18:30Legal

Privacy Policy

Effective: 1 September 2026

Last updated: 1 September 2026

This policy explains what personal information StaffVertex collects, why we collect it, who else sees it, how long we keep it, and what you can ask us to do with it. We have tried to write it plainly and to describe only what the product actually does.

StaffVertex is a service that businesses buy for their staff. That shapes almost everything below, so it is worth reading Our Role and Your Employer's before anything else.

1. Who We Are

StaffVertex is operated by Alphinex Solutions (Private) Limited, a private limited company incorporated in Pakistan under company registration number 0315829, registered with the Securities and Exchange Commission of Pakistan (SECP), with its registered office at Ali Arcade, 6th Road, Rawalpindi, Punjab, Pakistan.

In this policy, "StaffVertex", "we", "us" and "our" mean that company. The service covers our website, our web application, and our desktop apps for Windows and macOS. We do not currently publish a mobile app.

For anything about this policy or your personal information, write to privacy@staffvertex.com. We do not have a separate data protection officer; that mailbox is read by the people who run the service.

2. Our Role and Your Employer's

StaffVertex is sold to organizations. Almost always, the organization is your employer or client, and it decides what StaffVertex is used for.

  • Your organization decides. It chooses to use StaffVertex, decides which features are switched on, decides who can see what, and is responsible for telling you that it is tracking your work and for having a lawful reason to do so. In data protection terms it is the controller.
  • We follow those instructions. We host the data, keep it secure, and process it to run the service. In data protection terms we are the processor.

This matters in practice: if you are a member of an organization and you want your work records changed or deleted, your organization controls that, not us. Ask them first. We will still help. See Your Rights.

There is one exception. For our own website visitors, our own marketing emails, and our own billing relationship with the customer who pays us, we are the controller and we answer for those ourselves.

3. Information We Collect

a. Information you give us when you sign up

  • Your full name and email address.
  • Your password, stored only as a one-way hash. We never store it in a readable form and cannot recover it for you.
  • A profile photo, if you upload one, and your language and time zone preferences.
  • If you sign in with Google or a similar provider, the identifier that provider gives us. We do not receive your password.

b. Information you can add to your profile

These fields are optional and you fill them in yourself. They exist because organizations use StaffVertex for staff records as well as time tracking.

  • Date of birth and gender.
  • Home address, city, state or region, postal code and country.
  • A second email address and second phone number.
  • An emergency contact: their name, their relationship to you, and their phone number. This is information about someone else, so please only add it with that person's knowledge.
  • Education, qualifications, previous employment and skills.
  • Bank details: bank name, account number and account title. These are stored so that your organization's administrators can see them in order to pay you outside StaffVertex. We do not use your bank details for anything, and no payment is ever made through them by us.

c. Information your organization records about you

  • Your employee ID, job title, employment type, hire date, working days and hours, and whether you work on site, remotely or both.
  • Your role in the organization and what you are allowed to see.
  • Pay rates, pay cycle and currency, and the invoices, payroll records and payslips built from them.
  • Which projects, tasks and clients you are assigned to.

d. Work and time-tracking data

  • When you start and stop the timer, how long you worked, which project and task it was for, and any notes you add.
  • Time entries you add or edit by hand.
  • Whether a timesheet was approved or rejected, by whom, and any reason given.
  • Projects, tasks, comments, files and attachments you or your colleagues create.

e. Desktop app data

The desktop app can record screenshots, activity levels, the applications and websites you use, and idle time, but only while your timer is running, and only if your organization has switched those features on. Section 4 explains each one.

f. Technical information

  • Your IP address, browser, operating system, device details, language and time zone.
  • Records of your sign-in sessions, including the IP address they were created from, so you and your administrators can spot unfamiliar access.
  • Server logs and error diagnostics, including reports the desktop app sends when something fails.

g. Billing information

  • Your subscription plan, its status, billing dates, invoices and payment history.
  • We never see or store your card number. Card details go directly to Stripe, our payment processor. We receive only the result of a payment and the last few digits needed to show you which card was used.

h. Support and communications

  • Emails you send us, contact form submissions, support tickets and product feedback.
  • Conversations in the chat window on our public website and help centre, including the transcript, which is stored by our chat provider and by us.

i. Marketing preferences

  • Whether you have agreed to receive our marketing emails, when you agreed, how you agreed, and the IP address and browser you agreed from (so we can prove consent was given), along with any later withdrawal.

4. Desktop App Data

Our desktop app for Windows and macOS can capture additional information about your working session. Nothing in this section happens unless your timer is running and your organization's administrator has switched the feature on. Each one can be turned off independently.

Screenshots

If enabled, the app takes screenshots of your screen at an interval your organization chooses. Screenshots can optionally be blurred on your own machine before they leave it. They are compressed and uploaded straight to our storage provider, and linked to the time entry they belong to. Your organization's administrators and managers can view them.

