This Privacy Policy explains how Tickora ("we", "us", "our") collects, uses, and protects personal data when you use our website, our web platform, and the Tickora mobile app for iOS and Android (together, the "Services").
1. Who is responsible for your data
The Services are operated by [Legal entity name], [address], Germany. Contact: contact@tickora.de.
If you use Tickora as an employee: your employer created your account and decides what data is processed in its Tickora workspace (such as your schedule, time entries, and absences). In that case your employer is the data controller under the GDPR, and Tickora processes this data on your employer’s behalf as a data processor. Requests about this data are best directed to your employer; we support them in fulfilling your rights.
2. Data we collect
Account data — name, email address, phone number, role, and company, provided by you or your employer when the account is created.
Workforce data — data generated by using the Services: shifts and schedules, clock-in/clock-out times, breaks, absence and vacation requests, shift-change requests and the notes you attach to them, documents and payslips made available by your employer.
Mobile app data:
- Location (GPS): when you clock in or out with the mobile app, your precise location is captured at that moment only and stored with the time entry, so your employer can verify the entry was made at the workplace. The app does not track your location in the background or at any other time. You can decline the location permission; clock-in policies are then subject to your employer’s settings.
- Profile photo: if you choose to upload one, it is stored on our servers and shown to you and your team.
- Camera: used only to scan QR codes for signing in and, if you choose, to take a profile photo. Camera images from QR scanning are processed on your device and never uploaded.
- Face ID / Touch ID: biometric login is performed entirely on your device by the operating system. Biometric data never leaves your device and is never transmitted to us.
- Push notifications: we store a device push token so we can notify you about shift changes, approvals, and messages. You can disable notifications at any time in your device settings.
Support data — messages and optional attachments you send us through the in-app support form or by email.
Technical data — IP address, browser and device type, and strictly necessary cookies (web only). The mobile app contains no advertising and no third-party analytics or tracking SDKs.
3. Purposes and legal bases (Art. 6 GDPR)
- To provide the Services and operate your account — Art. 6(1)(b) (contract) and, for employee accounts, Art. 6(1)(f) / your employer’s instructions under a data-processing agreement.
- To verify clock-in location where your employer has enabled it — Art. 6(1)(f) (legitimate interest of your employer in accurate time records) or your employer’s applicable legal basis.
- To respond to support requests — Art. 6(1)(b) / (f).
- To meet legal obligations (e.g., tax and commercial retention duties) — Art. 6(1)(c).
- Optional analytics cookies on the website — Art. 6(1)(a) (consent).
4. Data sharing
We do not sell personal data and we do not share it for advertising. Data is shared only with vetted sub-processors strictly necessary to operate the Services (hosting in the EU, email delivery, push notification delivery via Apple and Google) under data-processing agreements, and with your employer’s workspace as described above.
5. Retention
We keep personal data only as long as necessary for the purposes above. Where German law requires longer retention, we do not delete the data but restrict its processing (Art. 18 GDPR) until the period expires, and delete it thereafter.
- Account and billing data (where Tickora is the controller): kept while your account is active. After you close your account or request deletion, we remove it within 30 days — except records we must retain by law. Under German commercial and tax law, invoices and accounting receipts (Buchungsbelege) are kept for 8 years (§ 257 HGB, § 147 AO), books and annual financial statements for 10 years, and commercial correspondence for 6 years.
- Workforce data in an employer workspace (where your employer is the controller): retained according to your employer’s instructions and its own legal duties. In Germany, working-time records must be kept for at least 2 years (§ 16 (2) ArbZG) and payroll-relevant records generally for 6 years (§ 41 EStG); some records fall under the longer tax-retention periods above. Location data attached to a time entry is kept as part of that working-time record.
6. Your rights
You have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interests (Art. 15–21 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority. To exercise your rights, contact contact@tickora.de — or your employer, where the employer is the controller.
7. Changes
We will update this policy when our Services or legal requirements change, and indicate the date of the latest revision above.
Contact
Questions? Email contact@tickora.de.
