Back

Privacy Policy

TimePlate — SlashHub Limited

Privacy Policy

Last updated: June 15, 2026

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.


1. Introduction

SlashHub Limited ("Company," "we," "us," "our") operates the TimePlate platform — a product of SlashHub Limited. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the TimePlate mobile application, admin web application, API and backend services (collectively, "the Platform").

This policy complies with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") and is informed by GDPR standards where applicable. Please read this policy carefully. By using the Platform, you acknowledge the practices described herein.

2. Data Controller & Platform Disclaimer

The data controller responsible for your personal data is SlashHub Limited (operator of the TimePlate platform). Contact: privacy@slashhub.hk. Jurisdiction: Hong Kong Special Administrative Region.

SlashHub Does Not Control the Underlying Infrastructure

TimePlate is built on third-party platforms. SlashHub Limited has limited control over how these platforms handle your data, including Firebase/Google Cloud (all user data), Airwallex (payment card details), Vercel (session data), Railway (server logs), Sentry (error logs), and Apple/Google App Stores (device identifiers).

Your Data, Your Responsibility

You (the restaurant/employer) are the data controller for your employee data. SlashHub is a data processor. You are responsible for obtaining necessary consents from your employees to use TimePlate and for ensuring your use complies with applicable privacy laws.

SlashHub Limited shall not be held liable for any data loss, data breach, unauthorized access, or privacy violation that occurs on the infrastructure of third-party providers, on your device, through your network, through your employees' devices, or due to operating system vulnerabilities.

3. Types of Data We Collect

Data You Provide Directly

  • Account Information: Full name, email address, phone number, profile photo, role/position — for account creation and authentication
  • Employment Information: Employee ID, employment type, position, department, hourly rate, MPF details, date of birth, gender, HKID (last 4 digits, optional), bank account details (for payroll export) — for workforce management and HK compliance
  • Restaurant Information: Company name, business registration number, shop addresses, operating hours — for restaurant setup
  • Payment Information: Credit card details (processed by Airwallex — we do not store full card numbers) — for subscription billing

Data Collected Automatically

  • Attendance Records: Clock-in/out timestamps, verification method (GPS/BLE/NFC/QR/face/manual), station assigned, shift details, check-out photos
  • Location Data: GPS coordinates at time of check-in, location accuracy, geofence radius data
  • Device Information: Device model, OS version, app version, device language, time zone, IP address
  • Usage Data: Features used, screens viewed, session duration, crash reports, error logs
  • Biometric Data: Face embeddings (mathematical representation of facial features) if face recognition is enabled
  • BLE/NFC Data: Beacon proximity data, NFC tag UID, timestamp of scan

Data We Do NOT Collect

Full HKID numbers (only last 4 digits optionally), complete credit card numbers, health insurance information, criminal records, political/religious beliefs, genetic data, fingerprints, contact lists, or personal messages.

4. Purposes of Data Processing

We process personal data for the following purposes:

PurposeDescriptionLegal Basis
Service ProvisionProvide attendance tracking, workforce management, scheduling, leave management, and reportingContract performance
Authentication & SecurityVerify user identity, prevent unauthorized access, detect fraudulent clock-insLegitimate interest
Verification MethodsEnable GPS, BLE, NFC, QR, and face recognition check-inContract performance
ComplianceComply with HK Employment Ordinance, MPF requirements, statutory leave calculationsLegal obligation
BillingProcess subscription payments and manage billingContract performance
SupportRespond to inquiries, troubleshoot issuesLegitimate interest
ImprovementAnalyze usage patterns to improve featuresLegitimate interest
Legal ComplianceRespond to lawful requests from regulators or law enforcementLegal obligation

5. Face Recognition Data — Special Provisions

If your restaurant enables face recognition check-in, we collect face embeddings (mathematical vector representation of facial features) and reference photos (one or more enrollment photos used to generate the initial embedding).

Face embeddings are processed on-device using the @vladmandic/face-api library. When the employee clocks in, the live camera feed is processed to generate a new embedding, which is compared against the stored reference embedding. If the match score exceeds the configured threshold, check-in is verified.

Face embeddings are stored in encrypted form in our database. Reference photos are stored in Google Cloud Storage with signed URL access only. We do not share facial recognition data with any third party. Employees may opt out of face recognition by requesting alternative verification methods from their manager.

Face recognition data is retained for such periods as we determine in our sole discretion. Retention periods are subject to change at any time without notice. Where required by applicable law, we will obtain explicit consent before collecting and processing biometric data. Employees may withdraw consent at any time by contacting privacy@slashhub.hk.

6. Location Data — Special Provisions

When GPS geofencing check-in is enabled, we collect GPS coordinates at the moment of clock-in/out, location accuracy (meters), and timestamp of location capture.

Location data is used to verify the employee is within the configured geofence radius of the restaurant and to log location evidence for attendance records.

The Mobile App does not track location in the background. Location is captured only when the employee actively performs a check-in or check-out action.

Employees may decline GPS data collection by disabling location permissions for the app in device settings (this will prevent GPS-based check-in) or by requesting alternative verification methods (BLE, NFC, QR, or face) from their manager.

