noneship

Privacy Policy

Effective 14 August 2026

Overview

This Privacy Policy explains how Noneship processes personal data when your organization uses our human capital management (HCM) workspace.

For employment records (leave, payroll, expenses, performance, and similar workforce data), your organization is typically the data controller and Noneship acts as a processor providing the software platform.

This policy covers administrators, managers, and employees who sign in to a registered company workspace.

Data we process

Account and access data: full name, work email, password hash, organization membership, role (admin, manager, employee), invite status, and two-factor authentication (TOTP) enrollment when enabled.

Employment and workforce data entered by your organization: employee directory profiles, departments, locations, shifts, attendance clock events, leave balances and requests, comp-off requests, timesheet entries (projects, clients, tasks), expense claims, payroll period data and payslips, and performance review records.

Organization configuration: company profile, branding assets, module settings, email templates, and policy rules configured by administrators.

Technical and security data: sign-in and refresh sessions (including httpOnly authentication cookies), a first-party profile cookie used to restore UI context, security audit events visible to administrators, and standard request metadata such as IP address and browser type in server logs.

Mobile app: precise location when clocking in or out, photos or files you attach, optional Microsoft sign-in, and reverse geocoding via OpenStreetMap Nominatim for attendance place labels.

Mobile app

The Noneship mobile app requests foreground location permission only for attendance clock in and clock out.

Profile photos, expense receipts, and document uploads use your device photo library or file picker. Data is sent to your organization's Noneship workspace.

Optional Microsoft sign-in delegates authentication to Microsoft Entra when your organization enables it.

How we use data

We process data to authenticate users, enforce license and module access, operate licensed HR workflows, deliver email notifications configured by your organization, maintain security, and provide support when authorized.

We do not sell personal data. We do not use employment records for advertising or unrelated profiling.

Infrastructure providers that host or secure the service may process data solely to deliver the platform on our instructions.

Optional AI features

When an administrator enables AI writing assist, selected text may be sent to a third-party AI provider using API credentials your organization supplies.

AI provider credentials are encrypted in the browser before save and stored encrypted on the server. Keys are not displayed after save.

Your organization decides whether to enable AI features and is responsible for the provider's terms and data handling.

Cookies and sessions

Noneship uses an httpOnly refresh cookie managed by the authentication service to keep you signed in securely, and a first-party profile cookie to restore user context after reload.

Local browser storage may hold non-sensitive UI preferences such as theme color, module layout, and sidebar state.

You can sign out to end your session. Clearing browser cookies will require you to sign in again.

Security

We apply technical measures appropriate for a business HR platform, including authenticated API access, optional mandatory TOTP two-factor authentication for members, encrypted storage for AI credentials, and organization security audit logs.

If your organization approves vendor support access in Settings, support staff may access your tenant only for the approved period and scope.

Retention, export, and deletion

Data is retained while your organization maintains an active workspace and as required by applicable law or your organization's policies.

Organization owners may request a GDPR export from Settings and download it after approval while that approval remains valid.

Organization owners may also request tenant deletion through the product's deletion workflow, which requires confirming the organization slug.

Your choices and rights

Employees and managers should contact their employer for access, correction, or deletion of employment records held on their behalf.

Administrators can manage member access and organization profile data. Only the organization owner can request an organization export.

Depending on applicable law, you may have rights to access, correct, delete, or restrict processing of personal data. Contact your organization first for employment data; contact us for account or platform questions.

Changes and contact

We may update this Privacy Policy from time to time. The effective date at the top of this page will change when we do.

Privacy inquiries: support@noneship.com

Effective date: 14 August 2026