Last updated March 30, 2026
Privacy Policy
This Privacy Policy ("Policy") describes how StaffRecorder ("StaffRecorder," "we," "us," or "our") collects, uses, discloses, and protects information when you visit staffrecorder.com, use our web dashboard, install our desktop application, or otherwise interact with our services (collectively, the "Service").
By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree, do not use the Service. This Policy is incorporated into our Terms of Service.
1. Roles and scope
StaffRecorder is a business-to-business platform used by agencies and employers ("Customers") to manage teams and, where configured, record screen activity during scheduled shifts.
- Customer as controller.For employee and contractor data processed through a Customer's account — including shift schedules, attendance, and screen recordings — the Customer is typically the data controller and determines the lawful basis, purpose, and retention of processing.
- StaffRecorder as processor/service provider.We process such data on the Customer's instructions to provide the Service, secure the platform, and support account operations. We do not control how Customers use recordings or whether they have obtained required notices or consents.
- Direct relationship with StaffRecorder. For account registration, billing, support inquiries, and optional marketing communications with us, StaffRecorder may act as an independent controller.
Important:Screen recordings may contain sensitive personal, financial, health, or confidential business information visible on a user's screen. Customers are solely responsible for determining whether recording is appropriate and lawful for their use case.
Employees or contractors whose activity may be recorded should direct privacy requests to their employer or agency first. We may redirect or decline requests that should be handled by the Customer. We will assist Customers in responding where required by applicable law and our agreements with them.
2. Information we collect
2.1 Information you provide
- Account registration details (name, email, phone, organization name)
- Team member profiles, roles, and invitation data
- Shift schedules, attendance records, and agency settings
- Support messages, contact form submissions, and correspondence
- Billing and subscription information processed by our payment providers
2.2 Information collected automatically
- Device and browser type, operating system, IP address, and general location (city/region)
- Log data, authentication events, API usage, and error diagnostics
- Session metadata related to recordings (timestamps, duration, upload status, file size)
- Cookies and similar technologies necessary to operate the Service and maintain sessions
2.3 Screen recordings and desktop app data
When a user runs the StaffRecorder desktop application during an authorized shift, the Service may capture screen recordings and related metadata. Recordings may be stored in our infrastructure and/or uploaded to a Customer-connected Google Drive account according to the Customer's configuration.
We do not intentionally collect keystroke logging, microphone audio, or webcam video unless explicitly enabled by product features and disclosed to the Customer. Customers are responsible for configuring and using recording features lawfully.
3. How we use information
We use information to:
- Provide, maintain, and improve the Service
- Authenticate users and enforce role-based access controls
- Process subscriptions, invoices, and account administration
- Send transactional communications (invites, password resets, service notices)
- Monitor platform security, prevent abuse, and investigate incidents
- Comply with legal obligations and enforce our Terms of Service
- Analyze aggregated, de-identified usage trends to improve reliability and product design
We do not sell or rent personal information. We do not use Customer recording content for advertising, AI model training, or unrelated commercial purposes.
4. Legal bases (where applicable)
Where data protection laws require a legal basis, we rely on: (a) performance of a contract; (b) legitimate interests in operating, securing, and improving the Service; (c) compliance with legal obligations; and (d) consent where required.
5. How we share information
We may share information with:
- Service providers (hosting, authentication, email, payments) under confidentiality and data protection obligations
- Google, when a Customer connects Google Drive or uses Google sign-in
- Authorized users within the same agency, according to role permissions set by the Customer
- Professional advisers, regulators, or law enforcement when required by law or to protect rights, safety, and security
- Successors in a merger, acquisition, or asset sale, with notice where required by law
We are not responsible for how Customers, their staff, or third parties access, copy, share, or misuse recordings after delivery through the Service or Google Drive.
6. International transfers
We and our service providers may process information in the United States and other countries. Where required, we implement appropriate safeguards for cross-border transfers consistent with applicable law.
7. Data retention
We retain information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Recording retention depends on the Customer's plan, settings, and Google Drive configuration.
Upon verified deletion request or account closure, we will delete or anonymize information within a reasonable period, except where retention is required by law, security, or backup systems that purge on schedule.
8. Security
We implement measures designed to protect information, including encryption in transit, access controls, and agency-scoped isolation. No method of transmission or storage is completely secure. See our Security page. Security incidents are addressed under our Terms and applicable law; we disclaim liability beyond what is permitted in those Terms.
9. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing, and to data portability. Contact your employer or agency first for recording and employment-related data. Direct requests to StaffRecorder: info@staffrecorder.com.
We may verify identity, charge a reasonable fee where permitted, and deny manifestly unfounded or excessive requests. We do not discriminate against you for exercising privacy rights where prohibited by law.
California residents: We do not sell personal information as defined by the CCPA/CPRA. You may submit requests using the contact email above.
10. Children
The Service is not directed to individuals under 16. We do not knowingly collect personal information from children. Contact us to request deletion if you believe we have received such data.
11. Third-party services
Third-party services (such as Google) have their own privacy policies. We are not responsible for their practices or availability.
12. Limitation of liability
To the fullest extent permitted by law, StaffRecorder is not liable for unauthorized access, disclosure, or loss of information caused by Customer misconfiguration, weak credentials, third-party breaches, or events outside our reasonable control. Additional limits appear in our Terms of Service.
13. Changes to this Policy
We may update this Policy at any time. Material changes will be posted here with an updated date. Continued use after changes become effective constitutes acceptance.
14. Contact us
Privacy questions or requests: info@staffrecorder.com