7. Data Sharing and Disclosure

Within Your Organization

Data TypeVisible To
Employee attendance recordsEmployee (self), manager, owner
Employee personal profileEmployee (self), manager, owner
Location data at check-inManager, owner (audit purposes)
Face recognition dataEmployee (self), no other users directly
Check-out photosManager, owner
Leave requests and balancesEmployee (self), manager, owner
Payroll/MPF dataManager, owner

Third-Party Service Providers

We share data with Google Cloud/Firebase (cloud infrastructure), Airwallex (payment processing), Vercel (web hosting), Railway (API hosting), and Sentry (error monitoring). All providers are contractually obligated to process data only as instructed and to maintain appropriate security measures.

Legal Disclosures

We may disclose personal data if required by law, regulation, or legal process. In the event of a merger, acquisition, or sale of assets, personal data may be transferred with notice to you.

We do not sell, rent, or trade personal data to third parties for their marketing purposes.

AI & Machine Learning Training

We may use data from the Platform for machine learning model training, algorithm improvement, and product development, in our sole discretion. Any descriptions of specific data types used or excluded from training are illustrative and subject to change at any time without notice. Restaurant owners may opt out by contacting support@slashhub.hk.

8. Data Retention

Retention Periods

Retention periods are determined at our sole discretion and may be changed at any time without notice. The following are illustrative only:

Data CategoryIllustrative Retention Period
Account dataDuration of account relationship
Attendance recordsAs required by applicable law
Payroll/MPF dataAs required by applicable law
Location logsAs determined by us
Face embeddingsAs determined by us
Check-out photosAs determined by us
Support ticketsAs determined by us
Error logsAs determined by us
Payment recordsAs required by applicable law

Upon account termination, we may delete data at any time thereafter, in our sole discretion. Records required by law are retained for the statutory period and then securely deleted. Deleted data is irrecoverable.

You may request a copy of your personal data by emailing privacy@slashhub.hk. We will respond within a reasonable timeframe.

9. Data Security

We implement the following security measures:

  • Encryption in Transit: TLS 1.3 for all API communications
  • Encryption at Rest: AES-256 for database and storage
  • Authentication: Firebase Authentication with Custom Claims (role-based access control)
  • File Access: Signed URLs with expiration for storage access
  • API Security: Rate limiting, request validation (Zod), idempotency keys
  • Audit Logging: All admin actions logged with timestamp and actor
  • Access Control: Role-based (employee/manager/owner) with fine-grained permissions
  • Regular Audits: Security reviews and penetration testing

In the event of a data breach, we will take reasonable steps to contain and remediate the breach and will provide notifications as required by applicable law. Any notifications we provide are made in our sole discretion and are not an admission of liability or fault.

You are responsible for maintaining strong passwords, not sharing credentials, reporting unauthorized access, and keeping your device and app updated.

10. Your Rights Under Hong Kong PDPO

You have the following rights:

  • Right of Access: Request confirmation of whether we hold your personal data and receive a copy
  • Right to Correction: Request correction of inaccurate personal data
  • Right to Erasure: Request deletion of your personal data (subject to legal retention requirements)
  • Right to Restrict Processing: Request restriction of processing in certain circumstances
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent where processing is based on consent

To exercise these rights, email privacy@slashhub.hk. We will respond to all legitimate requests within 30 days. We may need to verify your identity before processing your request.

11. International Data Transfers

Your data may be processed in:

  • Hong Kong — Primary processing location
  • United States — Google Cloud (Firebase), Airwallex, Vercel, Railway, Sentry
  • Asia (Google Cloud regions) — For latency optimization

When data is transferred outside Hong Kong, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required, data processing agreements with all third-party providers, and ensuring the receiving jurisdiction has adequate data protection laws.

12. Changes to This Privacy Policy

We may update this Privacy Policy at any time, in our sole discretion, with or without notice. All changes are effective immediately upon posting. We may notify you of material changes via email, in-app notification, or notice on the Admin Web App, but we are under no obligation to provide notice of any kind. The "Last Updated" date at the top of this policy will reflect the most recent changes. Your continued use of the Platform after any changes constitutes acceptance of the updated Privacy Policy.

13. Contact and Complaints

Contact Us

PurposeContact
Privacy inquiriesprivacy@slashhub.hk
Data Protection Officerdpo@slashhub.hk
General supportsupport@slashhub.hk

Complaints

If you believe we have violated your privacy rights, contact us at privacy@slashhub.hk. We will investigate and respond within a reasonable timeframe, not to exceed 60 days. All determinations regarding your complaint are at our sole discretion and are final and binding. You may also lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (https://www.pcpd.org.hk).

14. SlashHub's Authority & Legal Interpretation

All determinations, interpretations, and decisions regarding this Privacy Policy and the handling of your personal data are at SlashHub Limited's sole and absolute discretion and are final and binding on you. SlashHub Limited reserves the right to modify its data handling practices, retention periods, and processing activities at any time, in its sole discretion, with or without notice, to the extent permitted by applicable law. SlashHub Limited reserves the sole and exclusive right to interpret how any applicable privacy laws, data protection laws, or other legal requirements apply to the Platform, your data, and all related matters. SlashHub Limited's interpretation of any legal requirement is final and binding on you. You waive any right to assert that SlashHub Limited's interpretation of any law is incorrect or that SlashHub Limited should have acted differently under any legal standard. Nothing in this section places SlashHub Limited above the law — this section establishes that SlashHub Limited, not you, determines how the law applies to the Platform and your data. Nothing in this Privacy Policy shall create any third-party rights or be construed as a contractual obligation beyond what is required by applicable data protection laws.

TimePlate v1.0.0 — SlashHub Limited © 2026