLSA 29 CFR 516, generally 3 years for payroll records and 2 years for the supporting time records. Your employer may configure longer retention.
- Tax-credit evidence — retained for the period your employer needs to claim, defend, or audit the credit, generally 4 years after filing.
- Clock-event location data — retained alongside the time events they verify, subject to the same retention schedule.
- Authentication and security logs — retained for 90 days unless a security incident extends the retention.
- Account-level data — retained while the account is active, then deleted on request consistent with any overlapping legal obligations.
When you request deletion, we remove identifying data except where retention is required by law. Aggregated, de-identified data may be retained indefinitely.
6. Data Security
We use administrative, technical, and physical safeguards that reflect industry practice for systems handling employment and location data:
- Encryption — data in transit is protected by TLS 1.2+; data at rest is encrypted in our managed database.
- Access control — least-privilege role-based access to production systems; multi-factor authentication for administrators.
- Audit trail — time events are written with a tamper-evident SHA-256 hash chain so unauthorized modification is detectable.
- Monitoring — server errors and anomalies are tracked via Sentry, with response procedures for security incidents.
- Vendor review — we evaluate third-party processors before engagement and review their security posture periodically.
No system is perfectly secure. If a breach affecting your personal data occurs, we will notify affected users and applicable authorities within the timeframes required by Oregon (ORS 646A.602), California, and other applicable laws.
7. Your Rights and Choices
You have rights over your personal data. Specific rights depend on where you live and the relationship you have with us.
A. All users
-
Access — request a copy of the personal data we hold about you.
-
Correction — request that we correct inaccurate data.
-
Location choices — you can turn punch location sharing on or off at any time in Settings → Permissions & privacy; turning it off takes effect right away and your punches still save, though farms that review punches for location may review them. You can also revoke the device location permission in your device settings; then no feature in the app can read your location.
-
Account deletion — you may delete your account and associated personal data at any time, subject to the retention obligations described in Section 5. Two paths:
- In the app — open Farm TimeCard, go to Settings → Account & Session → Delete My Account, and confirm.
- By email — write to support@farmtimecard.com with the subject line "Delete my account" from the email address on file. We will verify your identity and complete the deletion within 30 days.
Full instructions are also published at https://farmtimecard.com/account/delete.
B. Oregon residents (Oregon Consumer Privacy Act — effective July 1, 2024)
OCPA gives Oregon consumers rights to access, correct, delete, obtain a copy of, and opt out of targeted advertising or profiling with significant legal effects. Employment-scoped data processed on behalf of your employer is subject to the controller/processor relationship described in Section 1; rights to employment data are directed to your employer as controller. For account-level data we control directly, contact us using the information in Section 9.
C. California residents (CCPA / CPRA)
California consumers have the right to know the categories of personal information we collect, the purposes for which we use it, the categories of third parties we share it with, and to request deletion or correction. We do not sell personal information and do not share personal information for cross-context behavioral advertising. To exercise CCPA/CPRA rights, contact us using the information in Section 9. We will verify your identity before responding.
Categories of personal information collected (California Disclosure)
| Category | Examples | Collected | |----------|----------|-----------| | Identifiers | Name, email, phone, employee ID | Yes | | Geolocation | Location attached to punches when location sharing is on; field boundaries you walk; device location rounded to about 11 meters for weather lookups | Yes | | Professional/Employment info | Job title, pay rate, department | Yes | | Internet/Electronic activity | App usage, device info | Yes | | Sensitive personal info | Precise geolocation attached to punches (only when location sharing is on) | Yes |
D. Exercising your rights
Send your request to the address in Section 9. We will respond within the timeframes required by applicable law (generally 45 days under OCPA and CCPA, with a possible extension). There is no fee for the first request in any 12-month period. We may deny manifestly unfounded or excessive requests as permitted by law.
8. Children's Privacy and Agricultural Minors
The Service is not intended for individuals under 13. We do not knowingly collect data from children under 13. Under federal and Oregon agricultural labor rules, minors 14 and older may be employed in certain non-hazardous agricultural work. If a minor 14–17 is employed by your farm and will use the app, your farm is responsible for ensuring appropriate parental or guardian consent under ORS 653.305 (employment of minors) and for compliance with applicable youth-labor restrictions. Employer accounts may configure permission and visibility settings for minor employees.
9. Contact Us
For privacy questions, data-subject requests, security concerns, or general support:
- Email: support@farmtimecard.com
- Mailing address: Farm TimeCard LLC, (street address on request)
For security incidents, please use the same email address with the subject line "Security incident" so the message is routed appropriately.
10. Changes to This Policy
We may update this policy to reflect product changes, new legal requirements, or operational improvements. Material changes will be announced in-app at least 30 days before taking effect; the change log at the top of this document tracks every revision. Continuing to use the Service after an update means you accept the updated policy.
11. Governing Law
This policy is governed by the laws of the State of Oregon, without regard to conflicts-of-law principles, unless preempted by federal or other applicable law where you reside.