Privacy and Security
Explain self-hosted data, WordPress database storage, GPS/face data sensitivity, and admin responsibilities.
Self-hosted attendance data
WPChef Tracker stores attendance records in the WordPress database on the site where the plugin is installed. This supports the WPChef privacy message: your attendance operations remain under your own WordPress hosting and database control.
Data that may be stored
- Employee user ID and employee identifier.
- Clock in/out and break event times.
- Break notes, admin notes, HR/approval notes, and explanations.
- IP address, user agent, and device details.
- GPS coordinates, accuracy, address, and geofence result data when enabled.
- Mobile device/session details when the mobile app is enabled.
- Face profile, verification, liveness, match result, and selfie snapshot data when Pro face verification is enabled.
Admin responsibilities
Site owners are responsible for HTTPS, secure hosting, strong administrator passwords, least-privilege user roles, regular backups, employee privacy notices, data retention policies, and compliance with local employment/privacy laws.
External services
Google Maps services are used only when an administrator configures a Google Maps API key and uses map/address/GPS lookup features. Mobile license/agency sync connects to the WPChef Agency Connector for license and agency status; attendance records are not sent by the Free license sync.
