TimePlate — SlashHub Limited
Last updated: June 15, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
SlashHub Limited ("Company," "we," "us," "our") operates the TimePlate platform — a product of SlashHub Limited. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the TimePlate mobile application, admin web application, API and backend services (collectively, "the Platform").
This policy complies with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") and is informed by GDPR standards where applicable. Please read this policy carefully. By using the Platform, you acknowledge the practices described herein.
The data controller responsible for your personal data is SlashHub Limited (operator of the TimePlate platform). Contact: privacy@slashhub.hk. Jurisdiction: Hong Kong Special Administrative Region.
TimePlate is built on third-party platforms. SlashHub Limited has limited control over how these platforms handle your data, including Firebase/Google Cloud (all user data), Airwallex (payment card details), Vercel (session data), Railway (server logs), Sentry (error logs), and Apple/Google App Stores (device identifiers).
You (the restaurant/employer) are the data controller for your employee data. SlashHub is a data processor. You are responsible for obtaining necessary consents from your employees to use TimePlate and for ensuring your use complies with applicable privacy laws.
SlashHub Limited shall not be held liable for any data loss, data breach, unauthorized access, or privacy violation that occurs on the infrastructure of third-party providers, on your device, through your network, through your employees' devices, or due to operating system vulnerabilities.
Full HKID numbers (only last 4 digits optionally), complete credit card numbers, health insurance information, criminal records, political/religious beliefs, genetic data, fingerprints, contact lists, or personal messages.
We process personal data for the following purposes:
| Purpose | Description | Legal Basis |
|---|---|---|
| Service Provision | Provide attendance tracking, workforce management, scheduling, leave management, and reporting | Contract performance |
| Authentication & Security | Verify user identity, prevent unauthorized access, detect fraudulent clock-ins | Legitimate interest |
| Verification Methods | Enable GPS, BLE, NFC, QR, and face recognition check-in | Contract performance |
| Compliance | Comply with HK Employment Ordinance, MPF requirements, statutory leave calculations | Legal obligation |
| Billing | Process subscription payments and manage billing | Contract performance |
| Support | Respond to inquiries, troubleshoot issues | Legitimate interest |
| Improvement | Analyze usage patterns to improve features | Legitimate interest |
| Legal Compliance | Respond to lawful requests from regulators or law enforcement | Legal obligation |
If your restaurant enables face recognition check-in, we collect face embeddings (mathematical vector representation of facial features) and reference photos (one or more enrollment photos used to generate the initial embedding).
Face embeddings are processed on-device using the @vladmandic/face-api library. When the employee clocks in, the live camera feed is processed to generate a new embedding, which is compared against the stored reference embedding. If the match score exceeds the configured threshold, check-in is verified.
Face embeddings are stored in encrypted form in our database. Reference photos are stored in Google Cloud Storage with signed URL access only. We do not share facial recognition data with any third party. Employees may opt out of face recognition by requesting alternative verification methods from their manager.
Face recognition data is retained for such periods as we determine in our sole discretion. Retention periods are subject to change at any time without notice. Where required by applicable law, we will obtain explicit consent before collecting and processing biometric data. Employees may withdraw consent at any time by contacting privacy@slashhub.hk.
When GPS geofencing check-in is enabled, we collect GPS coordinates at the moment of clock-in/out, location accuracy (meters), and timestamp of location capture.
Location data is used to verify the employee is within the configured geofence radius of the restaurant and to log location evidence for attendance records.
The Mobile App does not track location in the background. Location is captured only when the employee actively performs a check-in or check-out action.
Employees may decline GPS data collection by disabling location permissions for the app in device settings (this will prevent GPS-based check-in) or by requesting alternative verification methods (BLE, NFC, QR, or face) from their manager.
| Data Type | Visible To |
|---|---|
| Employee attendance records | Employee (self), manager, owner |
| Employee personal profile | Employee (self), manager, owner |
| Location data at check-in | Manager, owner (audit purposes) |
| Face recognition data | Employee (self), no other users directly |
| Check-out photos | Manager, owner |
| Leave requests and balances | Employee (self), manager, owner |
| Payroll/MPF data | Manager, owner |
We share data with Google Cloud/Firebase (cloud infrastructure), Airwallex (payment processing), Vercel (web hosting), Railway (API hosting), and Sentry (error monitoring). All providers are contractually obligated to process data only as instructed and to maintain appropriate security measures.
