Company Hub legal
Privacy Policy
This policy explains how Company Hub processes personal information and uses Google services to provide attendance-media storage and approved reporting synchronization.
Effective date: August 15, 2026
1. Scope and roles
Company Hub is an employee-operations application used by participating organizations. The organization that provides your account controls its workforce records and decides how Company Hub is used. Access is limited to authorized employees, company administrators, and separately authorized system administrators.
This public website does not display employee profiles, attendance records, attendance media, or authenticated dashboards.
2. Information Company Hub processes
Depending on the features enabled by your organization, Company Hub may process:
- account, employment, role, reporting-line, and profile information;
- attendance time, approved work mode, location-validation results, and attendance selfies;
- leave, calendar, announcement, resource, and notification information; and
- technical information needed for security, sessions, synchronization, recovery, and service health.
3. Google Drive access and attendance media
Purpose. Company Hub uses Google Drive through OAuth 2.0 access granted by an authorized operational Google account. This access is used to create, locate, verify, read, and manage attendance-media files that Company Hub creates or that the operational account explicitly authorizes through Google Picker in the configured Selfies folder. Company Hub does not request general access to unrelated Drive content.
Storage and access. Google Drive file identifiers and synchronization metadata are stored in Company Hub. OAuth credentials remain server-side and are not sent to browsers or stored in employee records. Attendance media is not made public; authorized Company Hub server routes enforce organization and role checks before a preview is returned. Each folder and file is checked as app-authorized before metadata access, download, recovery reuse, or verifier cleanup.
Synchronization and retention. A private temporary recovery copy may be retained in Company Hub's storage until the Drive upload is verified and for a 72-hour recovery period afterward. The verified Drive copy is retained according to the participating organization's attendance, legal, and records-retention requirements, and may be removed through an authorized operational process. Automated cleanup removes the temporary Company Hub recovery copy, not the permanent attendance file in Drive. A temporary synthetic verifier file is deleted after its verification run.
4. Google Sheets access and reporting synchronization
Company Hub uses a dedicated Google service account—not a visitor's or employee's Google OAuth grant—to access only the configured reporting workbook. The service account has no domain-wide delegation.
The current Google Sheets integration synchronizes an approved Holidays reporting dataset. It may write stable record identifiers, calendar names, holiday dates and titles, holiday type, working-day status, descriptions, record status, and source update time. Employee, leave, attendance, and attendance-media datasets are not part of this Sheets projection.
Sheets data is a derived reporting copy; Company Hub's operational database remains authoritative. Synchronization uses durable events, idempotent updates, retry handling, and reconciliation to repair missed, duplicate, or stale reporting rows. Reporting rows are retained or removed in line with the source record and the organization's reporting requirements.
5. How information is used and disclosed
Information is used to authenticate users, provide workforce workflows, validate and review attendance, deliver approved reporting, maintain security, recover failed synchronization, and support the service.
Information may be available to authorized personnel of the participating organization and to infrastructure providers that process it to operate Company Hub, including Supabase, Vercel, and Google. Company Hub does not sell Google user data or use it for advertising, credit decisions, or unrelated profiling.
6. Google API Services User Data Policy
Company Hub's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google access is limited to the purposes described in this policy and is not transferred for advertising or sold to third parties.
7. Security and retention
Company Hub uses encrypted network connections, server-only provider credentials, authenticated routes, role and organization checks, database row-level security, private storage, and redacted provider errors. No internet service can guarantee absolute security.
Records are retained for the period needed to provide the service and meet the participating organization's operational, legal, audit, and retention obligations. The organization administering your account determines applicable workforce-record retention and authorized deletion.
8. Your choices and requests
To request access, correction, deletion, or information about records associated with your Company Hub account, contact the organization that provided the account or your Company Hub administrator. Requests are handled subject to applicable law and the organization's employment and records obligations. The operational Google account owner may revoke Google Drive access through their Google Account controls, although doing so will stop new Drive synchronization until access is restored.
9. Policy changes and contact
This policy may be updated when Company Hub's data practices or legal obligations change. The effective date above identifies the current version. Questions about this policy should be directed to your Company Hub administrator or the organization that provided your account.