Activity level

The app counts how many keyboard and mouse events occur each minute and turns that into an activity percentage. We do not record what you type. There is no keylogging. We do not store the keys pressed, the text entered, passwords, or where your mouse pointer was. We store only how many events happened.

Applications and window titles

If enabled, the app records which application is in the foreground and the title of that window, so your organization can categorise time. Window titles can contain the name of a document, a message or a page you have open, so this is a revealing setting.

Websites

If enabled, and when a browser is the active window, the app records the address of the tab you are viewing. We advise organizations to record only the site name rather than full addresses, and to tell their people clearly that it is switched on.

Idle time

The app notices when you stop using the keyboard and mouse for longer than a threshold your organization sets. Depending on that setting, the idle period is kept, discarded, or you are asked what to do with it.

Everything is written to an encrypted database on your own computer first and sent to us when you are online, so a dropped connection does not cost you your hours. You can stop the timer at any time, and you can uninstall the app at any time. Your sign-in token is held in your operating system's keychain, not in a file we leave lying about.

We strongly recommend that organizations tell their people in writing before switching any of this on, and obtain consent where the law where those people work requires it. That obligation is the organization's, not ours.

5. How We Use Your Information

We use it for these purposes and no others:

  • Run the service: sign you in, show your workspace, and keep it working.
  • Record time, calculate totals, and produce timesheets and reports for your organization.
  • Apply the settings your organization's administrator has chosen, including any monitoring features they have switched on.
  • Take payment for subscriptions, issue invoices, and prevent payment fraud.
  • Send you the emails the service needs to send: sign-in links, invitations, receipts, and security notices.
  • Answer your questions when you contact support or use the chat window.
  • Keep the service secure: detect abuse, enforce our Terms, and investigate incidents.
  • Fix problems and improve the product, using diagnostic logs and aggregate usage statistics.
  • Meet our legal, tax and accounting obligations.

We do not sell or rent your personal information. We do not share it with advertisers or ad networks. We do not use your content, screenshots or time records to train artificial intelligence models.

7. Sharing and Subprocessors

a. Inside your organization

Administrators, managers and colleagues with the right permissions can see your time entries, screenshots, activity levels, apps and websites, project assignments, and the staff and pay records your organization keeps about you. What each person can see is decided by your organization, not by us.

b. Companies that work for us

We use the following providers to run StaffVertex. Each handles data on our instructions under a contract, and each is listed with what it does and where it holds data.

ProviderWhat it doesWhere
StripePayment, subscription and invoice processingUnited States
MongoDB AtlasOur primary database, where your account and workspace data livesUnited States (Northern Virginia)
Cloudflare R2Storage for screenshots and uploaded files, and network protectionUnited States
VercelHosting for the web application, and request logsUnited States
ResendSending our emails (account, billing and product messages)United States
tawk.toThe live chat window on our public website and help centreUnited States
PostHogVisitor statistics on our public marketing site only, and only if you accept cookiesUnited States
Google reCAPTCHABlocking automated abuse of our sign-up and contact formsGlobal

This is the complete list. If we add a provider that handles personal information, we will update this page before or at the time it starts, and tell customers by email where the change is significant.

We do use artificial intelligence tools internally to help test the product. They run against our own test accounts. Customer data is not sent to them.

c. When the law requires it

We may disclose information if we are legally obliged to (for example under a court order or a valid request from an authority) or where we need to in order to protect the safety, rights or property of our users, the public or ourselves. Where we are allowed to tell you, we will.

d. If the business changes hands

If StaffVertex or Alphinex Solutions is sold, merged, or transfers its assets, customer data may transfer with the business. We will tell you before your information becomes subject to a different privacy policy.

8. Cookies and Analytics

We use a small number of cookies. The ones that keep you signed in and protect our forms are necessary and always on. The only optional ones are website statistics on our public marketing pages, and those are off until you press Accept on the banner. We do not use advertising cookies, retargeting pixels or cross-site tracking, and we run no analytics at all inside the signed-in application.

Our Cookie Policy lists every cookie, what it does, how long it lasts, and how to change your mind.

9. Marketing Email

We send product news and occasional promotional email, but only to people who have actively agreed to receive it. We never treat signing up, accepting an invitation or starting a trial as agreement, and the box is never ticked for you.

Every marketing email carries an unsubscribe link that works immediately and without signing in. You can also email privacy@staffvertex.com and we will remove you. Withdrawing always wins: once you unsubscribe we do not put you back on the list.

Emails the service has to send you (invitations, password resets, receipts, security alerts, and notices about your subscription) are not marketing and continue regardless, because they are part of providing the service.

We record whether our emails were delivered, bounced or were reported as spam, so that we can keep our sending reliable. We do not track whether you opened an email or clicked inside it.

