TimeTrackby SIPL India

PRODUCT INFORMATION · 04 OCT 2026

Privacy policy

Who provides TimeTrack

TimeTrack by SIPL and TimeTrack Scanner by SIPL are provided by Sai Infratel Private Limited under the public brand SIPL India.

Support and privacy enquiries: info@sipl.pro

Scope and responsibility

This policy covers TimeTrack by SIPL, TimeTrack Scanner by SIPL and the TimeTrack website. Sai Infratel Private Limited operates the service under the SIPL India brand. Your employer or workspace owner decides which staff, branches, schedules and employment records belong in its workspace. We process those records to provide the requested service and manage account security and support. The service is intended for authorized workplace users aged 18 or over.

Information we process

Account information includes your name, work email, user identifier, language, role, invitations and authentication or recovery information. Workspace information includes business and branch names, branch addresses, contact email, employee names and codes, departments, assignments, schedules, holidays, attendance times, correction reasons and audit history. Device information includes an app-generated scanner identity and public key, pairing details, app/device status, synchronization events and error or security diagnostics. Hosting services also receive network information, such as IP addresses, when handling requests. Support and demo enquiries contain the information you choose to send.

Why we use information

We use information to authenticate users, enforce workspace and branch access, manage staff and schedules, record and review attendance, generate reports, synchronize authorized devices, recover accounts, answer enquiries and investigate errors or misuse. Required fields are identified in the app; optional contact and enquiry details can be omitted. We do not sell personal data or use employee records or face templates for advertising. The apps contain no advertising SDK or advertising-ID feature.

Camera and face information

The management app does not request camera access. The Scanner asks for camera permission when you choose a camera function. Camera checks process the preview on the device. Where your organization has an enabled, qualified face-attendance setup, local models process camera frames for face matching and live-presence checks. Raw camera photos and video are not uploaded by this capture flow. Encrypted face templates, employee identifiers and signed attendance evidence can be sent to our service and synchronized to authorized branch scanners; face templates are therefore not exclusively on-device. Enrollment requires a separate notice and affirmative consent. You may decline enrollment or ask to withdraw it and use manager-approved manual attendance. Installing the Scanner does not by itself enable face attendance. Camera access stops when the app leaves the foreground.

Who can receive information

Authorized people in your workspace see records according to their role and branch scope. We use Supabase for account and database services, Vercel for hosting and request processing, and Resend for transactional emails when enabled. These providers process the information needed to deliver their services. Authorized support staff may handle your enquiry; access to workspace records is limited by the support permissions granted. A report you explicitly export or share is delivered to the destination you choose. We may disclose information when required by applicable law or to address a security incident. The primary production database is in Mumbai, India; hosting, email, support or provider subprocessors may process information in other countries.

Storage and security

Connections to the service use HTTPS. Workspace permissions, authentication checks and audit records restrict access. Native sign-in secrets and scanner keys use protected device storage, and scanner template and queue data are encrypted. Web sessions use cookies and browser storage for authentication, preferences and scanner operation. Report downloads and files you share are under your control. These protections are not a claim of end-to-end encryption or a guarantee that every device or network is secure. Keep shared devices locked and current, protect recovery credentials and tell us about suspected unauthorized access.

Retention and deletion

Account information is retained while the account is active and needed for access, support or security. Permanent account closure removes the personal login, profile, active access, saved setup drafts and personal report snapshots. Employer-managed employee, attendance and audit records have a separate lifecycle and are not automatically erased by closing a login. Workspace owners manage their required employment-record retention and authorized deletion requests; contact the owner or us about a specific record. We retain limited deletion, security and audit identifiers where necessary to prevent deleted records from being replayed, investigate abuse or meet a legal obligation. We explain any applicable retention reason when responding to a deletion request. There is no universal automatic deletion period for all workspace records. Offline scanner copies require device cleanup or reconnection; any backups expire under their applicable backup cycle and cannot be represented as instantly erased. Downloaded or externally shared copies must be deleted by their holders. Demo form contact details and triage notes are scheduled for automatic deletion 90 days after submission, or earlier after a verified deletion request. Limited replay-prevention and audit identifiers remain; separately held emails follow their own lifecycle. We do not keep support or demo information for unrelated advertising; request its deletion through the contact below.

Your choices and privacy requests

You can review your profile, request corrections, manage available sessions and camera permission, decline face enrollment, and request account or data deletion. In the app, use Account security → Review account closure. If you cannot sign in, email info@sipl.pro with the subject “TimeTrack account/data deletion” and your account email and workspace name. You can also request access to your information, withdrawal of consent, correction or a privacy complaint at that address. We may verify your identity and authority before acting and coordinate employer-held records with the workspace owner. Never email a password, one-time code, face photo or secret key. The Data deletion page explains account, employer-record, device and backup handling.

Changes and contact

This policy is effective 4 October 2026. Updates will be published here with a revised date. Material new data uses require the relevant notice and consent before activation. Contact the privacy/support team at info@sipl.pro or write to Sai Infratel Private Limited, B-202, Sector-9 Kamal Vihar, Raipur 492001, India. If you believe information about a child has been supplied, contact us so we can review and address it.

Request account or data deletionHelp and contact