We may disclose personal data if required by law, regulation, or legal process. In the event of a merger, acquisition, or sale of assets, personal data may be transferred with notice to you.
We do not sell, rent, or trade personal data to third parties for their marketing purposes.
We may use data from the Platform for machine learning model training, algorithm improvement, and product development, in our sole discretion. Any descriptions of specific data types used or excluded from training are illustrative and subject to change at any time without notice. Restaurant owners may opt out by contacting support@slashhub.hk.
Retention periods are determined at our sole discretion and may be changed at any time without notice. The following are illustrative only:
| Data Category | Illustrative Retention Period |
|---|---|
| Account data | Duration of account relationship |
| Attendance records | As required by applicable law |
| Payroll/MPF data | As required by applicable law |
| Location logs | As determined by us |
| Face embeddings | As determined by us |
| Check-out photos | As determined by us |
| Support tickets | As determined by us |
| Error logs | As determined by us |
| Payment records | As required by applicable law |
Upon account termination, we may delete data at any time thereafter, in our sole discretion. Records required by law are retained for the statutory period and then securely deleted. Deleted data is irrecoverable.
You may request a copy of your personal data by emailing privacy@slashhub.hk. We will respond within a reasonable timeframe.
We implement the following security measures:
In the event of a data breach, we will take reasonable steps to contain and remediate the breach and will provide notifications as required by applicable law. Any notifications we provide are made in our sole discretion and are not an admission of liability or fault.
You are responsible for maintaining strong passwords, not sharing credentials, reporting unauthorized access, and keeping your device and app updated.
You have the following rights:
To exercise these rights, email privacy@slashhub.hk. We will respond to all legitimate requests within 30 days. We may need to verify your identity before processing your request.
Your data may be processed in:
When data is transferred outside Hong Kong, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required, data processing agreements with all third-party providers, and ensuring the receiving jurisdiction has adequate data protection laws.
We may update this Privacy Policy at any time, in our sole discretion, with or without notice. All changes are effective immediately upon posting. We may notify you of material changes via email, in-app notification, or notice on the Admin Web App, but we are under no obligation to provide notice of any kind. The "Last Updated" date at the top of this policy will reflect the most recent changes. Your continued use of the Platform after any changes constitutes acceptance of the updated Privacy Policy.
| Purpose | Contact |
|---|---|
| Privacy inquiries | privacy@slashhub.hk |
| Data Protection Officer | dpo@slashhub.hk |
| General support | support@slashhub.hk |
If you believe we have violated your privacy rights, contact us at privacy@slashhub.hk. We will investigate and respond within a reasonable timeframe, not to exceed 60 days. All determinations regarding your complaint are at our sole discretion and are final and binding. You may also lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (https://www.pcpd.org.hk).
All determinations, interpretations, and decisions regarding this Privacy Policy and the handling of your personal data are at SlashHub Limited's sole and absolute discretion and are final and binding on you. SlashHub Limited reserves the right to modify its data handling practices, retention periods, and processing activities at any time, in its sole discretion, with or without notice, to the extent permitted by applicable law. SlashHub Limited reserves the sole and exclusive right to interpret how any applicable privacy laws, data protection laws, or other legal requirements apply to the Platform, your data, and all related matters. SlashHub Limited's interpretation of any legal requirement is final and binding on you. You waive any right to assert that SlashHub Limited's interpretation of any law is incorrect or that SlashHub Limited should have acted differently under any legal standard. Nothing in this section places SlashHub Limited above the law — this section establishes that SlashHub Limited, not you, determines how the law applies to the Platform and your data. Nothing in this Privacy Policy shall create any third-party rights or be construed as a contractual obligation beyond what is required by applicable data protection laws.
TimePlate v1.0.0 — SlashHub Limited © 2026