10. Data Security

These are the measures we actually have in place:

  • All traffic between you and us is encrypted in transit using current TLS.
  • Data stored in our database and file storage is encrypted at rest by those providers.
  • Passwords are stored only as one-way hashes and are never recoverable.
  • The desktop app keeps its local database encrypted, with the key held in your operating system's keychain rather than on disk.
  • Every part of the application checks permissions before returning data, and organizations are separated from one another.
  • Sensitive administrative actions are recorded in an audit log.
  • Staff access is limited to those who need it to run and support the service.

To be straightforward with you: we do not hold a SOC 2 or ISO 27001 certificate, and we do not currently offer two-factor sign-in. Please use a strong, unique password. If you think someone has reached your account, write to security@staffvertex.com immediately.

You can read more about how we protect the service on our Security page.

11. How Long We Keep Data

We keep information for as long as it is needed for the purpose it was collected for, or as long as the law requires.

WhatHow long
Your account and workspace dataKept for as long as your organization's account is open.
Screenshots and activity recordsKept until your organization deletes them or closes the account. They are not deleted automatically on a timer.
Members and projects you deleteHidden from the app straight away, and permanently erased once the retention period set for your organization has passed.
Closed accountsRemoved from the app immediately, and permanently erased (including stored screenshots) within 30 days.
Database backupsKept for 8 days on a rolling basis, so deleted data disappears from backups within 8 days of being erased.
Billing and financial recordsKept for 6 years, because tax and accounting rules require it. This applies even after an account is closed.

Please read the screenshot line carefully. Screenshots and activity records are not deleted automatically after a set period. They stay until your organization removes them or closes the account. If your organization wants them cleared on a schedule, it should ask us and we will arrange it.

We may close and erase an account that has been unused for a long period. Where we do, we email the account owner first.

12. International Transfers

We are based in Pakistan and our customers are worldwide. The providers listed in Section 7 hold data mainly in the United States. So wherever you are, your information will be sent across borders: to Pakistan, where we operate, and to the United States, where it is stored.

Those countries may not give personal information the same legal protection as your own. We choose established providers that offer standard contractual protections for international transfers, and we apply the safeguards described in this policy to your information wherever it is held. If you need our transfer terms in writing for your own records, email privacy@staffvertex.com and we will provide them.

We have not appointed a representative in the European Union or the United Kingdom. If you are in either and want to raise something, contact us directly at the address above; we answer these ourselves.

13. Your Rights

Depending on where you live, you may have some or all of the rights below. We extend them to everyone, wherever you are, rather than only where a law forces us to.

  • Know and access: ask what information we hold about you and get a copy of it.
  • Correct: have inaccurate or incomplete information fixed.
  • Delete: ask us to erase your personal information.
  • Take it with you: receive your information in a structured, machine-readable format.
  • Restrict or object: ask us to pause or stop certain uses, including any direct marketing.
  • Withdraw consent: where we relied on consent, take it back at any time.
  • No penalty: we will not treat you worse for exercising any of these.
  • Complain: raise a concern with your local data protection authority.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing for you to opt out of on that front.

How to make a request

Email privacy@staffvertex.com from the address on your account and tell us what you want. We check who you are before acting, and we reply within 30 days. If your request is complicated we may need longer, and we will tell you within those 30 days if so. There is no charge.

There is no self-service export button in the app today. If you want a copy of your data, ask us and we will put it together for you.

If your account was created by an employer or client, most of your work records belong to them. Ask them first. They can act immediately, whereas we have to check with them before changing their records. We will always help you reach the right person.

14. Children's Privacy

StaffVertex is a tool for work and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has given us personal information, email privacy@staffvertex.com and we will delete it.

15. If Something Goes Wrong

If personal information is exposed or accessed without authority in a way that puts people at risk, we will notify the affected organizations without undue delay and, where we can, within 72 hours of establishing what happened. We will tell you what occurred, what information was involved, what it may mean for you, and what we are doing about it. Where the law requires us to notify an authority, we will.

If you find a security problem in StaffVertex, please tell us at security@staffvertex.com. We welcome the report and we will not pursue anyone who investigates in good faith and follows our Security page.

17. Billing and Refunds

Stripe processes payments for StaffVertex and we do not store card numbers. Billing and invoice records are kept for 6 years, as Section 11 sets out, because tax and accounting rules require it. This applies even after an account is closed.

Our refund terms, including what happens to your data when a refund is issued, are in the Refund Policy.

18. Changes to This Policy

We update this policy when the product or the law changes. If a change materially affects how we handle your information, we will email account owners at least 30 days before it takes effect and show a notice in the app. Smaller changes (clarifications, corrections, tidying) take effect when posted, and the date at the top of this page always shows the current version.

If you do not accept a change, you can stop using StaffVertex and ask us to delete your information before the change takes effect.

19. Contact Us

For any question about this policy or your personal information:

Company:Alphinex Solutions (Private) Limited
Address:Ali Arcade, 6th Road, Rawalpindi, Punjab, Pakistan