Privacy Policy

Last Modified: May 28, 2026

ELITEBASE PRIVACY POLICY

Elitebase ("we," "us," or "our") provides workforce time-tracking software for employers and on-site kiosk clock-in. This policy describes how we handle personal information and biometric data when you use our website, employer dashboard, and related services (collectively, the "Service").

1. Who this policy applies to.

This policy applies to company administrators who register and manage accounts on Elitebase, and to employees whose employers add them to the platform. Employees typically interact with Elitebase only through an employer-provided kiosk tablet (PIN and optional face verification), not through a personal web login in Phase 1.

2. Information we collect.

Depending on how you use the Service, we may collect:

  • Account data (employers): name, email address, password (stored in hashed form), and company profile details.
  • Employee profile data (added by the employer): name, optional email, role, department, position, and hire date.
  • Kiosk PIN: a short numeric code used to identify an employee at a tablet. PINs are stored using one-way hashing; we do not store plain-text PINs after initial setup.
  • Biometric data (face templates): if an employer enrolls employees in face verification, the kiosk may capture a facial image and convert it into a mathematical face template (a numeric "face descriptor"). We do not use biometric data for surveillance, marketing, or identification outside of timekeeping at the employer's kiosk.
  • Attendance records: clock-in, clock-out, break events, timestamps, optional face-match scores, and the tablet used.
  • Technical data: device/tablet identifiers, API logs, and similar data needed to operate and secure the Service.

3. Biometric data — purpose and consent.

Biometric information is collected only for timekeeping and fraud preventionat the employer's direction: to verify that the person clocking in is the enrolled employee. We do not use biometric data for surveillance, marketing, or identification outside of timekeeping at the employer's kiosk.

On the kiosk, employees are shown a consent screen before the camera is used for enrollment. Enrollment does not proceed without acceptance. Face templates are compared only to the enrolled employee's stored template during clock-in verification.

4. Employer responsibilities (biometric & employee consent).

If you register as a company administrator and use face recognition for your workforce, you agree that your company is responsible for compliance with applicable privacy and biometric laws—not Elitebase acting as your legal advisor.

Before enrolling any employee in face recognition, your company must obtain written consent from that employee (or otherwise satisfy legal requirements in your jurisdiction). This includes, where applicable:

  • Illinois — Biometric Information Privacy Act (BIPA): written notice, purpose, retention schedule, and written release before collecting or using biometric identifiers or information.
  • Texas — Capture or Use of Biometric Identifier Act (CUBI): notice and consent before capturing biometric identifiers for commercial purposes.
  • California — California Consumer Privacy Act (CCPA/CPRA): notice at collection, purpose limitation, and employee rights for sensitive personal information, including biometrics where applicable.

Elitebase provides kiosk consent flows and technical controls to support your program, but you remain responsible for obtaining and documenting employee consent, maintaining required notices, and honoring employee rights requests. Do not enable face enrollment for employees who have not provided valid consent.

5. How we use information.

We use collected information to:

  • Provide, maintain, and improve the Service;
  • Authenticate employer accounts and secure the platform;
  • Record and display attendance and timesheets for the employer;
  • Operate kiosk pairing, PIN verification, and face matching;
  • Respond to support requests and legal obligations;
  • Detect abuse, fraud, and security incidents.

6. Retention.

We retain personal and employment-related data for as long as the employer's account is active and as needed to provide the Service.

Biometric face templates and related enrollment metadata are retained for up to one (1) year after the employee is deactivated or the employer deletes the enrollment, whichever occurs first, unless a longer period is required by law or agreed in writing with the employer. After that period, templates are deleted or irreversibly destroyed.

Attendance records are retained according to the employer's business needs and applicable wage-and-hour laws; employers may export data before account closure.

7. We do not sell your information.

We do not sell, rent, or trade personal information or biometric data to third parties for their marketing purposes. We do not disclose biometric data to third parties except as described in this policy.

8. Service providers and disclosures.

We use trusted infrastructure providers to run the Service (for example, cloud hosting, database, and email delivery). They process data only on our instructions and under contractual safeguards. We may also disclose information if required by law, court order, or to protect rights, safety, and security.

9. Your rights and choices.

Depending on your location, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to withdraw consent for biometric processing where applicable.

Employees should contact their employer first to request access, correction, or deletion of employment and biometric data, since the employer controls the workplace program. We will assist employers in fulfilling valid requests.

Employer account holders may update company and account settings in the dashboard or contact us using the information below.

California residents may have additional rights under the CCPA/CPRA, including the right to know, delete, and correct personal information, and to limit use of sensitive personal information. We do not use biometric data for purposes beyond timekeeping as described in this policy.

10. Security.

We use administrative, technical, and organizational measures designed to protect data, including encryption in transit, access controls, and hashed storage for credentials and PINs. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

11. Children.

The Service is intended for workplace use and is not directed to children under 16. We do not knowingly collect information from children.

12. Changes to this policy.

We may update this policy from time to time. We will post the revised version on this page and update the "Last Modified" date. Material changes may be communicated to account holders by email or in-product notice where appropriate.

13. Contact us.

For privacy questions, biometric data requests, or to exercise your rights, contact:

Elitebase Privacy
Email: privacy@elitebase.com

Please include your name, employer (if you are an employee), and a description of your request. We aim to respond within 30 days where required by law.

See also our Terms of Service and Cookie Policy.